Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-23 08:02 UTC

Sahith59 / BoLD

Python · TypeScriptKeine Lizenz erkannt★ 0 Sterne⑂ 0 Forksseit Juni 2026Auf GitHub ansehen ↗

Sahith59/BoLD erreicht einen Gesundheitsindex von 40 von 100 und liegt damit im Bereich Gefährdet. Am stärksten schneidet es bei Engineering Quality (72/100) ab, am schwächsten bei Community & Adoption (22/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

40
gesamt / 100
Gefährdet

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

40
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Sahith59Persönliches Konto
1 Follower52 öffentliche Reposseit Jan. 2022

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

36Gefährdet · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
4.8/36Commit-Rhythmus — 7/52 Wochen mit Commits
18/18Commit-Volumen — 403 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year403
human_commit_share1
days_since_last_push0
active_weeks_last_year7
Wie die Bewertung erfolgt
0/27Liefert Releases aus — keine Releases veröffentlicht
0/36Release-Aktualität — keine Releases
0/27Release-Rhythmus — keine Releases
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

22Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
0/22.5Lizenz — keine Lizenzdatei erkannt
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licensenein
has_contributingja
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

40Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.1/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
2.7/13.5Breite der Beitragenden — 2 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled2
top_contributor_share0,995
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
38.2/38.3PR-Annahme — 2/2 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/28 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs2
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
2.2/25Reichweite des Inhabers — 1 Follower von Sahith59
21.7/25Kontohistorie — 52 öffentliche Repos, Kontoalter ca. 4 Jahre
Verwendete Eingangsdaten
followers1
owner_typeUser
is_verified
owner_loginSahith59
public_repos52
account_age_days1.661
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

72Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 2 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — eslint.config.mjs
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://bold-lemon.vercel.app
0/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepagehttps://bold-lemon.vercel.app
has_readmeja
has_docs_dirnein
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

23Kritisch · 16 % des Gesamtindex

Sicherheitslage

23Kritisch
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Lizenz — license file not detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — keine Daten
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 49 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate2,3
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

70Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — web/frontend/AGENTS.md, web/frontend/CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 99 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,99
agent_instruction_filesweb/frontend/AGENTS.md, web/frontend/CLAUDE.md
agent_instruction_max_bytes327
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — eslint.config.mjs
11/11Statische Typprüfung — src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 97 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json, uv.lock
has_dockerfileja
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_configja
typecheck_configssrc/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json
agent_commit_share0,97
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
27/45Typprüfbarer Code — Python mit Typprüfungs-Konfiguration (src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json)
54.1/55Handhabbare Dateigrößen — 10/611 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languagePython
largest_source_bytes245.593
source_files_sampled611
oversized_source_files10
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

0GitHub-Sterne
2Mitwirkende
403Commits, letzte 12 Monate
0Tage seit letztem Push
0Releases
1Bus-Faktor
0offene Issues
PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Could not fetch pypi package 'ideax' from its registry
  • Could not fetch pypi package 'bold-backend' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 2.3 / 10
2.3Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-23 08:02 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
k. A.Packagingpackaging workflow not detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities49 existing vulnerabilities detected
Direkte Abhängigkeiten 39
RegistryPaketVersionsvorgabeManifest
PyPIhttpx>=0.27pyproject.toml
PyPIpyyaml>=6.0pyproject.toml
PyPIideaxweb/backend/pyproject.toml
PyPIfastapi>=0.115web/backend/pyproject.toml
PyPIuvicorn>=0.32web/backend/pyproject.toml
PyPIpydantic>=2.9web/backend/pyproject.toml
PyPIpydantic-settings>=2.6web/backend/pyproject.toml
PyPIsqlalchemy>=2.0web/backend/pyproject.toml
PyPIalembic>=1.14web/backend/pyproject.toml
PyPIasyncpg>=0.30web/backend/pyproject.toml
PyPIaiosqlite>=0.20web/backend/pyproject.toml
PyPIpython-multipart>=0.0.12web/backend/pyproject.toml
PyPIargon2-cffi>=23.1web/backend/pyproject.toml
PyPIauthlib>=1.3web/backend/pyproject.toml
PyPIemail-validator>=2.2web/backend/pyproject.toml
PyPIitsdangerous>=2.2web/backend/pyproject.toml
PyPIanthropic>=0.40web/backend/pyproject.toml
PyPIreportlab>=4.2web/backend/pyproject.toml
PyPIpython-docx>=1.1web/backend/pyproject.toml
npm@hookform/resolvers^5.4.0web/frontend/package.json
npm@radix-ui/react-avatar^1.1.12web/frontend/package.json
npm@radix-ui/react-dialog^1.1.16web/frontend/package.json
npm@radix-ui/react-dropdown-menu^2.1.17web/frontend/package.json
npm@radix-ui/react-label^2.1.9web/frontend/package.json
npm@radix-ui/react-separator^1.1.9web/frontend/package.json
npm@radix-ui/react-slot^1.2.5web/frontend/package.json
npmclass-variance-authority^0.7.1web/frontend/package.json
npmclsx^2.1.1web/frontend/package.json
npmcmdk^1.1.1web/frontend/package.json
npmframer-motion^12.40.0web/frontend/package.json
npmlucide-react^1.18.0web/frontend/package.json
npmnext16.2.9web/frontend/package.json
npmposthog-js^1.395.0web/frontend/package.json
npmreact19.2.4web/frontend/package.json
npmreact-dom19.2.4web/frontend/package.json
npmreact-hook-form^7.79.0web/frontend/package.json
npmsonner^2.0.7web/frontend/package.json
npmtailwind-merge^3.6.0web/frontend/package.json
npmzod^4.4.3web/frontend/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 3678,
      "has_wiki": true,
      "homepage": "https://bold-lemon.vercel.app",
      "languages": {
        "CSS": 29434,
        "HTML": 30733,
        "Mako": 704,
        "Shell": 4375,
        "Python": 3548357,
        "Dockerfile": 3424,
        "JavaScript": 121294,
        "TypeScript": 2072614
      },
      "pushed_at": "2026-07-22T16:16:08Z",
      "created_at": "2026-06-08T01:30:42Z",
      "owner_type": "User",
      "updated_at": "2026-07-22T15:04:02Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "Sahith59",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/97082825?v=4",
      "created_at": "2022-01-04T06:26:35Z",
      "is_verified": null,
      "public_repos": 52,
      "account_age_days": 1661
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "06065e27b947b60ea3ca4e378a9f0d9c50ee7b4c",
          "body": "docs: record the UAT + manual-promotion deploy pipeline is live",
          "is_bot": false,
          "headline": "Merge pull request #2 from Sahith59/docs/deploy-pipeline-state",
          "author_name": "Sahith59",
          "author_login": "Sahith59",
          "committed_at": "2026-07-22T15:00:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fff8ce36fc098c0f48d4dea322cefbac2cf6165",
          "body": "Pranav's PR #1 rewired deploys so merging to main ships to UAT only and\nproduction is a manual, un-bypassable promotion. Log it in the running state\nalongside the open findings (public prod /docs, start.sh boot re-sync, ungated\nfrontend) and the Vercel git-author-authorization gap, so the pipeline change\nand its trade-offs are recorded where the build state is tracked rather than\nleft only in PIPELINE.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: record the UAT + manual-promotion deploy pipeline is live",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-22T14:47:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5b161f4a58b5c5dfaed861d972a3409d21faad41",
          "body": "Gate production behind UAT and a manual promotion",
          "is_bot": false,
          "headline": "Merge pull request #1 from Sahith59/pipeline/uat-and-manual-promotion",
          "author_name": "PranavNagothu",
          "author_login": "PranavNagothu",
          "committed_at": "2026-07-22T14:10:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d29508209eccbda673500f3f7695a538143f865e",
          "body": null,
          "is_bot": false,
          "headline": "Gate production behind UAT and a manual promotion",
          "author_name": "Pranav Nagothu",
          "author_login": "PranavNagothu",
          "committed_at": "2026-07-22T01:22:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "660fec50c4deec07bde8e2b651b5ce56ed152edb",
          "body": "Backend deployed first (main 83e4e80, Fly success, healthy) then @boldsec/core\n0.1.1 published (native-wins + provenance) — order satisfied, no false-clean\nwindow. Fresh-install functional verification confirmed the published package\ncarries the 1.6c behavior. @boldsec/mcp 0.13.0 published (1.5c review tools).\nNotes the @boldsec/next git/npm version skew as a tracked hygiene item.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: close P16C-DEPLOY-ORDER — Phase 1.5+1.6 shipped end to end",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T22:34:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "83e4e80dc241cd74941474bb73e727498d355c28",
          "body": "main at 43ae27d, CI green, Fly backend deploy succeeded (api.boldsec.io healthy);\nthe backend now accepts owner_field/declared_owner_provisional (deploy-order\nprecondition met). Records the two latent CI test issues the first push caught +\nthe remaining founder publish step.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: record Phase 1.5+1.6 pushed + backend deployed live on prod",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T19:09:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43ae27d49f2f85bcd7b1ed7966035682f164f794",
          "body": "The 1.5+1.6 stack had never been on main, so the real-Postgres CI + the adapter\nnpm-test fixtures had never run on it. The first main push caught two TEST issues\n(the deploy gate held -- deploy-backend SKIPPED -- so nothing shipped to prod).\nNeither is a product bug; the tri-gated mechanism is uncha\n[…]\nnot the CI gate. Run each adapter's npm test (exact fixture)\nAND the PG-gated tests against a real Postgres before claiming green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix two latent CI-only test failures the first main push exposed",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T18:59:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "313d83b838f18a91b0651e15ca8b54fe15579b33",
          "body": "…locklist\n\nThe Phase 1.6 tri-gate (Critics + Security + BOSS-2) all independently found the\nsame defect: _unsafe_owner_field tokenizes camelCase/snake atomically (sessionId\n-> session + id), so the CONCATENATED blocklist entries (sessionid, apikey,\ncreditcard) were unreachable -- sessionId, apiKey, \n[…]\nase 1.6 (authoritative-but-provisional owner) is\ncode-complete + tri-gated. Backend 1091/0, root engine exit 0, ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6 gate fix (L1): close the camelCase/snake gap in the owner-field b…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T16:00:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c533d64b0ef9d9f6aaf2aa5e942bedcb9aba792",
          "body": "The crown-jewel-ADJACENT core of Phase 1.6. It consumes declared_owner_provisional\nin the ownership model to close the false-CONFIRMED / false-clean the 1.6a design\ngate found. classify() is UNTOUCHED -- only what the ownership model REPORTS changes.\n\nThe hole: the engine trusted ANY declared_owner \n[…]\npy\nclean; classify() untouched. Remaining for 1.6 sign-off: the full BOSS-2 + Security\n+ Critics re-gate on the verdict-path code.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6c-3/d: corroboration gate for a provisional owner (verdict-path core)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T15:41:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8d531309f0221d3eafa0645e4c7279de421a757e",
          "body": "The wire + carry for the authoritative-owner mechanism. Changes NO verdict\nyet -- the corroboration gate that consumes it is 1.6c-3. classify() untouched.\nTwo steps ship together because of a hard extra=\"forbid\" coupling (below).\n\nNative-field-wins (S2 false-clean): @boldsec/core ownerFieldAndValue \n[…]\n ruff + mypy clean. New backend accept-test is fail-on-old\n(neuter the IngestEvent fields -> the post 422s -> RED). Next = 1.6c-3.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6c-1/2: owner-field provenance + native-field-wins (plumbing, inert)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T15:21:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e47a5bf18fe77c0dce51478da6047e774ef539e",
          "body": "Phase 1.6 (PATH 2) storage floor. The review screen already lets a human\nconfirm which field owns a route; until now that confirmation was coverage-only\nand never reached detection. 1.6b persists it so a later sub-phase can steer SDK\nextraction toward the right field -- but stores it safely and chan\n[…]\n3e4f5a6b7c8. The verdict-path corroboration gate\n(1.6c-3) and the full BOSS-2 + Security + Critics re-gate come at the end of 1.6.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.6b: store the human-confirmed owner field name, guarded, as metadata",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T14:47:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "db6893a4e764c45369413a3905d72603d21b0366",
          "body": "…done)\n\nThe review page told the user what BoLD would watch, but not what they\nwould actually hear from it, or whether BoLD was even receiving their\ntraffic yet. This closes Phase 1.5 by answering both on the screen where\nthe trust decision is made: proof-of-life, plus a faithful preview of\nthe one \n[…]\n field as an authoritative-but-provisional detection\ninput) is next and gets its own design and gate before any verdict-path\ncode.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5f: proof-of-life + the one-alarm expectation (Phase 1.5 …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T14:03:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c3bfd1dc4b68da78ab6b9f48b06afaa799598ba",
          "body": "The review page could only be reached from the exact link a coding\nagent handed the user. A developer who wired an app through the manual\npath, or who closed that link, had no way back to confirm what BoLD\nwatches. And when an agent re-drafted after a confirm, the UI said\nnothing about the fact that\n[…]\nkend 1083/0, root engine clean; frontend 394/394, next build clean;\nthe new tests fail-on-old (KeyError on the pre-1.5e response).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5e: make the review surface reachable + honest on re-draft",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T13:40:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a287f14f3cce1c1d8c446306daf69cba64113300",
          "body": "The manual (non-MCP) path had no review surface. A developer who wired\nan app and let traffic flow had nothing to confirm — the review page\nonly understood a coding agent's draft. This evolves the Review UI so it\nconsumes BOTH draft sources honestly (an agent's code claim, or a draft\nBoLD built from\n[…]\ncurity PASS-with-conditions; frontend Critics SHIP + Security PASS.\nFrontend: tsc + eslint clean, next build clean, 390/390 tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5d frontend: the resumable, source-aware Review UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T12:29:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a85bb088a10309871d67dceca0947bf0a93f5dbb",
          "body": "The Review manifest could only be authored by the MCP path. A user who\nwired an app and let real requests flow had nothing to review — the\ndraft stayed empty until an agent declared routes. This lands the\nobserved-source builder so a monitor's own traffic fills its draft,\nwith the consent gate untou\n[…]\nd3e4f5a6b7). New POST /observe is owner-scoped, rate-limited,\ncounts-only. Contract mirror added to the frontend types (additive).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5d backend: build a reviewable draft from live traffic",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T11:49:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e73e5e1731b82c8af33960203941d95d41be57b9",
          "body": "0.12.0 is already published and predates 1.5c, so the two new review tools\n(bold_prepare_review, bold_review_status) are not in the published package and\nnpm cannot overwrite a released version. Bump to 0.13.0 so the package is\npublish-ready once the backend deploys. Publish itself stays a founder-run,\none-way step (deploy the backend first so the tools call a live endpoint).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump @boldsec/mcp to 0.13.0 for the review-manifest tools",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T03:46:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "450f068d9167a9ba55e8b678c52e12cca2a2778e",
          "body": "…(N2)\n\nThe Security gate on 1.5c noted that /confirm — the one manifest endpoint\nthat seeds DeclaredRoute, i.e. the human agreeing to what BoLD watches — used\nthe PAT-permissive auth pair, so a Bearer token (the credential the MCP holds)\ncould authenticate and skip CSRF and confirm without a browser\n[…]\nEN: Critics = SHIP, Security = PASS. web/backend 1067 passed/0\nfailed; root engine green; ruff + mypy clean. classify() untouched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden the review consent gate: /confirm is browser-only server-side …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T03:22:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "635f530c4c6c02a5eff0bc0fde04a3173209c9a3",
          "body": "Until now the review-manifest could only be reached by a human in the\nbrowser; a coding agent had no way to turn what it found in the repo into\na review the human confirms. 1.5c wires that path so setup stays \"connect\nonce, let the agent do the heavy lifting\" instead of hand-authoring a draft.\n\nTwo \n[…]\nCONDITIONS (0 blockers).\nweb/backend 1065 passed/0 failed; root engine green; MCP 148 pass + typecheck\n+ build; ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5c: the MCP path's review-manifest driver",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T02:52:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ed23748b5875d0c6d7d80fe2dfe0650b0d6cd6a",
          "body": "LiveEndpoint tracked only verdict-outcome counters (owner_ok/cross_user/\nunresolved), never \"was an owner field READ on this route.\" An observed-draft\nthat inferred owner-detected from those counters would risk a false green AND a\nfalse needs-input (Critics B4). This adds the explicit signal the hon\n[…]\neview contract is method+path, and DeclaredRoute is\npath-only, so reconciling the granularities is a UI decision for the consumer.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5b Part 1: the durable owner-SEEN signal (Critics B4 fix)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T00:55:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ed048e34c22af3221e320184cd8053be4f8e9858",
          "body": "The review-manifest (where a developer confirms what BoLD watches and the owner\nfield per route) was built but orphaned. 1.5a lays the backend foundation so the\nsurface can be honest and resumable, per web/PHASE_1_5_REVIEW_MANIFEST_PLAN.md.\n\n- The load path returns per-route resolution + resolvedVal\n[…]\nlassify() untouched. 14 new tests (the rejection tests proven to fail on old\nbehavior); double-gated Security PASS + Critics SHIP.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Phase 1.5a: honest, resumable, dedup-safe review-manifest backend",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-17T00:10:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04e3403cc5d01fbf86ee35a5efaaf0d7b9bb3e21",
          "body": "… prep)\n\nSo the first (permanent) npm publish of the public SDK is clean:\n- READMEs for @boldsec/core + express/fastify/koa/hono/nestjs (had none -> blank npm\n  pages). Each: install + one-place wire + the resolveCallerId namespace note + the\n  honest omit-it-get-a-loud-needs-review rule + metadata-\n[…]\n next 85, 5 adapters, conformance x2, 5\n  adapter conformance, Nest smoke, typecheck); READMEs confirmed in every dry-run tarball.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add READMEs for the 6 SDK packages + pin the core dependency (publish…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T16:22:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "241800b97684cb624cbc61c35fa85b8cf810581f",
          "body": "Phase 0+1 fast-forwarded to main (262ec35) and deployed live: @boldsec/core + 5\nframework adapters, the framework-aware MCP guide + /connect picker, and the P1.2\nreview-manifest flow (manifest_drafts/manifest_routes via alembic f7a8b9c0d1e2).\nVerified: health 200, /api/manifest-draft 401 (deployed), landing + app /connect 200.\nnpm publish of the 8 packages remains as the one-way founder-run step.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the Universal SDK Phase 0+1 prod deploy in the state docs",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T16:12:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "262ec35332f9288c1e273173daba937ceabc5d8b",
          "body": "…t flake\n\nWith ruff fixed, pytest ran on CI Postgres for the first time on this branch: the\nmanifest suite passed (the real Alembic migration + unique/CASCADE constraints proven;\nthe PG-log duplicate-key line is that test's asserted pytest.raises(IntegrityError),\nbenign). The only failure was test_d\n[…]\nls at 30s, so nothing real is masked. This also\nde-risks the main deploy run, which is gated on this same backend job being green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden the app_client lifespan fixture against a CI-contention timeou…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T15:53:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b5b568ea25f8bcc7228c127791ced2654ed84be",
          "body": "The on-branch CI run (branch-first, so main never goes red) caught two gaps a\nwarm local had masked:\n\n- app/db.py: CI's uv-pinned ruff flagged UP037 on two new Mapped[...] relationship\n  annotations whose quotes are redundant under `from __future__ import annotations`\n  and deviate from the file's u\n[…]\nd.\n\nBoth proven fail->pass; full backend suite (1038 passed) + the whole sdk-conformance\njob re-run locally in CI order are green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix two clean-checkout CI gaps blocking the Phase-1 deploy",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T15:41:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3cdb22b9ef116553477ae04dc44d88304646395f",
          "body": "The Nest conformance drives the interceptor through a mock ExecutionContext\nbecause a plain-.mjs harness cannot bootstrap NestFactory. This smoke closes\nthe one gap that leaves open: whether Nest's real Express platform hands the\ninterceptor the request shape it reads.\n\nIt bootstraps a genuine NestF\n[…]\nirst cut (numeric ids converge with the regex floor and\nprove nothing) and cleared the slug fix: @boldsec/nestjs is publish-ready.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Prove the NestJS adapter over real Nest HTTP, closing the publish gate",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T15:24:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02dd1c70733a5f15d041e2b4daec999c10e2ec1c",
          "body": "The four new adapters exist, but the guidance still only knew Next.js. Now the\nMCP wiring guide and the connect page wire any of the six frameworks.\n\nwiringGuide(stack) gains a framework registry: a recognized stack gets a\nfocused install + the one-place wire snippet for its adapter; an unknown or\nh\n[…]\n-bearing conformance,\nthe review-manifest product, the Express live-finding proof, and the\nframework-aware guide and connect page.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the wiring guide and connect page framework-aware (P1.4)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T13:45:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6afbff81b2121bd69157ecfcb3bff0b76e1b6f0c",
          "body": "Express proved the one-deep vertical; these four replicate it to the rest of\nthe JS ecosystem. Each is a thin translator that fills the one neutral\nObservedRequest and hands it to @boldsec/core — zero extraction logic in the\nadapter, so the deterministic engine is never forked and every tap reaches \n[…]\not bootstrap NestFactory;\na real-Nest HTTP smoke test is tracked as a gate before that package is\npublished (SDKX-NEST-REAL-HTTP).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the Fastify, Koa, Hono, and NestJS adapters (P1.3b)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T13:33:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56839a57bac7ae6ffb83e08d44c9691e4d1c037b",
          "body": "The 59 golden vectors proved extraction parity on path- and body-derived\nsignals, but set no resolvers — so identity, caller_in_scope,\ncaller_non_privileged, caller_tenant, object_tenant, and the route flags were\nbound only by each adapter's own unit tests, never by the shared cross-adapter\ngate. \"5\n[…]\n7, Express\n67/67; the base-59 consumers are unchanged. Critics SHIP (golden values\nhand-reasoned against the engine, not the run).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bind the resolver-fed fields in the conformance gate (P1.3a)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:55:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f81c3a180a5b2a4d3b95648d701d395b983a3499",
          "body": "The Express adapter, the review manifest, and a live catch are each tested,\nbut never as one chain. This proves the whole vertical: a real Express app +\n@boldsec/express emits the exact events, and the real ingest pipeline +\nclassify() turn a cross-user read into a live CONFIRMED finding.\n\nThe two h\n[…]\n pipeline).\n\nThis completes the one-deep vertical; the contract is now safe to replicate\nto the four remaining framework adapters.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Prove the Express vertical end to end with a live finding (P1.1c)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:44:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e66337d1aa390a18f463a1a2ba555960c40a0bf2",
          "body": "The review page was read-only: it showed the drafted manifest but the\nAccept/Edit/Confirm controls did nothing. This makes them real.\n\n- Resolving a route or a caller field now PATCHes it, optimistically: the row\n  reflects the choice immediately, and on a write failure it ROLLS BACK and\n  shows a l\n[…]\ncount). 7 render tests cover accept-persists, rollback on\nfailure, the deduped confirm count, failed confirm, and the empty state.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wire the review-manifest to confirm and connect (P1.2c)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:31:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "76e0d9afee1a7aaef13645f2d5b52f049ba20640",
          "body": "The coding agent (via the BoLD MCP) drafts what an app exposes; the user\nconfirms it in the browser before BoLD watches anything. This is the backend\nbehind /connect/review: four endpoints (submit / load / resolve / confirm) over\ntwo new metadata-only tables (manifest_drafts, manifest_routes), plus \n[…]\n\n\nThe interactive Accept/Edit/Confirm write-back is the next sub-phase (P1.2c);\nthe page loads and renders real server state here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the P1.2 review-manifest backend (draft submit/load/resolve/confirm)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T12:11:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "92f8d8e5a41fd1755ca991064ed73a0f13c1df17",
          "body": "The authed page where a user confirms what BoLD will watch after their coding\nagent drafts it — the agent-assist flow the universal-SDK plan locks in: the\nagent drafts, a human confirms an editable manifest, and a drafted owner stays\nprovisional until observed. Nothing connects until the user confir\n[…]\necondary primary action (distinct from the single\nbrand-amber CTA). Also records the P1.1 gate outcome + fixes in the ledger/plan.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the P1.2 review-manifest UI (frontend, on-brand)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T11:09:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a4079ab39ae57f601d66e70d5f490b2322200e04",
          "body": "Ran an independent Critics + Security gate on the framework-neutral core +\nExpress adapter BEFORE replicating the contract to four more adapters, so a\nflaw is caught once, not five times. Security passed; Critics caught two:\n\nF1 (silent false-clean): observeNeutral read the response body with a bare\n[…]\nreplication.\n\nRe-proven green: core 35/35, next 85/85, express 9/9, conformance 59/59 x3\n(pure, e2e-over-HTTP, Express-over-HTTP).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden the P1.1 SDK contract per the early Critics/Security gate",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-16T11:09:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7ae73d5fa093229859c93106f9deaa49820c7e1",
          "body": "… and the Express adapter\n\nPhase 0 + Phase 1.1 of the universal SDK plan (web/UNIVERSAL_SDK_PLAN.md). The goal is to let BoLD\nconnect from any framework with the SAME deterministic alarm and the same honest coverage ceiling,\nwithout ever letting a false CONFIRMED or a false-clean differ between the \n[…]\n the two phases share the finished core/next files\nand a single lockfile; splitting would risk a non-building intermediate commit.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the universal SDK conformance foundation + framework-neutral core…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T23:07:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b9a3fb16882cb927aeab6c797859b0cbef016d6",
          "body": "Add the concrete deploy details (a9e1c75, CI 29387439898, prod verified)\nnow that it shipped, and drop the prose em dashes I introduced.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record P2.6 as deployed + live",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:58:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a9e1c7562ef805134313dfaa214175e08fd43f1c",
          "body": "Two things the founder hit on the deployed dashboard.\n\nThe live-tail flagged-route marker painted an alarm-red left border on\nevery row whose route has an open finding, regardless of that request's\nown verdict. So a legitimate \"own object\" or \"public access\" request on\na flagged route read like a vi\n[…]\nCritics-gated (the tail change is anthem-in-pixels); +2 fail-on-old\ntests. Frontend suite 374 pass, tsc, eslint, next build clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the live tail honest per-row and the dashboard update live (P2.6)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:48:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5cfd0624d1df6b619ccd679ce8439172acd3b9db",
          "body": "The running log and ledger still read \"not pushed yet\"; the fix\nshipped in 6797f43 (CI 29386121196 green incl. Fly deploy, prod\nverified). Update the record and note the two extra founder preview\nrounds that were folded in before push.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record P2.5 dashboard fix as deployed + live",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:25:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6797f43d635821aedae9ffa662d6cd0b20b0ff33",
          "body": "The deployed dashboard read as unprofessional and the info (i)\ndisclosures did not open at all: an `absolute` panel inside a\n`.glass` card was clipped away by the card's `overflow:hidden`.\nFix the whole class of issues at the root rather than papering over\nsymptoms.\n\n- Info popover now renders throu\n[…]\n Frontend suite +5\n(popover open/close, monotone no-overshoot, viewport-clamp\nplacement sweep); tsc, eslint, and next build clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix the live dashboard on founder real-data feedback (P2.5)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T03:16:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0ba7f267534f3c8bfbb34e29e9a1e5c47ad1550",
          "body": "… events (P2.4)\n\nThe founder used the deployed dashboard on a real monitor and found real issues.\nDiagnosed each against the code; this fixes them and the reliability gap behind one.\n\n- Charts render on real/sparse data. The verdict-mix chart was BLANK because both\n  charts positioned points by arra\n[…]\nt deploys does not retroactively clear (an all-time\ncounter). Clearing it is a separate careful reconciliation, ledgered as P24-RESIDUAL-STALE.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix the live dashboard on real-data feedback + stop the worker losing…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-15T01:30:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63b8976e492f0fb68bae2e0d1ea8d2b5388c2580",
          "body": "The founder's original concern was that the live view was \"only a small link under\neach project.\" P2.1b gave it a dedicated page but left the link buried at the bottom\nof the receiving section among the coverage/leads/tail toggles. This promotes it to a\nprominent primary button at the top of the row\n[…]\n live-traffic dashboard (storage -> API -> page -> destination),\nall gated, no engine touch. Frontend gate green (lint, 346 tests, next build).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the live dashboard the primary destination on each app row (P2.2)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T16:25:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8158229b52ccfca2cc68dfc1f1e39334efbec792",
          "body": "The founder-locked v4 dashboard, ported into the real app at /live/[monitorId] and\nwired to the P2.1a owner-scoped API. This is the trust surface the whole live alarm\nis judged on, so it is COUNTS-ONLY (the frontend computes every share) and holds the\nanthem in pixels: no unearned green, a real viol\n[…]\nt clean, npm test 346 passed (48 files), next build OK. The nav entry\n(P2.2) and the \"not stored\" story are the only pieces left in this phase.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the live-traffic dashboard page (P2.1b)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T16:21:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2523811a9ce1a87651d91ed62f7fe3c75ce89a89",
          "body": "The founder-locked v4 dashboard needs graphs and headline numbers OVER TIME; P2.0\nbuilt the durable metadata-only buckets, this serves them. It is the crown-jewel\nDOGFOOD: our OWN dashboard must never be BOLA-vulnerable, so every read here goes\nthrough the same `_owned_monitor` owner check the rest \n[…]\n;\nbackend 991 passed + root engine 716; ruff + mypy clean.\n\nThe page + the pixel-honesty gate (Critics condition B) come in P2.1b; nav in P2.2.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add the owner-scoped live-traffic dashboard READ API (P2.1a)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T15:30:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "38ec19e34e033a586c6691124e404a79aa62c11d",
          "body": "…2.0)\n\nPhase 2 of the live-traffic dashboard needs graphs OVER TIME; the all-time\ncounters on live_endpoints cannot show a trend. This adds the storage the\nfounder approved: time-bucketed aggregate COUNTS per (monitor, endpoint,\nverdict) per 15 minutes, rolled up to daily after 30 days.\n\nMETADATA ON\n[…]\nmodels are storage + query only; the owner-scoped HTTP surface + the\npage come in P2.1 (owner-scoping is a ledgered binding requirement there).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add durable time-bucketed aggregate storage for the live dashboard (P…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T14:31:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65a2a13ca258742ecb44a37bb5bfa0ebb5b24701",
          "body": "The expandFirstApp test helper waited only for the honesty boundary note,\nwhich renders immediately and independent of the async getCoverage() fetch,\nthen SYNCHRONOUSLY queried for the app-card button that only exists after\nthat fetch resolves. On an idle machine the microtask wins the race; under\nC\n[…]\nverage test files already await findByTestId and are unaffected.\n\nFrontend gate green locally: eslint clean, 46 files / 317 tests, build clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix a pre-existing async race in the Coverage test helper (CI flake)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-14T00:31:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2897d2683badf5bdd303b3c33d37124790508d59",
          "body": "The founder said the Info banner \"looks like an odd one out; the design is\nnot uniform.\" This is the final Phase-1 trust fix: a pure visual / token /\ncopy-voice pass, no logic change.\n\n- The Info banner and the fail-loud banner now share the system vsurface-*\n  grammar (slate vsurface-neutral for in\n[…]\nolor math), BOSS-2 SHIP (\"Phase 1 is\ngenuinely done\"). 317 frontend + build clean; backend untouched.\n\nPhase 1 (P1.1 through P1.5) is complete.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Unify the live-traffic surfaces into one visual language (P1.5)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T20:18:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02768280cdda770b6d40b07a8bcffdb8e0a5f10c",
          "body": "The founder could not parse the live labels (\"owner-access / cross-user /\nneeds review / still classifying / traffic makeup\"). Rewritten by hand\n(founder chose \"Own / allowed\"):\n\n- Coverage makeup segments (traffic-composition.ts): Own / allowed, Needs\n  review, Cross-user access, Not inspected, Bei\n[…]\nSHIP,\nBOSS-2 SHIP. A label-lock regression test guards the copy (mutation-proven).\n949 backend + 317 frontend green; ruff + mypy + build clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Rewrite the live-surface labels into plain English (P1.4)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T20:00:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce04bbd341067367fb837aab64bfb1c2a38d5289",
          "body": "…route (P1.3)\n\nA live-tail row shows a per-request BOLA verdict, but a route can carry an OPEN\nfinding of ANOTHER family (tenant/BFLA/BOPLA/missing-auth), or an open BOLA\nCONFIRMED, while a given request looks calm (owner-access / public access). The\ntail had no cross-reference at all, and the Cover\n[…]\nCLEARED via the summary-strip redesign. Backend 949, frontend 316, root engine\ngreen; ruff + mypy + build clean; 4 fail-on-old mutation proofs.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cross-reference open findings so no live row reads calm on a flagged …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T19:30:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b43784876c095444ece2ed4c94a83e1462f3354d",
          "body": "A NOT_VULNERABLE verdict is reached for reasons other than \"the caller owns\nthe object\": the object is public (read by many), the caller is a broad-access\nadmin, the caller is a proven tenant/group member, or the object is team-shared.\nThe live tail collapsed all of them into one \"owner-access\" chip\n[…]\nn),\nSecurity PASS (no findings), BOSS-2 SHIP. Backend 935, frontend 306, root engine\ngreen; ruff and mypy clean. Ledger LTV-TAIL-REASON closed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Surface the verdict reason on every live-tail row (P1.2, image-4 fix)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T18:31:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c462c0644ffabb958275cd2b58e1863c78d5d1e",
          "body": "The Coverage traffic-makeup bar parked requests that were DROPPED under load\nforever under \"Still classifying, usually judged within seconds\". The ingest path\ncounts every request in `hits` on arrival, but when the queue is full `submit()`\nsheds the event and it is never judged, so the seen-minus-ju\n[…]\ngreen.\n\nTriple-gated unanimous (Critics SHIP + Security PASS + BOSS-2 SHIP); both\nregression tests mutation-proven to fail on the old behavior.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Split dropped-under-load traffic out of \"still classifying\" (P1.1)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T17:23:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d565aae650cfb230f6b7adf1d960bdef364f2db",
          "body": "…ard plan\n\nThe live-traffic visibility feature is now live on prod, and after using it on\nreal connected apps the founder surfaced trust + UX concerns. A code investigation\nconfirmed two real honesty bugs (dropped-under-load requests parked forever as\n\"still classifying\"; the tail/makeup hide the ve\n[…]\nadmap and tracked bugs are never\nlost. Storage decision locked: durable aggregates only, never a per-request\nreal-id log (the anthem red line).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record live-traffic visibility deployed-live + store the trust/dashbo…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T17:20:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e24f3410579749befa5f30fcfc122b496a09f18",
          "body": "… re-audit\n\nAll five phases are done and each was gated: composition counters (P1),\nthe Coverage composition UI (P2), the ephemeral zero-persist tail backend\n(P3), and the live-tail console (P4). P5 re-verified the whole feature:\nboth CI suites green (root engine + backend 931), frontend clean, the \n[…]\nent capstone sign-off passed.\n\nRecords the whole-feature state in the plan build log and RUNNING_STAGE3.\nCommitted, not yet pushed or deployed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Mark live-traffic-visibility plan complete after the P5 whole-feature…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T13:20:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bce0ad5507c443ebcf9710ea3d6986db881260a1",
          "body": "The tail backend streams judged events per monitor; this is the console\nthat watches it. On the /live page each monitor row gains a \"Watch live\ntraffic\" toggle that opens a live feed of judged requests: per row a\ntimestamp, the caller reaching an object and that object's owner (the\nmetadata that ans\n[…]\n-proved the no-green\nguard), Design SHIP (5 fixes, including a real Tailwind-v4 border bug and\na truncated-identity-line fix, all re-verified).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add live-tail console to the /live monitor row (#2 UI)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T13:08:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7b4b5dd748d27dad0d03c8da658b1ba61e892b2",
          "body": "…ist (#2 backend)\n\nThe Coverage composition (#1) tells an owner the aggregate makeup of a\nroute's traffic. This adds the live counterpart: an owner can watch judged\nevents stream in real time (endpoint, verdict owner-access/cross-user/\nunresolved, and the caller/object/owner ids BoLD already receive\n[…]\nostgres LISTEN/NOTIFY) is deferred.\n\nTriple-gated: Security PASS (runtime-proved zero-persist + no connection\nheld), Critics SHIP, BOSS-2 SHIP.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add ephemeral live tail: owner-scoped SSE of judged events, zero-pers…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T12:49:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e1306d96e77f06040f3ed5547736fc0690e321c",
          "body": "Coverage could show a route was seen in live traffic, but not WHAT that\ntraffic was. A user could not tell whether requests were owners reaching\ntheir own objects or cross-user violations, and clean same-user access\nwas invisible entirely. This surfaces the makeup: expand a live route to\nsee a stack\n[…]\nated then reconciled: Critics SHIP (mutation-proven), Design\nrevise (applied), BOSS-2 SHIP after its one regression was fixed and\nre-confirmed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add per-endpoint live traffic-makeup drill-down to Coverage (#1 UI)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T12:05:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "430d7408aa20681503e900855a62b103b3d6ddc6",
          "body": "…-only)\n\nCoverage could show that an endpoint was seen in live traffic, but not\nwhat that traffic was: a user could not tell whether requests were owners\nreaching their own objects or cross-user violations, and clean same-user\naccess was invisible entirely. This surfaces that split WITHOUT a\npersist\n[…]\n\n(the live lens has no green branch at all). Fail-isolated: a counter error\nis logged and skipped, never touching the verdict or finding write.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add per-endpoint live-traffic health composition (aggregate, metadata…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-13T11:30:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3a693ccfd106262fef6aa24cbf013ff1ac6ebc42",
          "body": "A staging backend deploy job gated to a future 'staging' branch (inert on main), its fly.staging.toml targeting a separate Fly app + deploy token so it can never touch production, plus CODEOWNERS and CONTRIBUTING.md.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a staging deploy pipeline and contribution guardrails",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T22:48:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "38809438d4a47ec7e83f3018f3befdd33174ceb0",
          "body": "The gated frontier-expansion research (market numbers verified to primary sources, the OWASP agentic threat map, the competitive + pricing landscape, buyer/pain signal, and the moat-safe AI/ML workstreams), plus the reconciled findings, the pre-research checkpoint, the pitch-clarity brief, the desig\n[…]\nle record behind the permission-violation-alarm-for-the-AI-era positioning. (.docx originals stay local per the repo's standing *.docx ignore.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add Scope-Expansion: frontier research, positioning, and GTM docs",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T22:48:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d129b78a47b717e13a909ed2459c2b96f58ef91",
          "body": "POSITIONING.md and PRICING.md were not git-ignored — a real risk of leaking the founder's private positioning and pricing into version control. Ignore them explicitly, and ignore agent working-memory wherever it lands (including under Scope-Expansion/).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Protect private strategy files from ever being committed",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T22:48:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d0adc31af7a08c364f0978cd393388a7836a2ed7",
          "body": "…rod)\n\nThe Authorization nav's \"Missing Auth\" entry, the command palette, and the\nconnect guide all link to /noauth, but no /noauth landing page existed --\nR5.5c built only /noauth/run/[pending_id] (the consent page reached from a\nprepared check). Every other authz family has a landing page; missing\n[…]\n\nsurface for other orphan/broken-link gaps -- none) + Security PASS. 279\nfrontend tests green; lint + build clean; /noauth is now a real route.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(noauth): add the missing /noauth landing page (dead nav link on p…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T15:18:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7ca467b72d3c6a24d7f51791ad56e4140e69316b",
          "body": "…y + orthogonality\n\nThe final R5 hardening phase. Three guards, then the family is code-complete.\n\nCOPY-HONESTY INVARIANT (BOSS-2's binding trust guard). R5-active is the softest\nCONFIRMED in the authorization family — its whole true-vs-false-positive\ndistance rests on the declaration-relative copy \n[…]\n the whole-family deploy sign-off). Folds the\nold R5.6. 912 backend + 273 frontend green; mypy + ruff + lint clean; crown\njewel byte-untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5f: close the missing-auth family — copy-honesty invariant + parit…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T14:36:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "845f09020424af027ffa117129e2e7e3ed27f296",
          "body": "Coverage: a missing-auth route earns GREEN only from an ACTIVE NOT_VULNERABLE\n(the seeded no-credential check refused on a declared route) -- \"noauth\" joins\n_ACTIVE_SOURCES. The passive \"noauth-live\" lens joins _LIVE_SOURCES so a missed\nlead is visible, but it can NEVER be green: the live lens's _li\n[…]\nCONCLUSIVE companion stays green, the\ndistinguishing catch). 883 backend + 270 frontend + mypy + ruff + lint clean;\nengine + testapp untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5e: missing-auth coverage-green + connect-guide ceilings",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T13:53:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80653657f2c966fecbe56e84c5a8749aae4cd37b",
          "body": "…mcp 0.11.0)\n\nbold_noauth_guide + bold_prepare_noauth_check + bold_noauth_status, mirroring\nthe shipped bopla/tenant MCP tools. The MCP is a thin client that drives the\nflow but is structurally incapable of crossing any anthem line:\n\n  - It NEVER handles a credential -- no session/credential field i\n[…]\nP tests +\ntsc clean. Docs cover R5.5c + R5.5d. NOT published -- 0.11.0 publish is\nfounder-gated behind the R5 backend deploy (R5-DEPLOY-ORDER).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5d: MCP orchestration for the missing-auth active check (@boldsec/…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T13:23:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6a241abf46a8a0cb1744814b0a4f3e306c88c376",
          "body": "The browser page (/noauth/run/[pending_id]) where the operator confirms the\nplan, supplies ONE authenticated seed session, affirms the route is meant to\nrequire auth (the D3 checkbox), and runs the active check. Mirrors the shipped\nbopla/tenant consent pages.\n\nThe anthem, in pixels: green is EARNED,\n[…]\ny me; Critics\nmutation-proved every rendering branch (null->green and CONFIRMED->neutral both\ngo red). 263 frontend tests + lint + build clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5c: the missing-auth active-check consent + run UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T13:23:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "66f2828eb69b29380265a81151d32f4c1d305ad3",
          "body": "… path)\n\nR5-active is the only authorization sibling whose CONFIRMED carries no second\ncredential -- the whole true-vs-false-positive distance collapses onto the\noperator's one authRequired declaration, so a mis-declared public+seedable\nroute could manufacture a false CONFIRMED. The engine hardcodes\n[…]\nted by me, danger gate mutation-proven on every axis. Crown jewel\nuntouched. 876 backend + root-engine + 247 frontend green; mypy + ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5b: the active missing-auth check + THE DANGER GATE (the CONFIRMED…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T12:48:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fef31cb5fa7173a72525fa59fae0755406c7fe81",
          "body": "The R5.3 noauth-live passive lead persisted as a Finding but every product\nsurface still spoke BOLA for it: the explain card, the source badge, the\nfamily filter, and the finding-detail blurb all fell through to object-\nownership copy. That is a false-family-in-pixels failure -- the anthem bans a\nfi\n[…]\ntypes.\nTracked as R5-OPENAPI-DRIFT for a dedicated resync pass.\n\nCrown jewel untouched. 849 backend + 246 frontend green; mypy/ruff/lint clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5a: render the missing-auth passive lead truthfully on every surface",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T05:03:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e019eb743c0c9c2ac246a74abb37e5f7d2a625de",
          "body": "…spine)\n\nThe R5.3 noauth-live lead misfiled into the BOLA family bucket and rendered BOLA\ncopy. This threads is_noauth across every backend surface that branches on family,\nso a missing-auth finding is bucketed, badged, explained, fixed, reported, and\nnotified as missing-auth -- never BOLA. First R5\n[…]\n re-confirmed with a fail-on-old test) + Security PASS +\nBOSS-2 SHIP. Crown jewel decision.py untouched. 840 backend tests + ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5.0: give missing-auth its own finding-family identity (the model …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T04:20:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d083d3c4ced902eaf283431d109ff819d398eb0",
          "body": "…= protocol\n\nR5.2 widened RequestSender.unauthenticated_request with a keyword-only headers=\nargument (the R5 cache-prevent) but did not update two implementers, leaving them\nnon-conforming. The 3 mypy errors were latent on main since R5.2 because the mypy\nchecks in R5.2/R5.3 were scoped to app/live/ and the engine, never full app/. Add\nthe keyword-only headers param + pass it through on both. Full `mypy app/` clean again.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: conform OriginLockedSession/_Sender to the RequestSender headers…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T04:19:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3e821fd12974f792618fee0bd227232e8fb6103b",
          "body": "The last R5 phase, planned end-to-end and double-gated (Critics SHIP + BOSS-2\nSHIP) before any code. 7 sub-phases (R5.5.0 model spine -> a passive UI -> b\nactive backend + danger gate -> c consent UI -> d MCP -> e coverage/ceilings ->\nf hardening/discovery/claims), each grounded in the shipped BFLA/\n[…]\niscovery-surface parity (the R4.7 lesson), the family-branch\nsurfaces, and the connect-guide honesty (resolveCallerId ceiling + the N2 clause).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.5: the end-to-end missing-auth product-surface plan (gated)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T03:34:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9d5006f2549ff1555c7c7a4fd633737465fc7b90",
          "body": "The operator-facing half of R5. A per-route `authRequired?: boolean` on the SDK's\nBoldConfig, mirroring the shipped `privileged` (BFLA) flag exactly: when set, the\nSDK adds `route_auth_required: true` to the metadata event, which the R5.3 backend\nturns into a needs-review lead when a no-credential r\n[…]\nion 0.10.0 -> 0.11.0, BUILT NOT PUBLISHED: the R5.3 backend\nmust deploy first (IngestEvent is extra=\"forbid\", so an unshipped field would 422).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.4: add the @boldsec/next authRequired declaration for missing-auth",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T01:57:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0ddbf8a9e801880065031f7f671d04de9e5b91c",
          "body": "The live twin of R5.1's classifier and R5.2's active check. A real anonymous\nrequest (no credential) that succeeds on a route the operator DECLARED requires\nauth is now surfaced as a loud needs-review lead -- never a CONFIRMED, because\npassive traffic has no authenticated baseline to fingerprint aga\n[…]\nver forked).\nTriple-gated (Critics SHIP + Security PASS + BOSS-2 SHIP, all re-audited). Engine 716\n+ backend 819 tests green on fresh bytecode.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.3: add the passive/live missing-authorization lead",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-10T01:33:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f6ca4098cfe94419cfe34f9167f5ae29ea1bd5f8",
          "body": "R5 is the first BoLD check ever issued with NO credential, which opens a\nfalse-CONFIRMED hazard unique to it: an auth-keyless CDN could serve a cached\nauthenticated body back to the no-cred probe. The defense is structural, not a\ndetector. The no-credential probe is issued FIRST, on a fresh\nnever-be\n[…]\ns byte-untouched (classify_noauth unforked). Triple-gated\n(Critics SHIP + Security PASS + BOSS-2 SHIP, all re-audited). 690 engine tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "R5.2: add the active missing-authorization check (no-credential probe)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T23:27:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "05197fcf0fc7c80f6b01af4afbf828dcdb33eba7",
          "body": "R5 catches missing authorization: a request that succeeded with no credential on a route the operator declared must require auth. It is the positive-detection twin of the engine's existing no-auth guard (G3) -- the same 'reachable with no credentials' signal that clears an object as public now incri\n[…]\nache-prevent are R5.2. Double-gated (Critics SHIP + Security PASS); 24 unit tests incl. a 300-case combinatorial grid; full engine suite green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add classify_noauth, the fifth authorization-family classifier (R5.1)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T22:10:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1faeddfeab551318fc63c18e3772ebf668556a4c",
          "body": "R4.8 hardened the tenant active check against a path-traversal hole where an operator-supplied id or path is interpolated into a request path. The same class was pre-existing in BOLA, BFLA, and BOPLA, and reached through the object_path_template / collection_path literals as well as the ids. Close i\n[…]\ntics double-gate (which between them found five stored-read sites neither found alone). Engine and backend suites green; decision.py unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Close the operator path-traversal class across all authz families (R4.9)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T12:59:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d37849bbb656b9a802848957903d1d7fa649c9da",
          "body": "The backend CI lint runs ruff over app/ AND tests/; a 102-char f-string in the new traversal test tripped E501 and failed the Backend job (so R4.8 did not deploy). Shorten the message under 100. No behavior change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reflow an over-long assertion message in the R4.8 backend test",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T05:05:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "abfc2bcc28eae5047d8f5d76dbed12157f8877f1",
          "body": "A path-based multi-tenant app (tenant in the URL, e.g. /api/tenants/{tenantId}/reports/{id}) crashed the tenant active check: object_path_template.format(id=...) supplied only `id`, so any other placeholder raised KeyError, escaped the EngineError guard, and became an unhandled 500 (\"try again\"). Re\n[…]\nnow shows the resolved path.\n\nCaught by the Security + Critics double-gate before ship. Engine and backend suites green; decision.py unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix tenant active-check crash on path-based multi-tenant apps (R4.8)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T04:58:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a347f3b275553eb591b04d379a90d7fb8d40819",
          "body": "R4 shipped tenant detection end to end but only into the surfaces where a finding is VIEWED (findings inbox, badge, detail, coverage). The surfaces where a user DISCOVERS and launches a check -- the Authorization nav dropdown, the Cmd-K palette, and the connect-guide -- still listed only BOLA/BFLA/B\n[…]\n in the nav tests so a future family cannot silently skip a discovery surface.\n\nFrontend-only; the engine, backend, and SDK are byte-unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wire tenant isolation into every discovery surface (R4.7)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T02:54:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8fde11eec19bd9fb2b77fe8201ca0ed665877f5",
          "body": "Both packages are now live on npm at 0.10.0 with tenant-isolation support in their SDK/MCP surfaces. Bump the versions and add \"tenant isolation\" to the package descriptions so the repo matches the registry.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record @boldsec/next + @boldsec/mcp 0.10.0 publish",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T02:54:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c3194c2dcce2ffb2dfc2ca8ad17a15370c6d34ce",
          "body": "The closer for R4. tests/test_r46_orthogonality.py proves the two \"wrong\nstones\" the R4 gate named, at the engine (crown-jewel) layer the R4.3\npipeline suite did not reach:\n\n  #1 the false-CLEAN trap -- tenant-match is not \"safe\". A same-tenant\n  access to a DIFFERENT user's private object clears th\n[…]\nily is green\ntogether: engine + backend + frontend + @boldsec/next + @boldsec/mcp.\nDouble-gated: Critics SHIP + Security PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.6: the tenant orthogonality regression suite + closing hardening",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T01:55:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6bd9acc8803643bfc4fab7bd2e8483b1f7b84c51",
          "body": "Completes R4.5. bold_prepare_tenant_check + bold_tenant_status +\nbold_tenant_guide in @boldsec/mcp, mirroring the shipped BOPLA MCP.\nThe MCP is a thin client: it never reaches a verdict (classify_tenant\ndoes), and the two tenant sessions are never a tool argument -- the\nhuman pastes them into the br\n[…]\nre re-verify link and never\nsources an object.\n\nBackend and engine byte-unchanged. Double-gated: Critics SHIP +\nSecurity PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.5: the MCP tenant-isolation tools",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T01:23:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cccf16ee680666eb753e6dea55446b5fcf5822c3",
          "body": "Coverage tells the user, per route, what BoLD can honestly say. Its one\nrule: GREEN (\"verified safe on what BoLD can see\") is earned only by an\nactive check returning NOT_VULNERABLE, in the active lens; passive\nsilence has no path to green.\n\nThis wires tenant in without weakening that rule. The enti\n[…]\nge renders on state, never source, with\na neutral default). Engine byte-unchanged. Double-gated: Critics SHIP +\nSecurity PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.4: wire tenant isolation into Coverage",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T00:53:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0b4d0b110f492284d2333c73724921094eac5f27",
          "body": "R4.5.2 earns a CONFIRMED tenant finding; R4.5.3 is the surface a user\ndrives it from. Mirroring the shipped /bopla UI: a /tenant teaching +\nlaunch page, a consent + credential-handoff run page that collects the\nTWO throwaway-tenant sessions (owner + cross-tenant caller) and fresh\nattestation, a Tena\n[…]\nno\nconfirmed finding.\n\nFrontend-only; no backend or engine change. Triple-gated: Design\nAPPROVE + Critics SHIP + Security PASS, all re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.3: the active tenant-isolation check UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-09T00:27:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3f170e6cf478fc1cba82f7ba66d1cbf67c9073c3",
          "body": "R4.5.1 rendered tenant findings; R4.5.2 is where a CONFIRMED tenant\nfinding is earned. tenant_checks_api.py mirrors the shipped BOPLA active\ncheck: a 4-endpoint pending flow (prepare -> plan -> run -> status) that\nwires the R4.2 TenantOrchestrator to seed a throwaway object under one\ntest tenant, at\n[…]\nectly blocked\", a false-clean.\n\nclassify_tenant and the engine are byte-unchanged. Double-gated: Critics\nSHIP + Security PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.2: the active tenant-isolation check backend",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T23:50:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f994f0c9c761fdffc76327c3d80cc28d66643231",
          "body": "R4.3/R4.4 made the passive tenant lead fire and persist findings with\nsource=\"tenant-live\", but they rendered with BOLA \"another user's\nobject\" copy -- a wrong-family, honest-pixels violation. R4.5.1 makes\nTENANT a first-class finding family everywhere is_bopla/is_bfla are\nhandled: the badge (Tenant\n[…]\nr the BOLA tell) plus two mutation proofs confirm the tests bite.\n\nTriple-gated: Critics SHIP + Security PASS + Design APPROVE, all\nre-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.5.1: render tenant findings as a first-class family",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T23:01:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "74c8c56de31c713a5ad46713e0ad91c217de21aa",
          "body": "R4.3 gave the engine + backend a live tenant judge, but it was inert:\nnothing supplied caller_tenant/object_tenant on real traffic. R4.4 is\nthe SDK side — the wrapper now resolves and emits both, so the passive\ncross-tenant LEAD fires on a connected app.\n\nThree opt-in options mirror the owner/scope/\n[…]\nnly ever a needs-review LEAD, never a CONFIRMED.\n\nEngine + backend byte-unchanged. Double-gated: Critics SHIP + Security\nPASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.4: the @boldsec/next SDK tenant declaration/emission",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T21:58:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6dac1ee69ab7b26a0ce6739f5a154e1eef62d06a",
          "body": "The R4.2 active check only fires on our own seeded tenants. Real\ncustomer traffic needs a passive path that raises a needs-review LEAD\nwhen a caller in one tenant is seen reaching another tenant's object —\nbut the anthem forbids a passive CONFIRMED, so the lead must be\nstructurally incapable of ever\n[…]\nd (R4-CARRY-5 avoided).\nclassify_tenant is byte-unchanged — reused, never forked.\n\nDouble-gated: Critics SHIP + Security PASS, both re-audited.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.3: the live/passive tenant-isolation lead",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T20:32:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c06166a08b440501c6c5183111d2e3d645e5bdd9",
          "body": "The tenant-isolation CONFIRMED path -- the fourth active check, a sibling of the BOLA/BFLA/BOPLA orchestrators. TenantReplaySession seeds a throwaway object as a tenant-A test account and attempts cross-tenant access as a tenant-B account; TenantOrchestrator runs it behind the same rails (permission\n[…]\nnt_a_id != tenant_b_id is enforced at construction. Double-gated (Critics SHIP + Security PASS). 20 machinery tests over a real mock transport.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add R4.2: the active tenant-isolation check (engine)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T19:24:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b2927a89e8a9dc285a79de7ab97ac3e8563e8588",
          "body": "classify_tenant's TG4 (public-endpoint guard) cleared a cross-tenant access as NOT_VULNERABLE on ANY unauthenticated 2xx-with-body response. Unlike BOLA's G3, it did not require the anonymous read to actually return the object (a fingerprint match with the owner's baseline). So an app answering unau\n[…]\nd no-false-CLEAN (0/0); reverting the fix reintroduces 1,260 grid false-cleans (fail-on-old). The three sibling classifiers are byte-unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix a soft-200 false-clean in classify_tenant (TG4 + new TG4c)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T19:24:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04afaa1b6d0fc6fe3ca881b80739c17adeb50acc",
          "body": "Tenant/boundary isolation ('did a caller in tenant B reach tenant A's object?') needs its own verdict logic, but the crown jewel must never fork: classify_tenant is a pure SIBLING of classify/classify_privilege/classify_property, sharing the Verdict/Decision/Action spine and adding zero lines to the\n[…]\n SHIP + Security PASS); three independent stress grids (~4.6M cases) each found 0 false CONFIRMED; fail-on-old proven by mutating all 8 guards.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add classify_tenant, the 4th deterministic decision sibling (R4.1)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T16:52:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a69c05e7547ec088c8b2183c65725a5a1ee120c0",
          "body": "R4.0 (the R4 tenant research + convergence gate) ran: product + tech research, my re-audit, and an independent Critics BLOCK -- the gate working, not rubber-stamping. Captures the converged decisions (tenant CONFIRMED is active-only, sitting with BFLA/BOPLA; object_scope [A5 org-readability] is dist\n[…]\n1 fix + double-gate outcome + the anthem-required noise tradeoff. R4.0's blockers are cleared; the gate awaits founder go to lock + begin R4.1.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the R4.0 tenant-isolation gate + the B1 fix",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T13:51:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1db7bf1d6669769915ed8092319ff75de38ffbcc",
          "body": "On a scoped URL (/orgs/{org}/items/{id}) the SDK and backend auto-derive object_scope from the URL, so a per-user PRIVATE object read by a DIFFERENT same-org member (caller_in_scope=True) was exempted to NOT_VULNERABLE via ExemptReason.SCOPE -- silently clearing an intra-tenant BOLA. object_scope an\n[…]\n that encoded the false-clean are corrected (proven fail-on-old) + a learned-owner regression added. Double-gated: Security PASS, Critics SHIP.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Close a live A5/SCOPE false-clean: hold a per-user-owner conflict",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-08T13:50:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5904486e89967d937873d493dc6795409d599e53",
          "body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: log the ACTION->POST method-hint fix (METHOD-HINT)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:48:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "118bbf6cd7f8669257777b16879fc7af0ee3ab29",
          "body": "The frontend METHOD_BY_ACTION and backend _HTTP_BY_ACTION both re-declared\nthe action->HTTP-method map and both had drifted from the engine: a\nphantom CREATE and no ACTION. So a state-changing \"action\" finding (a\nrefund / share / invite / promote, which is exactly the shape of a\nprivileged BFLA func\n[…]\n sides are proven to\nfail on the old maps (they returned GET for an ACTION finding). Hint-line\nonly: no verdict, auth, or data surface changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: map the ACTION verb to POST in the AI-fix method hint",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:48:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "38e138cae964ffcb30e4c6e16e9f3f25f040ae7e",
          "body": "… redesign\n\nRecord the two founder-reported BOPLA-surface fixes plus the BFLA-FIXCOPY\nfollow-up in the running log and the hardening ledger: BOPLA-FIXTHIS,\nBOPLA-CHIPS, BOPLA-REDOS (addressed inline), and BFLA-FIXCOPY (fixed, not\ndeferred). All double-gated.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: log the family-correct Fix this (BOPLA + BFLA) and consent chip…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:16:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6bdd4fab4d71a5155ebef7db08ca6d3951be9f1c",
          "body": "… amber\n\nThe declared-field chips painted \"write-protected\" with verdict-review,\nthe amber reserved for the \"needs review\" verdict. But these chips are\nthe subjects of the check, not a verdict, so the reuse was both\nsemantically wrong and read as AI-generated tag soup. Use one calm glass\nchip per fi\n[…]\nmeaning, so it never relies on\ncolor alone. Purely visual: the credential/consent/attestation logic is\nuntouched. Critics SHIP + Security PASS.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "bopla consent: premium glass field chips, gold accent not the verdict…",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:16:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0694d7e80e561e3fd09b38849c520ddb5b39dbf2",
          "body": "…this\n\nA CONFIRMED BOPLA finding rendered only \"Verify your fix\" with no\nremediation: it presumed the user knew to allow-list the field but never\nshowed how. A CONFIRMED non-live BFLA fell through to the shared BOLA\nblock, showing ownership copy (reproduce/fix/AI prompt all said\n\"BOLA/IDOR ownership\n[…]\nktracking). Regression tests proven to fail on the old behavior.\nDouble-gated: Critics SHIP + Security PASS on both the BOPLA and BFLA\nchanges.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "findings: give CONFIRMED BOPLA and BFLA their own family-correct Fix …",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T03:16:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7a5dd6b72dd8aab3d97da0d931f5424a813b672",
          "body": "Log the two Findings changes, the Critics SHIP + Security PASS double-gate, and\nledger the now-orphaned /api/findings/suggest surface (DEAD-SUGGEST) as a safe\nbroom-pass follow-up per the founder's call to push now and clean up next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the findings overlay removal + type filter (both gates green)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T01:37:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ddb95496ecfb058032ed05f4cd7b4d1aa6e5d97c",
          "body": "The findings list already filters live as you type, so the floating autocomplete\ndropdown was a second, redundant overlay sitting on top of the real filtered\nlist. Replace it with a plain search input (the instant live filter, the\nshareable ?q= URL, and the no-flicker refetch are all unchanged) and \n[…]\nsing with the status filter and\nsearch via ?family=. An empty family-filtered view stays honest (\"never an\nall-clear\"); it never reads as safe.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Drop the redundant findings search overlay; add type-filter chips",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T01:37:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "997eb2cbe74f1fc01c4a58bcadbbe7add1662054",
          "body": "Add a family view-filter to the findings query, keyed off Finding.source\n(bfla/bfla-live -> BFLA, bopla/bopla-live -> BOPLA, else BOLA -- the same map as\nFinding.is_bfla/is_bopla, asserted to agree in tests so the filter and the\nsource badges can never disagree about a finding's family). It composes\n[…]\nnly: it never touches a verdict, \"All types\" hides nothing, and an\nunknown value falls back to \"all\" so a partial view can never read as clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Filter findings by authorization family (BOLA / BFLA / BOPLA)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-07T01:37:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1116328e576062bd9a67d54dd5db3c2037356cf8",
          "body": "The Settings > Developer MCP card and the other places that show the connect\ncommand still displayed the bare `npx @boldsec/mcp`, which npx can pin to a\nstale cached build (the drift that lost a client the BOPLA detector). Show\n`@boldsec/mcp@latest` everywhere a user can copy it, and add a \"Staying \n[…]\nupdate. Deliberately do not\nimply `status` verifies the running version (it only checks the connection), so\nnothing reads as a false all-clear.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Teach @latest and the restart-to-update step in the MCP setup UI",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-06T20:55:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45fc6bfcd3e369e16dd95312c6660b707c977918",
          "body": "Log the findings-search opacity fix and the MCP anti-drift fix, note the\nSecurity/Critics double-gate, and ledger the pin-exact-at-wire-time supply-chain\nhardening as a tracked founder decision. Also record that the live passive BOPLA\n\"needs review\" is correct by design (classify_property PRP4), not a defect.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record the three prod fixes (search, MCP drift, BOPLA needs-review)",
          "author_name": "Sahith Reddy Thummala",
          "author_login": "Sahith59",
          "committed_at": "2026-07-06T20:37:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 0,
      "commits_last_year": 403,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 7,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": false,
      "has_contributing": true,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "src/ideax/py.typed",
        "web/frontend/tsconfig.json",
        "web/sdk/bold-core/tsconfig.json",
        "web/sdk/bold-express/tsconfig.json",
        "web/sdk/bold-fastify/tsconfig.json",
        "web/sdk/bold-hono/tsconfig.json",
        "web/sdk/bold-koa/tsconfig.json",
        "web/sdk/bold-mcp/tsconfig.json",
        "web/sdk/bold-nestjs/tsconfig.json",
        "web/sdk/bold-next/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 245593,
      "source_files_sampled": 611,
      "oversized_source_files": 10,
      "agent_instruction_files": [
        "web/frontend/AGENTS.md",
        "web/frontend/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 327
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.27"
        },
        {
          "name": "pyyaml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0"
        },
        {
          "name": "ideax",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "fastapi",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.115"
        },
        {
          "name": "uvicorn",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.32"
        },
        {
          "name": "pydantic",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.9"
        },
        {
          "name": "pydantic-settings",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0"
        },
        {
          "name": "alembic",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.14"
        },
        {
          "name": "asyncpg",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.30"
        },
        {
          "name": "aiosqlite",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.20"
        },
        {
          "name": "python-multipart",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.0.12"
        },
        {
          "name": "argon2-cffi",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=23.1"
        },
        {
          "name": "authlib",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.3"
        },
        {
          "name": "email-validator",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.2"
        },
        {
          "name": "itsdangerous",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.2"
        },
        {
          "name": "anthropic",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.40"
        },
        {
          "name": "reportlab",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.2"
        },
        {
          "name": "python-docx",
          "manifest": "web/backend/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1"
        },
        {
          "name": "@hookform/resolvers",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.0"
        },
        {
          "name": "@radix-ui/react-avatar",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.12"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.16"
        },
        {
          "name": "@radix-ui/react-dropdown-menu",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.17"
        },
        {
          "name": "@radix-ui/react-label",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.9"
        },
        {
          "name": "@radix-ui/react-separator",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.9"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.5"
        },
        {
          "name": "class-variance-authority",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "cmdk",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "framer-motion",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.40.0"
        },
        {
          "name": "lucide-react",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.18.0"
        },
        {
          "name": "next",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "16.2.9"
        },
        {
          "name": "posthog-js",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.395.0"
        },
        {
          "name": "react",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.2.4"
        },
        {
          "name": "react-dom",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "19.2.4"
        },
        {
          "name": "react-hook-form",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.79.0"
        },
        {
          "name": "sonner",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.0"
        },
        {
          "name": "zod",
          "manifest": "web/frontend/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 2,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Sahith59",
          "commits": 401,
          "avatar_url": "https://avatars.githubusercontent.com/u/97082825?v=4"
        },
        {
          "type": "User",
          "login": "PranavNagothu",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/274616405?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.995
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "promote-to-production.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "49 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "06065e27b947b60ea3ca4e378a9f0d9c50ee7b4c",
        "ran_at": "2026-07-23T08:02:49Z",
        "aggregate_score": 2.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T15:06:37Z",
      "oldest_open_prs": [
        {
          "number": 3,
          "created_at": "2026-07-22T16:16:56Z",
          "last_comment_at": "2026-07-22T16:16:57Z",
          "last_comment_author": "vercel"
        }
      ],
      "last_merged_pr_at": "2026-07-22T15:00:50Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Sahith59/BoLD",
    "host": "github.com",
    "name": "BoLD",
    "owner": "Sahith59"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 40,
      "inputs": {
        "security": 23,
        "vitality": 36,
        "community": 22,
        "governance": 40,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 36,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "commits_last_year": 403,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "403 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 403
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 22,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 40,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.995
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 2,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2/2 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Sahith59",
              "public_repos": 52,
              "account_age_days": 1661
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of Sahith59",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "Sahith59"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "52 public repos, account ~4 yr old",
                "points": 21.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 52
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://bold-lemon.vercel.app",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://bold-lemon.vercel.app",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 23,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 23,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 2.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "49 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "web/frontend/AGENTS.md",
                "web/frontend/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 327
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "web/frontend/AGENTS.md, web/frontend/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "web/frontend/AGENTS.md, web/frontend/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "src/ideax/py.typed",
                "web/frontend/tsconfig.json",
                "web/sdk/bold-core/tsconfig.json",
                "web/sdk/bold-express/tsconfig.json",
                "web/sdk/bold-fastify/tsconfig.json",
                "web/sdk/bold-hono/tsconfig.json",
                "web/sdk/bold-koa/tsconfig.json",
                "web/sdk/bold-mcp/tsconfig.json",
                "web/sdk/bold-nestjs/tsconfig.json",
                "web/sdk/bold-next/tsconfig.json"
              ],
              "agent_commit_share": 0.97,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "97 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 245593,
              "source_files_sampled": 611,
              "oversized_source_files": 10
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "src/ideax/py.typed, web/frontend/tsconfig.json, web/sdk/bold-core/tsconfig.json, web/sdk/bold-express/tsconfig.json, web/sdk/bold-fastify/tsconfig.json, web/sdk/bold-hono/tsconfig.json, web/sdk/bold-koa/tsconfig.json, web/sdk/bold-mcp/tsconfig.json, web/sdk/bold-nestjs/tsconfig.json, web/sdk/bold-next/tsconfig.json",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "10/611 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 611,
                      "oversized": 10
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch pypi package 'ideax' from its registry",
    "Could not fetch pypi package 'bold-backend' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T08:02:56.487773Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/Sahith59/BoLD.svg",
  "full_name": "Sahith59/BoLD",
  "license_state": "absent",
  "license_spdx": null
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistiken.