Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-29 19:13 UTC

InverseAltruism / csd-sdk

Compute Substrate (CSD) SDK + light client - canonical codec/crypto/tx/RPC + headers-first verified light client.

TypeScript · JavaScriptMIT★ 0 Sterne⑂ 0 Forksseit Juni 2026Auf GitHub ansehen ↗

InverseAltruism/csd-sdk erreicht einen Gesundheitsindex von 54 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (71/100) ab, am schwächsten bei Community & Adoption (34/100). Zuletzt vor 6 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

54
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

54
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

InversePersönliches Konto
16 Follower12 öffentliche Reposseit Apr. 2023

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
npm@inversealtruism/csd-tx0.1.1783514vor 12 Tagen
npm@inversealtruism/csd-siwc0.1.152515vor 26 Tagen
npm@inversealtruism/csd-codec0.1.1593212vor 26 Tagen
npm@inversealtruism/csd-light0.1.1875914vor 16 Tagen
npm@inversealtruism/cairnx-core0.1.403.40530vor 8 Tagen
npm@inversealtruism/csd-client0.1.1550111vor 26 Tagen
npm@inversealtruism/csd-crypto0.1.1571911vor 26 Tagen
npm@inversealtruism/csd-vectors0.1.1533611vor 26 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

71Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 6 Tagen
5.5/36Commit-Rhythmus — 8/52 Wochen mit Commits
18/18Commit-Volumen — 147 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year147
human_commit_share1
days_since_last_push6
active_weeks_last_year8
Wie die Bewertung erfolgt
16.2/27Liefert Releases aus — 7 Versions-Tags (keine GitHub-Releases)
36/36Release-Aktualität — letztes Release vor 42 Tagen
27/27Release-Rhythmus — ein Release etwa alle 1,4 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count7
latest_release_tagv0.1.10
releases_from_tagsja
days_since_latest_release42
mean_days_between_releases1,4
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

34Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
51.8/80Downloads pro Monat — 7.738 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packages@inversealtruism/csd-tx, @inversealtruism/csd-siwc, @inversealtruism/csd-codec, @inversealtruism/csd-light, @inversealtruism/cairnx-core, @inversealtruism/csd-client, @inversealtruism/csd-crypto, @inversealtruism/csd-vectors
dependents
ecosystemsnpm
total_downloads
monthly_downloads7.738
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

52Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
38.2/38.3PR-Annahme — 1/1 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs1
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
8.8/25Reichweite des Inhabers — 16 Follower von InverseAltruism
14.7/25Kontohistorie — 12 öffentliche Repos, Kontoalter ca. 3 Jahre
Verwendete Eingangsdaten
followers16
owner_typeUser
is_verified
owner_loginInverseAltruism
public_repos12
account_age_days1.211
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 8 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 8 Tagen
20/20Versionshistorie — 30 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packages@inversealtruism/csd-tx, @inversealtruism/csd-siwc, @inversealtruism/csd-codec, @inversealtruism/csd-light, @inversealtruism/cairnx-core, @inversealtruism/csd-client, @inversealtruism/csd-crypto, @inversealtruism/csd-vectors
ecosystemsnpm
any_deprecatednein
min_days_since_publish8

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

62Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 1 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — http://cairn-substrate.com
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepagehttp://cairn-substrate.com
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

44Gefährdet · 16 % des Gesamtindex

Sicherheitslage

30Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — keine Daten
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate3
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, packaging, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages4
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:@inversealtruism/csd-tx@0.1.17 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 4 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

68Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md, CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 99 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,99
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes18.646
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — packages/cairnx/tsconfig.json, packages/client/tsconfig.json, packages/codec/tsconfig.json, packages/crypto/tsconfig.json, packages/indexwire/tsconfig.json, packages/light/tsconfig.json, packages/registry/tsconfig.json, packages/siwc/tsconfig.json, packages/tx/tsconfig.json, packages/vectors/tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 95 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespnpm-lock.yaml
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configspackages/cairnx/tsconfig.json, packages/client/tsconfig.json, packages/codec/tsconfig.json, packages/crypto/tsconfig.json, packages/indexwire/tsconfig.json, packages/light/tsconfig.json, packages/registry/tsconfig.json, packages/siwc/tsconfig.json, packages/tx/tsconfig.json, packages/vectors/tsconfig.json
agent_commit_share0,95
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
53.9/55Handhabbare Dateigrößen — 2/98 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes72.348
source_files_sampled98
oversized_source_files2
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

0GitHub-Sterne
1Mitwirkende
147Commits, letzte 12 Monate
6Tage seit letztem Push
7Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 3.0 / 10
3.0Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-29 19:13 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
k. A.Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direkte Abhängigkeiten 15
RegistryPaketVersionsvorgabeManifest
npm@inversealtruism/csd-codecworkspace:*packages/cairnx/package.json
npm@inversealtruism/csd-codecworkspace:*packages/client/package.json
npm@noble/hashes1.8.0packages/codec/package.json
npm@inversealtruism/csd-codecworkspace:*packages/crypto/package.json
npm@noble/curves1.9.7packages/crypto/package.json
npm@noble/hashes1.8.0packages/crypto/package.json
npm@inversealtruism/csd-codecworkspace:*packages/light/package.json
npm@inversealtruism/csd-clientworkspace:*packages/light/package.json
npm@inversealtruism/csd-codecworkspace:*packages/registry/package.json
npm@inversealtruism/csd-cryptoworkspace:*packages/registry/package.json
npm@inversealtruism/csd-codecworkspace:*packages/siwc/package.json
npm@inversealtruism/csd-cryptoworkspace:*packages/siwc/package.json
npm@noble/hashes1.8.0packages/siwc/package.json
npm@inversealtruism/csd-codecworkspace:*packages/tx/package.json
npm@inversealtruism/csd-cryptoworkspace:*packages/tx/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 0

Die Installation von npm:@inversealtruism/csd-tx@0.1.17 zieht 4 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1444,
      "has_wiki": true,
      "homepage": "http://cairn-substrate.com",
      "languages": {
        "Shell": 2340,
        "Python": 72053,
        "JavaScript": 353250,
        "TypeScript": 635641
      },
      "pushed_at": "2026-07-23T18:00:18Z",
      "created_at": "2026-06-06T22:32:53Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T18:00:32Z",
      "description": "Compute Substrate (CSD) SDK + light client - canonical codec/crypto/tx/RPC + headers-first verified light client.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://cairn-substrate.com",
      "name": "Inverse",
      "type": "User",
      "login": "InverseAltruism",
      "company": null,
      "location": null,
      "followers": 16,
      "avatar_url": "https://avatars.githubusercontent.com/u/129900527?v=4",
      "created_at": "2023-04-04T20:12:40Z",
      "is_verified": null,
      "public_repos": 12,
      "account_age_days": 1211
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-06-16T22:33:02Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-06-15T19:25:38Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-06-15T00:45:31Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-06-14T23:31:38Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-06-14T06:09:25Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-06-12T22:27:42Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-06-08T18:56:16Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "f2ac1286f3cd9cc695eb8bae7260af24daa2d980",
          "body": "…TS State snapshot\n\n- seal-differential header no longer lists replay-hashes.json among the frozen step-2 pins\n  (the code narrowed it out for B8-hash; header now matches).\n- types.ts V28 comment: point-in-time phrasing, marks the 2026-07-23 crossing and the\n  extended pin range.\n- AGENTS.md State snapshot to the post-REBIND LTS baseline (0.1.40 published, V28 crossed,\n  B8-hash pinned, FU-A skew recorded, V29 the only pending gate).",
          "is_bot": false,
          "headline": "docs: close the two G15 LOW stale-comment findings + refresh the AGEN…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-23T18:00:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49c13a84d3beb9fc86a0adda585884a3fbbfafa7",
          "body": "- Section 32 written from resolve.ts/types.ts and cross-checked against the independent\n  Python oracle: M4 duplicate-event drop (one identity per tx; first-in-consensus-order\n  kept; no straddle case, a duplicate pair shares one block) and M5 open-holds-only\n  concurrent-claim count (strict subset,\n[…]\nHANGES rollout note 2 closed; note 1 updated for the executed B8-hash\n  baseline (corpus + V28-inclusive pins now load-bearing in-tree).\n- AGENTS.md cairnx-core row: CONVENTION v2.9 no longer pending.",
          "is_bot": false,
          "headline": "CONVENTION section 32: the v2.9 normative spec (REBIND M4 + M5)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-23T17:56:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7e52902e02b7551d22af0e6fdf51950fa489ff0",
          "body": "- replay-hashes.json re-pinned at the V28 crossing (captured 2026-07-23, tip 60,425).\n  STOP RULE verified: all 13 pre-existing 45,959-era heights reproduce byte-identically;\n  V24/V25/V26/V27/V23/V28 entries ADDED, none changed.\n- replay-corpus.json: the deterministic on-chain event corpus (389 eve\n[…]\nrom the B6-era byte-freeze by\n  the same narrowing pattern B9 established (it is the deliberate B8-hash deliverable, now\n  independently guarded by the vectors.test assertion). SEAL re-run: PASS (GO).",
          "is_bot": false,
          "headline": "B8-hash (REBIND F8): V28-inclusive replay-hash baseline, load-bearing",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-23T17:52:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "722b427ba43ad06e71fd355e8b9ba4318f5ec529",
          "body": "…y surface + B9 V29 gate @ 88,000)\n\nB6 CORE-ADDITIVE (default-off, SEAL byte-identical to 0.1.38 with features off) + B9 M4/M5 gated at\nV29_HEIGHT=88,000 (below-gate byte-identical, fork-lens proven). Below tip 88,000 every 0.1.40 replayer\nis byte-identical to 0.1.38. npm publish is the operator step; the replay-hash re-pin lands at the crossing.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: cairnx-core 0.1.40 (Plan 71 REBIND: B6 additive fill-boundar…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-21T00:54:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "eb99580dbb287df9da9c43f8f8df9c4dafb8640b",
          "body": "- CONSENSUS_CHANGES.md: V29 @ 88,000 entry (M4 event de-dup + M5 concurrent-hold\n  status filter, event-height gated; post-crossing replay-hash re-pin checklist\n  step + stop rule; adoption discipline + abort lever). Lands BEFORE the 0.1.40\n  bump per the close-out order.\n- publish-guard.mjs: honest\n[…]\nariant.\n- types.ts: claimWindowOf JSDoc corrected for the expiry-capped EARLY-side\n  over-state (G10-B flag); comment-only, stripped from dist.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B8-docs (REBIND): csd-sdk AGENTS/truth pass",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-21T00:20:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "94cd992dfefb881dd32dcaf86a0753fd31f39b2a",
          "body": "…raddle, below-gate differential, fork-lens fixture\n\nThe independent-verification half of the V29 gate. No resolve() behavior change; this\ncommit is the proof that B9a is a sound, correctly-scheduled consensus relaxation.\n\n- conformance/cairnx_ref.py: the M4 (event de-dup) + M5 (open-holds-only cap)\n[…]\ntep clean (version UNCHANGED at 0.1.38); audit:all exit 0 (sealed-band\nburns 0); B6 seal-differential still SEAL PASS; em-dash 0 in added lines.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B9b (REBIND M4+M5 proof half): Python oracle mirror, V29 crosslang st…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T19:38:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c30a43810a18346bef490bf3e5f30e2b4049be9",
          "body": "…88,000\n\nTwo resolve() corrections that both move canonical state, so both ride ONE height\ngate V29_HEIGHT = 88,000 (operator decision 2026-07-20). Below the gate the core is\nBYTE-IDENTICAL to v2.8: 72/72 B6-era golden vectors unchanged, every pinned replay\nheight (<= 45,959) far below 88,000.\n\n- M5\n[…]\n this diff): the 0.1.40 version bump + publish, and the V29\nreplay-hash re-pin (needs the live-indexer generator reachable into the V29 region).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B9a (REBIND M4+M5): the V29 consensus gate, resolve()-side, gated at …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T19:26:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6d71e31161395707fb56c6c934ff895674a5d44c",
          "body": "- conformance/crosscheck-siwc.mjs: replace the em-dash in the zero-length\n  deny-leg console.error with a regular hyphen (the remaining em-dash on the\n  case-2 SIWC statement is deliberate pinned test-vector data; changing it\n  would move a pinned digest and drop non-ASCII coverage, so it stays).\n- \n[…]\n it\n  cannot go dead-green if the export is renamed/removed. RED-FIRST verified.\n\nTest/conformance-only: no built dist byte changes (SEAL-safe).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6 gate fold-ins (G10): em-dash strip + unsafeMint prod-guard",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T19:05:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26fb628dc05d29184b00d94e885b3958457bfe8b",
          "body": "…tch (standing rule: zero in added text)\n\nComment/string-only; dist semantics unchanged (the SEAL differential re-run pins that).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6 polish: strip em dashes from strings and comments added by this ba…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:25:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "058f3710aa0c75ca392d5eed4592f3bcd5216047",
          "body": "…referee executes at the gate)\n\nnode scripts/seal-differential.mjs [baselineRef=84f22d7]:\n1. settled-tree check (check-lockstep: dist fresh);\n2. vector-corpus non-movement vs the baseline ref (cases.json / replay-hashes.json /\n   wa-parity untouched - the differential runs on unmoved pins);\n3. build\n[…]\n150->151 in the tree dist -> DIVERGED on the v16 rebate vectors,\nexit 1; rebuild -> exit 0. Any nonzero exit = B6-SEAL no-go, nothing publishes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6-SEAL harness: the 0.1.38 byte-identity differential (author half; …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:23:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dc4580284a21f17784b0bba37a1b2ccdf04ef1cc",
          "body": "…2 exact-gate both(), R3 premise pins\n\n- export-surface.test.ts: pins CONF_TOKEN_FILL (the 1_000_000 token-fill confidence\n  sentinel) in src AND in the built dist/index.d.ts the wallet re-vendor consumes.\n  Verified already exported (types.ts export *); the pin makes regression loud\n  (red-first: a\n[…]\nlog. Red-first: each premise relaxed in dist failed exactly its own pin.\n  Wired into test:crosslang. Test-only; the Python oracle is untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6 conformance riders (REBIND): export pin, proven-terms tripwire, F-…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:20:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9a4c50fde95e6c212307c43d5c7898019a0b98de",
          "body": "…fier boolean, node byte caps in builders, SIWC zero-length parity\n\nAll four leaf LOWs verified against the live tree before coding; every fix authored\nred-first (test written, observed RED, then fixed):\n\n- registry reverseName: encodeURIComponent(address) (sibling parity with resolveName;\n  a path-\n[…]\ned RED against the unfixed ref (JS refused, Python built).\n  The wallet-builder half of the audit LOW is cairn-wallet scope and rides its batch.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B8-sdklow rider (REBIND audit LOWs): registry URL-encode, merkle veri…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:14:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e43ca8eeeb939e5b83e9aeb7b3deafdc96904e75",
          "body": "…aced by a glob runner\n\n- scripts/publish-guard.mjs (every package's prepublishOnly) now runs the package's own\n  test suite and, for cairnx-core, the root cross-language conformance gate\n  (test:crosslang), after the pnpm-client + lockstep checks. Opt-out is EXPLICIT ONLY\n  (CSD_PUBLISH_SKIP_TESTS=\n[…]\nthe summary\n- red cairnx suite -> publish-guard exit 1 'REFUSING to publish'\n- CSD_PUBLISH_SKIP_TESTS=1 -> loud banner, tests skipped explicitly\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6d (REBIND M13): publish gate runs the tests; cairnx test chain repl…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:10:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0deb7babd89e55941825aa261f447c639efba10a",
          "body": "…parameter, mirrors claimGraceOf)\n\nAn fclaim hold's claimUntilHeight = (E+1)*EPOCH_LEN is epoch-quantized, so the legacy\n40-block era inverse under-derives the grant by 6..35 blocks (true span 46..75) and the\nclaim-depth consumer shows a false 'not ready' on the flagship name-buy flow. With the\noffe\n[…]\nn truth), P4 (strictly wider than 40),\nP5 (true span inside [46,75]); mutation proof that deleting the fclaim branch reverts\nto the M6 behavior.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6c (REBIND M6): claimWindowOf made fclaim-aware in place (claimTxid …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:07:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "38bec3872fddf09e3a64b8d2baa1a2cb4d9194fc",
          "body": "…uccessors; fillIsSafe/requiredFillOutputs frozen, doc-corrected, deprecated\n\n- fillEndorsement(offer, me, pay, tip, {fillTargetId}): a discriminated honest verdict\n  (endorsed / refused / not-endorsable). Token wants get the DISTINCT not-endorsable\n  verdict (honest non-endorsement, never a refusal\n[…]\n tests: Correction-1 red/green pair, frozen-behavior pins, per-guard mutation proofs\n  (each new guard is the sole rejecter of its doomed case).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6b (REBIND W10/M1): fillEndorsement + fillOutputPlan discriminated s…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:06:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e11f3fb4d3b7abf966ac9d94b1e0958c57856132",
          "body": "…yment bind, ProvenOfferTerms brand\n\nAll additive and DEFAULT-OFF (decision D4); resolve.ts untouched, replay byte-identical.\n\n- bindOfferTerms gains OPT-IN give.ticker/give.amount/give.name legs (explicit presence +\n  verbatim string equality, never a deep object compare) and a symmetric want-type \n[…]\nproofs (each new guard is the sole rejecter), and an executable tsc\n  compile gate for the brand (test/brand.test.ts + fixtures/brand-usage.ts).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "B6a (REBIND W2/W3/W7): opt-in give/wantType term legs, opt-in sums pa…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-20T18:02:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "815683f3c26b11bc7c46dbfd3bc685c61c1ab015",
          "body": "The V28 differential guard was blind. Measured over 20,000 generated sequences,\nevent heights DID exceed V28 (via lapseFlow's far-future re-claims) but every one\nof those was a `propose`, so not one attest ever reached the gate. Every v2.8\nbranch - grant, fclaim fill routing, Correction 1, and the l\n[…]\nstored\nbyte-identical after every mutation experiment.\n\nMutation-proven: delete the gate and the differential itself now diverges.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "conformance(B0a): repair the vacuous V28 fork gate",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-19T19:09:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29806897259e3a53334fbfde95de794db42118f4",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "Merge Plan 70 R2 into master (cairnx-core 0.1.38 + csd-tx 0.1.17)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T09:07:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "84f22d7c77cda9049c9f728074efafc97d0c0abb",
          "body": "…-identical)\n\ncairnx-core 0.1.38: the Option-B shared bindOfferTerms fill-boundary predicate (exported) +\nL1 FILL_TIP_MARGIN 2->4 (client fclaim deadline cushion, fail-safe reject-more). csd-tx 0.1.17:\nbuildProposeVerified/buildAttestVerified (F9-C). CONSENSUS_CHANGES entry added: CLIENT reject-more\n[…]\n2/72 golden vectors + replay-hashes unmoved), non-retroactive, no gate.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "release: cairnx-core 0.1.38 + csd-tx 0.1.17 (Plan 70 R2; resolve byte…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T09:03:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7c01e8b34683479a5d11b222fcece1591bf8b2a",
          "body": "…ndOfferTerms) + FILL_TIP_MARGIN 2->4 (Plan 70 R2 Batch G)\n\nverifyfill.ts: export the ONE fill-boundary TERM-mismatch verdict `bindOfferTerms`\n(byte-identical to the R1 wallet provenTermsMismatch + site amount-leg hand-copies,\nwhich were already behaviourally identical, differing only in shape) plus\n[…]\ndentical, consumer-pin + lockstep OK. No version bump (not publishing).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "feat(cairnx §Option B): single-source the fill-boundary term bind (bi…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T02:26:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dcc761107aaf169083bf38b8531967ca87ac2320",
          "body": "…e-verified money-out builders)\n\nAdd the verified twins of buildPropose/buildAttest, mirroring buildSendVerified: select inputs by\nreported value, await verify(sel.inputs) against the chain (fail-closed on !ok or throw), then assemble\nthe Propose/Attest from the VERIFIED total with the same fee-floo\n[…]\nfied-total change, fee-floor twin,\nCONF_TOKEN_FILL marker (68/68 pass).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "feat(tx F9-C): buildProposeVerified + buildAttestVerified (input-valu…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T01:59:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fb9b70ae29deac7eabe8513218a00ef13b3de27e",
          "body": "…vector + oracle comment honesty\n\nPlan 70 R2/R3 finding I1 (oracle independence for the name-give fclaim path). Every prior\nfclaim crosslang vector is TOKEN-give; the v2.8 fclaim NAME-GIVE delivery path (an offer selling\na .csd name, settled via an fclaim hold + fill) had ZERO dedicated cross-impl v\n[…]\nnt violations). No JS consensus logic, versions, or\npublishing touched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "test(conformance §I1): CONVENTION-derived NAME-GIVE fclaim crosslang …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T01:13:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d02dd8065703d208117f354af6ba4e1cdf94885",
          "body": "…io + TREASURY_ADDR bind\n\nReview follow-ups: (1) the withheld-cancel scenario - a seller ocancel on-chain but\nOMITTED from the resolver hint list (the real F8 completeness attack, distinct from\nocancel-before-grant where the cancel IS served). cairnx-core verifyFillSpv canNOT catch\na withheld event \n[…]\nHash 0x0a4e1072...).\n\nPlan 70 R2 / W-A (WA-PARITY seam 1 review fixes).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "test(cairnx §WA-PARITY): add withheld-cancel (F8 completeness) scenar…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T00:42:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f6ca30dda9884ee03f2ca8b8bca1d87b105b1849",
          "body": "…apter (seam 1/3)\n\nThe W-A defense-in-depth fixture that keeps the three fill-boundary seams (cairnx-core\nverifyFillSpv, cairn-wallet fillspv.ts, cairn swapguard.js) from ever diverging again.\n\nwa-parity-corpus.json: one canonical, seam-agnostic hostile-case corpus (record-level\nscenarios; symbolic \n[…]\nxist.\n\nPlan 70 R2 / W-A (WA-PARITY, L4, SG-CLAIMGRANT folds to follow).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_017h7GYgP2JsDnoVu5uP1VAH",
          "is_bot": false,
          "headline": "test(cairnx §WA-PARITY): shared fill-boundary corpus + cairnx-core ad…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-17T00:36:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "008a80c7bb26c8006c7aa21a46080a512a8d2e46",
          "body": "… integration)\n\nThe A1 csd-light change was integrated into the V28 line during the build and published as csd-light 0.1.18\n(commit b09a54a on this branch is byte-identical to a1-sg-content-bind's a2ae930). This merge records the\nintegration and retires the feature branch; it changes ZERO content (git merge-tree == master^{tree}).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Merge branch 'a1-sg-content-bind' into master (V28 A1 SG-CONTENT-BIND…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-13T14:36:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0afd384ca789bab19a473cb1c547927186807c39",
          "body": "…1.18 (A1 SG-CONTENT-BIND) + clarvis-optional framing\n\n- V28_HEIGHT 55_000 -> 60_000 in types.ts + cairnx_ref.py; 7 v28 vectors regenerated at 60000.\n- csd-light 0.1.17 -> 0.1.18 (carries the cherry-picked SG-CONTENT-BIND-1 verifyTxInclusion bind).\n- CONSENSUS_CHANGES: V28 entry gate + csd-light 0.1\n[…]\nity hard requirement.\n- Fork gate re-verified: vectors 71/71 byte-identical, crosslang 26/26 JS==Python at 60000, audit:all clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(V28): bump gate 55,000 -> 60,000 (deploy runway) + csd-light 0.…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-13T13:33:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b09a54a0b6e71969e7dcdd79d17dc2695c06790c",
          "body": "…olds merkle over the re-derived leaf\n\nCloses SG-CONTENT-BIND-1: the light client's inclusion proof folded server-reported\ntxids and discarded the proven tx, so a merkle proof did not bind the tx CONTENT. Now\nverifyTxInclusion recomputes the consensus txid from the returned tx and folds the\nmerkle b\n[…]\n-content-bind (ship-first security track; needs a version\nbump + re-vendor at publish; MERGE INTO the V28 branches before deploy).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(light §SG-CONTENT-BIND-1): verifyTxInclusion re-derives txid + f…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-13T13:29:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a2ae93042bfc98df514dcac10ea4d428de36c179",
          "body": "…olds merkle over the re-derived leaf\n\nCloses SG-CONTENT-BIND-1: the light client's inclusion proof folded server-reported\ntxids and discarded the proven tx, so a merkle proof did not bind the tx CONTENT. Now\nverifyTxInclusion recomputes the consensus txid from the returned tx and folds the\nmerkle b\n[…]\n-content-bind (ship-first security track; needs a version\nbump + re-vendor at publish; MERGE INTO the V28 branches before deploy).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(light §SG-CONTENT-BIND-1): verifyTxInclusion re-derives txid + f…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-12T22:19:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a7183650c0e2fc6dda6722b133743a5caa9a964f",
          "body": "…e 55,000)\n\nCloses CX-DVP-CROSSBLOCK-1 (cross-block \"pay without delivery\" on the open-lane\nmarketplace buy). The open-lane claim becomes a short-expiry `fclaim` Propose and the\nfill Attests that fclaim's txid, so L0's own attest-existence + attest-after-expiry\nrules ARE the hold deadline (overlay d\n[…]\nent fill-SPV evidence layer is hand-implemented\ntwice (site + wallet) and should be consolidated into a shared cairnx-core helper.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx v2.8/§31): V28 fclaim open-lane settlement atomicity (gat…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-12T22:18:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1e745b9f9d965d56ed315bd13605f2b8e916350",
          "body": "…d home dir\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(scripts): read the demo key path from env/$HOME, not a hardcode…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-11T01:53:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "03f58a657efe7eb19a5039c3b62bd6a252a8938a",
          "body": "The docstring claimed the check is 'sound by the freeze arithmetic ... guarantees\nthe finalize lands' and the S1 hardening framed it as 'no resolver value can\ninduce a loss'. Both overclaim: the displacement guard (effectiveHeight !==\ncommitHeight) only bites when commitHeight comes from a source IN\n[…]\ns\nregistration-state SPV (roadmapped). Comment-only, no behavior change (rides the\nnext natural cairnx-core publish; not a docs-only republish).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx): honest trust-scope on finalizeWinnerCheck (meta-review)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T21:09:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a51ca920ba5a91499493a1e002ac46af83ec9663",
          "body": "…eck pure derivation (S1)\n\nPre-publish hardening from the 9-agent audit (csd-light 0.1.17 + cairnx-core\n0.1.36 were never published, so these fold into the same unreleased versions).\n\nH1 (consensus red-team, PoC-confirmed): the initial C1 anchor-containment only\nrequired the snapshot to CONTAIN its \n[…]\nolve/records/types unchanged):\ncrosslang exit 0, audit:all exit 0 (byte-identity 1000/1000, sealed-band 0),\nlockstep + per-package suites green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "harden(light+cairnx): complete C1 anchor band (H1) + finalizeWinnerCh…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T20:01:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "59dbdba92c7ce78da2a456245c84129863179268",
          "body": "…T-5 mirror)\n\nThe helpers judge a record the caller hands them, so the fail-closed fetch\nposture (a clean 404 or status-less 200 means the resolver will not settle\nthe fill; the L1 payment burns) is now stated in the shared contract header,\nmirroring the wallet 0.2.57 OFFER_UNKNOWN behavior. Comment-only; rides the\nunpublished 0.1.36.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx): state the fetch posture in the preflight contract (M-MK…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T19:02:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "19d77d9b8dfc40bb8e2e87138c6ce196902ed22e",
          "body": "…ct replayers unchanged\n\nPlans/68 D3b. CONSUMERS gains a tier column: strict (cairnx svc, cairn-cli;\nany cairnx-core pin mismatch fatal, as before) vs graded (cairn-sdk, clarvis;\na lag is fatal ONLY when the pinned-version..HEAD diff touches the consensus\nsurface resolve/records/types - a helpers-on\n[…]\nect version check.\n\nCloses the guard's blind spot on exactly the repo the external review\nflagged (cairn-sdk was previously not checked at all).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(scripts): consumer-pins tiers - cairn-sdk + clarvis graded, stri…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T18:27:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "285a0486fb312c45b6afd2a72bf4988bddda1d6f",
          "body": "…airnx-core 0.1.36)\n\nPlans/68 B2 (revives Plan 63 N-2). finalizeWinnerCheck accepts an optional\ntip and, when passed, refuses BOTH sides of the finalize window: too-early\n(displacement contest not frozen: the resolver rejects the nfinalize after\nthe reg fee moved, a burn) and too-late (mines past fi\n[…]\n test:crosslang exit 0 (resolve 64/64, fuzz\n1500/1500), audit:all exit 0 (0 invariant violations, sealed-band burns 0,\nbyte-identity 1000/1000).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx): finalizeWinnerCheck gains the finalize-window checks (c…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T18:27:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41c192fa1bce0c012ca72b17cb2958345927ab74",
          "body": "…s (csd-light 0.1.17)\n\nPlans/68 C1. fromSnapshot hardens the restore path, reject-more only:\n\n- Anchor containment: a checkpoint-configured client refuses any snapshot\n  whose range does not CONTAIN its lowest pinned checkpoint (genesis-rooted\n  snapshots stay exempt, anchored by the H4 genesis chec\n[…]\nht-offline.test.ts, each verified to FAIL on 0.1.16 (29/32) and pass on\n0.1.17 (32/32). CONSENSUS_CHANGES entry included; no height gate needed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(light): snapshot anchor containment + restore-time timestamp rule…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T18:26:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c2e0926636d4385e895fb1f4fa1f229b4b1b135b",
          "body": "…byte-identical)\n\nfromSnapshot restores measured ~85% LWMA re-derivation: the sliding 45-header\nwindow re-converts the same header's bits up to 45x. Module-scope capped memo\nof the pure targetToBigInt(bitsToTarget(bits)) composition cuts restore cost\n~4x (192 -> 47 us/header on the real-header fixtu\n[…]\ne window + edge encodings + forced cap eviction) and the unchanged\nlight-offline golden (incl. H4 poison vector). CONSENSUS_CHANGES entry added.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(light): memoize LWMA bits->target conversion (csd-light 0.1.16, …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-10T15:48:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1034ab23b16f9e64ae7cbafdfdce15836fd3fa26",
          "body": "AGENTS.md is the canonical repo briefing for coding agents and outside\ncontributors; CLAUDE.md imports it via @AGENTS.md (edit AGENTS.md only).\nProduction and operations specifics are intentionally out of scope and\nmaintained privately.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add public agent onboarding briefing (AGENTS.md + CLAUDE.md)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-09T22:59:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6cccfd15de0c3510ee30c3859c406329acbb5a5e",
          "body": "…03 re-pin (46400/46440/46480/46520)\n\nCONVENTION.md (normative, published in the npm package) still carried the pre-re-pin heights\n49200/51000/51200/52500: a third party implementing from the published spec would gate v2.4-v2.7\nthousands of blocks late and fork replay. Heights corrected everywhere (\n[…]\nTION.md.\nNOTE: npm cairnx-core@0.1.35 still ships the stale spec; a docs-only 0.1.36 republish is the\nrecommended follow-up (operator decision).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx-core): correct V24-V27 activation heights to the 2026-07-…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-06T19:14:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5e1c4995ef644877921863e8706973a4786476a",
          "body": "…ndings)\n\n- csd-tx: selectInputs exclude param coverage (excluded-best-coin, pool exhaustion -> null,\n  case-sensitive key contract, 2-arg unchanged). The param shipped in 0.1.16 with its only lock\n  living downstream in cairn-wallet's parity file; csd-tx CI can now catch its own regression.\n- cairn\n[…]\nr (whole-fill\n  overpay == par; partial overpay clamped to the remainder, fee on the clamp, resolver accepts\n  exactly and completes the offer).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: in-repo locks for the 0.1.35/0.1.16 promotions (verification fi…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-06T19:14:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b71f08969d5305b68ffc0ba129297586f5d41b4e",
          "body": "…eview finding\n\nThe uppercase-query test used an all-digit hex address, so .toUpperCase() was a no-op and the\ntest passed with or without the defensive .toLowerCase() in pickPrimaryName. Use a C-bearing\naddress that genuinely round-trips through the case-fold. Verified by mutation: dropping the\nlowercase now fails the test (null !== 'casefold'), restoring it passes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(primary): make the case-fold pin actually bite (a-f address) — r…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-06T16:31:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc90c14cb5a1105e3547f5aa2533f28bd0b6bde8",
          "body": "…ind HEAD)\n\nThe wallet/cairn freshness gates prove their bundle matches the PINNED csd-sdk commit but say\nnothing about how far behind HEAD that pin sits. Warn (never fail) when the vendored commit is\nolder than 14 days of csd-sdk history. Verified against the live PROVENANCE files (both 0d today).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "check-consumer-pins: advisory vendored-consumer lag warning (>14d beh…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-06T15:29:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6325edb96e411401ac6faa051bb875bcee229b95",
          "body": "…eight owns the gate list)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: V28+ gate/fee-tier rollout checklist (post-promotion, buildFeeH…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-06T15:27:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "94e801f8505bcab6ae314c91409383c9acb3fa0b",
          "body": "… repos hand-copied\n\ncairnx-core 0.1.35 (preflight.ts + new primary.ts; resolve.ts/types.ts UNTOUCHED - replay-identical,\nfull crosslang conformance green):\n- requiredFillOutputs(offer, payRaw): the resolver's fill value-gate need-map (resolve.ts:699-712\n  whole / :643-649 partial) as a build-ready \n[…]\nxos, need, exclude?): upstream the wallet 0.2.53 ghost-coin exclude param\n  (positional, additive; key format documented: lowercased txid:vout).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cairnx-core 0.1.35 + csd-tx 0.1.16: promote the app-band helpers four…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-06T14:37:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c4ae122c61ca8ca04a5b45c0d3902a8621d871db",
          "body": "…ct resolver mirror at feeBps=0)\n\npreviewFill coerced a stored feeBps=0 (a pre-v1.1-era offer, resolve.ts stamps 0 and charges nothing)\nto the FEE_BPS fallback, quoting a 1% fee the chain does not require — an over-quote a taker would\noverpay to the treasury. Use the offer's own feeBps; the existing\n[…]\n-band burns 0; package suite + dts build clean).\n\nSecond-reviewer finding F3, /opt/cairn_substrate/REVIEW-NOTES-PLAN60-61-ROLLOUT-2026-07-04.md.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "preflight: quote the offer's stamped feeBps verbatim (review F3 — exa…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-04T17:09:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "18a916f98eb881a19a12ffe43f78e66f39be302c",
          "body": "…ed + loser-follow-on burn fixtures\n\nTier 1 (deep-review 2026-07-03): new pure preflight.ts exports (previewFill / fillIsSafe /\nfinalizeWinnerCheck + isOpenClaimLane / hasLiveClaim) mirroring the resolver's fill pro-rata floor,\nopen-CSD claim gate, and registration-finalize freeze arithmetic EXACTLY\n[…]\no-delivery) — findBurns re-surfaces every one;\nselftest classifies all 13 scenarios correctly. cairn-sdk 0.2.1 pins re-staged to these versions.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cairnx-core 0.1.34: shared pre-flight helpers + M2 registry fail-clos…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-04T16:22:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0a38a5c4470185502eaae2523042daf7b38dfeae",
          "body": "…40 / V26 46,480 / V27 46,520)\n\nZERO rule changes: the same gates activate sooner (operator-approved private-alpha\ncompression of the adoption windows; coordinated same-day re-pin of every verifier).\nBoth mirrors moved (types.ts + cairnx_ref.py). The four v24 boundary vectors are\nre-pointed to the n\n[…]\n4/64 vectors, crosslang battery\n(v20-v27 + nprofile + regex + siwc), audit:all (sealed-band burns 0, byte-identity\n1000/1000). Published to npm.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cairnx-core 0.1.33: pull activation heights in (V24 46,400 / V25 46,4…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-03T12:56:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bb59e41d3763be2e720d9c3fce7bb1590c27f1eb",
          "body": "…es to tip 45,959\n\nThe published spec ended at v2.1 while the shipped core gates v2.2-v2.7, so a\nthird-party implementer following the published CONVENTION diverges at 41,300\nand hard-forks on fees at 49,200. New sections: 25 (v2.2 uncap, anchor-keyed),\n26 (v2.3 nset zero-addr clear), 27 (v2.4 fee c\n[…]\nt\ncairnx-core publish; the docs no longer have to say pins stop pre-V21.\n\nDoc + test-vector data only: no dist change, cairnx-core stays 0.1.32.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CONVENTION.md: extend the normative spec to v2.7 + re-pin replay hash…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-03T08:37:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e232dfa3acf48693f1660741dee1af38fec5f379",
          "body": "…consumer-posture guards)\n\nNew zero-dep @inversealtruism/csd-indexwire 0.1.0: the REST row shapes (proposals,\nattestations, txs/outputs, /health) that were hand-maintained in 5 places, plus\nruntime guards extracted VERBATIM from the production consumer postures: fail-loud\non structure (requireArrayP\n[…]\ncairn project.ts, cairn-sdk typing) — consumers swap only after\nthis publishes (clarvis installs from npm). Lockstep 10 packages OK, dist fresh.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(indexwire): the csd-indexer wire contract as a package (types + …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-03T08:20:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5e915f7af8ba44276d10fd461feb43f0030667a",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: CONSENSUS_CHANGES 0.1.32 (V27 sale-embargo relaxation + polish)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-03T05:28:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4a40c0194a01dde3db9dd7e6d71129aca4f4c575",
          "body": "…rving polish (cairnx-core 0.1.32)\n\nV27 (gate 52,500, past V26 and the unrelated V23 nset-clear gate at 52,000): the young-name SALE\nembargo drops from COMMIT_MAX_BLOCKS (240, ~8h) to REG_COMMIT_MAX_BLOCKS (8, ~16min) for events\n>= V27. Provably redundant under the V25 sealed model (a finalized name\n[…]\nIP (the one\nfinding, the CONVENTION.md paragraph, fixed + empirically re-verified). Staged UNPUBLISHED (freeze\nuntil the operator token window).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx): V27 young-name sale-embargo relaxation + behavior-prese…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-03T05:21:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b2af107326a7f51ade4aa35825b7efbc28b03a6f",
          "body": "…ity; harden paidTo accumulator (Plan 57 R1)\n\nA configured-but-failing batch source (origin outage, 429 storm, empty page) now degrades the\none-shot cold start to the per-height provider instead of hard-failing it; sync() keeps the\nhard fail on purpose (incremental callers re-poll). Only the fetch i\n[…]\n dict semantics; hostile prototype-key addrs land as own\nkeys). 6 new asserts pin the degraded paths, the recovery path, and both hostile edges.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(light): syncFromCheckpoint fails SOFT on batch-source unavailabil…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-02T22:19:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56ef74a0548ebc725a80182d1e013fb11b364a23",
          "body": "…nsus-adjacent code (Plan 57 B4)\n\n- csd-crypto: parseScriptSig + signerAddrFromScriptSig (SCANNER contract:\n  >=198, trailing tolerated, no verify; drop-in for the chainscan.ts and\n  decode.ts copies) and recoverSigner (STRICT wallet contract: exact length,\n  verifyDigest, lowercase addr). One docum\n[…]\n proven for the\nhot-loadable packages, dist shapes verified ESM+CJS+nodenext types.\nIndependent review: SHIP (1 test fix + 4 nits, all applied).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sdk): widen the export surface that made consumers re-roll conse…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-02T19:45:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f86b76d75abcfbf00b024e973b2182c02f5a469",
          "body": "…x(client): 4xx no longer spends the retry budget; test(client): offline hostile-boundary suite\n\nPlan 57 B1 (Plan 56 items 15+19). The publish guard closes the 0.1.22\nbroken-workspace-artifact class: npm publish is refused (rehearsed), pnpm\nruns check-lockstep. The client fix aligns behavior with th\n[…]\nipline,\nverifyInputValues fail-closed). No dist rebuild here on purpose: the live\ncheckout's dists stay at 0.1.30 bytes until the B5b promotion.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "guard(publish): prepublishOnly pnpm+lockstep gate in all packages; fi…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-02T18:20:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c0bb71d084da500b4fdda5dd83e012de2ea5ced",
          "body": "…irective\n\nCritical-review of coverage found two real gaps where the fuel under-exercised\nthe invariants it claims to check:\n- name-give offers were rejected (listed within the 240-block young-name window,\n  and with expiresEpoch beyond the lease), so INV6 name-lock was ~untested\n  (nameLocked 26/50\n[…]\n to add as the system grows, and a pointer in\nCONSENSUS_CHANGES.md so a future consensus-changer runs it alongside test:crosslang.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit: widen invariant fuel (name-lock + token-to-token) + standing d…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T21:32:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2f8fb03e68df307b6593b417b186d763789b4f98",
          "body": "The prior tools (money-safety.mjs, race-harness.mjs) target ONE known failure\nmode. invariants.mjs is the general, future-proof tool: 7 properties that must\nhold for EVERY resolved state regardless of feature — no negative balance, token\nconservation (no mint-from-nothing), mint within supply cap, l\n[…]\no a real state.\n\nWire audit:invariants + chain into audit:all/audit:selftest. Report-only, non-\ngating, no consensus code touched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit: add general ledger-soundness invariants (feature-agnostic oracle)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T21:22:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "842cd08bf5a9fceade8ea6edcbed97459055e878",
          "body": "…age)\n\nbuildRec never emitted nfinalize, so the JS/Python differential fork-guard had ZERO coverage of the sealed reserve-to-finalize state transition (the gates sit far above the fuzz height range). Adds a regFlow (commit -> payment-free reveal -> winner-only nfinalize, with contested + reject vari\n[…]\nor, a pendingReg coverage counter, and a deterministic finalize self-check. 6000 sequences, 0 diverged; full test:crosslang green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "conformance: fuzz the V25/V26 reserve->finalize path (nfinalize cover…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T20:32:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "83451d735fece91036a42e91a755b83b22f2008f",
          "body": "…lse positives\n\nCritical-review pass on money-safety.mjs / race-harness.mjs found and fixed:\n- race-harness.mjs had no main-module guard, so importing its detectors\n  (findDisplacementBurns / findPaymentWithoutDelivery) ran the whole harness and\n  exited. Guard run() behind an import.meta.url check \n[…]\ns is unchanged (harness output byte-identical to before);\nthe guards only affect arbitrary stdin input. No consensus code touched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit tooling QA: fix importability, add detector self-test, guard fa…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T20:12:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e4a55e734c1bd5645249344c45fd4a3d887eafa1",
          "body": "money-safety.mjs and race-harness.mjs (already committed) are report-only\naudit tools for the honest-user-burn class (a fee anchored then rejected).\nWire them as on-demand pnpm scripts (audit:money-safety / audit:race /\naudit:all), kept OUT of the test:crosslang gate so they never block a merge.\nAdd\n[…]\ne observability-gap review, the rubric) and a README pointer.\n\nNo consensus code changed; no runtime guard shipped; nothing gated.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "audit tooling: wire non-gating audit:* scripts + AUDIT.md",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T19:44:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d7b6451fd07d95cf2e0af4583014b8a238874034",
          "body": "…ns 0)\n\nConfirms the V25 fix on the live gate: 'sealed-band (>=V25) name-race burns = 0', JS==Python 1000/1000.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "race-harness: gate-aware register-race (sealed flow >=V25 → loser bur…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T19:38:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3508ddc272015f78f3ef51b862d220da98f296ac",
          "body": "…ion, V26=51200 recapture)\n\nThe only consensus change vs 0.1.28 is the two activation heights (resolve.ts/records.ts\nbyte-identical). Gates chosen with the operator: ~1 week out, cleanly spaced, non-retroactive.\nV25 sits just above V24 (49200) so the fee-schedule vectors stay byte-identical; V26 sit\n[…]\n4 21/21, package vectors 64/64, e2e all pass.\n\n+ Plan 55 audit harnesses (money-safety, race-harness): report-only internal tools.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "cairnx-core 0.1.30: activate V25/V26 close gates (V25=51000 registrat…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T19:30:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8391ccdf0dfaed45e4a1598d5443dfa406242bb3",
          "body": "…lize\n\nAt height >= V26 a name reveal on a LAPSED name is payment-free and reserves it (internal\n`recaptures` map; the lapsed record stays UNTOUCHED so the premium basis is preserved and an\nabandoned reservation cannot bypass the premium); the decaying premium moves to the winner-only\nnfinalize, pri\n[…]\nclient can confirm it is still the winner\nbefore paying the premium. V26_HEIGHT dormant placeholder. Published cairnx-core 0.1.28.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "V26 sealed-recapture: payment-free reveal + winner-only premium nfina…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T18:32:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e7d652fb7522bbf67c7c88242e11f1b61148c0d",
          "body": "…reg fee-burn root fix)\n\nRegistration-only (recapture deferred to a future V26). At height >= V25_HEIGHT a .csd name\nreveal is payment-free and creates a pending reservation; the reg fee moves to a new winner-only\nnfinalize valid ONLY after the displacement contest freezes, so a lost race never burn\n[…]\n500 fuzz). REG_FINALIZE_GRACE_BLOCKS 20 per review.\nV25_HEIGHT dormant placeholder (set at rollout). Published cairnx-core 0.1.26.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "V25 sealed-reservation: payment-free reveal + winner-only nfinalize (…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-07-01T17:45:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ea48345bf227fc05d7ba6a036edc42d739f15218",
          "body": "Locks the V24 length-graded .csd registration/renewal fee gate (the audit flagged it as the\nonly recent gate without a dedicated crosslang test). Proves, against both the JS resolver and\nthe Python reference, byte-identical: a registration at height >= V24 paying the OLD (V18) fee\nis REJECTED on bot\n[…]\n V18 price still applies below the gate, and every length tier prices\nidentically. Wired into test:crosslang (21 cases, 0 failed).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(conformance): V24 name-fee JS-vs-Python crosslang parity gate",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-30T23:10:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "96fff0ddb528e27b8b05aa27de6b4572a481cd1e",
          "body": "A steeper, length-graded short-name premium (anti-squat), gated at V24_HEIGHT=49200\n(~7 days out for wallet CWS adoption). At height >= V24: name length <=3 -> 15 CSD,\n==4 -> 10, 5-9 -> 5, >=10 -> 3 CSD. Below the gate the V18 2-tier is byte-identical\n(every pre-V24 canonical hash + pinned vector un\n[…]\n 64/64 vectors, 1500-ledger fuzz spanning V24 (0 diverged),\nlockstep OK. Adversarial review found no consensus/fund vulnerability.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx-core): v2.4 length-graded .csd name-fee gate (V24) — 0.1.24",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-30T20:03:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3e981d74dda94bb6fe57653ca7b7fb8dc2cf1682",
          "body": "…hipped workspace:* deps)\n\n0.1.22 was published with `npm publish`, which (unlike `pnpm publish`) did NOT rewrite the\n`@inversealtruism/csd-codec: workspace:*` dependency to the real version, so the 0.1.22 tarball\nis uninstallable by npm consumers. Same code (V23_HEIGHT=52000 + paidTo hardening); republished\nas 0.1.23 via `pnpm publish` so the dep resolves to csd-codec 0.1.14. 0.1.22 is unpublished.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(cairnx-core): 0.1.22 -> 0.1.23 (republish; 0.1.22 npm tarball s…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-27T14:52:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "90a7aa24212c28b58615c64833520428706803d0",
          "body": "…rdening (cairnx-core 0.1.22)\n\nV23 nset-clear activation: V23_HEIGHT placeholder 43500 -> 52000 (set at tip ~41,836,\n~14 days runway so wallet 0.2.36 adopts before the unset feature activates chain-wide).\n\npaidTo hardening (release QA): the 5 external paidTo/pt amount reads now gate through\nAMOUNT_R\n[…]\nyte-identical, fuzz 3000 + adversarial 0-diverged,\ntest:crosslang green (v23 52/52, all V-gates), cairnx-core package tests green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx)!: V23 activation height 52000 + paidTo input-contract ha…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-27T14:42:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fbb29f11e958f96df06a35f70b8400c069c93e2c",
          "body": "…rce-only ([email protected])\n\nAn nset to the ZERO address at EVENT height >= V23_HEIGHT clears the resolver\nrecord (name falls back to owner; drops out of the primary candidate set) instead\nof pointing at 0x000..0. Gated on event height so all history is byte-identical;\nthe zero address is already \n[…]\n published/\nactivated: V23_HEIGHT is a placeholder above tip; publish + re-vendor ALL mirrors +\nwallet ADOPTION before raising it.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx)!: V23 nset-clear (\"unset\") consensus change — gated, sou…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-26T23:58:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d38253c4f1a711aa2e0e10745108a9eadf31d486",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: remove em dashes from READMEs and docs (house style, no AI-slop)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-26T19:38:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "027b89a2934cf2a4bfe41d7c06a59aacf05b51d5",
          "body": "…olution diagrams\n\nRewrite the cairnx-core README to lead with CNS (the .csd name service, first product to ship):\nlayered-overlay architecture (ASCII + mermaid), the .csd lifecycle state machine, the name-\nresolution + SPV trust flow (sequence), tokens, DvP swap flow, the build/determinism model, t\n[…]\nable, and honest limits. .csd suffix framed as UI-presentation (the rebrand\nto CNS + any suffix change is UI-only, not consensus).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx): CNS-led README with architecture + name-lifecycle + res…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-26T18:54:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f42d222a2ef3d5978769fbb4bee32a64822fff35",
          "body": "…ensus (UI-only)\n\nV22_HEIGHT=41300 un-caps offers/bids anchored >=V22 (effExpiry + creation rejects +\nofferExpiryHeightOf), keyed on the offer ANCHOR height so [V21,V22) and pre-V21 history stay\nbyte-identical (non-retroactive relaxation). Number.isSafeInteger(expiresEpoch) is now the\nsole consensus\n[…]\nrashing on fork-prone inputs.\n\nPublishes cairnx-core 0.1.20. Plan: docs/Plans/47. Independent review + 4-dim red-team = FORK-SAFE.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx-core)!: V22 — remove the offer/bid duration cap from cons…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-26T15:42:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eac040702e9d03aff8974b9eadddd3131d53c02b",
          "body": "…flow + pin-coherence guard\n\nSo the ecosystem doesn't re-drift into hand-mirrors (the bug class docs/Plans/46 deleted):\n- README \"Single source of truth\": cairnx-core is THE canonical impl; the consumer table (svc/UI/wallet/cli +\n  the Python oracle KEEP-list) and how each gets consensus; the full c\n[…]\nng consumers (cairnx svc,\n  cli) all pin the canonical cairnx-core version (the within-csd-sdk check-lockstep can't see siblings).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx): document the single-source consensus contract + change …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-24T19:17:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "791e2d601991d3557c2955aaf4f175c4f78e0ab1",
          "body": "…ts bytes)\n\nAudit Batch-1 finding (medium): Phase 0.5 (626c83f) added exports to cairnx-core but left the version at\n0.1.18 — so the local dist the vendored bundles were built from is \"0.1.18 with different bytes\" than the\npublished npm 0.1.18. That is the same-version-different-bytes hazard `check-\n[…]\nring is not in the bundled code, so the committed\nvendor bundles are unchanged). check-lockstep stays green (independent cadence).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump cairnx-core 0.1.18 → 0.1.19 (Phase 0.5 changed i…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-24T18:36:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "626c83f3a4751272a78ff16b92cf2bd004514a38",
          "body": "…S + codec re-exports (Phase 0.5)\n\nPrep for the shared-core de-duplication (cairn docs/Plans/46): make cairnx-core export EVERYTHING the\nbrowser UI / wallet / swapguard re-derive by hand, so the consumers can import a single source instead of\nmirroring consensus math (a re-derivation forks who-may-f\n[…]\nv20-69csd + v21-cap); tsc clean. No consensus change — canonicalState\nis byte-identical, so every pinned replay hash is preserved.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx-core): export the client selectors + reorg-safety + *_KEY…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-24T17:06:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb656aa86ecd66559d053b77929dee059e26f9cc",
          "body": "…ign docs\n\ncheck-lockstep.mjs required a single uniform version across packages/*, which has\nbeen false (and failing CI's `test` job) since cairnx-core bumped to 0.1.18 ahead of\nthe stable csd-* primitives at 0.1.14. Consensus changes (V18–V21) touch only\ncairnx-core; lockstep-bumping the other 8 by\n[…]\nns enforced by the conformance job (the REAL guard).\nNegative-tested: forbidden caret inter-dep and invalid semver still rejected.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): independent version cadence — fix check-lockstep + al…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-24T16:47:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8b80f81dcbcb29f7e16ca5a17125a57f3a0de74",
          "body": "…o npm\n\nPublishes the v2.1 CONVENTION.md, the 60-vector cases.json, the through-V20 replay-hashes, and the deduped resolve.ts to npm. Behaviorally BYTE-IDENTICAL to the published 0.1.17 (the dedup is a proven no-op + spec/vectors are conformance artifacts), so the live cairnx service + clarvis + the wallet bundle do NOT need a redeploy — they remain byte-identical. Deps: csd-codec 0.1.14.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): cairnx-core 0.1.18 — ship the remediation artifacts t…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-23T19:33:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "be252743bbc98f8612ad0cd0fc1f00678cf6e611",
          "body": "…s (JS + Python)\n\nThe token / partial / whole-CSD fill paths each re-implemented the v1.7 open-claim gate, the name-delivery+viaFill stamp, and the give-lock release — a 'fix it in six places' hazard the audit flagged (M1). Extracts openFillReject / deliverNameToBuyer / releaseGiveLock in resolve.ts\n[…]\nepublished — byte-identical to the live 0.1.17, so it propagates to npm + the wallet bundle at the next release; no deploy needed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(cairnx): dedup the three SCORE_FILL paths into shared helper…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-23T17:36:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e12aa54bfa4ea0faae42e4bb2fb8ef6976d3f5e1",
          "body": "…e (v2.1, normative v1.6-v2.1)\n\nThe published cairnx-core CONVENTION.md (the copy a third party 'npm install' fetches) was stale (DRAFT v1.0 header, missing the §5.1 A1-A7 expansion and all v1.6-v2.1 normative semantics) while the app-repo copy was kept current. Promotes the verified, full spec here\n[…]\n source of truth matches the shipping resolver. Byte-identical to the cairnx app-repo copy. Ships on the next cairnx-core publish.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(spec): promote the current CONVENTION.md to the published packag…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-23T16:20:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "797fe893d490bc6232de19668c82325a6726e95e",
          "body": "… (through V20, tip 39017)\n\nThe csd-sdk (published) replay-hashes copy was stale at 4 pre-V14 pins while the operator copy in the cairnx repo pinned through V19+. Syncs it to the freshly re-pinned set (through V20) so the artifact a third-party 'npm install cairnx-core' receives matches the real-chain anchor. Pure data sync; non-retroactive (historical hashes unchanged).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "conformance: sync published replay-hashes.json to the current pin set…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-23T16:06:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12c059729b900c0c77b1b6cd4bec2fb55126ad36",
          "body": "…e-ops/lapse/rejects) + wire V21 cross-lang into CI\n\nCloses the conformance-coverage gap the resolver audit found: cases.json (the CI-enforced, no-node bar + the JS<->Python differential) covered only through v1.8, so a 3rd-party resolver could pass every vector and still fork on V20 grace / V21 cap\n[…]\n. Negative control: a planted Python MAX_OFFER_EPOCHS off-by-one is caught by the new v21-atcap vector. No consensus code changed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(cairnx): add post-v1.8 conformance vectors (V20/V21/nprofile/nam…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-23T16:02:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ba9f9e1b62593deec1f65b81cc94e7d6457d9601",
          "body": "…1.17)\n\nLowers the v2.1 max offer/bid duration cap from the 42000 placeholder to 40100 so it activates ~40h out (tip ~38907) while clearing every conformance fixture (highest over-cap fixture is h40004) — zero fixture edits. Non-retroactive; all 4 mirrors agree (param-drift 0). resolve 37/37, fuzz 1500/1500, v20-grace 17/0, v21-cap 12/0 byte-identical JS=Python. Bumps cairnx-core 0.1.16->0.1.17.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx-core): set V21 offer-duration cap activation to 40100 (0.…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-23T13:23:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "27c4b9151dd2614eaa2188bb20449fc3f2004eb8",
          "body": "…hed to npm\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): cairnx-core 0.1.16 (v2.1 offer-duration cap) — publis…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-22T18:05:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "af4bbbd1e7536431892ff7a03237114062219617",
          "body": "… V21)",
          "is_bot": false,
          "headline": "Merge feat/v21-offer-duration-cap: v2.1 offer/bid duration cap (gated…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-22T17:56:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dffb77a775c9760240616ee3564acd56b3a66c33",
          "body": "… the SPV checkpoint shallow\n\nAn offer/bid could rest for an unbounded time (UI capped at 30d but the resolver did not cap, and non-UI\noffers rested far longer — e.g. PRBX2 @ ~60k-block life). A long-resting offer forces the swapguard SPV\ncheckpoint to sit below it (so its anchor tx stays merkle-ver\n[…]\n21_HEIGHT=42000 (a stale\nresolver vs a fresh one would diverge at the gate). Adjust V21_HEIGHT upward if deploy needs more runway.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(v2.1): max offer/bid duration cap (7 days), gated at V21 — keeps…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-22T17:56:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6f161eff3b5b99c1175ddad1c04136b857f2f106",
          "body": "An open-offer fill mining at the claim-window boundary was rejected after its\npayment was already on-chain → the buyer lost it (real incident: 69.csd, ~46 CSD).\nGated at V20_HEIGHT (non-retroactive):\n\n- claim window 15→40 + a bounded 5-block fill GRACE. Within the hold (window+grace)\n  the claimer's\n[…]\nn-hold,\n  JS==Python) + v20-incident-69csd.mjs (the real purchase now delivers, exact split).\n- bump cairnx-core 0.1.14 -> 0.1.15.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v2.0 (V20): open-lane claim→fill late-fill fund-loss fix (bounded grace)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-22T00:03:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f1a4671bbbba412c1298e58bc4583e7ac5bb5390",
          "body": "The 'test' job ran 'node scripts/check-lockstep.mjs' before the package\nbuild, but check-lockstep's M4 guard requires every package's dist/ to\nexist (dist/ is gitignored) -> 'no dist/' -> exit 1 -> build+tests were\nskipped and CI went red. Reorder so 'pnpm -r build' runs before the\nlockstep check. Also add a workflow-level concurrency block to cancel\nsuperseded in-flight runs.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: build before check-lockstep in test job + add concurrency",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-21T00:58:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4481e2e85c04408e7ac89ce228f76ac765dd85eb",
          "body": "…ADME) — 0.1.14\n\nNo runtime/consensus change (differential vs the live node stays 0; suites byte-identical):\n- Comment-truth: resolve.ts header + records.ts onlyKeys + conformance/README now name what is GUARDED\n  by the conformance differential vs merely asserted (the audit's over-claim findings).\n\n[…]\nackage without one).\nDeferred (documented): TREASURY_ADDR single-sourcing (now consts-parity-guarded) + the 600L resolve.ts split.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "quality: Phase-2 AI-slop pass (comment-truth + type hygiene + siwc RE…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-20T13:15:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84e61e19743a052c3d5c874b735f7988dc9e3ff3",
          "body": "… lockstep 0.1.13\n\nForward consensus codec executed-verified against the live Rust node (JS == Python ==\nRust, 0 divergence); every change is reject-more, never accept-different (replay-identical).\n\nCRITICAL/HIGH:\n- C1: cairnx_ref.py schema regexes .match -> .fullmatch (trailing-\\n cross-language fo\n[…]\n17 SIWC line-terminators.\n\nCONSENSUS_CHANGES.md documents V16-V19 + this remediation. All suites green; live re-anchor 0-mismatch.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security: Phase-1 audit remediation (csd-sdk-deep-audit-2026-06-20) +…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-20T13:04:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3dc28d3f6a1ae5a2724fbdf4acbcf7feb31b9ab8",
          "body": "…p version bump\n\nSets the v1.9 ENS-class identity (nprofile) activation height to 36700 (~7.4h above the deploy tip 36477; non-retroactive — no existing record is reinterpreted, replay-hash pins unchanged) and bumps all 9 csd-* packages 0.1.11 -> 0.1.12 in lockstep (exact-version discipline; deps via workspace:*). Build + META-1 23/23 + nprofile 42/42 + dormancy pins green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release(v0.1.12): activate v1.9 nprofile (V19_HEIGHT=36700) + lockste…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-20T03:02:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9ef8a009c2cd89aea3ccf3627dfd0eb246a768db",
          "body": "Height-gated at V19_HEIGHT (placeholder 50000, non-retroactive). A new inert nprofile record carries a charset-locked string->string identity map on a .csd name (avatar/display/socials/url) — cosmetic, never a send target.\n\n- types/records/resolve: NameProfileRecord, PKEY (ASCII => sort-invariant), \n[…]\nGED (dormancy). Live real-chain differential: 0-diverged. Spec=cairn docs/ecosystem/36. Independently red-teamed: SHIP-AS-DORMANT.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx-core): v1.9 nprofile — ENS-class identity records (DORMANT)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-20T02:42:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "821091c10bec99cff5a2859ed11563ef0204db81",
          "body": "Reject a SIWC message issued in the future (beyond skew) or >1h ago. The age bound also caps effective\nvalidity to ~1h from issuance regardless of a far-future expirationTime. Lockstep with cairn vendored copy.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security(phase2): SIWC-IAT — bound issuedAt in verifySiwc",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-19T19:31:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d566dbc34e1ee5a909fd4c8b5455f48b107339e1",
          "body": "…e=true\n\nExcludes immature/locked coinbase UTXOs by default so SDK consumers don't build txs spending\nun-spendable outputs (the node would silently reject them). Pass {available:false} for the full set.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security(phase1): TXB-1-SDK — CsdClient.utxos() defaults to ?availabl…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-19T19:17:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e8afb0b3b048d698300a2e9097c47c78fc104f1a",
          "body": "Realigned the drifted versions (L0 @0.1.8, cairnx-core/siwc @0.1.10) to one version and\nPUBLISHED all 9 public packages to npm @0.1.11, incl. the new @inversealtruism/csd-siwc\n(first publish) and cairnx-core (0.1.9→0.1.11). check-lockstep OK; build + per-package tests\n+ JS⇄Python conformance (37/37, SIWC 4/4, 1500-fuzz 0-diverged) all green pre-publish.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: lockstep realign — all csd-* packages @0.1.11 (published)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-17T15:31:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c55350d611f6e22b793266e4310c709f1cc2e154",
          "body": "…SIWC\n\nThe cross-language byte-contract (resolver, record codec, and now SIWC) is what\nactually prevents an inter-implementation chain fork, but it was never run in CI —\nonly the version-lockstep check was. And test:crosslang omitted the new csd-siwc\n4-impl byte-contract.\n\n- test:crosslang now also \n[…]\n csd-* versions realign ahead of a publish).\n\nVerified green locally: META-1 23/23, resolve 37/37, SIWC 4/4, fuzz 1500 0-diverged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(conformance): enforce the JS⇄Python cross-language lockstep + add …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-17T13:04:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3476498bd623dc43eaee79f22baf104aab395786",
          "body": "feat: @inversealtruism/csd-siwc — Sign in with CSD (Phase 1)",
          "is_bot": false,
          "headline": "Merge pull request #1 from InverseAltruism/feat/siwc",
          "author_name": "Inverse",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-17T12:33:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5acd186aa9156fad902740bc0114359f5bc524e",
          "body": "…check\n\nsiwc_ref.py is an independent Python reference for the SIWC byte-contract; crosscheck-siwc.mjs feeds\nthe same field-sets (incl. astral/U+FFFF statement) to the shipping JS impl and Python and asserts\nbyte-identical message+digest == pinned vectors. 4 cases green. SIWC has no object-key sorti\n[…]\nal-JSON UTF-16 traps don't apply; the only determinism surfaces are exact line layout + UTF-8\nhashing, both proven cross-language.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(siwc): conformance vectors + Python reference + JS⇄Python cross-…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-17T08:51:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2c2aeae93b5f57822102ec7650693cf728d921dc",
          "body": "Canonical audience-bound auth byte-contract: buildSiwcMessage / parseSiwcMessage (strict\ncanonical round-trip) / siwcDigest (sha256d(taggedHash('CSD-SIWC-v1', msg))) / signSiwc /\nverifySiwc (ordered fail-closed: domain/chain/nonce/time + sig + hash160==account) /\ngenerateNonce / CSD_CHAIN_MAINNET (c\n[…]\n incl. cross-domain\nreplay rejection + digest domain-separation; builds esm/cjs/dts. Version 0.1.10 (realign\nlockstep at publish).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(siwc): add @inversealtruism/csd-siwc — Sign in with CSD (CAIP-122)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-17T08:34:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "481d56c303bfb06e2d72af6f4dae71b842f50843",
          "body": "…+ v0.1.10 republish marker for V18\n\n- resolve.ts + cairnx_ref.py: document the known, bounded, non-fork cooldown\n  bypass (a 2nd-address intervening claim resets the per-offer cooldown) for the\n  lane re-enable phase. Comment-only — replay-identical, JS+Python lockstep.\n- bump cairnx-core 0.1.9 -> \n[…]\n.1.10 as the clean republishable marker including the\n  V18 2-tier name fee (height-gated, dormant) committed since the 0.1.9 tag.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx-core): V17 cooldown intervening-claimer bound (lockstep) …",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-16T22:33:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6d103625f738c91efcc6a2100821212627a486a1",
          "body": "… vectors)\n\n≤4 chars = 6.7 CSD, ≥5 chars = 3 CSD, gated at V18_HEIGHT=40000 (dormant placeholder). Below V18 the original 5-tier curve is byte-frozen so historical replay + pinned vectors are unchanged. nameRegFee/expiredClaimFee are height-aware and threaded through resolve.ts; mirrored exactly in cairnx_ref.py. 5 new v18-* vectors via gen-v18-vectors.mjs; cross-impl 37/37 byte-identical + 1500-fuzz 0-diverged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cairnx): V18 simplified 2-tier name fee (height-gated, lockstep,…",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-16T18:33:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3d6ef58b2cc132276f680c3fffdb638c3556e19c",
          "body": "Document why V17_HEIGHT=34000 is safe even if the tip crosses it before the UI\nrollout completes: V17 is non-retroactive (a score=50 attest / open CSD offer\nbelow the gate is a no-op), and no such event exists below it in the wild to\nreinterpret. Comment-only — the compiled dist is byte-identical, so the published\n@inversealtruism/cairnx-core@0.1.9 needs NO republish.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(cairnx-core): clarify V17_HEIGHT non-retroactivity (comment-only)",
          "author_name": "InverseAltruism",
          "author_login": "InverseAltruism",
          "committed_at": "2026-06-16T12:11:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 7,
      "commits_last_year": 147,
      "latest_release_at": "2026-06-16T22:33:02Z",
      "latest_release_tag": "v0.1.10",
      "releases_from_tags": true,
      "days_since_last_push": 6,
      "active_weeks_last_year": 8,
      "days_since_latest_release": 42,
      "mean_days_between_releases": 1.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@inversealtruism/csd-tx",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-tx",
          "is_deprecated": false,
          "latest_version": "0.1.17",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 835,
          "first_published_at": "2026-06-06T22:22:48.875000Z",
          "latest_published_at": "2026-07-17T18:00:19.988000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 12
        },
        {
          "name": "@inversealtruism/csd-siwc",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-siwc",
          "is_deprecated": false,
          "latest_version": "0.1.15",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 251,
          "first_published_at": "2026-06-17T15:29:41.765000Z",
          "latest_published_at": "2026-07-02T22:58:54.320000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 26
        },
        {
          "name": "@inversealtruism/csd-codec",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-codec",
          "is_deprecated": false,
          "latest_version": "0.1.15",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 932,
          "first_published_at": "2026-06-06T22:22:40.943000Z",
          "latest_published_at": "2026-07-02T22:58:44.594000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 26
        },
        {
          "name": "@inversealtruism/csd-light",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-light",
          "is_deprecated": false,
          "latest_version": "0.1.18",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 759,
          "first_published_at": "2026-06-06T22:22:46.989000Z",
          "latest_published_at": "2026-07-13T14:01:55.630000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 16
        },
        {
          "name": "@inversealtruism/cairnx-core",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/cairnx-core",
          "is_deprecated": false,
          "latest_version": "0.1.40",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 30,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3405,
          "first_published_at": "2026-06-15T08:32:45.999000Z",
          "latest_published_at": "2026-07-21T12:22:57.894000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        },
        {
          "name": "@inversealtruism/csd-client",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-client",
          "is_deprecated": false,
          "latest_version": "0.1.15",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 501,
          "first_published_at": "2026-06-06T22:22:43.157000Z",
          "latest_published_at": "2026-07-02T22:58:47.979000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 26
        },
        {
          "name": "@inversealtruism/csd-crypto",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-crypto",
          "is_deprecated": false,
          "latest_version": "0.1.15",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 719,
          "first_published_at": "2026-06-06T22:22:44.976000Z",
          "latest_published_at": "2026-07-02T22:58:49.629000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 26
        },
        {
          "name": "@inversealtruism/csd-vectors",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@inversealtruism/csd-vectors",
          "is_deprecated": false,
          "latest_version": "0.1.15",
          "repository_url": "https://github.com/InverseAltruism/csd-sdk",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 336,
          "first_published_at": "2026-06-06T22:22:39.092000Z",
          "latest_published_at": "2026-07-02T22:58:42.880000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 26
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/cairnx/tsconfig.json",
        "packages/client/tsconfig.json",
        "packages/codec/tsconfig.json",
        "packages/crypto/tsconfig.json",
        "packages/indexwire/tsconfig.json",
        "packages/light/tsconfig.json",
        "packages/registry/tsconfig.json",
        "packages/siwc/tsconfig.json",
        "packages/tx/tsconfig.json",
        "packages/vectors/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 72348,
      "source_files_sampled": 98,
      "oversized_source_files": 2,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 18646
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 4,
        "malicious_count": 0,
        "assessed_package": "npm:@inversealtruism/csd-tx@0.1.17",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/cairnx/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/client/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/codec/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.8.0"
        },
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@noble/curves",
          "manifest": "packages/crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.9.7"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.8.0"
        },
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/light/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-client",
          "manifest": "packages/light/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/registry/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-crypto",
          "manifest": "packages/registry/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/siwc/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-crypto",
          "manifest": "packages/siwc/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/siwc/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.8.0"
        },
        {
          "name": "@inversealtruism/csd-codec",
          "manifest": "packages/tx/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@inversealtruism/csd-crypto",
          "manifest": "packages/tx/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 1,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "InverseAltruism",
          "commits": 147,
          "avatar_url": "https://avatars.githubusercontent.com/u/129900527?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f2ac1286f3cd9cc695eb8bae7260af24daa2d980",
        "ran_at": "2026-07-29T19:13:07Z",
        "aggregate_score": 3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T18:00:52Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-06-17T12:33:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/InverseAltruism/csd-sdk",
    "host": "github.com",
    "name": "csd-sdk",
    "owner": "InverseAltruism"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 54,
      "inputs": {
        "security": 44,
        "vitality": 71,
        "community": 34,
        "governance": 52,
        "engineering": 62
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 71,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 147,
              "human_commit_share": 1,
              "days_since_last_push": 6,
              "active_weeks_last_year": 8
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "8/52 weeks with commits",
                "points": 5.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "147 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 147
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 7,
              "latest_release_tag": "v0.1.10",
              "releases_from_tags": true,
              "days_since_latest_release": 42,
              "mean_days_between_releases": 1.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "7 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 42 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 42
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 34,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 65,
            "inputs": {
              "packages": [
                "@inversealtruism/csd-tx",
                "@inversealtruism/csd-siwc",
                "@inversealtruism/csd-codec",
                "@inversealtruism/csd-light",
                "@inversealtruism/cairnx-core",
                "@inversealtruism/csd-client",
                "@inversealtruism/csd-crypto",
                "@inversealtruism/csd-vectors"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 7738
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "7,738 downloads/month across npm",
                "points": 51.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 7738,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 52,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 1,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "1/1 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 1,
                      "decided": 1
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "followers": 16,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "InverseAltruism",
              "public_repos": 12,
              "account_age_days": 1211
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "16 followers of InverseAltruism",
                "points": 8.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 16,
                      "login": "InverseAltruism"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "12 public repos, account ~3 yr old",
                "points": 14.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 12
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@inversealtruism/csd-tx",
                "@inversealtruism/csd-siwc",
                "@inversealtruism/csd-codec",
                "@inversealtruism/csd-light",
                "@inversealtruism/cairnx-core",
                "@inversealtruism/csd-client",
                "@inversealtruism/csd-crypto",
                "@inversealtruism/csd-vectors"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "30 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 62,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "http://cairn-substrate.com",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "http://cairn-substrate.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@inversealtruism/csd-tx@0.1.17 runtime dependency closure — what installing the published package pulls in — 4 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@inversealtruism/csd-tx@0.1.17",
                  "assessed": 4
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 4,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 4,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 68,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 18646
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/cairnx/tsconfig.json",
                "packages/client/tsconfig.json",
                "packages/codec/tsconfig.json",
                "packages/crypto/tsconfig.json",
                "packages/indexwire/tsconfig.json",
                "packages/light/tsconfig.json",
                "packages/registry/tsconfig.json",
                "packages/siwc/tsconfig.json",
                "packages/tx/tsconfig.json",
                "packages/vectors/tsconfig.json"
              ],
              "agent_commit_share": 0.95,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/cairnx/tsconfig.json, packages/client/tsconfig.json, packages/codec/tsconfig.json, packages/crypto/tsconfig.json, packages/indexwire/tsconfig.json, packages/light/tsconfig.json, packages/registry/tsconfig.json, packages/siwc/tsconfig.json, packages/tx/tsconfig.json, packages/vectors/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/cairnx/tsconfig.json, packages/client/tsconfig.json, packages/codec/tsconfig.json, packages/crypto/tsconfig.json, packages/indexwire/tsconfig.json, packages/light/tsconfig.json, packages/registry/tsconfig.json, packages/siwc/tsconfig.json, packages/tx/tsconfig.json, packages/vectors/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "95 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 72348,
              "source_files_sampled": 98,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/98 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 98,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T19:13:11.672794Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/InverseAltruism/csd-sdk.svg",
  "full_name": "InverseAltruism/csd-sdk",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.