Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-28 03:43 UTC

CIRISAI / CIRISPersist

Unified Rust persistence for the CIRIS Trinity — signed events, time-series, runtime state. AGPL-3.0-or-later.

RustKeine Lizenz erkannt★ 0 Sterne⑂ 0 Forksseit Mai 2026Auf GitHub ansehen ↗

CIRISAI/CIRISPersist erreicht einen Gesundheitsindex von 53 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Engineering Quality (77/100) ab, am schwächsten bei Community & Adoption (12/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

53
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

53
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

CIRISAIOrganisation
20 Follower46 öffentliche Reposseit Apr. 2025

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
PyPIciris-persist21.10.0-332vor 0 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

74Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
9/36Commit-Rhythmus — 13/52 Wochen mit Commits
18/18Commit-Volumen — 846 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year846
human_commit_share1
days_since_last_push0
active_weeks_last_year13
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 100 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 0 Tagen
27/27Release-Rhythmus — ein Release etwa alle 0,3 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count100
latest_release_tagv21.11.0
releases_from_tagsnein
days_since_latest_release0
mean_days_between_releases0,3

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

12Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
0/22.5Lizenz — keine Lizenzdatei erkannt
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licensenein
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

58Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.1/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
2.7/13.5Breite der Beitragenden — 2 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled2
top_contributor_share0,995
Wie die Bewertung erfolgt
45.5/46.8Issue-Lösungsquote — 97 % der Issues geschlossen
37.8/38.3PR-Annahme — 177/179 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/9 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs177
open_issues9
closed_issues343
issue_closed_ratio0,974
closed_unmerged_prs2
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
9.5/25Reichweite des Inhabers — 20 Follower von CIRISAI
14.7/25Kontohistorie — 46 öffentliche Repos, Kontoalter ca. 1 Jahre
Verwendete Eingangsdaten
followers20
owner_typeOrganization
is_verified
owner_loginCIRISAI
public_repos46
account_age_days465

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf pypi
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 0 Tagen
20/20Versionshistorie — 332 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesciris-persist
ecosystemspypi
any_deprecatednein
min_days_since_publish0

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

77Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 3 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 9 out of 9 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

90Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://ciris.ai
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepagehttps://ciris.ai
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

31Gefährdet · 16 % des Gesamtindex

Sicherheitslage

31Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 9 out of 9 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/9 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Lizenz — license file not detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3,1

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

57Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 99 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,99
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — Cargo.toml (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Rust (statisch typisiert)
0/10Reproduzierbare Umgebung
10/10Belegte Agentenpraxis — 65 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfiles
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,65
toolchain_manifestsCargo.toml
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Rust (statisch typisiert)
50.7/55Handhabbare Dateigrößen — 26/335 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageRust
largest_source_bytes1.634.688
source_files_sampled335
oversized_source_files26

Eckdaten

0GitHub-Sterne
2Mitwirkende
846Commits, letzte 12 Monate
0Tage seit letztem Push
100Releases
1Bus-Faktor
9offene Issues
crates.io, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Could not fetch crates package 'ciris-persist' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index pypi:ciris-persist@21.10.0; advisories assessed against the repository dependency graph instead

Weitere Details

OpenSSF Scorecard 3.1 / 10
3.1Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 03:42 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests9 out of 9 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/9 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direkte Abhängigkeiten 50
RegistryPaketVersionsvorgabeManifest
crates.iociris-keyring10Cargo.toml
crates.iociris-verify-core10Cargo.toml
crates.iociris-crypto10Cargo.toml
crates.ioasync-trait0.1Cargo.toml
crates.iofs40.13Cargo.toml
crates.iolibc0.2Cargo.toml
crates.iobacktrace0.3Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.ioed25519-dalek2Cargo.toml
crates.iosha20.10Cargo.toml
crates.iozeroize1Cargo.toml
crates.iochrono0.4Cargo.toml
crates.iothiserror2Cargo.toml
crates.iotracing0.1Cargo.toml
crates.iobase640.22Cargo.toml
crates.iohex0.4Cargo.toml
crates.ioh3o0.7Cargo.toml
crates.iouuid1Cargo.toml
crates.iojsonschema0.46Cargo.toml
crates.iotokio-postgres0.7.18Cargo.toml
crates.iodeadpool-postgres0.14Cargo.toml
crates.iopostgres-types0.2.14Cargo.toml
crates.iorefinery0.9Cargo.toml
crates.iotokio-postgres-rustls0.13Cargo.toml
crates.iorustls0.23Cargo.toml
crates.iorustls-native-certs0.8Cargo.toml
crates.ioaxum0.8Cargo.toml
crates.iotower0.5Cargo.toml
crates.iohttp-body-util0.1Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.iourl2.5Cargo.toml
crates.iopyo30.29Cargo.toml
crates.ioregex1.10Cargo.toml
crates.ioanyhow1Cargo.toml
crates.iolog0.4Cargo.toml
crates.ioparking_lot0.12Cargo.toml
crates.iocandle-core0.10Cargo.toml
crates.iocandle-nn0.10Cargo.toml
crates.iocandle-transformers0.10Cargo.toml
crates.iotokenizers0.20Cargo.toml
crates.iohf-hub0.4Cargo.toml
crates.ioort=2.0.0-rc.10Cargo.toml
crates.iondarray0.16Cargo.toml
crates.iorusqlite0.31Cargo.toml
crates.ioredb4Cargo.toml
crates.iotokio1Cargo.toml
crates.iofutures-core0.3Cargo.toml
crates.iotokio-stream0.1Cargo.toml
PyPIciris-verify>=10.0.0,<11pyproject.toml
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 33293,
      "has_wiki": true,
      "homepage": "https://ciris.ai",
      "languages": {
        "Rust": 13172460,
        "Shell": 16277,
        "Python": 166778,
        "PLpgSQL": 82788
      },
      "pushed_at": "2026-07-28T03:27:41Z",
      "created_at": "2026-05-01T01:37:08Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-28T03:27:20Z",
      "description": "Unified Rust persistence for the CIRIS Trinity — signed events, time-series, runtime state. AGPL-3.0-or-later.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "ciris.ai",
      "name": null,
      "type": "Organization",
      "login": "CIRISAI",
      "company": null,
      "location": "United States of America",
      "followers": 20,
      "avatar_url": "https://avatars.githubusercontent.com/u/208221206?v=4",
      "created_at": "2025-04-19T01:47:21Z",
      "is_verified": null,
      "public_repos": 46,
      "account_age_days": 465
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v21.11.0",
          "kind": "minor",
          "published_at": "2026-07-28T03:38:52Z"
        },
        {
          "tag": "v21.10.0",
          "kind": "minor",
          "published_at": "2026-07-27T23:56:57Z"
        },
        {
          "tag": "v21.9.0",
          "kind": "minor",
          "published_at": "2026-07-27T20:21:03Z"
        },
        {
          "tag": "v21.8.0",
          "kind": "minor",
          "published_at": "2026-07-27T19:09:57Z"
        },
        {
          "tag": "v21.7.0",
          "kind": "minor",
          "published_at": "2026-07-27T17:17:39Z"
        },
        {
          "tag": "v21.6.0",
          "kind": "minor",
          "published_at": "2026-07-27T15:27:17Z"
        },
        {
          "tag": "v21.5.0",
          "kind": "minor",
          "published_at": "2026-07-27T05:41:07Z"
        },
        {
          "tag": "v21.4.0",
          "kind": "minor",
          "published_at": "2026-07-26T21:29:19Z"
        },
        {
          "tag": "v21.3.0",
          "kind": "minor",
          "published_at": "2026-07-26T17:18:52Z"
        },
        {
          "tag": "v21.2.0",
          "kind": "minor",
          "published_at": "2026-07-25T20:01:10Z"
        },
        {
          "tag": "v21.1.0",
          "kind": "minor",
          "published_at": "2026-07-25T00:40:45Z"
        },
        {
          "tag": "v21.0.0",
          "kind": "major",
          "published_at": "2026-07-24T22:40:08Z"
        },
        {
          "tag": "v20.1.0",
          "kind": "minor",
          "published_at": "2026-07-24T15:21:16Z"
        },
        {
          "tag": "v20.0.0",
          "kind": "major",
          "published_at": "2026-07-24T06:31:48Z"
        },
        {
          "tag": "v19.1.1",
          "kind": "patch",
          "published_at": "2026-07-23T17:01:49Z"
        },
        {
          "tag": "v19.1.0",
          "kind": "minor",
          "published_at": "2026-07-23T04:20:29Z"
        },
        {
          "tag": "v19.0.0",
          "kind": "major",
          "published_at": "2026-07-22T16:11:09Z"
        },
        {
          "tag": "v18.3.0",
          "kind": "minor",
          "published_at": "2026-07-21T08:57:26Z"
        },
        {
          "tag": "v18.2.0",
          "kind": "minor",
          "published_at": "2026-07-21T01:19:52Z"
        },
        {
          "tag": "v18.1.0",
          "kind": "minor",
          "published_at": "2026-07-20T19:42:27Z"
        },
        {
          "tag": "v18.0.0",
          "kind": "major",
          "published_at": "2026-07-20T18:44:08Z"
        },
        {
          "tag": "v17.9.0",
          "kind": "minor",
          "published_at": "2026-07-20T17:52:41Z"
        },
        {
          "tag": "v17.8.0",
          "kind": "minor",
          "published_at": "2026-07-16T16:50:50Z"
        },
        {
          "tag": "v17.7.0",
          "kind": "minor",
          "published_at": "2026-07-16T16:39:40Z"
        },
        {
          "tag": "v17.6.0",
          "kind": "minor",
          "published_at": "2026-07-16T13:50:39Z"
        },
        {
          "tag": "v17.5.2",
          "kind": "patch",
          "published_at": "2026-07-15T20:25:20Z"
        },
        {
          "tag": "v17.5.1",
          "kind": "patch",
          "published_at": "2026-07-15T18:22:58Z"
        },
        {
          "tag": "v17.5.0",
          "kind": "minor",
          "published_at": "2026-07-15T16:11:15Z"
        },
        {
          "tag": "v17.4.0",
          "kind": "minor",
          "published_at": "2026-07-15T14:15:53Z"
        },
        {
          "tag": "v17.3.0",
          "kind": "minor",
          "published_at": "2026-07-15T01:02:41Z"
        },
        {
          "tag": "v17.2.0",
          "kind": "minor",
          "published_at": "2026-07-14T17:54:55Z"
        },
        {
          "tag": "v17.1.0",
          "kind": "minor",
          "published_at": "2026-07-14T16:16:24Z"
        },
        {
          "tag": "v17.0.2",
          "kind": "patch",
          "published_at": "2026-07-14T13:26:30Z"
        },
        {
          "tag": "v17.0.1",
          "kind": "patch",
          "published_at": "2026-07-13T19:19:46Z"
        },
        {
          "tag": "v17.0.0",
          "kind": "major",
          "published_at": "2026-07-13T18:12:25Z"
        },
        {
          "tag": "v16.1.1",
          "kind": "patch",
          "published_at": "2026-07-13T01:38:34Z"
        },
        {
          "tag": "v16.1.0",
          "kind": "minor",
          "published_at": "2026-07-13T00:05:32Z"
        },
        {
          "tag": "v16.0.0",
          "kind": "major",
          "published_at": "2026-07-12T20:55:14Z"
        },
        {
          "tag": "v15.1.2",
          "kind": "patch",
          "published_at": "2026-07-12T18:12:34Z"
        },
        {
          "tag": "v15.1.1",
          "kind": "patch",
          "published_at": "2026-07-12T16:25:06Z"
        },
        {
          "tag": "v15.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T20:28:09Z"
        },
        {
          "tag": "v15.0.0",
          "kind": "major",
          "published_at": "2026-07-11T18:13:25Z"
        },
        {
          "tag": "v14.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T14:54:44Z"
        },
        {
          "tag": "v14.0.0",
          "kind": "major",
          "published_at": "2026-07-11T14:00:12Z"
        },
        {
          "tag": "v13.9.1",
          "kind": "patch",
          "published_at": "2026-07-10T22:01:55Z"
        },
        {
          "tag": "v13.9.0",
          "kind": "minor",
          "published_at": "2026-07-10T16:01:26Z"
        },
        {
          "tag": "v13.8.0",
          "kind": "minor",
          "published_at": "2026-07-10T08:08:01Z"
        },
        {
          "tag": "v13.7.0",
          "kind": "minor",
          "published_at": "2026-07-10T07:26:14Z"
        },
        {
          "tag": "v13.6.1",
          "kind": "patch",
          "published_at": "2026-07-10T05:02:28Z"
        },
        {
          "tag": "v13.6.0",
          "kind": "minor",
          "published_at": "2026-07-10T01:25:31Z"
        },
        {
          "tag": "v13.5.0",
          "kind": "minor",
          "published_at": "2026-07-09T18:14:38Z"
        },
        {
          "tag": "v13.4.2",
          "kind": "patch",
          "published_at": "2026-07-09T00:48:55Z"
        },
        {
          "tag": "v13.4.1",
          "kind": "patch",
          "published_at": "2026-07-08T17:02:24Z"
        },
        {
          "tag": "v13.4.0",
          "kind": "minor",
          "published_at": "2026-07-06T18:47:06Z"
        },
        {
          "tag": "v13.3.1",
          "kind": "patch",
          "published_at": "2026-07-06T05:26:35Z"
        },
        {
          "tag": "v13.3.0",
          "kind": "minor",
          "published_at": "2026-07-06T03:17:50Z"
        },
        {
          "tag": "v13.2.0",
          "kind": "minor",
          "published_at": "2026-07-05T19:12:01Z"
        },
        {
          "tag": "v13.1.0",
          "kind": "minor",
          "published_at": "2026-07-05T04:58:35Z"
        },
        {
          "tag": "v13.0.1",
          "kind": "patch",
          "published_at": "2026-07-04T21:30:49Z"
        },
        {
          "tag": "v13.0.0",
          "kind": "major",
          "published_at": "2026-07-04T17:36:14Z"
        },
        {
          "tag": "v12.6.0",
          "kind": "minor",
          "published_at": "2026-07-04T14:23:25Z"
        },
        {
          "tag": "v12.5.0",
          "kind": "minor",
          "published_at": "2026-07-04T04:12:27Z"
        },
        {
          "tag": "v12.4.0",
          "kind": "minor",
          "published_at": "2026-07-04T02:13:30Z"
        },
        {
          "tag": "v12.3.0",
          "kind": "minor",
          "published_at": "2026-07-04T00:35:37Z"
        },
        {
          "tag": "v12.2.0",
          "kind": "minor",
          "published_at": "2026-07-03T19:22:26Z"
        },
        {
          "tag": "v12.1.0",
          "kind": "minor",
          "published_at": "2026-07-03T15:49:46Z"
        },
        {
          "tag": "v12.0.2",
          "kind": "patch",
          "published_at": "2026-07-03T04:14:02Z"
        },
        {
          "tag": "v12.0.1",
          "kind": "patch",
          "published_at": "2026-07-03T01:33:25Z"
        },
        {
          "tag": "v12.0.0",
          "kind": "major",
          "published_at": "2026-07-02T22:43:28Z"
        },
        {
          "tag": "v11.9.1",
          "kind": "patch",
          "published_at": "2026-07-02T02:59:56Z"
        },
        {
          "tag": "v11.9.0",
          "kind": "minor",
          "published_at": "2026-07-02T01:45:42Z"
        },
        {
          "tag": "v11.8.2",
          "kind": "patch",
          "published_at": "2026-07-01T23:37:38Z"
        },
        {
          "tag": "v11.8.1",
          "kind": "patch",
          "published_at": "2026-07-01T22:42:27Z"
        },
        {
          "tag": "v11.8.0",
          "kind": "minor",
          "published_at": "2026-07-01T21:40:50Z"
        },
        {
          "tag": "v11.7.0",
          "kind": "minor",
          "published_at": "2026-07-01T21:00:21Z"
        },
        {
          "tag": "v11.6.1",
          "kind": "patch",
          "published_at": "2026-07-01T20:19:16Z"
        },
        {
          "tag": "v11.6.0",
          "kind": "minor",
          "published_at": "2026-07-01T18:59:45Z"
        },
        {
          "tag": "v11.5.0",
          "kind": "minor",
          "published_at": "2026-06-28T00:40:04Z"
        },
        {
          "tag": "v11.4.0",
          "kind": "minor",
          "published_at": "2026-06-27T23:54:36Z"
        },
        {
          "tag": "v11.3.0",
          "kind": "minor",
          "published_at": "2026-06-27T22:34:42Z"
        },
        {
          "tag": "v11.2.0",
          "kind": "minor",
          "published_at": "2026-06-27T04:05:13Z"
        },
        {
          "tag": "v11.1.0",
          "kind": "minor",
          "published_at": "2026-06-27T03:27:13Z"
        },
        {
          "tag": "v11.0.1",
          "kind": "patch",
          "published_at": "2026-06-27T01:29:04Z"
        },
        {
          "tag": "v11.0.0",
          "kind": "major",
          "published_at": "2026-06-26T21:45:06Z"
        },
        {
          "tag": "v10.7.0",
          "kind": "minor",
          "published_at": "2026-06-26T21:09:09Z"
        },
        {
          "tag": "v10.6.0",
          "kind": "minor",
          "published_at": "2026-06-26T16:07:17Z"
        },
        {
          "tag": "v10.5.0",
          "kind": "minor",
          "published_at": "2026-06-26T00:56:43Z"
        },
        {
          "tag": "v10.4.0",
          "kind": "minor",
          "published_at": "2026-06-25T20:53:13Z"
        },
        {
          "tag": "v10.3.0",
          "kind": "minor",
          "published_at": "2026-06-25T20:15:23Z"
        },
        {
          "tag": "v10.2.2",
          "kind": "patch",
          "published_at": "2026-06-25T18:56:07Z"
        },
        {
          "tag": "v10.2.1",
          "kind": "patch",
          "published_at": "2026-06-25T15:08:31Z"
        },
        {
          "tag": "v10.2.0",
          "kind": "minor",
          "published_at": "2026-06-25T02:42:17Z"
        },
        {
          "tag": "v10.1.2",
          "kind": "patch",
          "published_at": "2026-06-24T23:06:05Z"
        },
        {
          "tag": "v10.1.1",
          "kind": "patch",
          "published_at": "2026-06-24T18:11:39Z"
        },
        {
          "tag": "v10.1.0",
          "kind": "minor",
          "published_at": "2026-06-24T16:50:54Z"
        },
        {
          "tag": "v10.0.2",
          "kind": "patch",
          "published_at": "2026-06-24T16:22:59Z"
        },
        {
          "tag": "v10.0.1",
          "kind": "patch",
          "published_at": "2026-06-24T14:41:27Z"
        },
        {
          "tag": "v10.0.0",
          "kind": "major",
          "published_at": "2026-06-23T22:46:11Z"
        },
        {
          "tag": "v9.11.0",
          "kind": "minor",
          "published_at": "2026-06-23T16:11:04Z"
        },
        {
          "tag": "v9.10.2",
          "kind": "patch",
          "published_at": "2026-06-23T02:16:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "f7e63e0655493943f4ae6c39f5dbb6630661148e",
          "body": "v21.12.0 — #530 repair sweep for stranded (self|family, federation) rows.",
          "is_bot": false,
          "headline": "Merge pull request #531 from CIRISAI/feat-530-repair-sweep",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T03:27:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcb4bcaadd6b4b72f38677028f99499f19d11912",
          "body": "…ration) rows\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.12.0 — #530 repair sweep for stranded (self|family, fede…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T02:56:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "865aaa513cb4f5fe951e62447505f43301524d2b",
          "body": "promote_consented_backlog's page source is WHERE tier='local', so the\nself-limiting property that makes it safe to call unconditionally (a promoted\nrow leaves the local tier and is never revisited) is EXACTLY what makes it\nunable to repair a row that already reached (cohort_scope=self, tier=federati\n[…]\nlivery_status\nARMED-BUT-STRANDED hint is the detector this fix answers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#530): repair sweep for stranded (self|family, federation) rows",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T02:56:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fe455a9024ea1f1752da7d759936d0130760bdb2",
          "body": "v21.11.0 — authority/fail-open hardening (#527/#517/#528/#518).",
          "is_bot": false,
          "headline": "Merge pull request #529 from CIRISAI/feat-v2111-authority-failopen",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T02:54:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cc3e4c44ff87e46cdbee9dcdafd78a6b2e6ff7f",
          "body": "pg_moderation_scores_full_matrix encoded the same pre-#517 vulnerable behavior\nas the memory twins (as-self subject and subject-delegated admitted). Missed in\nthe first pass because the combined sqlite-side run SKIPS pg tests when\nCIRIS_PERSIST_TEST_PG_URL is unset — only the pg-serial run (with the\n[…]\ntion unaffected). Caught by a cautious solo pg-serial run before\nmerge.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "fix(#517): re-root the postgres moderation matrix twin too",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T02:15:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "023c6b56d94f2b627dff33fa4af691e676b74e96",
          "body": "… #528 + #518)",
          "is_bot": false,
          "headline": "release: v21.11.0 — authority/fail-open hardening pass (#527 + #517 +…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T02:01:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3af2e9edc452a1387fcb610a213dfc8945d3aabc",
          "body": "refresh_factor_rollup's csdma/idma_k_eff/idma_correlation_risk\n{m}_sum/{m}_n columns disagreed across backends: Postgres pooled ROWS\n(SUM/COUNT directly over trace_events), while SQLite already collapsed\nto a per-trace average first (two-level WITH per_trace AS (...)). They\ndiverge whenever a trace \n[…]\nd unmodified throughout (SQLite was never the buggy side).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01L5bfwC99EGsUmB6Kg3tV2s",
          "is_bot": false,
          "headline": "fix: #518 — trace-weighted capacity rollup value-means, both backends",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T01:59:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a55bd50467e884b47969364f4be5448674d1d074",
          "body": "… CIRISServer v21.10.0 adoption)\n\n#527 — EmitAttestationInput::with_envelope no longer fail-OPENs the recipient\naxis: cohort_scope is a REQUIRED argument (the compiler forces every producer to\nstate it, matching attestation_promote(id, cohort_scope)); the write-path default\n(the read-path back-compa\n[…]\ne-side 1744/0.\n#518 (rollup parity) bundles into the same v21.11.0 cut.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "fix(#527/#517/#528): the authority/fail-open hardening pass (found in…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-28T01:45:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf345df1a19e58a717bccbe6655e7a7e1caef6d3",
          "body": "v21.10.0 — #519 NOfM tally (b2) + persist evidence rows (b5); persist's #519 half complete.",
          "is_bot": false,
          "headline": "Merge pull request #526 from CIRISAI/feat-519-final-cut",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T23:40:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c235213ae598c02324e3f479aa89b17f9913614",
          "body": "… evidence-registry rows (b5) — persist's #519 half complete\n\nb2 — SignerForm::NOfMCosigned is now a real m-of-n tally (was 1-of-1). The\nprimary attester counts as one signer; the co-signer set rides the touch\nenvelope's extra under freshness::TOUCH_COSIGNATURES_FIELD (a JCS\nThresholdSignature array\n[…]\nngs shapes, CI-exact clippy, fmt, sqlite-side 1741/0, pg serial\n1192/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.10.0 — #519: NOfMCosigned freshness tally (b2) + persist…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T23:13:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "890f2508e7963e65ed335c753b00e00cf6eb6770",
          "body": "v21.9.0 — #519 item 2: delivery_mode/deletion_window typed + deletion_window lifecycle processor.",
          "is_bot": false,
          "headline": "Merge pull request #525 from CIRISAI/feat-519-field-hoist",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T19:59:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a574d77f03ef4d876cd46a0445469edd01c9584b",
          "body": "… to typed EnvelopeCore fields + the deletion_window lifecycle processor\n\nField-hoist (byte-invariant): delivery_mode + deletion_window move from untyped\n`extra` cargo to typed Option<String> EnvelopeCore fields with\npaths::DELIVERY_MODE / DELETION_WINDOW constants. skip_serializing_if under the\nsam\n[…]\nngs shapes, CI-exact clippy, fmt, sqlite-side 1737/0, pg serial\n1189/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.9.0 — #519 item 2: hoist delivery_mode + deletion_window…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T19:18:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6be1e98123b54bdb1e8dba22973a8668bdf174e",
          "body": "v21.8.0 — #519 ownerless-lock reclaim (CC 3.2 MUST), activated with a conservative accord-quorum default. CIRISConstitution#43.",
          "is_bot": false,
          "headline": "Merge pull request #524 from CIRISAI/feat-519-b1-reclaim",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T18:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a7acd6e8d6ecdfa739812c60e89ca694626d1c7",
          "body": "…ED with a conservative accord-quorum default\n\nfederation::ownership_reclaim: the sanctioned exception to CC 2.4.1.1 that\ncloses the CC 3.2 \"no permanent ownerless lock\" MUST — a third-party withdraws\nagainst a live owner-binding is admitted IFF the incumbent is provably-abandoned\nAND a verified m-o\n[…]\nngs shapes, CI-exact clippy, fmt, sqlite-side 1731/0, pg serial\n1183/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.8.0 — #519 ownerless-lock reclaim (CC 3.2 MUST), ACTIVAT…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T18:14:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9023e47bc45c97d373c5e6892c1386343d210c70",
          "body": "…D for postgres\n\nThe postgres backend's federation_attestations.attestation_id column is\n::uuid-typed; sqlite's laxer TEXT column silently accepted the\nhuman-readable tag strings (e.g. \"recl-binding-sq\") the fixtures used, so\nthe sqlite run passed while the postgres companion test\n(ownership_reclaim\n[…]\natures \"postgres server pyo3\nsqlite cirisaudit secrets cirisnode cirisgraph telemetry\" -- -D\nwarnings; cargo fmt --all. All green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(#519): ownership_reclaim witnesses — attestation_id must be a UUI…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T17:33:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "657a263689ded7ca4e260ad721d5f190e3a4b711",
          "body": "…ipped inert\n\nCC 3.2 \"No permanent ownerless lock (MUST)\" has no wire path today: a\nthird-party withdraws against a live owner-binding is (correctly) refused\nby the CEG §3.2.3 4-rule gate, but if the owner dies or loses custody the\nbinding never withdraws and the node is locked forever.\n\nAdd the mec\n[…]\nargets --features \"postgres server pyo3 sqlite cirisaudit secrets\ncirisnode cirisgraph telemetry\" -- -D warnings; cargo fmt --all.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#519): ownership:* ownerless-lock reclaim MECHANISM (CC 3.2), sh…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T17:33:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a11bc161c6dbcab0d0e14a9ed5f33fb8bac0fad7",
          "body": "v21.7.0 — #519 wave 1: invariant-registry admission (item 3) + transform-serve generalization (2a-ii) + field-conformance FFI (CIRISConformance#83).",
          "is_bot": false,
          "headline": "Merge pull request #523 from CIRISAI/feat-519-wave1",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T17:01:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "981b357a8fcc8fddde8048ac4a909b7dde82081d",
          "body": "… + transform-serve generalization (2a-ii) + field-conformance FFI\n\nfederation::invariant: a typed reader over the vendored invariant_registry (571\ninvariants / 104 families) + admission enforcement of the persist-ownable\nsubset, wired at check_reserved_prefix_admission. Load-bearing:\nmanifest_reser\n[…]\nngs shapes, CI-exact clippy, fmt, sqlite-side 1723/0, pg serial\n1181/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.7.0 — #519 wave 1: invariant-registry admission (item 3)…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T15:58:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b947e55c5816fdfe04fc191d9111b7d4c53d3b8",
          "body": "…ency witness\n\nAdds federation::invariant: a typed reader over the vendored\ninvariant_registry (571 constitutional invariants / 104 CC-3.1 families),\na heuristic admission_enforceable() classifier, and the load-bearing\nconsistency witness that EXECUTES persist's real check_reserved_prefix_admission\n\n[…]\n::DimensionRejected with a new reason token rather than a new Error\nvariant, so the exhaustive pyo3.rs FFI match needs no change).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#519 item 3): invariant-registry admission enforcement + consist…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T15:30:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "245351c4c20125d66309ed88580fc18175b8a3b2",
          "body": "…e via PyO3\n\nThree module-level pyfunctions so a shared CIRISConformance harness can drive\nthe REAL persist wheel against the fields persist is tagged to own in the\nfield_processor_matrix (the \"same table generates every processor's tests\"\npattern):\n- persist_field_conformance() -> [str]  (violation\n[…]\n\n- transform_algebra_hash() -> str        (cross-check the algebra cut)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#519 / CIRISConformance#83): expose the field-conformance surfac…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T15:13:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "302aa3d6c62eeb67a3ae10245b60e301dd79d146",
          "body": "…clared transform pipeline\n\nThe consent-grammar promotion path (Engine::promote_attestation_with_strips)\napplied only StripField restrictions via a bespoke loop. Single-source that\nthrough the v21.6.0 transform algebra instead:\n\n- consent_grammar::to_transform_ops(&[RestrictionOp]) -> Vec<TransformO\n[…]\n\nthe promoted envelope equals TransformPipeline::apply_all's own output —\nstrip is routed through the algebra, not a bespoke loop.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#519 item 2a-ii): generalize promotion from strip-only to the de…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T15:08:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4f6c49c5df2e0a5629b1259a518340d310c0fae2",
          "body": "v21.6.0 — transform algebra (#519 2a-ii) + fresh_as_of floor (#519 2a-iii) + manifest-driven proptests + the conformance exemplar. Harness adoption CIRISConformance#83.",
          "is_bot": false,
          "headline": "Merge pull request #522 from CIRISAI/feat-519-transform-freshness",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T15:08:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06b2e603c8765617ee46a53ebb3f40029ccc16b9",
          "body": "…r (federation::namespace::conformance)\n\nThe pattern crystallized: the SAME vendored field_processor_matrix that declares\nWHO processes each field also GENERATES the property tests that owner must pass.\nPersist's reference implementation, over the fields it owns a behaviour for:\ncohort_scope (closed\n[…]\nors this exemplar as canonical and persist\nre-adopts the vendored form.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#519): manifest-driven field conformance — the reference exempla…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T14:29:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69612ff5bcb9f5b80f6520c54841b301a2fba78d",
          "body": "…lgebra + freshness floor\n\nThe vendored manifest DECLARES properties; these proptests VERIFY them as law\nrather than on samples — the manifest is the test oracle.\n\n- transform: the opcode table (namespace_supersets field_transforms.opcodes,\n  1:1-checked against Rust OPCODES) drives a totality fuzz \n[…]\ned there. These in-crate proptests test persist's own algebra\ndirectly.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "test(#519): manifest-declaration-driven proptests for the transform a…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T14:22:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8f1335db540ab75b1ce06c2127f0edcb31a7052",
          "body": "… fresh_as_of freshness floor (#519 item 2a-iii)\n\nTwo #519 persist-half subsystems on the v21.5.0 vendored manifest.\n\nfederation::transform (2a-ii): a closed, STRICTLY TOTAL algebra for what a\nplacement field becomes on the wire. TransformOp is a deny_unknown_fields\ntagged enum; apply is an exhausti\n[…]\npy, fmt; sqlite+pg suites green\nper-module (full combined suite in CI).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.6.0 — total transform algebra (#519 item 2a-ii) + signed…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T14:07:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "332b08341106fe48bb7cbe5502f863f8e8e30536",
          "body": "…st half)\n\nAdds the storage + monotonic-max merge + admission half of the signed\ntemporal LOWER bound `namespace_supersets.json` names `freshness_floor` —\nthe dual of the existing upper bounds (valid_until / expires_at /\ndeletion_window). Producer surface (edge/agent deciding when/how to touch\neach \n[…]\ner envelope\nto tally a real m-of-n quorum over. Flagged as a follow-up in\nverify_signed_touch_claim's doc comment, not built here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#519 item 2a-iii): the signed fresh_as_of freshness floor (persi…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T13:56:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cde0774a3139bae5d5a972dc047050da8ecb59f4",
          "body": "Closed, exhaustively-matched TransformOp opcode set (truncate/prefix/\nsuffix/bucket/round/concat/redact/strip_field/salted_hash/commit/\nnullifier/bbs_derive/gte/lt/in_range) mirroring namespace_supersets.json's\nfield_transforms manifest: named opcodes, fixed arity, no loops/recursion/\nuser-defined f\n[…]\ncirisaudit\nsecrets cirisnode cirisgraph telemetry\" -- -D warnings (clean); cargo fmt\n--all. No version bump / CHANGELOG per scope.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#519 2a-ii): the total (terminating) transform algebra",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T13:49:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3287edc1c25a169b01e68a28269a1f2465890622",
          "body": "v21.5.0 — namespace manifest as Registry-of-Record + complete the promotion primitive (#519 foundation). Follow-up phases tracked in #520.",
          "is_bot": false,
          "headline": "Merge pull request #521 from CIRISAI/feat-519-namespace-manifest-record",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T05:18:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca60500916e4c032fa69a600db494ef1820cbed0",
          "body": "…e the promotion primitive (#519 foundation)\n\n#519 (\"the namespace manifest IS the logic\") is a multi-cut epic; this lands\nthe self-contained foundation.\n\nThe empirically-settled defect (item 4 / the CIRISServer#315 dead-plane):\nEngine::attestation_promote flipped tier local->federation and re-signe\n[…]\nngs shapes, CI-exact clippy, fmt, sqlite-side 1655/0, pg\nserial 1120/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.5.0 — namespace manifest as Registry-of-Record + complet…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-27T04:21:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1b7a967d00e016a92c5203b0e9e38c7c1f834562",
          "body": "v21.4.0 — signed wins the shared key (#515) + hardware-free mesh simulation (verify v10.6.3, the #219→#221 arc complete). Sim guides: CIRISServer#321 / CIRISAgent#930.",
          "is_bot": false,
          "headline": "Merge pull request #516 from CIRISAI/fix-515-signed-wins-shared-key",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-26T21:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5c8655684d56833b94aa2039e9ddaad0d5ee928",
          "body": "…#221)\n\nRe-pin all six verify crates v10.6.2 → v10.6.3: MockAttestedMember now\ncarries the deterministic hybrid .holder signer, closing the one gap in\nthe mock-custody arc. New witness mock_full_quorum_mints_canonical_513:\nthree fabricated FIPS members co-scrub a NEW canonical (bound-hybrid\nscrubs o\n[…]\n: shapes + CI-exact clippy clean, sqlite-side 1651/0, pg serial 1117/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#513): verify v10.6.3 — the FULL hardware-free mint (CIRISVerify…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-26T20:38:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "549482724fe7d8f9a9dbbad57d58c2bc8eb6b062",
          "body": "…esh simulation (verify v10.6.2)\n\n#515: on the shared (occurrence_key_id, transport_kind) route key, an\nUNSIGNED writer (occurrence projection / edge announce) could NULL the\nadmitted signed row's signature by landing last with the freshest\nasserted_at, and the signed producer could never reclaim (c\n[…]\n sim shape, CI-exact clippy,\nfmt, sqlite-side 1650/0, pg serial 1116/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.4.0 — signed wins the shared key (#515) + mock-custody m…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-26T19:59:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1bd0b52dce52fa72e95bef3d86c96298c8faada",
          "body": "…ng-dyn\n\nv21.3.0 — route-encoding fix (#512) + dyn rooting (#508) + hardware anti-Sybil floor on trust-root minting (#513). CIRISVerify#219 filed for mock test support.",
          "is_bot": false,
          "headline": "Merge pull request #514 from CIRISAI/fix-512-508-route-encoding-rooti…",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-26T17:00:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "556736a74a1b973fa559ac7ece9032e7aaba9953",
          "body": "…ardware anti-Sybil floor (#513)\n\n#512: project_route normalizes the projected transport_destinations.destination\nto canonical lowercase hex (was: envelope base64 verbatim — the #393 item-2\nhex probe could never match an occurrence-projected route; one column, two\ndialects, live-diagnosed on the can\n[…]\nngs shapes, CI-exact clippy, fmt, sqlite-side 1647/0,\npg serial 1114/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.3.0 — route-encoding fix (#512) + dyn rooting (#508) + h…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-26T16:22:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30ff9ad0d172e8ea1bb557164ef0dfcb2151fcf3",
          "body": "v21.2.0 — consent-edge payload promotion (#509) + closed consent grammar (#510 P1) + hot-path serve reads (#507). Edge adoption: CIRISEdge#397.",
          "is_bot": false,
          "headline": "Merge pull request #511 from CIRISAI/feat-509-consent-follows-edge",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-25T19:47:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4f1d93132be8953592cebb2b07b525867e053e3",
          "body": "… #509 × #510)\n\nThe two cross-workstream catches from assembly review:\n\n1. Visibility cursor (#507 × #509): list_attestations_since cursors on\n   COALESCE(promoted_at, asserted_at) — a consent-promoted row becomes\n   wire-visible at promoted_at, so an asserted_at-only cursor would hide\n   late promo\n[…]\nxact clippy, fmt, full\nsqlite-side suite 1640/0, full pg serial 1108/0.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "release: v21.2.0 — consent-edge integration fixes + CHANGELOG (#507 ×…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-25T19:04:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6dcf35f492e04e5cc017be85c0af14808e1ed0b3",
          "body": "(c) Adds list_signed_{key_records,identity_occurrences,transport_\ndestinations,identity_occurrence_revocations}_since + list_attestations_\nsince -- the signed-wrapper bulk-read mirror of the #504 E4 keyless-plane\npattern, extended to the 5 PRIMARY signed planes, so the edge advertise/\nserve responde\n[…]\n the wire-index write hooks and\nreload dispatcher follow suit per kind.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#507): content-hash point-read + primary-plane signed-since reads",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-25T18:40:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d639546cb666947dc1d3e016c04370b23ee10012",
          "body": "…gate, strip_field promotion\n\nBuilds on the #509 FLOOR (payload-follows-consent-edge sweep). Extends\nsrc/federation/consent_grammar.rs from the raw attestation_prefixes seed\ninto the full closed consent-transfer grammar:\n\n- Direction/TransmissionPrinciple/RestrictionOp/Transferability: closed\n  enum\n[…]\nerified against a scratch\ndatabase on the same server, then dropped it).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#510 P1): the closed consent grammar — typed payload, admission …",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-25T18:38:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6de7ff64bb3c060e72f851dfa10632f4666e6b7d",
          "body": "…ote + emit/ingest chokepoints\n\nAdds promote_consented_backlog(), the single idempotent engine sweep that\npromotes local-tier attestations to federation tier once a live\nself-authored consent:replication:v1 grant's attestation_prefixes cover\ntheir dimension:\n\n- src/federation/consent_grammar.rs (new\n[…]\n::\n  exercise_509_backend_methods) run against both sqlite and postgres.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#509 FLOOR): payload-follows-consent-edge sweep — seal-time prom…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-25T17:38:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d394fb693444a53deeb2ce6e99212122146ac40a",
          "body": "v21.1.0 — signed since-cursor reads for the 5 keyless planes (#504 FLOOR); unblocks edge v14. Fast-follow tracked in #506.",
          "is_bot": false,
          "headline": "Merge pull request #505 from CIRISAI/feat-504-signed-keyless-reads",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-25T00:22:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b24ece2ac6b9a8410977ce2fb386ee2e7439e4c2",
          "body": "…-declaration planes\n\nAdds list_signed_{families,communities,location_proofs,family_membership_\nrevocations,community_membership_revocations}_since — the signed-wrapper\nbulk-read mirror of the org-trio's list_organizations_since, so the edge\nadvertise/serve responder can re-serve byte-exact what per\n[…]\nErr arm is the intended\nearly-return shape for an HTTP handler helper).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01LGCuW7wfXPdkHt3CPLYkTP",
          "is_bot": false,
          "headline": "feat(#504 FLOOR): 5 signed-since-cursor bulk reads for the E4 keyless…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T23:49:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d994ee11e594fb1d9447cc570b9b67116b975c5b",
          "body": "release: v21.0.0 — the Registry-of-Record: replication admission is mechanistically CEG-driven (#501/#502)",
          "is_bot": false,
          "headline": "Merge pull request #503 from CIRISAI/feat-501-502-trace-ship-tier",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T22:24:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b4af7f6bb6db1f9a14898af858d2f24419f8dcd",
          "body": "…no-backend -D warnings)\n\nexercise_consent_peer_set_fold + its grant/withdraws helpers are consumed\nonly by the sqlite/postgres parity tests; under `cargo test --features\nserver` (no backend, the darwin-aarch64 leg) they're dead code, and CI's\nRUSTFLAGS=-D warnings makes dead_code an error. Gate the module on\nany(feature=sqlite, postgres). Verified all 4 feature shapes clean under\n-D warnings locally (the gate my earlier --no-run missed).",
          "is_bot": false,
          "headline": "fix(ci): gate E7 consent_peer_set test_support on a backend feature (…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T21:57:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d2e5344ce8c7ff22fdf35e60674a34a2278f28c",
          "body": "…nd build)\n\nreplicated_trace_attestation_materializes_scorer_corpus_501 uses\nSqliteBackend for node_b; the darwin-aarch64 (no postgres) leg runs\n`cargo test --features server` with NO backend. Gate the witness on\nfeature=\"sqlite\" (the projection logic it proves is backend-generic;\nthe sqlite+pg paths are covered on the backend legs).",
          "is_bot": false,
          "headline": "fix(ci): gate the #501 corpus witness on the sqlite feature (no-backe…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T21:37:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fd31f2da9a75375bfb309fa6f68df3b04fde082",
          "body": "…echanistically CEG-driven (#501/#502)\n\nCloses the full CEG→replication audit. State changes only via a\nhybrid-Strict-verified claim by a signer resolved against our OWN\nregistered directory — never sender-supplied material, a stored flag, a\ncaller-passed roster, or bare FK existence.\n\nSpine: KindPo\n[…]\n CIRISServer#319.\nFull lib suite 1577/1577 serial with pg.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v21.0.0 — the Registry-of-Record: replication admission is m…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T21:05:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "facf2fb2b83817a1250a35aeebf8228c5febef9f",
          "body": "…durable self-verification\n\nE4 verified-then-discarded the authority sig; now V110 adds nullable\nauthority_key_id + scrub_signature_classical/pqc columns to all 5 keyless-\nplane tables, stored on every put_family/community/membership_revocation/\nlocation_proof (family plane UPDATEs post-insert since\n[…]\nmns persisted for the future serve\npath. Witness: e4_authority_signature_persists_502_followup (memory +\nsqlite direct read-back).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(#502 E4 followup / #6): persist the authority signature (V110) — …",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T20:59:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "168bac6f990ab3d243c3b75693b87bb303c1993c",
          "body": "…ign when unsigned\n\nThe E4 admission now requires an authority signature on family/community\nrecords. The put_*_json wheel verbs are the LOCAL create-my-{family,\ncommunity} API (not a wire path) — the node IS the authority for a group\nit creates, so when the caller supplies no authority signature th\n[…]\n-sign put → lookup). test_put_\ncommunity_json_round_trip_290 passes unchanged (its unsigned payload now\ntakes the self-sign path).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(#502 E4 followup / #7): put_family_json/put_community_json self-s…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T20:40:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d52d4e25a14ef13b03297518501fc54fd240b898",
          "body": "… (cherry-picked)\n\nAll 5 keyless Signed* wrappers (Family/Community/membership-revocations/\nLocationProof) gain authority_key_id + hybrid scrub sig, verified at\nadmission (verify_*_admission, fail-closed, all 3 backends) vs the\nauthority's REGISTERED key — was FK-only, a forgeable keyless declaratio\n[…]\n). ~90 fixtures\nupgraded; 5 forgery witnesses. Assembled six-edge object (E1/E2/E4/E5/E7/\nE9 + #501 + spine): 1574/1574 pg serial.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge(#502 E4): keyless-declaration planes get an authority signature…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T20:29:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5286bf84090f5fb3af17b9bd2a3338def4bfaa7a",
          "body": "…9) + pre-existing clippy cleanup",
          "is_bot": false,
          "headline": "merge(#502 E7): consent-peer-set projection with revocation fold (V10…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T19:58:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37edb7f20f885e33e7d979f1c7b9b035bc4a8822",
          "body": "…vocation\n\nCloses the E7 hole: CIRISServer's replication_peers_from_consent read\nlist_attestations_by(node), filtered dimension == \"consent:replication:v1\",\nand flat-mapped subject_key_ids — but never folded a subsequent\nwithdraws/recants against the grant, so a peer whose consent was revoked\nkept r\n[…]\ncomment gap in\npyo3.rs) inherited from the merge-base — mechanical, zero-behavior fixes\nneeded to pass the repo's pre-commit gate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#502 E7): consent_peer_set projection folds withdraws/recants re…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T19:55:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9803ff2b98f38d5ce854a131e92125fa1932fd6d",
          "body": "…ory + deterministic test Identity\n\nThe 3 operational put_* methods (put_organization/put_org_membership/\nput_partner_record) DROP the caller-passed key_directory/root_stewards/\nsteward_roster slices — genuine crypto verified against the WRONG root of\ntrust — and resolve the roster from persist's OW\n[…]\nion exposed). Witness: grant rooted at a non-registered\nsteward refused; at a registered steward admits. Operational family 30/30.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#502 E9): resolve the operational steward roster from OUR direct…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T19:12:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "20e7c30acc6194362573ba6b3522defc5a1071b6",
          "body": "…tion fixtures\n\nE2's verify_key_registration was pre-empting the canonical/accord/infra\nrole gates (which have their OWN m-of-n/HW admission in put_public_key) —\nrecord_is_role_gated now skips those, so E2 guards only the ungated\npeer-key path (the paths that don't verify at all), matching the FSD.\nRevocation fixtures in register.rs + pg persist-row-hash test upgraded to\nreal hybrid sigs (E1). 5 formerly-failing → green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(#502 E2): scope the PoP gate to ungated peer keys; upgrade revoca…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T18:40:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "64988600f4a68caedb3c55595ae2aeb9a92b18cc",
          "body": "resolve_steward_roster reads the registered identity_type=steward keys\nand builds the ThresholdMember roster from their REGISTERED pubkeys — the\nreplacement for the caller-passed key_directory/root_stewards/steward_\nroster slices (verified crypto, wrong root of trust). Reroute of the 3\noperational put_* methods onto this is the remaining mechanical step.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#502 E9): steward-roster resolver from own directory (foundation)",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T18:27:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "837d8983207d25047205d913ffb374543557484f",
          "body": "apply_replicated_key_record's Insert branch admitted first-sight keys\nTOFU (put_public_key, no verify_key_registration) — a self-consistent\nfake SignedKeyRecord{identity_ref: victim, pubkey: attacker} was\nadmitted and later attestations by it verified. The Strict hybrid PoP\ngate (the same register_f\n[…]\nupgrade branch\nalready ran) now guards the fresh insert too, fail-closed. Witness:\nforged-PoP fresh key rejected, leaves no trace.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#502 E2): fresh replicated-key insert runs the hybrid PoP gate",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T18:24:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a842e875598ec26b08a25ddcec0af16fbe7c0b5e",
          "body": "…voking key's REGISTERED pubkeys\n\nWas FK-existence + trust-score only; scrub sig stored, never verified —\nany linked peer could forge {revoked: victim, revoking: any-existing} for\na targeted de-peer/trust DoS. verify_revocation_admission (shared, all 3\nbackends) hybrid-Strict verifies vs the revokin\n[…]\nresolved from OUR\ndirectory. Fixtures upgraded to real hybrid sigs; forgery-rejection\nwitness added. 40/40 revocation tests green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#502 E1): put_revocation hybrid-verifies the scrub sig vs the re…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T18:13:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a73c7cbcb85fadc0d1545fe4bc15c69583d766c0",
          "body": "… attestation materializes trace_events via the SAME decompose as ingest\n\nThe corpus leg: replication carries the attestation surface; the scorer\nreads trace_events; put_attestation wrote only federation_attestations →\nn_summaries=0 forever. Now project_trace_events_from_attestation\n(re-running stor\n[…]\n real ingest → minted\nattestation → node B put_attestation (wire path) → list_trace_summaries\nsees it; replay lands no duplicates.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#501): inbound trace projection — a replicated trace:complete:v1…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T17:57:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4c0d910709e509c91f92cdebb92cfd3ef84f2fe2",
          "body": "The widest edge (under all 95 claim families): trust_root_valid /\ncapability_roots_to_trusted_root counted local-tier delegates_to/scores\nrows with no tier filter, so a local-tier row could forge the capability\ngate the instant one reached put_attestation from the wire. counts_in_\ncapability_walk gates every walk predicate to FEDERATION tier — closes\nthe exploit at the read side regardless of admission. Witnessed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#502 E5): trust-root walks ignore non-federation-tier rows",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T17:46:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7e1e438e766852dd9a49e4951e932dc2742202ec",
          "body": "…lopeKind, roots-as-variants, pinned manifest hash\n\nThe admission object's spine (FSD CEG_REPLICATION_MODEL.md §4): 14-kind\nclosed enum owned by persist (the APPLY authority), KindPolicy per kind\nvia exhaustive match, roots of trust as SignerSource variants\n(verify-against-sender-supplied is unrepresentable), WireTier::FederationOnly\nthe only tier (E5 by type), REPLICATION_POLICY_HASH pinned + gating witness.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(#501/#502): Registry-of-Record spine — KindPolicy on closed Enve…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T17:41:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "786ce5f6afd7c4ce6aa5336e2335c3d239d97cf3",
          "body": "ci: cap cache blobs at 4GB (CIRISCache LRU prune, all 6 save sites)",
          "is_bot": false,
          "headline": "Merge pull request #500 from CIRISAI/ci-cache-lru-budget",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T16:01:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3e74db75fa4eca1dbe887793666569cde1d495b",
          "body": "…6 save sites)\n\nThe fat-blob ratchet diagnosed on the v20.1.0 run (240-400s ciriscache\nsteps: ~145s download + ~196s extract of a multi-GB blob; superseded dep\ngenerations — e.g. the whole verify-10.5 artifact set — restored, never\nrebuilt, re-saved forever). CIRISCache v1/ff52ca3 prunes oldest-mtim\n[…]\n, every later lane pays less on both download AND extract.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "ci: cap cache blobs at 4GB via CIRISCache max-size-mb LRU prune (all …",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T15:03:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c0ecd8fc85df228bdcb90164598e7b65d72a353",
          "body": "release: v20.1.0 — the trace plane closes both directions (#498 + #478 + #477)",
          "is_bot": false,
          "headline": "Merge pull request #499 from CIRISAI/feat-498-agent-key-id",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T14:59:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1032f5287fb4b08ba4848005a919399a096aec",
          "body": "…n the summary (#498) + P5 backfill (#478) + P4 projection-pinning (#477)\n\n- #498: TraceSummary.agent_key_id = MIN(signing_key_id) — the emitter's\n  REGISTERED federation key (Full-verify resolved it FROM federation_keys\n  before any row admitted: registration by construction). FK-valid,\n  anti-Good\n[…]\nr retro-mutated.\n\nFull lib suite 1556/1556 serial with pg.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v20.1.0 — trace plane closes both directions: agent_key_id o…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T14:25:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a3287236478fb8bb01765ead99c72e4c689c8bc3",
          "body": "release: v20.0.0 — #495: the two serde_json::Value walls are gone",
          "is_bot": false,
          "headline": "Merge pull request #497 from CIRISAI/feat-495-value-walls-v20",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T06:11:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c14eb2fdde7c13316f95f13ed0e3892ccbae6e6",
          "body": "…issing toolchain binaries broke all android ABIs; keep the auto-retry signature half\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "ci: revert setup-ndk local-cache (#445 postscript) — restored cache m…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T05:43:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e878289dca6d52d17259090a07dc3d7cb2532ba",
          "body": "…oss-boundary field drift is a build/test failure\n\nThe umbrella cut, both walls in one release.\n\nWall 2 (attestation envelope, C2/C3, MAJOR):\n- federation::envelope::EnvelopeCore — universal keys typed (dimension,\n  references_attestation_id, scope [both wire shapes], charter fields,\n  withdrawal_re\n[…]\ntation_evidence.\n\nFull lib suite 1555/1555 serial with pg.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v20.0.0 — #495: the two serde_json::Value walls are gone; cr…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T05:06:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "596b38ca8a6bc78a8209836f14b3d5a6cd2e7e5c",
          "body": "release: v19.2.0 — self-enc pubkeys accessor (#493) + single-source trace-summary extraction contract (#494)",
          "is_bot": false,
          "headline": "Merge pull request #496 from CIRISAI/feat-493-494-contract-cut",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T04:44:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fdd8b01ec7f6198cef06efd9194ec1e24ffc83b",
          "body": "…race-summary extraction contract (#494)\n\nThe audit's two actionable slices.\n\n- #493 Engine::self_enc_pubkeys (unblocks CIRISServer#313's reverse-path\n  KEX stall): x25519 + ML-KEM-768 pubs derived INTERNALLY from the\n  engine's local signing seed via ciris_crypto::self_enc — public halves\n  only, p\n[…]\ndings it raised are fixed; CI\nre-runs the identical gate.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v19.2.0 — self-enc pubkeys accessor (#493) + single-source t…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-24T04:07:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bcdaae331e19220e808da001a69c0e322df2d836",
          "body": "release: v19.1.1 — verify 10.6.1 re-pin (RC3 vocab interop fix) + differential vocabulary guard + #445 android CI hardening",
          "is_bot": false,
          "headline": "Merge pull request #492 from CIRISAI/fix-verify-10.6.1-repin",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-23T16:42:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cfaf58cad8cad1105b31119fe79159c0b3d7e11",
          "body": "…ferential vocabulary guard + #445 android CI hardening\n\n- verify 10.6.0 → 10.6.1: verify's INFRA_SCOPES never got the #487 RC3 cut\n  (still had retired infra:join_communities, neither hold_*_membership) —\n  RC3 delegations passed persist but read UnknownScope on the verify/FFI\n  surface. One fact, \n[…]\n\n\nfederation family 362/362 pg serial incl. the new guard.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v19.1.1 — verify 10.6.1 re-pin (RC3 vocab interop fix) + dif…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-23T15:45:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0f6c89b1f3779331f1cab7452acc75f09dea3c61",
          "body": "release: v19.1.0 — bake the assembled genesis (#490) + the mesh goes bright (#480 finisher)",
          "is_bot": false,
          "headline": "Merge pull request #491 from CIRISAI/feat-490-genesis-bake",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-23T04:02:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d95cd3ed8914450263c2fe85475a05dbd466a3e8",
          "body": "…bright (#480 finisher)\n\nThe 2026-07-23 humanity-accord ceremony produced a valid artifact persist\ncould not land (anti-downgrade refusal, no authenticated path). This cut\nadds the path and bakes the ceremony's record into the seed.\n\n- #490 bake_assembled_genesis: quorum verified against persist's O\n[…]\nes, zero writes.\n\nFull lib suite 1545/1545 serial with pg.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v19.1.0 — bake the assembled genesis (#490) + the mesh goes …",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-23T03:27:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "486abfdf532d3d468910fc4a2b1b08c4ec70c858",
          "body": "release: v19.0.0 — RC3 charter alignment: roles lift (#486) + charter recovery/AND/expiry (#488) + crystal vocabulary (#487) + verify 10.6.0",
          "is_bot": false,
          "headline": "Merge pull request #489 from CIRISAI/feat-rc3-charter-alignment",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-22T15:51:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "003502e722b45205f5518fc1cddf7bf5ec330bd5",
          "body": "… recovery/AND/expiry (#488) + crystal vocabulary (#487) + verify 10.6.0\n\nThe centipede run against the finalized RC3 charter model (CIRISServer\nFSD/TRUST_ROOT_CAPABILITY_GATE.md 2026-07-22 + FSD/PRIOR_ART.md; CC#40).\n\n- #486 (the trace-plane unblock): lift_envelope_attested_roles — verify's\n  cerem\n[…]\ncommitted charters. Full lib suite 1544/1544 serial w/ pg.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v19.0.0 — RC3 charter alignment: roles lift (#486) + charter…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-22T15:21:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b3a4cafaf8b1caa799d4699194a57232e0af213",
          "body": "release: v18.3.0 — trust-serve composition (#483) + exported accord co-scrub helpers (#484) + canonical-role compat (#480)",
          "is_bot": false,
          "headline": "Merge pull request #485 from CIRISAI/feat-483-484-480-trust-serve",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-21T08:39:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c0e0a8a37f9ba1346a4371b596a9f29467af194",
          "body": "…o-scrub test helpers (#484) + canonical-role compat (#480)\n\nCompletes the #481 pluggable-trust-root arc into edge's trace-serve gate\n(CIRISEdge#386) and closes the fail-closed-blindness class behind CIRISEdge#379.\n\n- #483 capability_roots_to_trusted_root: composed walk — does `subject` hold\n  `scop\n[…]\ns_and_reads_both_480.\nfederation+memory 500/500 pg serial.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v18.3.0 — trust-serve composition (#483) + exported accord c…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-21T08:13:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9479429d901bf0cddb71fd6b5b49eb624e41dffa",
          "body": "release: v18.2.0 — pluggable-trust-root substrate (#481): trust_root_valid walk + admission/tombstone witnesses",
          "is_bot": false,
          "headline": "Merge pull request #482 from CIRISAI/feat-481-trust-root-walk",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-21T01:02:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4234f2efd29154aaefb1bebdcbb4e60578f4870c",
          "body": "…valid walk + admission/tombstone witnesses\n\nSubstrate half of CIRISServer FSD/TRUST_ROOT_CAPABILITY_GATE.md (CC#40).\nTrust is a layered graph of plain attestation/delegates_to objects — no new\nobject kind.\n\n- federation::trust_root::trust_root_valid — the FSD's pure graph predicate\n  (edge exists +\n[…]\nasks, real surfaces).\nfederation+memory 496/496 pg serial.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v18.2.0 — pluggable-trust-root substrate (#481): trust_root_…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-21T00:36:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c54ae12d85e2268c08a311c63e9e0604e248d0c4",
          "body": "release: v18.1.0 — trace:* Information-Type validator (dimension-as-type-registry; CIRISConstitution#39 interim)",
          "is_bot": false,
          "headline": "Merge pull request #479 from CIRISAI/feat-trace-dimension-validator",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-20T19:06:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e7f01ff9b83a89c1f50f5cfd1cd24a9125bc60e",
          "body": "…ype-registry; CC#39 interim)\n\nThe dimension is the CEG's Information-Type parameter and must be\nmachine-checkably validated — v18.0.0 shipped trace:complete:v1 as an\nunregistered free string. Interim validator (same posture as the CC#38 size\ncap; ratification filed as CIRISConstitution#39):\n\n- chec\n[…]\nvelope-native mint passes through the validator unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v18.1.0 — trace:* Information-Type validator (dimension-as-t…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-20T18:37:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d63b1dd41ca5114255fc81f85dd32a28d95f87cc",
          "body": "release: v18.0.0 — ENVELOPE-NATIVE traces (#473): a trace IS a scores attestation, saved as such",
          "is_bot": false,
          "headline": "Merge pull request #475 from CIRISAI/feat-473-envelope-native",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-20T18:22:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72f80ff019f129e6f9620caddcdbf538c6631f74",
          "body": "… attestation, saved as such\n\nThe owner doctrine, made structural: \"everything persist saves is a CEG-native\nobject put in an envelope.\" The #473 live-mesh failure (28 signed traces\nstranded local, 0 replicated) was the trace_events silo — an object off the\nsubstrate can never replicate by CEG state\n[…]\n (P4), backfill (P5), producers-emit-envelopes north star.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v18.0.0 — ENVELOPE-NATIVE traces (#473): a trace IS a scores…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-20T18:00:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "db9c43905fa185acceebf82894c0d7ff97b66738",
          "body": "release: v17.9.0 — envelope size cap at admission (CIRISConstitution#38 interim)",
          "is_bot": false,
          "headline": "Merge pull request #474 from CIRISAI/feat-envelope-size-cap",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-20T17:23:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b190211886e744c47255e9183727c68a3d24b6e",
          "body": "The CEG had NO envelope size bound at any layer (CC part 2 silent; no\nadmission check; 8 MiB HTTP body cap doesn't cover capsule/FFI writes;\nstorage physically bounded only). With #473's envelope-native inversion\nputting ~3 MB traces in scope of the attestation plane, ship the interim\nadmission boun\n[…]\nnit witnesses + backend integration on both path families.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v17.9.0 — envelope size cap at admission (CC#38 interim)",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-20T16:55:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26099d15c4a79d7d9db0e381ac23566c303f268e",
          "body": "release: v17.8.0 — seeder bridge (#469) + scores shape-witness gate + bench",
          "is_bot": false,
          "headline": "Merge pull request #472 from CIRISAI/feat-469-seeder-bridge",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T16:35:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10526378cf8273cee02971f5d5c431410ecea791",
          "body": "release: v17.7.0 — crypto-DRY closure set: single hybrid-sign verb (#470) + merkle single-sourcing + strict-verify hygiene",
          "is_bot": false,
          "headline": "Merge pull request #471 from CIRISAI/cut-17.7.0",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T16:00:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e0c13d8d1ccdfc7344ce245da87bb53d711f104",
          "body": "… bench\n\nVersion + CHANGELOG for the 17.8.0 cut: #469 announced-peers seeder bridge\n(V108, 4 invariants, 3-backend parity), the scores read surface's gating\nshape-witness tests (resolve_scores plateau at RESOLVE_CANDIDATE_CAP=4096 +\nlist_scores page-bounded + V106 EXPLAIN witness) and criterion benc\n[…]\nso RTLD_NOW-clean; pyo3 .so Chaquopy\ncontract enumerated).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v17.8.0 — seeder bridge (#469) + scores shape-witness gate +…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T15:59:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d6921fb9c1184cd1a9c46bf294da15be0742df94",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'feat-scores-bench-witness' into feat-469-seeder-bridge",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T15:58:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d241c0963a3c578d8c9b2712406e22423aa79c76",
          "body": "…p (#454/#455/#456)\n\nThe v17.4.0/v17.5.0 scores read handles (list_scores / resolve_scores /\nlist_attestation_log) shipped with zero bench coverage and no CI-gating\nguard on their two design invariants. Two deliverables:\n\n1. tests/scores_shape_witness.rs — a deterministic counting harness (the\n   CI\n[…]\nbench \"sqlite\" scores_read in .github/workflows/bench.yml.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "test+bench: scores read surface — shape witness gate + criterion swee…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T15:55:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ce73e47ab254e11043ba8f5d8afac5eb66e2965",
          "body": "…ical, untrusted directory bookmarks\n\nThe CIRISEdge#362 unblock: a self-consistent LAN announce that does NOT root\n(root_binding → UnknownKeyId) is edge-admitted as Advisory but left no\ndirectory-visible trace, so GET /v1/federation/peers never surfaced it.\n\n- V108 announced_peers (both dialects): S\n[…]\nhole-second timestamps — TIMESTAMPTZ truncates to micros).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "feat(#469): seeder bridge — announced/advisory LAN peers as non-canon…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T15:52:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14bef074b74568aeae091c5f43effb4350b8824c",
          "body": "…verb + merkle single-sourcing + strict-verify hygiene, each with a differential guard\n\nThe persist mirror of verify's v10.4.0 assessment cut. Every closure ships\nWITH a differential authority-equivalence test (the CIRISConstitution#36\nproof-centipede pilot):\n\n1. Engine.local_sign_hybrid (#470) — th\n[…]\nification, legacy json.dumps canonicalizer (sunset-gated).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v17.7.0 — crypto-DRY closure set (#470): single hybrid-sign …",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T15:27:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "745b29e40e4d39cd201c2da3ae91f416006a2b5c",
          "body": "ci: verify-agnostic phead cache fallback — stop cold-compiling every leg on a verify bump",
          "is_bot": false,
          "headline": "Merge pull request #468 from CIRISAI/ci-phead-verify-agnostic-fallback",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T13:18:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7491a830b9f4ae9a4777df0fbf2846d67e71167d",
          "body": "release: v17.6.0 — delete forked provenance verifier, delegate to CIRISVerify RequireHybrid walk (#465)",
          "is_bot": false,
          "headline": "Merge pull request #467 from CIRISAI/feat-465-verify-10.5.0",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T13:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1801589cb88fec7ef191a381edc9aa4516efb10",
          "body": "…leg on a verify bump\n\nThe `phead` rolling cache key embeds the VERIFY version\n(`...-phead-enone-v${V}`), so it's persist-version-independent but NOT\nverify-independent. A verify bump (e.g. #465's 10.3.0→10.5.0) rotates the key →\nphead misses → every leg cold-compiles persist's heavy deps (pyo3/rusq\n[…]\nextra\n`oras repo tags` call only when the exact keys miss.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "ci: verify-agnostic phead cache fallback — stop cold-compiling every …",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T12:33:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b96f947f7969bd9600b0f90ce3357de442121774",
          "body": "ci: always warm the cache (save on main + tags) + macos-x86_64 substrate blob (#463)",
          "is_bot": false,
          "headline": "Merge pull request #466 from CIRISAI/feat-463-macos-x86-cachewarm",
          "author_name": "Eric",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T12:30:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99e0afe0618fe5899dd623929b3dc6a8626a7e0d",
          "body": "…ISVerify (#465)\n\nCHANGELOG for the 17.6.0 cut. #210-decoupled: persist's substrate is not\nimplicated in the CIRISVerify#210 dual-registry / verify_unknown_key skew (that\nis CIRISServer in-wheel-identity + Python-verify-API, filed server-side).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "release: v17.6.0 — delete forked provenance verifier, delegate to CIR…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T12:16:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "70dce9508e2a3ab220f16d13402652700a307d05",
          "body": "…RISVerify#210\n\nFixture upgrade to hybrid (bound ML-DSA-65 scrub-sigs) + version bump to 17.6.0.\nFull federation suite 352/352 (sqlite + local pg, serial). NOT pushed / no PR:\n17.6.0 moves the in-wheel verify identity (Rust 10.5.0), which would add a\nvariable to the CIRISVerify#210 dual-registry / v\n[…]\nstration is\nsettled so 17.6.0's identity is accounted for.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "wip(#465): hybrid rooting fixtures + version 17.6.0 — HELD pending CI…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T12:08:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2a1cf28fb2541ef2f2d27fd441e7cfff23335396",
          "body": "…y RequireHybrid walk\n\nCIRISPersist#465 — the crypto-DRY #1 item. Both fork-collapse blockers are now\nreleased: v10.4.0 fixed the JCS-envelope preimage, v10.5.0 (CIRISVerify#208)\nparameterized the terminus role set. root_binding_anchored's step 4 stops\nre-implementing the chain-walk crypto (deleted \n[…]\nmit upgrades to hybrid). Lib\ncompiles; verify pin v10.5.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "feat(#465): delete forked provenance verifier, delegate to CIRISVerif…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T11:55:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "230ba4d79d555a87767aab81c2a6fccec3364751",
          "body": "…e #458 tag save-skip\n\nThe #458 \"save-skip on tags\" traded ~9-10min off the release path for NOT\nwarming the released version's blob — so edge/server/the next build cold-compile\npersist from source (tens of minutes, every build) to save ~10min once. A local\noptimization that's a global pessimization\n[…]\nore@v2 first-hit) stays — that was the real wall-time win.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "ci: always warm the cache (save on main AND release tags) — revert th…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T11:33:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8836073b1ed256d0e6057197dc82d683304be1e0",
          "body": "… warm job)\n\npersist's wheel matrix omits darwin-x86_64 (macos-13 Intel runner capacity —\nFSD §3.5 sunset target), so NO job produced a macos-x86_64 CIRISCache blob.\nCIRISServer's macos-x86_64 release wheel therefore restored only the verify leaf\nand COLD-COMPILED persist+edge every release (~19-min\n[…]\nh-once+alias pattern; timeout-minutes bounds a hung build.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "ci(#463): publish a macos-x86_64 CIRISCache substrate blob (save-only…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T11:10:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e61a6f6c282ca5651f69d07850d9ed7dd14408f1",
          "body": "…on + policy to follow)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UV9Rrc8ktu9ZZ2MsxXaxZb",
          "is_bot": false,
          "headline": "wip(#465): re-pin CIRISVerify 10.3.0 -> 10.4.0 (compiles; fork deleti…",
          "author_name": "Eric Moore",
          "author_login": "emooreatx",
          "committed_at": "2026-07-16T11:06:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 846,
      "latest_release_at": "2026-07-28T03:38:52Z",
      "latest_release_tag": "v21.11.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 13,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.3
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "ciris-persist",
          "exists": true,
          "license": "AGPL-3.0-or-later",
          "keywords": [
            "License :: OSI Approved :: GNU Affero General Public License v3 or later (AGPLv3+)",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Rust",
            "Topic :: Database",
            "Topic :: System :: Logging"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/ciris-persist/",
          "is_deprecated": false,
          "latest_version": "21.10.0",
          "repository_url": "https://github.com/CIRISAI/CIRISPersist",
          "versions_count": 332,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-05-01T21:50:41.034876Z",
          "latest_published_at": "2026-07-28T00:15:43.224578Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 9
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml"
      ],
      "largest_source_bytes": 1634688,
      "source_files_sampled": 335,
      "oversized_source_files": 26,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "ciris-keyring",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "10"
        },
        {
          "name": "ciris-verify-core",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "10"
        },
        {
          "name": "ciris-crypto",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "10"
        },
        {
          "name": "async-trait",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "fs4",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "libc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "backtrace",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "ed25519-dalek",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "zeroize",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "chrono",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "thiserror",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "tracing",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "base64",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "hex",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "h3o",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "uuid",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "jsonschema",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.46"
        },
        {
          "name": "tokio-postgres",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7.18"
        },
        {
          "name": "deadpool-postgres",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14"
        },
        {
          "name": "postgres-types",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2.14"
        },
        {
          "name": "refinery",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "tokio-postgres-rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "rustls-native-certs",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "axum",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "tower",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.5"
        },
        {
          "name": "http-body-util",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "url",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.5"
        },
        {
          "name": "pyo3",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.29"
        },
        {
          "name": "regex",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.10"
        },
        {
          "name": "anyhow",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "log",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "parking_lot",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "candle-core",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "candle-nn",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "candle-transformers",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "tokenizers",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.20"
        },
        {
          "name": "hf-hub",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "ort",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "=2.0.0-rc.10"
        },
        {
          "name": "ndarray",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.16"
        },
        {
          "name": "rusqlite",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.31"
        },
        {
          "name": "redb",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "tokio",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "futures-core",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "tokio-stream",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "ciris-verify",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=10.0.0,<11"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 177,
        "open_issues": 9,
        "closed_ratio": 0.974,
        "closed_issues": 343,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "emooreatx",
          "commits": 850,
          "avatar_url": "https://avatars.githubusercontent.com/u/3317461?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.995
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "auto-retry.yml",
        "bench.yml",
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "9 out of 9 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/9 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f7e63e0655493943f4ae6c39f5dbb6630661148e",
        "ran_at": "2026-07-28T03:42:59Z",
        "aggregate_score": 3.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-28T03:34:41Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-28T03:27:10Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 147,
          "created_at": "2026-05-31T13:50:49Z",
          "last_comment_at": "2026-06-24T22:37:58Z",
          "last_comment_author": "emooreatx"
        },
        {
          "number": 415,
          "created_at": "2026-07-10T16:29:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 476,
          "created_at": "2026-07-20T18:01:49Z",
          "last_comment_at": "2026-07-20T18:19:46Z",
          "last_comment_author": "emooreatx"
        },
        {
          "number": 510,
          "created_at": "2026-07-25T16:50:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 517,
          "created_at": "2026-07-27T01:17:32Z",
          "last_comment_at": "2026-07-28T01:30:59Z",
          "last_comment_author": "emooreatx"
        },
        {
          "number": 519,
          "created_at": "2026-07-27T03:35:01Z",
          "last_comment_at": "2026-07-28T01:21:21Z",
          "last_comment_author": "emooreatx"
        },
        {
          "number": 520,
          "created_at": "2026-07-27T04:14:33Z",
          "last_comment_at": "2026-07-28T01:14:32Z",
          "last_comment_author": "emooreatx"
        },
        {
          "number": 527,
          "created_at": "2026-07-28T01:12:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 528,
          "created_at": "2026-07-28T01:21:00Z",
          "last_comment_at": "2026-07-28T01:27:57Z",
          "last_comment_author": "emooreatx"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/CIRISAI/CIRISPersist",
    "host": "github.com",
    "name": "CIRISPersist",
    "owner": "CIRISAI"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 31,
        "vitality": 74,
        "community": 12,
        "governance": 58,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "commits_last_year": 846,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "846 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 846
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v21.11.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 12,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.995
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 83,
            "inputs": {
              "merged_prs": 177,
              "open_issues": 9,
              "closed_issues": 343,
              "issue_closed_ratio": 0.974,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "97% of issues closed",
                "points": 45.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "177/179 decided PRs merged",
                "points": 37.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 177,
                      "decided": 179
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/9 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 20,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "CIRISAI",
              "public_repos": 46,
              "account_age_days": 465
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "20 followers of CIRISAI",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 20,
                      "login": "CIRISAI"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "46 public repos, account ~1 yr old",
                "points": 14.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 46
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "ciris-persist"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "332 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 332
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "9 out of 9 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://ciris.ai",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://ciris.ai",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 31,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 31,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "9 out of 9 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/9 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.65,
              "toolchain_manifests": [
                "Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "65 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 65,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 1634688,
              "source_files_sampled": 335,
              "oversized_source_files": 26
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "26/335 source files over 60KB",
                "points": 50.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 335,
                      "oversized": 26
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch crates package 'ciris-persist' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index pypi:ciris-persist@21.10.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T03:43:18.511039Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/CIRISAI/CIRISPersist.svg",
  "full_name": "CIRISAI/CIRISPersist",
  "license_state": "absent",
  "license_spdx": null
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenPyPI.