Öffentliches Register
Software-GesundheitsberichtSchema 0.25.0 · Metriken 1.13.0 · 2026-07-21 21:36 UTC

OpenSIN-Code / SIN-Code

SIN-Code — the verification-first coding agent. CLI + TUI + WebUI + unified MCP server (44+ tools), multi-agent orchestrator with critic/adversary/governor, persistent memory, LSP.

Go · PythonMIT★ 1 Stern⑂ 0 Forksseit Mai 2026Auf GitHub ansehen ↗

OpenSIN-Code/SIN-Code erreicht einen Gesundheitsindex von 60 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Engineering Quality (84/100) ab, am schwächsten bei Community & Adoption (36/100). Zuletzt vor 2 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

60
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

60
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

OpenSIN-CodeOrganisation
1 Follower56 öffentliche Reposseit Apr. 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/OpenSIN-Code/SIN-Codev1.9.0-61vor 43 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

74Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 2 Tagen
4.8/36Commit-Rhythmus — 7/52 Wochen mit Commits
18/18Commit-Volumen — 793 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year793
human_commit_share0,99
days_since_last_push2
active_weeks_last_year7
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 43 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 22 Tagen
27/27Release-Rhythmus — ein Release etwa alle 2,4 Tage
6/10OpenSSF Scorecard: Signed-Releases — 4 out of the last 5 releases have a total of 4 signed artifacts.
Verwendete Eingangsdaten
releases_count43
latest_release_tagv3.26.0
releases_from_tagsnein
days_since_latest_release22
mean_days_between_releases2,4

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

36Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 1 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templateja

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

57Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.5/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 98 % der Commits
4.1/13.5Breite der Beitragenden — 3 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Verwendete Eingangsdaten
bus_factor1
contributors_sampled3
top_contributor_share0,978
Wie die Bewertung erfolgt
44.1/46.8Issue-Lösungsquote — 94 % der Issues geschlossen
29.5/38.3PR-Annahme — 115/149 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs115
open_issues20
closed_issues328
issue_closed_ratio0,943
closed_unmerged_prs34
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
2.2/25Reichweite des Inhabers — 1 Follower von OpenSIN-Code
13.2/25Kontohistorie — 56 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers1
owner_typeOrganization
is_verified
owner_loginOpenSIN-Code
public_repos56
account_age_days82

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 43 Tagen
20/20Versionshistorie — 61 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/OpenSIN-Code/SIN-Code
ecosystemsgo
any_deprecatednein
min_days_since_publish43

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

84Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 14 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — .golangci.yml
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.

Dokumentation

90Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://sin-code-indol.vercel.app
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepagehttps://sin-code-indol.vercel.app
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

44Gefährdet · 16 % des Gesamtindex

Sicherheitslage

44Gefährdet
Wie die Bewertung erfolgt
5.2/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — keine Daten
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
4.5/7.5Signed-Releases — 4 out of the last 5 releases have a total of 4 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 19 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,4
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection, ci_tests. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

82Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 99 von 99 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes75.242
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — .golangci.yml
11/11Statische Typprüfung — desktop/web/tsconfig.json
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
8/8Automatisierte Wartung — 1 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum, uv.lock
has_dockerfileja
typed_languageja
bootstrap_filesMakefile
has_devcontainernein
has_linter_configja
typecheck_configsdesktop/web/tsconfig.json
agent_commit_share0
toolchain_manifestsSIN-Code-Container-Tool-Go/go.mod, SIN-Code-SAST-Tool/go.mod, SIN-Code-SBOM-Generator-Go/go.mod, SIN-Code-SCA-Tool-Go/go.mod, SIN-Code-Secrets-Scanner/go.mod, desktop/src-tauri/Cargo.toml, go.mod, src/sin_code_bundle/tools/mcp_server_builder/templates/go-mcp/go.mod
dependency_bot_commit_share0,01
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
54.9/55Handhabbare Dateigrößen — 4/1.646 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes157.443
source_files_sampled1.646
oversized_source_files4
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
20/20MCP-Server
40/40Lauffähige Beispiele — examples, sample
Verwendete Eingangsdaten
example_dirsexamples, sample
has_mcp_signalja
api_schema_files

Eckdaten

1GitHub-Sterne
3Mitwirkende
793Commits, letzte 12 Monate
2Tage seit letztem Push
43Releases
1Bus-Faktor
20offene Issues
Go, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Could not fetch pypi package 'sin-code' from its registry
  • Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-SAST-Tool' from its registry
  • Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-SCA-Tool-Go' from its registry
  • Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-Secrets-Scanner' from its registry
  • Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-Container-Tool-Go' from its registry
  • Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-SBOM-Generator-Go' from its registry
  • Could not fetch pypi package 'sin-sbom-generator' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 4.4 / 10
4.4Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-21 21:36 UTC

7Binary-Artifactsbinaries present in source code
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
6Signed-Releases4 out of the last 5 releases have a total of 4 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities19 existing vulnerabilities detected
Direkte Abhängigkeiten 46
RegistryPaketVersionsvorgabeManifest
Gogithub.com/stretchr/testifyv1.8.4SIN-Code-Container-Tool-Go/go.mod
Gogithub.com/fatih/colorv1.16.0SIN-Code-SAST-Tool/go.mod
Gogithub.com/spf13/cobrav1.8.0SIN-Code-SAST-Tool/go.mod
Gogithub.com/stretchr/testifyv1.8.4SIN-Code-SBOM-Generator-Go/go.mod
Gogithub.com/google/uuidv1.6.0SIN-Code-SBOM-Generator-Go/go.mod
PyPIclick>=8.0SIN-Code-SBOM-Generator/pyproject.toml
PyPIrich>=13.0SIN-Code-SBOM-Generator/pyproject.toml
Gogithub.com/stretchr/testifyv1.8.4SIN-Code-SCA-Tool-Go/go.mod
Gogithub.com/fatih/colorv1.16.0SIN-Code-Secrets-Scanner/go.mod
Gogithub.com/spf13/cobrav1.8.0SIN-Code-Secrets-Scanner/go.mod
Gocharm.land/bubbles/v2v2.1.0go.mod
Gocharm.land/bubbletea/v2v2.0.7go.mod
Gocharm.land/glamour/v2v2.0.1go.mod
Gocharm.land/lipgloss/v2v2.0.4go.mod
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/Songmu/skillsmithv0.1.0go.mod
Gogithub.com/charmbracelet/bubblesv1.0.0go.mod
Gogithub.com/charmbracelet/bubbleteav1.3.10go.mod
Gogithub.com/charmbracelet/lipglossv1.1.0go.mod
Gogithub.com/chromedp/cdprotov0.0.0-20260427013145-5737772c319bgo.mod
Gogithub.com/chromedp/chromedpv0.15.1go.mod
Gogithub.com/modelcontextprotocol/go-sdkv1.6.1go.mod
Gogithub.com/rogpeppe/go-internalv1.15.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/pflagv1.0.10go.mod
Gogo.etcd.io/bboltv1.5.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogolang.org/x/modv0.37.0go.mod
Gogolang.org/x/netv0.56.0go.mod
Gogolang.org/x/sysv0.46.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gomodernc.org/sqlitev1.53.0go.mod
PyPItyper>=0.12pyproject.toml
PyPIpyyaml>=6.0pyproject.toml
PyPIclick>=8.0pyproject.toml
PyPIrich>=13.0pyproject.toml
PyPIfastmcp>=2.0pyproject.toml
PyPIjinja2>=3.0pyproject.toml
PyPIhttpx>=0.27pyproject.toml
PyPIgitpython>=3.1pyproject.toml
PyPItomli_w>=1.0pyproject.toml
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 18490,
      "has_wiki": true,
      "homepage": "https://sin-code-indol.vercel.app",
      "languages": {
        "Go": 10216671,
        "CSS": 7336,
        "HTML": 10964,
        "Ruby": 2348,
        "Rust": 5191,
        "Shell": 104147,
        "Python": 1540356,
        "Makefile": 1193,
        "JavaScript": 40610,
        "PowerShell": 1931,
        "TypeScript": 37273
      },
      "pushed_at": "2026-07-19T11:42:52Z",
      "created_at": "2026-05-30T04:07:24Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-14T05:30:43Z",
      "description": "SIN-Code — the verification-first coding agent. CLI + TUI + WebUI + unified MCP server (44+ tools), multi-agent orchestrator with critic/adversary/governor, persistent memory, LSP.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "OpenSIN-Code",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/280656502?v=4",
      "created_at": "2026-04-30T09:44:02Z",
      "is_verified": null,
      "public_repos": 56,
      "account_age_days": 82
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.26.0",
          "kind": "minor",
          "published_at": "2026-06-29T16:12:47Z"
        },
        {
          "tag": "v3.25.0",
          "kind": "minor",
          "published_at": "2026-06-25T10:10:07Z"
        },
        {
          "tag": "v3.24.1",
          "kind": "patch",
          "published_at": "2026-06-25T03:16:44Z"
        },
        {
          "tag": "v3.24.0",
          "kind": "minor",
          "published_at": "2026-06-24T21:12:54Z"
        },
        {
          "tag": "v3.23.0",
          "kind": "minor",
          "published_at": "2026-06-18T23:20:41Z"
        },
        {
          "tag": "v3.20.0",
          "kind": "minor",
          "published_at": "2026-06-17T21:00:23Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-06-11T13:19:59Z"
        },
        {
          "tag": "v1.7.3",
          "kind": "patch",
          "published_at": "2026-06-11T08:01:19Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-06-11T08:01:44Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-06-08T09:42:56Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-06-08T08:46:26Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-06-08T08:26:36Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-06-08T07:54:06Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-06-08T07:33:30Z"
        },
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2026-06-07T21:09:55Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-06-07T20:56:14Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-06-07T16:25:12Z"
        },
        {
          "tag": "v1.0.9",
          "kind": "patch",
          "published_at": "2026-06-07T15:38:12Z"
        },
        {
          "tag": "v1.0.8",
          "kind": "patch",
          "published_at": "2026-06-07T14:53:22Z"
        },
        {
          "tag": "v1.0.7",
          "kind": "patch",
          "published_at": "2026-06-07T14:28:10Z"
        },
        {
          "tag": "v1.0.6-sin-code",
          "kind": "prerelease",
          "published_at": "2026-06-07T13:05:26Z"
        },
        {
          "tag": "v1.0.5-sin-code",
          "kind": "prerelease",
          "published_at": "2026-06-07T11:36:53Z"
        },
        {
          "tag": "v1.0.4-sin-code",
          "kind": "prerelease",
          "published_at": "2026-06-07T10:50:59Z"
        },
        {
          "tag": "v1.0.3-sin-code",
          "kind": "prerelease",
          "published_at": "2026-06-07T10:38:42Z"
        },
        {
          "tag": "v1.0.2-sin-code",
          "kind": "prerelease",
          "published_at": "2026-06-07T10:27:29Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2026-06-05T17:17:50Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-06-05T17:14:49Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-06-05T13:09:37Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-06-05T11:03:46Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-06-05T10:41:16Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-06-05T07:41:42Z"
        },
        {
          "tag": "v0.6.6",
          "kind": "patch",
          "published_at": "2026-06-04T17:24:26Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-06-04T17:08:43Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-06-04T16:35:54Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-06-04T16:07:47Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-06-04T15:39:25Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-06-04T15:17:53Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-04T14:15:17Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-06-04T14:04:36Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-06-04T13:54:01Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-06-04T13:06:05Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-06-04T12:56:38Z"
        },
        {
          "tag": "v0.5.0-ceo-audit-v3",
          "kind": "prerelease",
          "published_at": "2026-06-04T12:38:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "dbc4b59c14e259e097ab62abd6dce035ec6d680d",
          "body": null,
          "is_bot": false,
          "headline": "chore: final sync before local cleanup",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-14T05:30:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e868ec556e1039ad08052841fe7d1c5eaea98706",
          "body": "- skill-process-gsd: fill empty context/, frameworks/, tasks/, templates/ with content\n- skill-process-pipeline: add missing frameworks/, tasks/, templates/ with content\n- skill-multimodal-web-tools: move lifecycle from metadata to top-level frontmatter\n- skill-multimodal-youtube: move lifecycle+sou\n[…]\nntmatter\n- skill-productivity-notion: move lifecycle+sources from metadata to top-level, fix 'bundled'→'external'\n- All 47 bundled skills pass: python3 scripts/validate_skill.py --all-bundled --strict",
          "is_bot": false,
          "headline": "fix: validate all 47 skills — 0 failures",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T02:20:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e15d56a518e4ba491cabdc48d320aa5b81d42bc4",
          "body": "- Version badge: v3.25.0 → v3.29.2\n- Add pipeline, GSD, DoDone to 'Why SIN-Code?' section\n- Update bundled skills: 41→43+, add process skills (gsd, pipeline, dodone, self-review, delegate)\n- Remove skill-code-plan and skill-planning-enterprise from skill list (absorbed into plan v2)\n- Add multimodal-skills and github-readme to category table\n- Add GSD + pipeline + unified planning documentation sections\n- Add 'sin-code gsd' commands to Usage section",
          "is_bot": false,
          "headline": "docs: update README to v3.29.2 — pipeline, GSD, DoDone, unified planning",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T02:08:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d1ff9cb226530de332faa97d81a92a6fa930164",
          "body": "Added 37 systems across all 10 stages:\n\nStage 0: + instinct+RAG, context-bridge, triage, config validate, rules loading,\n  sandbox verify, egress check, lsp-config, mcp-install discover, profile verify,\n  gh doctor, autolevel, agentteams setup, telemetry ON (16 new)\nStage 2: + research, web search (\n[…]\nP systems: stop-gate/dodone (M3), self-review, sin_quality_gate,\nsandbox+egress (M3/M4), web search (M8).\n\nLightweight alternatives: sin-code prp, sin-code auto (autopilot), plan --lite, dodone check.",
          "is_bot": false,
          "headline": "feat: pipeline v3.29.2 — 55+ systems, ~60% ecosystem coverage",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T01:26:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "493bc7d7981d4cf1df3ef7ed33b42366f3a13a03",
          "body": "Stage 0: PRE-FLIGHT — doctor, lessons query, memory prime, goal+contract, checkpoint\nStage 1: GRILL — adversarial design interview (unchanged)\nStage 2: PLAN — + cartographer (sckg), episodic memory, plan-merge (fusion)\nStage 3: GSD — + goal subtasks\nStage 4: EXECUTE — + worktree isolation, conflict \n[…]\nync (NEW)\n\nNew: 37 systems integrated (was 14). ~40% ecosystem coverage (was ~5%).\nAdded: failure handling table, checkpoint strategy, degradation rules, cost awareness, integration map ASCII diagram.",
          "is_bot": false,
          "headline": "feat: pipeline v2 — 10 stages, ~40% ecosystem coverage",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T01:19:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b312ed63891a8e6e66678614baea5f17f0789bd8",
          "body": "6-stage pipeline: grill-me → plan v2 → GSD → delegate-subagents → self-review → dodone check\n- SKILL.md: full stage-by-stage protocol with gates, failure handling, cost awareness\n- context/pipeline-context.md: stage boundaries, degradation rules, loop-back logic\n- scripts/sin-pipeline.sh: shell wrapper for GSD init + dodone check stages\n- Slash command: /pipeline <task> in Infra-SIN-OpenCode-Stack",
          "is_bot": false,
          "headline": "feat: add skill-process-pipeline — full SIN-Code stack in one shot",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T01:09:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "168e99662060c7e0a30f3cae75e93df3c5623ff6",
          "body": "…lan into plan v2\n\nGSD Go package (cmd/sin-code/internal/gsd/):\n- 8 files: gsd.go, project.go, phase.go, plan.go, execute.go, state.go, gsd_test.go, gsd.doc.md\n- Pure stdlib, CGO_ENABLED=0, 0o644 writes (M2 mandate)\n- 9 tests, all passing with -race -count=1\n- Types: Project, Phase, Plan, Task, Stat\n[…]\nan v2 → delegate-subagents → self-review → dodone\n\nDeleted:\n- skill-code-plan (absorbed into plan v2 --from-spec mode in Infra repo)\n- skills/planning-skills/ directory (empty after previous deletion)",
          "is_bot": false,
          "headline": "feat: GSD Go-native — replaces 8 npm GSD skills + absorb skill-code-p…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T01:03:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a074608b54d972d017bc4d710cfd53db10b47007",
          "body": "- Delete skill-planning-enterprise (merged into plan v2 --cli mode in Infra)\n- skill-process-delegate: mark SUPERSEDED, point to delegate-subagents\n- skill-process-grill: add plan v2 to Related Skills, add Companion Tools\n- skill-process-grill: add dodone + self-review cross-refs",
          "is_bot": false,
          "headline": "feat: merge plan skills + mark delegate v1 superseded",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-02T00:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "344ba9026fa1934ec997a2a06530379e77b8fa11",
          "body": "…w and lazy skills\n\n- New skill: skill-process-dodone (8 files: SKILL.md, context/, frameworks/, tasks/, templates/, scripts/, LICENSE)\n- skill-code-lazy: add DoDone to Related skills\n- skill-process-self-review: add 'Maschinelle Ergänzung: SIN-DoDone' section\n- Pipeline: self-review (CEO) → dodone check (machine) → Exit 0 = WIRKLICH FERTIG",
          "is_bot": false,
          "headline": "feat: add skill-process-dodone + cross-reference DoDone in self-revie…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-07-01T23:53:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41779d350007a569d9eb3c8f81db1b12d579258b",
          "body": "- Documented auto-extract-cookies.py workflow (browser_cookie3)\n- Added Infisical round-trip instructions (extract → store → download on other Macs)\n- Added manual fallback instructions (DevTools)\n- Updated all 3 skill locations: SIN-Code repo, Infra repo, opencode config",
          "is_bot": false,
          "headline": "docs: YouTube cookie auto-extraction guide in SKILL.md",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T17:52:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fad2a5a7173a265df49a77b94c8e9b901ba45815",
          "body": "- auto-extract-cookies.py: uses browser_cookie3 to read YouTube cookies\n  from Chrome/Safari/Firefox, saves to ~/.config/sin-youtube/cookies.json\n  (chmod 600), optionally stores in Infisical\n- Agents can run this autonomously — no DevTools, no manual extraction\n- 14 cookies extracted from Chrome, stored locally + in Infisical\n- Added to skill-multimodal-youtube/scripts/ + requirements.txt",
          "is_bot": false,
          "headline": "feat: auto-extract YouTube cookies from browser (no user interaction)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T16:35:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee0ac561ed9173510c96a712f9bafa94bb3543aa",
          "body": "Hard gate: agents must consult context7 for library docs + sin_web_search\nfor real-world examples BEFORE writing any code using external libraries.\nExceptions: pure stdlib, no external deps, or explicit user override.",
          "is_bot": false,
          "headline": "feat: add M8 mandate — context7 + web search before coding (MANDATORY)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T07:15:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc498406d140209ec47dca0fa9b3e25650ff343a",
          "body": "- cli_app.py: shared Typer app + all sub-apps (eliminates circular imports)\n- cli_serve.py: 491 lines (MCP server serve() command)\n- cli_misc.py: 654 lines (top-level @app.command() functions)\n- cli_sckg.py: 221 lines (11 SCKG commands)\n- cli_security.py: 123 lines (9 security commands)\n- cli_audit.\n[…]\ni_markitdown.py: 53 lines (3 MarkItDown commands)\n- cli_rtk.py: 50 lines (3 RTK commands)\n- cli.py: 100 lines (imports + entry point only)\n- Python tests: 66 passed, 1 skipped\n- No file over 654 lines",
          "is_bot": false,
          "headline": "refactor: split Python cli.py 3359→100 lines (22 modules)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T07:02:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad5807f359fe2fc162edf0c940851024832fca04",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove stray wifi-pmkid-audit.sh",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T06:27:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfe4bb9f5cca5a44064cbfdca0f591e5b735d0e3",
          "body": null,
          "is_bot": false,
          "headline": "fix: update golden help test for new subcommands (v3.28.0)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T06:26:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c40e23207bacc9f58487c5285ee06e2f671ad5e",
          "body": "…d v3.27.0 correction (19 tools)",
          "is_bot": false,
          "headline": "fix: notion permission defaults (upload_block, move_block) + AGENTS.m…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T00:38:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3f06937fa67f25328b694419e7475b10b071622",
          "body": "…cted)\n\n- chat_run.go: 389 lines (core run loop, LLM setup, streaming, REPL)\n- chat_run_flags.go: 375 lines (permission, checkpoint, hooks, MCP, loop config)\n- chat_run_headless.go: 90 lines (one-shot -p mode, progress writer)\n- chat_run_slash.go: 84 lines (/model, /mode slash command handlers)\n- All 14 chat tests pass, build clean",
          "is_bot": false,
          "headline": "refactor: split chat_run.go 779→389 lines (headless+slash+flags extra…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T00:34:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27dc3185fdc19e02116b84eafb63e4d13512bc07",
          "body": null,
          "is_bot": false,
          "headline": "docs: AGENTS.md + CHANGELOG v3.28.0 — 10 features, 106 subcommands",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T00:17:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "047d3c738ee6120538c2c434aec4772e65dc8409",
          "body": "…nstall, LSP auto-configure, plugin system (#479 #480 #482 #489 #490 #492)\n\n- #479 Background Agents: fire-and-forget async job manager (goroutine-backed, thread-safe)\n- #480 Spec-Driven Dev: EARS parser → architecture generator → code scaffolder (3-stage deterministic pipeline)\n- #482 Session Shari\n[…]\ng\n- 5 new CLI subcommands: background, spec-driven, share, mcp-install, lsp-config\n- 8 new internal packages with tests (all -race clean)\n- Infra opencode.json: 8 new baseline skills synced (24 total)",
          "is_bot": false,
          "headline": "feat: background agents, spec-driven dev, session sharing, MCP auto-i…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T00:05:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fbebfae75c44632c379469d05dc972f9e4410b01",
          "body": "17 MCP tools (10 read auto-allowed, 6 write gated ask, 1 raw escape hatch).\nBridged-External pattern wrapping vibe-notion npm CLI as subprocess.\nAct-as-user via token_v2 from browser session, or bot via NOTION_TOKEN.\n\n- config.go: notionConfig() + notionMCPPath() in DefaultServers()\n- permission_def\n[…]\n in MCP Skill Servers table\n- AGENTS.md: v3.27.0 roadmap, productivity skill row, notion permission rows\n- CHANGELOG.md: v3.27.0 entry with all 17 tools\n- .gitignore: vibe-notion credential protection",
          "is_bot": false,
          "headline": "feat: vibe-notion MCP bridge — full Notion access (v3.27.0)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-30T00:03:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36db957c114efa338f667e3accbf67e7764c534b",
          "body": "…tput (#484 #481 #488 #491)\n\n- ContextMeter: thread-safe token tracker with visual bar, warn at 80%, compact at 90%\n- sin-code context: CLI subcommand for context window inspection\n- Voice input: --voice flag, sox/ffmpeg recording + whisper transcription (no CGO)\n- Decision memory: SQLite-backed arc\n[…]\nI collapsible tool output: Tab to expand/collapse, 5-line preview with hint\n- Glamour syntax highlighting: already wired (code blocks via Highlight, prose via glamour)\n- 17 new tests (all -race clean)",
          "is_bot": false,
          "headline": "feat: context meter, voice input, decision memory, TUI collapsible ou…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T22:07:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "154ed54197abba10509c54828c683ff1cd90b068",
          "body": "…s, model switching\n\n5 features from SOTA CLI agent research, implemented in parallel:\n\n1. Auto-commit after verified task (#487):\n   --auto-commit flag, fires git commit after verify.pass (M3)\n   Auto-detects conventional commit prefix from prompt\n   8 tests, config keys: agentloop.auto_commit, age\n[…]\nect/debug/review = read-only (no writes)\n   10 tests, config key: agentloop.mode\n\n5. Mid-session model switching (#315, previous commit):\n   /model command, Loop.SetModel, preserves context\n   6 tests",
          "is_bot": false,
          "headline": "feat: 5 quick wins — auto-commit, checkpoints, file-watch, agent mode…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T21:27:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "990477e94add75454e23c156ba3f5b93c2c07c4f",
          "body": "Loop.SetModel(model) updates the LLM model in-place without losing\nconversation context. Thread-safe (M7) via sync.RWMutex.\n\n- loop_setmodel.go: SetModel/GetModel/getCompletion with CompletionBuilder\n- chat_model.go: availableChatModels() reads from config + env + defaults\n- chat_run.go: /model slas\n[…]\nh\n- model_popup.go: TUI /model — in-place switch, no runner reset\n- loopbuilder/builder.go: Model + CompletionBuilder fields\n- 6 tests pass with -race (SetModel updates, preserves messages, race-free)",
          "is_bot": false,
          "headline": "feat: mid-session model switching via /model command (#315)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T20:24:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5dc3c1976703ce315890dc6acf6e5ea00500ac35",
          "body": "Master skill covering ALL SIN-Code web research tools:\n- sin_web_search (builtin, free DuckDuckGo, no API key)\n- sin_http_get (builtin, URL fetch, no API key)\n- websearch MCP (7 tools, 20+ sources, SerpAPI)\n- YouTube MCP (9 tools, search/transcript/clip/reel, no API key)\n\nIncludes decision tree, workflow, complete parameter reference,\npermission policy, API key guide, and output templates.\n\nSynced to Infra-SIN-OpenCode-Stack (opencode.json + catalog.json).",
          "is_bot": false,
          "headline": "feat: add skill-multimodal-web-tools — master research skill",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T19:49:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14a531522228aee2b433fabdf3ce7ba041053da7",
          "body": "God-file splits (no file >800 lines remains):\n  complexity.go  997→201  (6 new files in audit/)\n  compressor.go  937→159  (5 new files in compress/)\n  eval_cmd.go    935→50   (6 new files in cmd/sin-code/)\n  finder.go      880→133  (8 new files in complexity/)\n  audit_cmd.go   878→217  (5 new files \n[…]\nions_fix.go normalises capabilities.extensions array→map\n  autodev: conditional registration — only when autodev.cli_mcp importable\n  native_browser: conditional registration — only when binary exists",
          "is_bot": false,
          "headline": "refactor: split 7 more god-files + fix 5 MCP servers",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T18:19:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5c5f76a11bade54091264f4fde6aa63cf2399af",
          "body": "New bundled skill in skills/multimodal-skills/skill-multimodal-youtube/:\n- SKILL.md with frontmatter (name, description, compatibility, required_tools)\n- context/triggers.md — activation triggers\n- context/tool-reference.md — all 9 tool parameters documented\n- tasks/workflow.md — SEARCH→ASSESS→WATCH\n[…]\ntemplates\n- templates/output.md — output format templates\n- LICENSE (MIT)\n\nSynced to Infra-SIN-OpenCode-Stack/skills/sin-youtube/ (commit d950e37).\nInstalled to ~/.config/opencode/skills/sin-youtube/.",
          "is_bot": false,
          "headline": "feat: add skill-multimodal-youtube — 9 YouTube MCP tools skill",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T16:14:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "593b3b03d90d38537afb2674022f48fc5705cae2",
          "body": "…P + god-file splits",
          "is_bot": false,
          "headline": "docs: v3.26.0 — AGENTS.md + CHANGELOG for sin_web_search + YouTube MC…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T16:07:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b78212065cd335971470d4066fd514254a6b5df1",
          "body": "…→307, chat_tools_extra.go 1126→192, loop.go 1009→465\n\nNo file over 1000 lines remains. Pure extraction, same packages, no functional changes.\n\nupdate.go (TUI) split into 8 files:\n  update_model.go, update_keys.go, update_palette.go, update_view.go,\n  update_chat.go, update_search.go, update_diff.go\n[…]\nhat_tools_quality.go, chat_tools_browser.go\n\nloop.go (agentloop) split into 5 files:\n  types.go, loop_struct.go, loop_run_init.go, loop_budget.go, loop_maxturns.go\n\nAll tests pass with -race -count=1.",
          "is_bot": false,
          "headline": "refactor: split 4 god-files — update.go 1747→371, chat_render.go 1107…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T16:04:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d002431a3350cae05a97490fc738c23ecdd76d34",
          "body": "…, transcript, clip, reel)\n\nRegisters youtube-for-ai-agents (github.com/JCodesMore/youtube-for-ai-agents)\nas an external MCP server. 9 tools available with no YouTube Data API key:\n  youtube__youtube_search        — search videos/channels/playlists\n  youtube__youtube_get_transcript — pull transcript\n[…]\nt timeout increased 3s → 10s (Node.js servers need more init time).\n\nE2E verified: sin-code chat -p 'search YouTube for Go tutorials' returns live\nresults with video titles, channels, views, and URLs.",
          "is_bot": false,
          "headline": "feat: youtube-for-ai-agents MCP integration — 9 YouTube tools (search…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T15:06:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "234ed1828c1616fa64a04013842fa1456a42ca52",
          "body": "…ve multi-provider web search\n\nWires the existing internal/websearch engine as a first-class chat tool so\nthe agent can search the web without an external MCP server. DuckDuckGo is\nkeyless and always available (zero config). Tavily/SerpAPI/Brave activate\nautomatically when their env keys are set (WE\n[…]\n[{phrase:...}]); add User-Agent\n- websearch/engine_test.go: update DuckDuckGo tests for real format\n\nE2E verified: sin-code chat -p 'search Go 1.26' returns live DuckDuckGo\nresults with zero API keys.",
          "is_bot": false,
          "headline": "feat: sin_web_search chat tool — free DuckDuckGo + Tavily/SerpAPI/Bra…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T14:10:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d54176b5b9a83b0632eaf9336221bd80b50b2ab",
          "body": "… spinner, categorized help, TUI input history\n\nCLI UX (like Claude Code):\n- 'sin-code' (no args) → launches chat/TUI instantly (not help dump)\n- 'sin-code foobar' → clean 'unknown command' error\n- Friendly error messages: 404/401/403/429/5xx/connection errors wrapped\n  with actionable config hints \n[…]\n calling works\n  $ sin-code chat -p 'create file' --yolo → file created\n  $ sin-code chat -p 'hi' (bad model) → friendly error, not raw 404\n\nBuild: PASS | Tests: PASS (race) | CEO Audit: Score 100, A+",
          "is_bot": false,
          "headline": "feat(cli): production-ready UX — bare sin-code→chat, friendly errors,…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T02:17:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "babd2040a58ae090cc59d0b118dee56542d8430b",
          "body": "…erbose, SilenceUsage\n\nClean headless output (like Claude Code):\n- Default: only answer + [session=...] line, no warnings\n- --json: compact single-line JSON only, all stderr suppressed\n- --verbose: all warnings visible (MCP, sandbox, etc)\n- SilenceUsage + SilenceErrors on chat command (no flag help \n[…]\n:...,summary:4,verified:true,turns:1,tokens:17750}\n\n  $ sin-code chat -p 'Create test_hello.go' --yolo\n  (file created, verified=true)\n\nCEO Audit: Score 100, A+, 48/48 gates.\nBuild ✅ | Tests ✅ | E2E ✅",
          "is_bot": false,
          "headline": "feat(cli): production-ready UX — clean output, streaming, --json, --v…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T01:29:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1d4344d00b01c2dd0e6a77b9ef1e3244cf27f0f",
          "body": "…nboarding, updated NIM models\n\nCritical production fixes:\n1. Config model/base_url fallback: sinCfg.LLMModel/LLMBaseURL were loaded\n   but never used in firstNonEmpty chain — chat always fell back to env\n   or hardcoded default. Now: CLI flag > agent profile > config file >\n   env > default.\n2. MCP\n[…]\ntup wizard + /model popup + model_switcher all use new list\n\nE2E verified: chat -p works with nemotron-3-nano, tool calling confirmed.\n\nCEO Audit: Score 100, A+, 48/48 gates.\nBuild ✅ | Tests ✅ | E2E ✅",
          "is_bot": false,
          "headline": "feat: production-ready CLI — config fallback, async MCP, TUI fixes, o…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T01:01:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc095def990a608b4bd3d6846bb88f21e5e14f35",
          "body": "10 monolith files (>1000 lines each) split into focused modules:\n\n1. analysis_tools.go (2094→0) → scout_tools.go, adw_tools.go, sckg_tools.go,\n   grasp_tools.go, harvest_tools.go\n2. todo/store.go (1966→402) → store_helpers.go, store_hooks.go, store_cmd_crud.go,\n   store_cmd_lifecycle.go, store_cmd_q\n[…]\n except tui/update.go and chat_render.go (1107, new from\nprior split). All new files carry sin-debt: shrink markers.\n\nCEO Audit: Score 100, A+, 48/48 gates.\nBuild ✅ | Full suite ✅ (0 failures) | Vet ✅",
          "is_bot": false,
          "headline": "refactor: split 10 god files into 45+ focused modules",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-29T00:30:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cbcabcaf7bafbffca868d252cf7f106e506aa72d",
          "body": "…6%, compress 61→75%, testgen 67→88%\n\nevalharness (59.8% → 77.2%): 50 tests for arm constructors, scorers,\nrunners, compare helpers, skill body readers, price lookups\n\ntelemetry (60.0% → 96.0%): 11 tests for DefaultProvider, defaultPath,\ntool event handling, multi-session aggregation, Stub provider\n\n[…]\n\n\ntestgen (66.5% → 88.4%): 35 tests for source parsing, LLM fill,\nrepair rounds, expression rendering, file detection, options\n\nCEO Audit: Score 100, A+, 48/48 gates.\nBuild ✅ | Tests ✅ (-race) | Vet ✅",
          "is_bot": false,
          "headline": "test(coverage): boost 4 packages — evalharness 60→77%, telemetry 60→9…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T23:19:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab9b6042baba9aad760097f73a5c63bfe05ea494",
          "body": "…verage\n\nTUI update.go split into 3 new files:\n- chat_render.go (1107 lines): View() rendering + chat display logic\n- mouse_handler.go (153 lines): mouse click/scroll/zoom handlers\n- agent_runner_msg.go (251 lines): AgentRunnerMsg type + handler\nEach has sin-debt: shrink marker (approved split).\n\nCo\n[…]\nages):\n- eval: 58.8% → 90.2% (24 new tests for SWE-bench functions)\n- stack: 59.4% → 83.3% (22 new tests for install/doctor functions)\n\nCEO Audit: Score 100, A+, 48/48 gates.\nBuild ✅ | Tests ✅ | Vet ✅",
          "is_bot": false,
          "headline": "refactor: split tui/update.go (3206→1729 lines) + boost eval/stack co…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T23:06:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7226c80d303aa4edd979027c4443fddbe6e8704",
          "body": "… coverages\n\ncommands.go split into 19 focused files:\n- daemon_cmd.go (531) | skill_cmd.go (644) | spec_cmd.go (520)\n- superpowers_cmd.go (410) | tokens_cmd.go (390) | debt_cmd.go (382)\n- swarm_cmd.go (373) | memory_cmd.go (560) | goal_cmd.go (336)\n- auto_cmd.go (322) | ledger_cmd.go (307) | compres\n[…]\n instinct: 45.6% → 72.9% (~40 tests)\n- prp: 55.5% → 77.3% (~30 tests)\n- install: 56.1% → 78.0% (~35 tests)\n\nCEO Audit: Score 100, A+, 48/48 gates, 0 unapproved findings.\nBuild ✅ | Full suite ✅ | Vet ✅",
          "is_bot": false,
          "headline": "refactor: split commands.go god file (6464→7 lines) + boost 3 package…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T22:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "606b8e427417cd3bcf3770f23bd7a6424692cec2",
          "body": "Autonomy (79.3% → 82.0%):\n- conflict_predict_test.go: mergeTree + diffNameOnly (0%→100%)\n- issue_pipeline_test.go: Run, Process, CreatePR, FetchIssue error paths\n- discover_test.go: priorityFor, normalizeKey, Discover edge cases\n\nOrchestrator (73.2% → 81.8%):\n- adversary_cov_test.go: NewAdversary, p\n[…]\nsts)\n- extra_cov_test.go: planToJSON, recvTypeName, Kernel, SpeculativeRunner,\n  MergeWinner, ClassifyTask, HashScratchpad (25 tests)\n\n74 new tests, all pass -race (M7).\n\nBuild ✅ | Tests ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "test(coverage): boost autonomy 79→82%, orchestrator 73→82%, 74 new tests",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T22:38:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "285e150c6ea544043a460eb00e823b55a22b71f5",
          "body": "…o binary)\n\nAllGoTools was emptied when the 7 external Go tool repos (discover, execute,\nmap, grasp, scout, harvest, orchestrate) were absorbed into the main\nsin-code binary as built-in subcommands. The tests still expected 7 entries.\n\n12 tests updated to expect 0 tools and verify RunGoPhase is a no-op.\n\nBuild ✅ | Full suite ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(tests): update 12 stale AllGoTools tests (7→0, tools absorbed int…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T22:25:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2fbebd414ef854be47113c2d78362f88b804625",
          "body": "…rsary, Governor\n\nThe 4 orchestrator sub-agents (Critic, Adversary, Governor, Cartographer)\nwere fully implemented with tests but NEVER called from production code.\nRun() only did Plan → Dispatch → Aggregate. Now:\n\n1. Cartographer.IndexAll() — runs BEFORE BuildPlan (repo symbol map)\n2. Adversary.Rev\n[…]\n). CLI wires\nCartographer with os.Getwd(); Adversary/Governor need LLM clients\nnot available in plain CLI context.\n\n12 new tests for the wiring (all pass -race).\n\nBuild ✅ | Tests ✅ (-race) | CEO 99/A+",
          "is_bot": false,
          "headline": "feat(orchestrator): wire 3 sub-agents into Run() — Cartographer, Adve…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T22:14:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23b5a29484110277af415305138e29aa589d6e4c",
          "body": "…add 30 tests\n\nDead code removal (−1665 lines):\n- epic_coordinator.go: 0 external refs, only used by own tests\n- subagent_parallel.go: 0 external refs, hook fires already in subagent.go\n- tool_retrieval.go: 0 external refs, CosineSimilarity duplicate of memory/rag\n- 3 test files + 17 coverage_test.g\n[…]\n→100% on all 9 methods\n- blame_test.go: 14 tests, 0%→100% on Diagnosis, git, checkAt, shortSHA\n\nCoverage:\n- autonomy: 75%→79.3%\n- orchestrator: 71%→73.2%\n\nBuild ✅ | Tests ✅ (-race) | E2E ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(core): remove 3 dead files, wire spawn_subgoal, fix golden help, …",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T22:07:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbbb4f5092cd4336d804938c84017b626fecffe8",
          "body": "8 slash commands were in autocomplete but did nothing when entered:\n- /compact: triggers manual context compaction (>10 messages)\n- /dag: switches to DAG view\n- /ctx-viz: switches to Context Visualization view\n- /dashboard: switches to Agent Dashboard view\n- /sessions: opens session switcher\n- /tools: switches to Tools view\n- /btw: shows usage hint (needs SideLLM for full function)\n- /undercover: full toggle via commands.UndercoverMode (on/off/status)\n\nBuild ✅ | Tests ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(tui): wire 8 dead slash commands + /undercover full toggle",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T21:49:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70b9fbf04b7ad4f2320fe84b66e5c7f73f0c680d",
          "body": "Hooks (AGENTS.md §10 defines 42 events, 9 were never fired):\n- TurnEnd: fired after each turn completes\n- SessionEnd: fired via defer on Run() return\n- MemoryWrite: fired when sin_memory_add tool executes\n- MemoryCompact: fired when compaction is applied\n- AgentSpawn/AgentComplete: fired in subagent\n[…]\nead code audit: 0 dead files. 2 wired (subagent.go, loop_observer.go),\n8 test-only (background.go is strongest removal candidate — superseded\nby autonomy queue).\n\nBuild ✅ | Tests ✅ (-race) | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(core): fire 9 missing hooks, add permission entries for 9 chat tools",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T21:42:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f96fabcf22fbe7b1559980534b59fbfaedd48ef2",
          "body": "…ring streaming\n\n3 real bugs fixed:\n\n1. CompactToggle (c key) was in keymap but never handled in handleKey.\n   Now toggles compact mode with system message feedback.\n\n2. CrashRecovery.Save() was never called on quit — chat history was\n   lost on crash/quit. Now saves on all 3 quit paths (Ctrl+X, Ctr\n[…]\nsg handler now blocks with\n   '⏳ Wait for the current response to finish (Esc to interrupt)'.\n   Input shows '⏳ Waiting for response…' placeholder when disabled.\n\nBuild ✅ | Tests ✅ (-race) | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(tui): wire compact toggle, crash recovery on quit, block input du…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T21:27:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e24b62d2681fd79101dd52de372f9b002286d08",
          "body": "…rrors\n\n3 UX fixes:\n\n1. /help now opens the HelpOverlay popup (235-line grouped keybinding\n   reference) instead of printing flat text into chat\n\n2. /search now scrolls viewport to matched message. Enter jumps to\n   current match, n/N cycle through matches, virtualized render range\n   expands to inc\n[…]\nzes errors (Timeout, Network, Auth, Rate\n   Limited, Permission) with bold header + actionable hint line:\n   '→ Check your API key with: sin-code config get llm.api_key'\n\nBuild ✅ | Tests ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(tui): /help opens overlay, /search scrolls to match, structured e…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T21:15:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a6472953f67c570835e64cc71ff4ee8394cebc1",
          "body": "…, render cache\n\n4 performance/correctness fixes:\n\n1. Virtualized rendering: only render last N messages that fit viewport\n   (chatHeight/4, min 5). Prevents O(n) re-render every 250ms tick.\n   Shows '⋯ N earlier messages' indicator when truncated.\n\n2. Empty message guard: submit() now trims whitesp\n[…]\non-streaming messages now hit LRU cache\n   (100 entries) before expensive markdown/syntax rendering. Cache\n   misses populate the cache. Streaming messages bypass cache.\n\nBuild ✅ | Tests ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(tui): virtualized rendering, empty message guard, typewriter copy…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T21:07:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60b36db335a65b328c51399af6e9b9fe34a7b0b2",
          "body": "3 real UX bugs fixed:\n\n1. Auto-scroll: viewport no longer jumps to bottom when user scrolled\n   up during streaming. userScrolledUp flag tracks manual scroll,\n   GotoBottom only fires when user is at bottom. Reset on new message.\n\n2. Tab completion: pressing Tab after /attach now autocompletes file\n\n[…]\n prefix. ~ expansion supported.\n\n3. /model command: now actually works. /model opens switcher popup,\n   /model <name> switches directly with system confirmation.\n\nBuild ✅ | Tests ✅ | Vet ✅ | CEO 99/A+",
          "is_bot": false,
          "headline": "fix(tui): auto-scroll respect, tab path completion, /model command",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T20:58:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80aba94b3227866adc1594c145260b49e1ae5dfe",
          "body": "… handle empty responses\n\n4 real bugs in existing rendering code:\n1. renderToolOutput: no line limit → truncate to 50 lines + indicator\n2. renderCodeBlock: no line wrapping → MaxWidth wrap + 200-line limit\n3. renderAssistantBubble: empty response → Thinking… or header-only\n4. renderToolCard: input truncation by byte len → display width\n\nBuild ✅ | Tests ✅",
          "is_bot": false,
          "headline": "fix(tui): rendering quality — truncate tool output, wrap code blocks,…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T20:25:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc5a9c04c8c9281042833f8b35031518da633b83",
          "body": "…licts\n\nAll 5 features were created but never integrated into the actual\nView/Update loop — they were dead code. Now wired:\n\n1. LinkifyText → renderMarkdownWithCodeBlocks (URLs in chat are now\n   clickable via OSC 8 + accent/underline styling)\n2. ContextMeter → renderChat footer (visual fill bar wit\n[…]\nd in ViewChat)\n- ctrl+a (diff approval) → F8 (conflicted with textarea select-all)\n- ctrl+e (copy mode) → F9 (conflicted with textarea end-of-line)\n\nBuild ✅ | Tests ✅ (-race) | Vet ✅ | CEO Audit 99/A+",
          "is_bot": false,
          "headline": "fix(tui): wire 5 dead features into rendering pipeline + fix key conf…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T20:19:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de25ccdd052cab91fb2619214936543892de4c1f",
          "body": "…eter, chat export\n\nNew features (11 files, ~1300 lines):\n- Typewriter streaming effect (typewriter.go) — progressive text reveal\n  at 200 chars/sec, batched, thread-safe, configurable\n- Copy/yank mode (copy_mode.go) — vim-style text selection from chat,\n  visual mode, yank to system clipboard (pbco\n[…]\nd saves chat as\n  markdown to ~/Desktop/sin-code-chat-TIMESTAMP.md\n- Clipboard support (clipboard_darwin/linux/windows/other.go)\n\nTests: 30 new tests, all PASS. Full TUI suite green.\nBuild: ✅ | Vet: ✅",
          "is_bot": false,
          "headline": "feat(tui): typewriter streaming, copy/yank mode, URL links, context m…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T19:28:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "466814638abdf7454c0a56b39d09ed94684f0fdf",
          "body": "…lcome screen, verify gate indicator, diff approval\n\nNew features (7 files, ~1000 lines):\n- Collapsible message blocks (chat_blocks.go) — Codex-style block rendering\n  with role icons, verify indicators, tool call counts, ctrl+g to toggle\n- Slash command menu (slash_menu.go) — popup with 16 commands\n[…]\napproval flow (diff_approval.go) — popup with syntax-highlighted\n  diff, approve/reject/edit buttons, ctrl+a to open\n\nTests: 31 new tests, all PASS. Full TUI suite (134 files) green.\nBuild: ✅ | Vet: ✅",
          "is_bot": false,
          "headline": "feat(tui): SOTA TUI improvements — collapsible blocks, slash menu, we…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T18:56:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5adbe07cd960aa417fa108031216dd79a639a6a",
          "body": "spec-ci, eval-n8n, sin-update-e2e were missing actions/checkout and\nactions/setup-go, causing 'directory prefix does not contain main module'\nerrors on the GitHub Actions runner before n8n delegation.\n\nAlso: n8n webhook is now configured (n8n.delqhi.com via Cloudflare Tunnel)",
          "is_bot": false,
          "headline": "fix(ci): add checkout+setup-go to workflows with go vet pre-check",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T18:16:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a2f3e5a2f497eb9fdea1aaf35861557fd1b2bfd",
          "body": null,
          "is_bot": false,
          "headline": "ci: trigger n8n-delegated CI with configured webhook secret",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T18:15:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4441f9119fac1cc69345f3e889fe9e12cd8e1e3",
          "body": "Go modules:\n- go.etcd.io/bbolt 1.4.3 → 1.5.0\n- modernc.org/sqlite 1.52.0 → 1.53.0\n- golang.org/x/mod 0.35.0 → 0.37.0\n- golang.org/x/sys 0.45.0 → 0.46.0\n- golang.org/x/net 0.55.0 → 0.56.0\n- modelcontextprotocol/go-sdk 1.4.1 → 1.6.1\n\nGitHub Actions:\n- actions/checkout v4 → v7\n- actions/setup-go v5 → v\n[…]\n2 → v3 (#468 already merged)\n\nECOSYSTEM.md: add Template-fuer-Repo-Skill, kubernetes-sota-practices\n.dockerignore: exclude vendored modules and .git from Docker context\n\nBuild ✅ | Vet ✅ | Race tests ✅",
          "is_bot": false,
          "headline": "chore(deps): batch-merge 11 dependabot PRs + add 2 repos to ECOSYSTEM.md",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T16:18:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b20a841b10bff0b99763ee69cfc5a918825f24cc",
          "body": "…(#468)\n\nBumps [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment) from 2 to 3.\n- [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases)\n- [Commits](https://github.com/marocchino/sticky-pull-request-comment/compare/v2...v3)\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump marocchino/sticky-pull-request-comment from 2 to 3 …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-28T16:13:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59d34207a4a96fdb0873f7dc6db28ae84036d6b5",
          "body": "#460: Replace 9 hardcoded 0644 → filemode.Default() (7 files)\n#461: goreleaser description 50+ → 90+ subcommands\n#462: Create RELEASE.md (tag→goreleaser→brew pipeline)\n#463: Create Dockerfile.sin-code (multi-stage, distroless, non-root)\n#464: Fix flaky TestRunnerCronEnqueue (blocking channel → non-b\n[…]\ngraph tests (0% → 86.2% coverage, 11 tests)\n#466: Populate empty compatibility fields in skill frontmatter\n#467: Add trigger phrases to 38 weak skill descriptions\n\nBuild ✅ | Vet ✅ | CEO Audit 100/A+ ✅",
          "is_bot": false,
          "headline": "fix: 8 issues fixed in parallel (#460-#467)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T16:11:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9bf526548e1feea0bdca3eac40fc60da71814c4",
          "body": "…on length, compatibility list\n\n- Add lifecycle: native to frontmatter\n- Shorten description from 1375 → 563 chars (≤1024 limit)\n- Move detailed trigger rules to body under ## TRIGGER RULES\n- Change compatibility: opencode → YAML list format",
          "is_bot": false,
          "headline": "fix(skills): skill-process-delegate validation — lifecycle, descripti…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T15:28:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e8705c9f7f3a26751bd70ad8a7958291552d749",
          "body": "… fix archived refs\n\n- Add research__* to ECOSYSTEM.md MCP Skill Servers table\n- Remove duplicate research__* block in permission_defaults.go (lines 146-149)\n- Fix 4 refs: registry.go → config.go in ECOSYSTEM.md\n- Remove 7 ghost Go tool repos from AllGoTools in update_phases.go (absorbed into main binary)\n- Remove archived SIN-Code-Websearch-Skill mapping from mcpclient/config.go\n- Fix AGENTS.md: sin-code-release.yml → release.yml (deleted workflow)",
          "is_bot": false,
          "headline": "fix(ecosystem): sync research__* to ECOSYSTEM.md, remove ghost repos,…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T15:24:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d7f05e99eaa70337a202a329b53e7a658c938fb",
          "body": "Security:\n- Container hardening: --user, --cap-drop=ALL, --network=none, --read-only (#441)\n- Verify-cmd sandbox routing via sandbox.Command (#442)\n- API key detection: chat fails fast with actionable error (#445)\n\nCI/CD:\n- 8 workflows migrated to n8n delegation pattern (M1 compliance) (#443)\n- spec\n[…]\nTemp files cleaned up\n- opencode-mobile plugin removed from config\n\nCEO Audit: Score 100, A+, 48/48 gates, 0 unapproved findings\nTest suite: 24/24 packages -race green, 8.697 Go tests, 66 Python tests",
          "is_bot": false,
          "headline": "feat(ultra-audit): CEO team audit fixes — 16 issues fixed in parallel",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-28T15:17:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "745e80529656384ad86d24fe664b03a008fbc9d6",
          "body": "Bundled skill for SIN-Code that teaches the orchestrator how to decompose\ncomplex tasks and delegate to subagents like a master. Based on Anthropic's\nmulti-agent research system findings + OpenCode subagent architecture.\n\n13 sections: core principles, delegation protocol, anti-patterns, subagent\ntyp\n[…]\nes: Anthropic multi-agent research findings, OpenCode subagent\narchitecture reference. Templates: code delegation + research delegation\nprompt templates. Task pattern: parallel feature implementation.",
          "is_bot": false,
          "headline": "feat(skills): add skill-process-delegate — master subagent delegation",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-25T10:45:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34a8dc0607899f3b96380b875a609a3145171395",
          "body": "4 new subcommands shipped: doctor, diff, benchmark, tokens cost.\nCEO Audit: Score 100, A+, 48/48 gates, 0 unapproved, 0 rot-risk.",
          "is_bot": false,
          "headline": "docs: v3.25.0 changelog + AGENTS.md roadmap update",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-25T10:05:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3bda89ac78988d9e5bd4eda5c97c5754b9a8766",
          "body": "4 parallel subagents implemented 4 new subcommands:\n\nsin-code doctor (subagent A):\n- Unified health check: Go toolchain, sin-code binary, config, 4 SQLite DBs,\n  MCP servers, external tools (git/gh/docker/ruff/python3/node), module path (M5),\n  CGO_ENABLED=0 (M2)\n- 11 checks with PASS/WARN/FAIL stat\n[…]\n80%, red >80%, critical >100%\n- --json, --model, --budget flags\n- 14 tests\n\nBuild: pass | Lint: 0 issues | Vet: clean | Tests: all green\nCEO Audit: Score 100, A+, 48/48 gates, 0 unapproved, 0 rot-risk",
          "is_bot": false,
          "headline": "feat(v3.25.0): doctor, diff, benchmark, tokens cost — 4 new subcommands",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-25T10:04:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15e92c12248b34f8f59840c42a7859dbd9eb1981",
          "body": "5 parallel subagents completed production-readiness sweep.\nCEO Audit: Score 100, A+, 48/48 gates, 0 unapproved, 0 rot-risk.",
          "is_bot": false,
          "headline": "docs: v3.24.1 changelog + AGENTS.md verified-against update",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-25T03:11:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9d0559e510fda01d8786a28d7e96046bc5f72ac",
          "body": "5 parallel subagents audited and fixed the entire codebase:\n\nAGENTS.md consistency (subagent 2):\n- Removed duplicate cmd/ layout blocks (3x duplicated internal packages)\n- Fixed CLI subcommand list: removed non-existent 'knowledge', fixed\n  underscore→hyphen for orchestrator-run/agents/plan, added h\n[…]\n8 gates, 0 unapproved\n- Rot-risk: 0 (136 markers, all with upgrade)\n- Build: pass | Lint: 0 issues | Vet: clean | Tests: all green\n- Python: ruff clean, 757 tests pass\n- Skills: 40/40 production-ready",
          "is_bot": false,
          "headline": "fix(production): multi-subagent production-readiness sweep",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-25T02:58:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55a42c72bb5d53fc6ac7fc37fabc15f5abd26556",
          "body": "The goreleaser config references .Env.TAP_GITHUB_TOKEN for pushing the\nhomebrew formula to OpenSIN-Code/homebrew-sin, but the release workflow\nonly passed GITHUB_TOKEN. Map SIN_GITHUB_FALLBACK_TOKEN → TAP_GITHUB_TOKEN\nso the formula push succeeds.",
          "is_bot": false,
          "headline": "fix(ci): pass TAP_GITHUB_TOKEN to goreleaser for homebrew tap push",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-24T21:14:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "902e2268a6976b3974a1ba3a34a3650cc82a6e57",
          "body": "- Add v3.24.0 changelog entry (TUI live progress, analyse-image, security V2,\n  complexity cleanup, analyzer fixes, test suite hardening)\n- Update AGENTS.md: v3.24.0 status WIP → SHIPPED, update verified-against header\n- CEO Audit: Score 100, A+, 48/48 gates, 0 unapproved, 0 rot-risk",
          "is_bot": false,
          "headline": "docs: v3.24.0 changelog + AGENTS.md status update",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-24T21:08:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1def6733a95a1f3d655c2d75a5311fe6b67aa5e5",
          "body": "…alyzers + 0 rot-risk\n\nComplexity cleanup (55+ files merged, 0 unapproved findings):\n- Merged all single-export subcommand files into natural caller modules\n- Consolidated security scan commands into security_scan_commands.go\n- Merged lsp/discover/map into core_tools.go\n- Merged grasp into analysis_\n[…]\n 0 unapproved findings (102 total, all approved)\n- 0 rot-risk markers (116 total, all with upgrade trigger)\n- 0 production rot-risk (was ~5 at session start)\n- Build: pass, Lint: 0 issues, Tests: pass",
          "is_bot": false,
          "headline": "feat(complexity): eliminate all shrink/yagni/delete findings + fix an…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-24T20:12:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7dfbc8751b4f6011d76390766de4d3b6238308f",
          "body": "This commit completes the ecosystem-skills activation phase:\n\n- PATH-binary skills (browser, codocs, frontend, goalmode, marketplace,\n  mcpbuilder, scheduler) are now reported as installed + runnable.\n- Python-module skills (analyse, contextbridge, grillme) resolve their\n  correct entrypoints (binar\n[…]\nsin-code passes\n- golangci-lint run ./... clean\n- sin-code ceo-audit ./: A+ / 48 gates\n- sin-code skill status: 13 non-deprecated skills installed + runnable,\n  3 deprecated shop skills clearly marked",
          "is_bot": false,
          "headline": "feat(skills): full ecosystem skill activation and diagnostics",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T21:37:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "516476308606004222365f508ea09ef12393215b",
          "body": null,
          "is_bot": false,
          "headline": "chore: remove temporary GSD planning files",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T19:02:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d36b09f1646aff3dfa364f2e01186bf2a0a2c73",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt skill manager and registry files",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T19:02:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7daf936a7b308e73607a9f11b6f86dfb664216c",
          "body": "… skills)\n\nPreserves subagent working notes for the ecosystem-skills-full-activation phase. PLAN.md + RESEARCH.md living docs from parallel-agent run on 2026-06-23.",
          "is_bot": false,
          "headline": "docs: archive subagent phase planning docs (PLAN + RESEARCH ecosystem…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T17:44:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c46fd93152c1d34615c764c8c19e1668117b3901",
          "body": "…kip + status columns\n\n- skillmgr.SkillInfo{Name, Repo, Deprecated, DeprecatedReason, SkipInInstallAll}\n- skillStatus adds Deprecated columns to text + JSON output\n- skillmgrInstallAllHook test seam so tests don't run real git clone\n- registry.go: 13 line wiring update + 34 new test lines\n- status/r\n[…]\nthreading status through new layout\n- shop-skills: 3 SKILL.md updates (cj-dropshipping/stripe/tiktok) — frontmatter add 'lifecycle' flag\n- 34 stashes NOT pushed (parallel branch parking; subagent WIP)",
          "is_bot": false,
          "headline": "feat(skillmgr,status): SkillInfo deprecation tracking + install-all s…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T17:41:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0beaee53f365379ebca60569e8f1aef1f129efb0",
          "body": "…udit integration\n\nThis commit adds the remaining security scanning pieces on top of the\ninitial secrets + SAST work:\n\n- sin-code security scan sca - vendored SCA scanner integration\n- sin-code security scan sbom - SPDX/CycloneDX SBOM generation\n- sin-code security scan container - Apple container r\n[…]\ncurity gate integration\n- Tests for all new scanners\n\nVerification:\n- go build ./... passes\n- go test -race -count=1 ./... passes\n- golangci-lint run ./... clean\n- sin-code ceo-audit ./: A+ / 48 gates",
          "is_bot": false,
          "headline": "feat(security): complete V2 scanners - SCA, SBOM, container, SARIF, a…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T16:04:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3507b6b1a918826f734ce66a82475b55326874b",
          "body": "This commit bundles three CEO-priority workstreams:\n\n1. Vision image analysis (closes #423)\n   - New command: sin-code analyse-image <path>\n   - Replaces Tesseract with vision-capable LLM (default: minimax-m3)\n   - OpenAI-compatible endpoint, configurable via env/config\n   - New MCP tool: sin_analys\n[…]\nternal/security.doc.md\n- testdata golden help output\n\nVerification:\n- go build ./... passes\n- go test -race -count=1 ./... passes\n- golangci-lint run ./... clean\n- sin-code ceo-audit ./: A+ / 48 gates",
          "is_bot": false,
          "headline": "feat: image analysis, security scans, and ecosystem skill fixes",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T12:10:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ee915576ef3bdecf205557759b5e599efe60e00",
          "body": "…r modules (issue #426)\n\nConsolidates the following single-export files to address CEO audit\nshrink findings:\n\n- cmd/sin-code/daemon_cmd.go -> cmd/sin-code/commands.go\n- cmd/sin-code/skill_cmd.go -> cmd/sin-code/commands.go\n- cmd/sin-code/spec_cmd.go -> cmd/sin-code/commands.go\n- cmd/sin-code/eval_c\n[…]\n> cmd/sin-code/internal/todo/commands.go\n\nVerification:\n- go build ./... passes\n- go test -race -count=1 ./... passes\n- golangci-lint run ./... clean\n- sin-code ceo-audit ./: A+ / 48 gates\n\nIssue #426",
          "is_bot": false,
          "headline": "refactor(complexity): merge single-export subcommand files into calle…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T10:21:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d26bf6b61a526ab6f24471e5fd92cbe977381225",
          "body": "Add browserExecHook to openInBrowser so tests can mock the OS-specific\nbrowser command. Update TestOpenInBrowserDoesNotPanic, TestOpenInBrowserWindows,\nand TestOpenInBrowserLinux to use a no-op command instead of actually\nopening http://127.0.0.1:1 in the user's browser.\n\nFixes the ERR_UNSAFE_PORT browser popup during go test.",
          "is_bot": false,
          "headline": "test(webui): prevent browser from opening during tests",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T08:56:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b61b41a21204ca2cf9dd2f578bbaa50c6a89ec90",
          "body": "- AGENTS.md: refresh single-source-of-truth header, architecture, config\n  contract, roadmap, and CLI subcommand list for v3.24.0.\n- CHANGELOG.md: add Unreleased entries for live tool timing/NDJSON\n  progress/live footer, Esc interrupt, stale-branch merge, and the\n  environment-independent test fixes.",
          "is_bot": false,
          "headline": "docs: update AGENTS.md and CHANGELOG.md for recent changes (issue #424)",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-23T08:29:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89277187e39c3eaba433d87f86b3c1c1dc482dba",
          "body": "After a trigger loop selects ticker.C, check ctx.Err() before doing work.\nThis prevents the loop from starting another Queue.Add or scan after the\ncontext is cancelled, which caused the runner to hang in tests using a\nfast ticker. Applied to cron, watch, discover, and dream triggers.\n\nNo production behavior change except faster shutdown on cancellation.",
          "is_bot": false,
          "headline": "fix(autonomy): exit trigger loops promptly when context is cancelled",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T23:42:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4a6736a8c1854c57c94f3f633a4d75ccb32c38f",
          "body": "Replace the dockerAvailable boolean probe with a dockerAvailableReason\nhelper that actually exercises the daemon (docker ps with a 10s timeout).\nAdd requireDocker(t) which calls t.Skip with a concrete reason when the\ndaemon or runtime is unavailable.\n\nApply the helper to TestDockerComposeStatus_NoContainers and\nTestRunEFM_UpWithStartedStatus so the suite stays green in environments\nwithout Docker/OrbStack.",
          "is_bot": false,
          "headline": "test(internal): skip Docker-dependent tests when daemon is unavailable",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T21:49:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d4af5afe3d54c12b2d85f82babbf69d430c4b41",
          "body": "Move the per-goroutine started signal to after the atomic inFlight\nincrement and peak CAS loop. The gate now closes only once all\nrunners are provably inside the critical section, so the parallel\nexecution assertion is deterministic and race-free.",
          "is_bot": false,
          "headline": "test(orchestrator): remove timing race in parallel DAG test",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T21:24:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98c9d11e235f54cdf1b09c24967e8cc6e1b2ffe1",
          "body": "Add a nil-safe onEnqueue test hook to Runner that fires after a goal is\nsuccessfully added to the queue. TestRunnerCronEnqueue and\nTestRunnerWatchEnqueue now wait for the hook signal instead of sleeping,\nremoving the timing race between context cancellation and Queue.Add.\n\nProduction behavior unchanged.",
          "is_bot": false,
          "headline": "test(autonomy): eliminate race in cron/watch enqueue tests",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T21:11:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b54a3d84fdaf912b602e3cc2b866c697b4e783b5",
          "body": "- Replace hardcoded /tmp with a fresh t.TempDir() in project-type detection test.\n- Bind SIN_CODE_BIN to the current test binary in serve-test setup so\n  subprocess harvest tests use the code under test.\n- Add SIN_CODE_TEST_HARVEST_EGRESS_ALLOW=1 test-only override so httptest\n  loopback servers are reachable under the sandbox egress policy.\n\nThese tests were failing only in this environment (macOS + sandbox).",
          "is_bot": false,
          "headline": "test(internal): make security + harvest tests environment-independent",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T20:56:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "043f57418c1b0633aa3267161c227425852b0aa8",
          "body": "… token/cost footer\n\n- Add ToolStart/ToolEnd callbacks to agentloop.Loop\n- Wire live tool timing into TUI tool tree\n- Add structured NDJSON progress output for headless chat/daemon\n- Add live token/cost footer updates during streaming/agent runs\n- Add race-clean tests for all new behavior\n- Update AGENTS.md with output.progress config contract\n\nVerification: go build, go test -race, golangci-lint 0 issues,\nsin-code ceo-audit Grade A+ Score 302",
          "is_bot": false,
          "headline": "feat(tui,agentloop,headless): live tool timing, NDJSON progress, live…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T19:17:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "290f70bdebb76759c0d0029a4305f7374746f55c",
          "body": "- Add Model.promptCtx / promptCancel for per-prompt cancelable contexts\n\n- startPromptContext() creates a new cancelable context; CancelPrompt() cancels it\n\n- submitAgentPrompt and runAgentSkillPrompt use the cancelable context\n\n- Raw ChatRunner fallback also uses the cancelable context\n\n- /clear cancels any pending prompt\n\n- AgentRunner emits friendly 'interrupted' / 'timeout' error messages\n\n- Add Model.IsStreaming() helper",
          "is_bot": false,
          "headline": "feat(tui): make Esc interrupt actually cancel the in-flight prompt",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T16:58:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0945e52ddbdfe5d6aa9d4f2511b96b216b386ca",
          "body": "…ation can run",
          "is_bot": false,
          "headline": "fix(swebench-nightly): add checkout and setup-go steps so local valid…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T16:28:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea0b0adee5730526b8c4e7a0b3bf3e08e618501b",
          "body": "Merged (cherry-picked) content from:\n\n- feat/native-websearch: cmd/sin-code/internal/native_websearch/ (DuckDuckGo native websearch, issue #381)\n\n- feat/spawn-subgoal: cmd/sin-code/internal/agentloop/spawn_subgoal.go + test, plus Queue.GetStatus() (issue #385)\n\n- feat/coverage-drohne: cmd/sin-code/s\n[…]\nt.go overlap\n\nSkipped: web submodule, scripts/install-sin-skills.sh (references non-existent skills/builtin), and destructive full merges.\n\nBranches remain on origin; not deleted per operator request.",
          "is_bot": false,
          "headline": "feat: merge valuable content from 5 stale branches into main",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T16:14:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9bf47894b0f88ed55e5468b560c173534b1d923",
          "body": "…y when secret is missing",
          "is_bot": false,
          "headline": "fix(swebench-nightly): run local validation first, skip n8n gracefull…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T16:07:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d1e6e7b633f608a18d7d7abcba2f8bf7083c4ec",
          "body": "…-Code-Security-Bundle to requirements-ecosystem.txt",
          "is_bot": false,
          "headline": "fix(ecosystem-sync): add SIN-Code-FireworksAI-OpenCode-Config and SIN…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T16:06:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d2b8d9f58665e1c731b0393320acf1c2e8b8496",
          "body": "Fixes lint-and-security CI pipeline: 67 gofmt + 48 goimports issues",
          "is_bot": false,
          "headline": "style: gofmt + goimports across all Go files",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-22T16:05:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff53d00291980b8c1f581442431139564da30337",
          "body": null,
          "is_bot": false,
          "headline": "docs: CEO audit report for sin_run_loop + sin_goal_* MCP tools — Grade B",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-20T11:46:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04cc8f6ad6b5bbb446bd47ec0d812914f68b5e57",
          "body": "…oal_* MCP tools",
          "is_bot": false,
          "headline": "docs: PLAN-LOOP-MCP.md — implementation plan for sin_run_loop + sin_g…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-20T11:32:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15a5ea69ee21fb2c88d567c126c45ad21320b08c",
          "body": "…SYSTEM, CoDocs",
          "is_bot": false,
          "headline": "docs: sin_run_loop + sin_goal_* MCP tools — AGENTS.md, CHANGELOG, ECO…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-20T11:00:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4bb28c5b45b60a34e95680e88e399480022e757",
          "body": "Exposes the autonomous goal queue (autonomy.Queue) as 4 MCP tools:\n- sin_goal_add: enqueue a goal for daemon execution\n- sin_goal_list: list goals (filterable by status)\n- sin_goal_status: show one goal + children\n- sin_goal_complete: mark goal verified\n\nopencode (or any MCP client) can now enqueue autonomous goals that\nthe sin-code daemon will execute with full Verify-Gate + Stop-Gate.\n\nRefs: PLAN-LOOP-MCP.md Wave 2",
          "is_bot": false,
          "headline": "feat: sin_goal_* MCP tools — asynchronous goal queue management via MCP",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-20T10:55:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9a120c8c585777481fa57cd6b8a4f132e53f48f",
          "body": "…via MCP\n\nExposes the complete SIN-Code agent loop (PLAN→ACT→VERIFY→DONE with\nVerify-Gate, Stop-Gate, Lessons, Compaction, Loop-Detection) as a single\nMCP tool. Any MCP client (opencode, Claude Code, Codex) can now delegate\na full verified task in one call instead of writing 100 prompts.\n\nIn-process\n[…]\n calls loopbuilder.Build() via a factory registered by\npackage main (avoids internal←loopbuilder←internal import cycle).\nReturns: {session_id, summary, verified, turns}.\n\nRefs: PLAN-LOOP-MCP.md Wave 1",
          "is_bot": false,
          "headline": "feat: sin_run_loop MCP tool — synchronous full-agent-loop delegation …",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-20T10:48:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74b05d550fc4c757b3abf3f96fe77989d2105368",
          "body": "Closes #422 — operators can dial write-path default permissions down\n(0o600) for security-sensitive deployments via SIN_CODE_FILE_MODE env var.\n\n- AGENTS.md §9 'Development workflow' gains a File-mode policy note\n- CHANGELOG under Unreleased gains a Security entry referencing #422\n- The knob refuses modes that would loosen the 0o644 baseline\n- Close-to-source exceptions stay tight: install manifest 0o600,\n  index directory 0o750 (per the established convention)",
          "is_bot": false,
          "headline": "docs: document SIN_CODE_FILE_MODE env knob in AGENTS.md §9 and CHANGELOG",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-19T19:21:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5ab70fb210621a30835ce0cd646565fb31cf75b",
          "body": "…rowser context checks, gh pr timeout",
          "is_bot": false,
          "headline": "fix: autodev .Run() error handling, detectRepo context propagation, b…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-19T19:19:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa30db4e70ab2626f8b25585928337f0204cfd3a",
          "body": "…ape) + 0o644 → filemode.Default() migration\n\nIssue #420 partial: applies to chat -p / --json / daemon.\n- chat_cmd.go: applyChatSandboxPolicy(opts, headless, ws) sets sandbox + emits WARN when --no-sandbox forces 'none'; headless default is platform backend.\n- detection via cmd.Context() instead of \n[…]\nledger writes, etc).\n- autodev/pipeline.go: in-Go stage state machine + ghbridge-IssueFetcher (pluggable via SetFetcher for tests).\n- detectRepo(ctx context.Context) signature propagated to 4 callers.",
          "is_bot": false,
          "headline": "feat(sandbox,filemode): headless sandbox default ON (--no-sandbox esc…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-19T19:04:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff8b008496722b10322036c8567897868ba01580",
          "body": "… knob\n\n- cmd/sin-code/internal/filemode/: Default() returns 0o644 (or SIN_CODE_FILE_MODE override); refuses modes that grant group/other write\n- scripts/migrate_filemode.py: codemod that swaps 0o644 literals to filemode.Default() across the cmd/ tree (run-by-target-list)",
          "is_bot": false,
          "headline": "feat(config): filemode package centralises 0o644 + SIN_CODE_FILE_MODE…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-19T18:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e4fface24fb13aa7d4580bc1250a4234f519280",
          "body": "…nce v3.20.0)",
          "is_bot": false,
          "headline": "fix: skills count 37 → 40 (multimodal-skills/ + 3 new skills added si…",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-19T18:33:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3870910d1722545ad6b622592e20436f92824a5c",
          "body": "…AGENTS.md tree",
          "is_bot": false,
          "headline": "fix: skill count drift — 37 → 40; add multimodal-skills/ category to …",
          "author_name": "SIN CI",
          "author_login": null,
          "committed_at": "2026-06-19T18:25:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 43,
      "commits_last_year": 793,
      "latest_release_at": "2026-06-29T16:12:47Z",
      "latest_release_tag": "v3.26.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 22,
      "mean_days_between_releases": 2.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/OpenSIN-Code/SIN-Code",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/OpenSIN-Code/SIN-Code",
          "is_deprecated": false,
          "latest_version": "v1.9.0",
          "repository_url": "https://github.com/OpenSIN-Code/SIN-Code",
          "versions_count": 61,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-08T07:20:36Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 43
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [
          {
            "date": "2026-06-14",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_stars": 1
      },
      "open_issues_and_prs": 33
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "sample"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "desktop/web/tsconfig.json"
      ],
      "toolchain_manifests": [
        "SIN-Code-Container-Tool-Go/go.mod",
        "SIN-Code-SAST-Tool/go.mod",
        "SIN-Code-SBOM-Generator-Go/go.mod",
        "SIN-Code-SCA-Tool-Go/go.mod",
        "SIN-Code-Secrets-Scanner/go.mod",
        "desktop/src-tauri/Cargo.toml",
        "go.mod",
        "src/sin_code_bundle/tools/mcp_server_builder/templates/go-mcp/go.mod"
      ],
      "largest_source_bytes": 157443,
      "source_files_sampled": 1646,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 75242
    },
    "dependencies": {
      "manifests": [
        "SIN-Code-Container-Tool-Go/go.mod",
        "SIN-Code-SAST-Tool/go.mod",
        "SIN-Code-SBOM-Generator-Go/go.mod",
        "SIN-Code-SBOM-Generator/pyproject.toml",
        "SIN-Code-SCA-Tool-Go/go.mod",
        "SIN-Code-Secrets-Scanner/go.mod",
        "go.mod",
        "pyproject.toml",
        "requirements-ecosystem.txt"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "github.com/stretchr/testify",
          "manifest": "SIN-Code-Container-Tool-Go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.4"
        },
        {
          "name": "github.com/fatih/color",
          "manifest": "SIN-Code-SAST-Tool/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.16.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "SIN-Code-SAST-Tool/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.0"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "SIN-Code-SBOM-Generator-Go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.4"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "SIN-Code-SBOM-Generator-Go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "click",
          "manifest": "SIN-Code-SBOM-Generator/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=8.0"
        },
        {
          "name": "rich",
          "manifest": "SIN-Code-SBOM-Generator/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.0"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "SIN-Code-SCA-Tool-Go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.4"
        },
        {
          "name": "github.com/fatih/color",
          "manifest": "SIN-Code-Secrets-Scanner/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.16.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "SIN-Code-Secrets-Scanner/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.0"
        },
        {
          "name": "charm.land/bubbles/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.0"
        },
        {
          "name": "charm.land/bubbletea/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.7"
        },
        {
          "name": "charm.land/glamour/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.1"
        },
        {
          "name": "charm.land/lipgloss/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.4"
        },
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/Songmu/skillsmith",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.0"
        },
        {
          "name": "github.com/charmbracelet/bubbles",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/charmbracelet/bubbletea",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.10"
        },
        {
          "name": "github.com/charmbracelet/lipgloss",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/chromedp/cdproto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260427013145-5737772c319b"
        },
        {
          "name": "github.com/chromedp/chromedp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.15.1"
        },
        {
          "name": "github.com/modelcontextprotocol/go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.1"
        },
        {
          "name": "github.com/rogpeppe/go-internal",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.15.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/pflag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.10"
        },
        {
          "name": "go.etcd.io/bbolt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.37.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.56.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.46.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.12"
        },
        {
          "name": "pyyaml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0"
        },
        {
          "name": "click",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=8.0"
        },
        {
          "name": "rich",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.0"
        },
        {
          "name": "fastmcp",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0"
        },
        {
          "name": "jinja2",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.0"
        },
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.27"
        },
        {
          "name": "gitpython",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1"
        },
        {
          "name": "tomli_w",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 13,
        "merged_prs": 115,
        "open_issues": 20,
        "closed_ratio": 0.943,
        "closed_issues": 328,
        "closed_unmerged_prs": 34
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "Delqhi",
          "commits": 308,
          "avatar_url": "https://avatars.githubusercontent.com/u/197647907?v=4"
        },
        {
          "type": "User",
          "login": "v0",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/286459218?v=4"
        },
        {
          "type": "User",
          "login": "Sinator",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1321158?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.978
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ceo-audit.yml",
        "ci.yml",
        "ecosystem-sync.yml",
        "eval-n8n.yml",
        "go-ci.yml",
        "lint.yml",
        "release-python.yml",
        "release.yml",
        "sin-update-e2e.yml",
        "sin-verify.yml",
        "skill-e2e.yml",
        "spec-ci.yml",
        "swebench-nightly.yml",
        "test-delegate.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 7,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 6,
            "reason": "4 out of the last 5 releases have a total of 4 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "19 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "dbc4b59c14e259e097ab62abd6dce035ec6d680d",
        "ran_at": "2026-07-21T21:36:05Z",
        "aggregate_score": 4.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T08:38:41Z",
      "oldest_open_prs": [
        {
          "number": 498,
          "created_at": "2026-07-01T11:49:19Z",
          "last_comment_at": "2026-07-01T11:49:38Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 499,
          "created_at": "2026-07-01T11:49:22Z",
          "last_comment_at": "2026-07-01T11:49:42Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 500,
          "created_at": "2026-07-01T11:49:26Z",
          "last_comment_at": "2026-07-01T11:49:52Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 501,
          "created_at": "2026-07-01T11:49:30Z",
          "last_comment_at": "2026-07-01T11:49:50Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 502,
          "created_at": "2026-07-01T11:49:33Z",
          "last_comment_at": "2026-07-01T11:49:51Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 503,
          "created_at": "2026-07-05T11:42:48Z",
          "last_comment_at": "2026-07-05T11:43:09Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 504,
          "created_at": "2026-07-05T11:42:55Z",
          "last_comment_at": "2026-07-05T11:43:13Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 505,
          "created_at": "2026-07-05T11:42:59Z",
          "last_comment_at": "2026-07-05T11:43:21Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 506,
          "created_at": "2026-07-12T11:42:50Z",
          "last_comment_at": "2026-07-12T11:43:18Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 507,
          "created_at": "2026-07-12T11:42:54Z",
          "last_comment_at": "2026-07-12T11:43:16Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 508,
          "created_at": "2026-07-12T11:43:01Z",
          "last_comment_at": "2026-07-12T11:43:26Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 509,
          "created_at": "2026-07-19T11:42:44Z",
          "last_comment_at": "2026-07-19T11:43:03Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 510,
          "created_at": "2026-07-19T11:42:53Z",
          "last_comment_at": "2026-07-19T11:43:19Z",
          "last_comment_author": "github-actions"
        }
      ],
      "last_merged_pr_at": "2026-06-28T16:13:46Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 159,
          "created_at": "2026-06-16T12:14:33Z",
          "last_comment_at": "2026-06-28T15:26:03Z",
          "last_comment_author": "Delqhi"
        },
        {
          "number": 479,
          "created_at": "2026-06-29T20:21:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 480,
          "created_at": "2026-06-29T20:21:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 481,
          "created_at": "2026-06-29T20:21:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 482,
          "created_at": "2026-06-29T20:21:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 483,
          "created_at": "2026-06-29T20:21:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 484,
          "created_at": "2026-06-29T20:21:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 485,
          "created_at": "2026-06-29T20:22:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 486,
          "created_at": "2026-06-29T20:22:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 487,
          "created_at": "2026-06-29T20:22:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 488,
          "created_at": "2026-06-29T20:22:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 489,
          "created_at": "2026-06-29T20:22:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 490,
          "created_at": "2026-06-29T20:22:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 491,
          "created_at": "2026-06-29T20:22:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 492,
          "created_at": "2026-06-29T20:22:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 493,
          "created_at": "2026-06-30T02:31:42Z",
          "last_comment_at": "2026-06-30T05:29:00Z",
          "last_comment_author": "Delqhi"
        },
        {
          "number": 494,
          "created_at": "2026-06-30T02:31:51Z",
          "last_comment_at": "2026-06-30T05:29:29Z",
          "last_comment_author": "Delqhi"
        },
        {
          "number": 495,
          "created_at": "2026-06-30T02:32:03Z",
          "last_comment_at": "2026-06-30T05:29:51Z",
          "last_comment_author": "Delqhi"
        },
        {
          "number": 496,
          "created_at": "2026-06-30T02:32:12Z",
          "last_comment_at": "2026-06-30T05:30:10Z",
          "last_comment_author": "Delqhi"
        },
        {
          "number": 497,
          "created_at": "2026-06-30T02:32:22Z",
          "last_comment_at": "2026-06-30T05:30:34Z",
          "last_comment_author": "Delqhi"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/OpenSIN-Code/SIN-Code",
    "host": "github.com",
    "name": "SIN-Code",
    "owner": "OpenSIN-Code"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 60,
      "inputs": {
        "security": 44,
        "vitality": 74,
        "community": 36,
        "governance": 57,
        "engineering": 84
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "commits_last_year": 793,
              "human_commit_share": 0.99,
              "days_since_last_push": 2,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "793 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 793
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "releases_count": 43,
              "latest_release_tag": "v3.26.0",
              "releases_from_tags": false,
              "days_since_latest_release": 22,
              "mean_days_between_releases": 2.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "43 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 43
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 22 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "4 out of the last 5 releases have a total of 4 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.978
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "merged_prs": 115,
              "open_issues": 20,
              "closed_issues": 328,
              "issue_closed_ratio": 0.943,
              "closed_unmerged_prs": 34
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "94% of issues closed",
                "points": 44.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "115/149 decided PRs merged",
                "points": 29.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 115,
                      "decided": 149
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "OpenSIN-Code",
              "public_repos": 56,
              "account_age_days": 82
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of OpenSIN-Code",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "OpenSIN-Code"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "56 public repos, account ~0 yr old",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 56
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/OpenSIN-Code/SIN-Code"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 43
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 43 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 43
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "61 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 61
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 84,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "14 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://sin-code-indol.vercel.app",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://sin-code-indol.vercel.app",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "4 out of the last 5 releases have a total of 4 signed artifacts.",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "19 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 82,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 75242
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "desktop/web/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "SIN-Code-Container-Tool-Go/go.mod",
                "SIN-Code-SAST-Tool/go.mod",
                "SIN-Code-SBOM-Generator-Go/go.mod",
                "SIN-Code-SCA-Tool-Go/go.mod",
                "SIN-Code-Secrets-Scanner/go.mod",
                "desktop/src-tauri/Cargo.toml",
                "go.mod",
                "src/sin_code_bundle/tools/mcp_server_builder/templates/go-mcp/go.mod"
              ],
              "dependency_bot_commit_share": 0.01
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "desktop/web/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "desktop/web/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "1 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 157443,
              "source_files_sampled": 1646,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/1646 source files over 60KB",
                "points": 54.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1646,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples",
                "sample"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, sample",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, sample"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch pypi package 'sin-code' from its registry",
    "Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-SAST-Tool' from its registry",
    "Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-SCA-Tool-Go' from its registry",
    "Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-Secrets-Scanner' from its registry",
    "Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-Container-Tool-Go' from its registry",
    "Could not fetch go package 'github.com/OpenSIN-Code/SIN-Code-SBOM-Generator-Go' from its registry",
    "Could not fetch pypi package 'sin-sbom-generator' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T21:36:15.376587Z",
  "schema_version": "0.25.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/OpenSIN-Code/SIN-Code.svg",
  "full_name": "OpenSIN-Code/SIN-Code",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.25.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.