Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-25 07:28 UTC

Tnsor-Labs / brokoli

Brokoli — self-hosted data pipeline orchestration

Go · SvelteApache-2.0★ 1 Stern⑂ 0 Forksseit Mai 2026Auf GitHub ansehen ↗

Tnsor-Labs/brokoli erreicht einen Gesundheitsindex von 53 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Engineering Quality (81/100) ab, am schwächsten bei Community & Adoption (24/100). Zuletzt vor 5 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

53
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

53
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Tnsor LabsOrganisation
0 Follower2 öffentliche Reposseit Apr. 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/Tnsor-Labs/brokoliv0.10.0-18vor 6 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

74Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 5 Tagen
18/36Commit-Rhythmus — 26/52 Wochen mit Commits
18/18Commit-Volumen — 285 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year285
human_commit_share1
days_since_last_push5
active_weeks_last_year26
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 1 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 6 Tagen
12.6/27Release-Rhythmus — Rhythmus unbekannt (nur ein Release)
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count1
latest_release_tagv0.10.0
releases_from_tagsnein
days_since_latest_release6
mean_days_between_releases

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

24Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 1 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

49Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
23.4/46.8Issue-Lösungsquote — 50 % der Issues geschlossen
38.2/38.3PR-Annahme — 1/1 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/28 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs1
open_issues1
closed_issues1
issue_closed_ratio0,5
closed_unmerged_prs0
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
0/25Reichweite des Inhabers — 0 Follower von Tnsor-Labs
4.1/25Kontohistorie — 2 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers0
owner_typeOrganization
is_verified
owner_loginTnsor-Labs
public_repos2
account_age_days109

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 6 Tagen
20/20Versionshistorie — 18 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/Tnsor-Labs/brokoli
ecosystemsgo
any_deprecatednein
min_days_since_publish6

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

81Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 4 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

100Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://brokoli.orkestri.site
10/10Repository-Beschreibung
10/10Topics — 15 Topics
10/10Wiki
Verwendete Eingangsdaten
topicsdata-engineering, data-ops, data-pipeline, data-quality, etl, go, golang, open-source, orchestration, pipeline, self-hosted, single-binary, sqlite, visual-editor, workflow
has_wikija
homepagehttps://brokoli.orkestri.site
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

28Kritisch · 16 % des Gesamtindex

Sicherheitslage

28Kritisch
Wie die Bewertung erfolgt
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 50 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate2,8

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

60Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 100 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — go.mod (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — ui/tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
3/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum, package-lock.json
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configsui/tsconfig.json
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/185 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes57.127
source_files_sampled185
oversized_source_files0

Eckdaten

1GitHub-Sterne
1Mitwirkende
285Commits, letzte 12 Monate
5Tage seit letztem Push
1Releases
1Bus-Faktor
1offene Issues
Go, npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 2.8 / 10
2.8Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-25 07:28 UTC

9Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities50 existing vulnerabilities detected
Direkte Abhängigkeiten 19
RegistryPaketVersionsvorgabeManifest
Gogithub.com/go-chi/chi/v5v5.2.5go.mod
Gogithub.com/go-sql-driver/mysqlv1.9.3go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogithub.com/jackc/pgx/v5v5.9.1go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogolang.org/x/cryptov0.49.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gomodernc.org/sqlitev1.37.1go.mod
npm@sodp/client^0.2.1ui/package.json
npm@types/prismjs^1.26.6ui/package.json
npmjs-yaml^4.1.1ui/package.json
npmprismjs^1.30.0ui/package.json
npmsvelte-spa-router^5.0.0ui/package.json
npmtimeline-arrows^4.8.0ui/package.json
npmvis-data^8.0.3ui/package.json
npmvis-timeline^8.5.0ui/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "data-engineering",
        "data-ops",
        "data-pipeline",
        "data-quality",
        "etl",
        "go",
        "golang",
        "open-source",
        "orchestration",
        "pipeline",
        "self-hosted",
        "single-binary",
        "sqlite",
        "visual-editor",
        "workflow"
      ],
      "is_fork": false,
      "size_kb": 14515,
      "has_wiki": true,
      "homepage": "https://brokoli.orkestri.site",
      "languages": {
        "Go": 1069078,
        "CSS": 9087,
        "HTML": 1337,
        "Shell": 11345,
        "Svelte": 531137,
        "JavaScript": 85,
        "TypeScript": 36435
      },
      "pushed_at": "2026-07-20T03:18:58Z",
      "created_at": "2026-05-09T10:56:25Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-18T23:33:08Z",
      "description": "Brokoli — self-hosted data pipeline orchestration",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Svelte"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Tnsor Labs",
      "type": "Organization",
      "login": "Tnsor-Labs",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/274098069?v=4",
      "created_at": "2026-04-06T19:38:03Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 109
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-18T23:45:22Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ee0f93f72ddc44fab3a8b4b1df42aa6257f67aaf",
          "body": "…tence\n\nfix: persist JWT token and attach auth headers to initial fetch calls",
          "is_bot": false,
          "headline": "Merge pull request #3 from Tnsor-Labs/fix/jwt-auth-headers-and-persis…",
          "author_name": "Pitch dev",
          "author_login": "hc12r",
          "committed_at": "2026-07-18T23:33:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18ccbc706bc0e9f56051bd81c2abe46a9037ae91",
          "body": null,
          "is_bot": false,
          "headline": "lint: fix lint issues in code",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-07-18T23:27:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eca1268c90d52ce80425f74bb2d96bfad4e7190c",
          "body": "Closes #2",
          "is_bot": false,
          "headline": "fix: persist JWT token and attach auth headers to initial fetch calls",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-07-18T23:21:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e579ecf88f7007cb811e8788ffa9bcfedab45342",
          "body": null,
          "is_bot": false,
          "headline": "brand: redesign — bold TL monogram, drop decorative nodes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:26:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfd5f9c7824990bbc0dec9c8ff209e071770c891",
          "body": null,
          "is_bot": false,
          "headline": "brand: add Tnsor-Labs logo system — mark, wordmark, favicon, palette",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:21:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7844b2f23d9a45c6e0234e0efb11c579e0a6ee57",
          "body": null,
          "is_bot": false,
          "headline": "docs: rename Enterprise to Brokoli Cloud, highlight free tier",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:13:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d85587d59d2acb99188adefefb01070d9a8b8fe",
          "body": null,
          "is_bot": false,
          "headline": "docs: remove enterprise comparison table and API reference section",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:10:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d99ebef24a2aa8ace72f99c4e1ba2f4b86e5e43d",
          "body": null,
          "is_bot": false,
          "headline": "docs: trim README — remove comparison table and architecture section",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:07:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d6e5bf7151bd18042b0dd33fc0ac879dbde9a43",
          "body": "Add shield badges (release, stars, license, activity), a tight\none-paragraph project description, and 15 GitHub repository topics\nto improve search and discoverability.",
          "is_bot": false,
          "headline": "docs: improve README with badges and discoverability",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:03:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1cf36f7f1c4acc98d0c239d3afd5660ce9ef8ff",
          "body": "…/go-vet/prettier",
          "is_bot": false,
          "headline": "chore(tooling): add Prettier for frontend + pre-commit hook for gofmt…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T08:52:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5505dc9ca03af9d95a421bf2a576af281c51e415",
          "body": "- Add nodePortConfig and canConnect() to dag.ts — source nodes have no\n  input port, sink/notify nodes have no output port, join accepts exactly\n  2 inputs, migrate is fully standalone\n- NodeCard conditionally renders ports based on portConfig; migrate nodes\n  display a \"standalone\" sub-label\n- Pipe\n[…]\n which rejects bad edge types\n  at the backend level; \"has source\" check now counts dbt and migrate;\n  disconnected-node check skips migrate nodes\n- Add dbt and notify to the TypeScript NodeType union",
          "is_bot": false,
          "headline": "feat(editor): enforce semantic connection rules in pipeline editor",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T08:44:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c7c5195da61d7fefd59d95238a23567b8008e66",
          "body": "Connections now store URI-scheme references (env://, vault://, k8s://,\nencrypted://) instead of raw encrypted passwords. The secrets.Chain\nresolver dispatches to the matching backend at execution time; plaintext\nexists only in worker memory for the duration of one pipeline run.\n\n- pkg/secrets: Resol\n[…]\n/ refs\n- API: create/update accept password_ref, responses mask encrypted refs\n  as encrypted://********, never return plaintext\n- 10 unit tests including namespace isolation, injection, and traversal",
          "is_bot": false,
          "headline": "security(connections): credential references — never store secrets in DB",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-16T06:31:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3c7bf74642d3294fde7f6177c3c975e0b046cad",
          "body": "Captures the reasoning behind SODP, plugin protocol/runtime/distribution,\nworker WebSocket, install UX, and the docs framework — so future work has\na durable record of what was considered and why.",
          "is_bot": false,
          "headline": "docs(adr): seed ADR log with 8 records of decisions to date",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-15T19:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a2b19a58aa603981d864707d59f7943dcc35a21",
          "body": "Implements the Phase 1 runtime for a connector plugin system that\nlets Brokoli load custom source/sink node types from external\nbinaries without recompiling the core.\n\nMotivation: shipping a data orchestrator with four built-in\nconnection types (Postgres, MySQL, REST API, files) isn't a\ncompetitive \n[…]\n\nTenant isolation, secret injection from Vault, and plugin\nsandboxing are enterprise concerns by design — the core plugin\nsystem is OSS because a plugin ecosystem that requires a license\ndoesn't grow.",
          "is_bot": false,
          "headline": "feat(plugins): subprocess plugin protocol for pluggable connectors",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-14T20:45:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4df2fe281c9297b8b097aaf819cf39a8646ca25f",
          "body": "…rite\n\nTwo related quality-of-life fixes for the CLI and install story.\n\n1. `brokoli --version` now works.\n\nThe goreleaser config has always injected\n  -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date={{.Date}}\ninto the binary, but main.go never declared those package-level vars,\n[…]\n the live release on a fresh temp dir:\nplatform detected, v0.7.5 resolved from /releases/latest redirect,\ntarball downloaded with progress bar, extracted, installed, and\n`brokoli --help` runs cleanly.",
          "is_bot": false,
          "headline": "feat(cli): --version flag wired through ldflags + full install.sh rew…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-14T04:16:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8fa72567a5c6d7459897247db32ba330650853f",
          "body": "…ule shape\n\nThe \"Data Quality\" pipeline template in Pipelines.svelte shipped with a\nrename rule in the shape\n\n  { type: \"rename\", old_name: \"hire_date\", new_name: \"start_date\" }\n\nbut the backend TransformRule expects\n\n  { type: \"rename\", mapping: { hire_date: \"start_date\" } }\n\n…so the deserializer s\n[…]\nion test that locks in a clear error for the\nOLD broken shape — if someone pastes the pre-fix template back in,\nthey get a loud \"rename_columns requires mapping\" error instead of a\nsilent passthrough.",
          "is_bot": false,
          "headline": "fix(ui): Data Quality template's rename rule uses the real TransformR…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T21:31:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "494d76348d4eff5c49de3bb33c5f7953da8f0f7f",
          "body": "…phans in multi-tenant mode\n\nTwo paired fixes that eliminate a class of \"I created it but can't see\nit\" bug that bit every enterprise self-hosted deployment:\n\n1) api/users.go: add UserPostCreateHook\n\nThe OSS /api/auth/users admin endpoint creates a row in `users` but\ndoesn't know anything about orgs\n[…]\nended up with an empty\norg_id, the 4 pipelines in the DB all had org_id=\"\", and the UI\nshowed \"0 pipelines\" with \"Build your first pipeline\" empty state.\nThe test pair locks in both halves of the fix.",
          "is_bot": false,
          "headline": "fix(api): UserPostCreateHook + requirePipelineOrg — prevent silent or…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T20:14:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1cee5dd4fd26f9c8868f738d62e327b4ff3200b4",
          "body": "…on realtime updates\n\nPipelines.svelte's loadPipelines() was flipping loading=true on every\ncall. The SODP dashboard tripwire then fired loadPipelines() on every\nrun state change, so the whole list re-rendered as a skeleton for the\nduration of the REST refetch. Visually identical to a forced page\nre\n[…]\nes.\n\nDashboard.svelte already did this right (applySnapshot never touches\nloading). PipelineRuns.svelte already did this right (reloadRunList\nnever touches loading). Only Pipelines.svelte had the bug.",
          "is_bot": false,
          "headline": "fix(ui): silent mode for tripwire refetches — stop flashing skeleton …",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T18:28:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9aa590a056f32de8c1a10c38605d85e58e3379b",
          "body": "The UI hardcoded \"dashboard.default\" in 5 places. In OSS open-mode\nevery user's org is \"default\" so it silently worked. In multi-tenant\nEE the user's org is their JWT's org_id (e.g. 019d6b80-…) and the\nbridge updates dashboard.{org_id}. The UI was watching a key that\nnever received deltas — so pipel\n[…]\n/auth/me\n(the backend already puts it in the JWT claims — the UI just wasn't\nparsing it).\n\nCall sites updated: App.svelte, Dashboard.svelte, Pipelines.svelte,\nPipelineRuns.svelte, RunIndicator.svelte.",
          "is_bot": false,
          "headline": "fix(ui): derive dashboard SODP key from auth user's org_id",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T06:12:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a3aa28201d4887fbf27936c5972e3d4b160cf8a",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog entry for v0.7.1",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T05:30:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15911a5e59c8ffdc259165bf68d8bbccba77dbae",
          "body": "The SSRF guard blocked relative /api/samples/... URLs once resolved\nagainst BROKOLI_SERVER_URL, because in k8s/docker deployments the\nserver hostname resolves to a private cluster IP. Workers couldn't\nfetch sample data from the API they were already authenticated to.\n\nTrack whether the URL originate\n[…]\n and skip the SSRF check in that\ncase only. Absolute URLs with private IPs are still blocked.\n\nAlso removes a dead HasPrefix check that ran after the URL had already\nbeen rewritten to an http:// form.",
          "is_bot": false,
          "headline": "fix(fetchers): allow SSRF guard to trust self-references in k8s/docker",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T05:16:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "347fe3646691e515bd5df534a7063cd497adea32",
          "body": "… check\n\nThe API server generates a persistent JWT signing secret at the path\n`.brokoli-jwt-secret` (relative to its CWD) on first start when no\nBROKOLI_JWT_SECRET env var is set. The file is plain credential\nmaterial, never meant to be committed, and lands at one of two paths\ndepending on which dir\n[…]\nunanchored above this line) does. Verified locally with\n`git check-ignore -v .brokoli-jwt-secret api/.brokoli-jwt-secret` —\nboth paths now resolve through the new rule and disappear from\n`git status`.",
          "is_bot": false,
          "headline": "chore: gitignore .brokoli-jwt-secret to unblock goreleaser dirty-tree…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:43:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6f112baeada82fb0f278f0103e36937d38e093f",
          "body": "…ference\n\n@sodp/client@0.2.1 references WebSocket.OPEN as a bare global inside\nSodpClient.send(), even when a custom WebSocket implementation is passed\nvia the constructor's WebSocket option:\n\n  send(type, streamId, body) {\n      if (!this.ws || this.ws.readyState !== WebSocket.OPEN)\n          retur\n[…]\nen upstream ships a fix in 0.2.2 or later, the polyfill block in the\ntest script and this entry in WORKAROUNDS.md can both be deleted in a\nsingle commit (same workflow as the previous closed entries).",
          "is_bot": false,
          "headline": "fix(ci): polyfill globalThis.WebSocket to bypass @sodp/client bare re…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:38:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d8d32905b273017bb6aa0531d51adfb2fd8eab6",
          "body": "TestCrossLanguage_SodpClient was failing on the GitHub Actions runner\nwith:\n\n  FATAL: Error: [SODP] No WebSocket implementation found.\n  Pass `{ WebSocket }` from the `ws` npm package in Node.js < 21.\n\n@sodp/client reads `globalThis.WebSocket` which only exists natively on\nNode 21+. CI runs an older\n[…]\nal Node 24 verified with the native path (still works); the ws\nfallback path verified by deleting globalThis.WebSocket and running an\ninline import('ws') resolution. No behavior change on modern Node.",
          "is_bot": false,
          "headline": "fix(ci): cross-language test falls back to ws package on Node < 21",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:26:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cfbe20bfd397e572fdc5a23f76f168d3a551b54",
          "body": "Pure whitespace + comment-list normalization produced by `./lint.sh --fix`\non the files touched by the SODP migration series. No semantic changes:\n\n  • api/handlers_misc.go      — JSON-literal column alignment in\n                                dashboardHandler's writeJSON(...) map\n  • pkg/sodp/brid\n[…]\n                           struct field column alignment\n  • pkg/sodp/session.go       — Session struct field-comment column alignment\n\n`gofmt -l` is now clean repo-wide; `go vet ./...` is also clean.",
          "is_bot": false,
          "headline": "style: gofmt — re-align comment blocks, constant tables, struct columns",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:13:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85b8b46382493ff57a70d9d06cae4bb1c03cb38e",
          "body": "  • docs/realtime.md — new architecture document covering the SODP\n    components (server, bridge, sodp.ts adapter, EventBus distributed\n    bridge), the state key namespace (runs.{id} / runs.{id}.nodes.{node}\n    / runs.{id}.logs / dashboard.{org}), the wire format with all 13\n    frame types, tena\n[…]\n, server concurrent-write race.\n  • README.md — Monitoring & Alerts bullet now mentions SODP and links\n    to docs/realtime.md. Architecture section adds pkg/sodp/ and docs/\n    to the directory tree.",
          "is_bot": false,
          "headline": "docs: realtime architecture, CHANGELOG, README link",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a8e8adef0f053e71620dee11ad0243c498a021f",
          "body": "web/dist/index.html points at the new bundle hashes produced by the\nSODP UI refactor build. The hashed asset files themselves\n(web/dist/assets/index-*.js, index-*.css) are gitignored — only\nindex.html is tracked, and it changes each rebuild because the\ncontent-addressed asset URLs change.",
          "is_bot": false,
          "headline": "chore(web): refresh embedded UI bundle reference",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69528911b5e4ffb8f55c76a25d9cc9e29c513ef3",
          "body": "The previous flat-grid calendar:\n\n  • Required scrolling for any range over ~30 days\n  • Marked any day with even one failure as solid red, hiding successes\n  • Showed two unrelated '12' numbers (date + run count) stacked\n\nNew design:\n\n  • GitHub-style horizontal layout: weeks as columns, weekdays a\n[…]\ns a proportional bar with success /\n    running / failed segments containing the actual counts inside, plus\n    a per-day success rate that's color-coded with the same thresholds\n    as the stats bar.",
          "is_bot": false,
          "headline": "feat(ui): Calendar — compact horizontal heatmap with mixed-outcome cells",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d1e95eeb5c5db597c9b97748243940f226a5e0b",
          "body": "… modal\n\nBoth pages defined the modal state variable as 'showModal' but the\nempty-state handler set a phantom 'showCreateModal' that didn't exist.\nThe top-right '+ New Connection' / '+ New Variable' buttons worked;\nthe prominent center CTAs in the empty state did nothing on click.\nNow both pages call the proper openCreate() handler that initializes\nthe form and opens the modal.",
          "is_bot": false,
          "headline": "fix(ui): EmptyState CTAs on Connections and Variables open the create…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f43038c2da1155bd44afd642a681ad66b5d93a3f",
          "body": "The previous architecture forced an event-stream model on top of SODP's\nstate-sync protocol via a server-side _events array key, client-side\ndeduplication, and a liveRunStatuses store that the dashboard had to\nperiodically reconcile against the server's authoritative state. The\nimpedance mismatch be\n[…]\nmain.\n  • ws.ts — deleted. Pages call getSodpClient() from sodp.ts directly.\n\nThe bridge in pkg/sodp/bridge.go is updated separately to maintain\nthe dashboard.{org} snapshot key these pages now watch.",
          "is_bot": false,
          "headline": "refactor(ui): state-driven realtime — pages watch SODP state directly",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d190e5068271fbe9e9a3d954ce2acfdc3fd182a",
          "body": "  • ui/package.json + package-lock.json — add @sodp/client@^0.2.1 as a\n    runtime dependency. Bundles transparently via vite; the embedded\n    UI build picks it up automatically.\n  • ui/src/lib/sodp.ts — singleton wrapper exposing getSodpClient() and\n    closeSodpClient(). The client is created laz\n[…]\ny App.svelte's reactive auth state — opened on login,\n    closed on logout — to prevent the SODP client from burning\n    exponential-backoff retries against /api/ws while no session\n    cookie exists.",
          "is_bot": false,
          "headline": "feat(ui): @sodp/client dependency and SodpClient singleton wrapper",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b489e15a18e3a6e56257989b14612652999c4a66",
          "body": "The previous dashboardHandler loaded only the last 3 runs per pipeline\nand the frontend then derived runs_today / success_rate / failed_24h /\nrunning_now by iterating that 6-entry sample. As soon as a workload\nexceeded the sample cap, the counters silently undercounted (observed:\n6 reported when the\n[…]\nrends and top_failing also iterate the full\nwindow, not the truncated sample.\n\nThe frontend Dashboard.svelte (refactored separately later in this\nseries) reads these fields directly from the response.",
          "is_bot": false,
          "headline": "fix(api): dashboard aggregates computed from full run window",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13c05cf0547e1e1952609787c65512807dbafa0d",
          "body": "…User errors\n\nTwo unrelated bugs in api/users.go fixed in one pass since they touch\nthe same file.\n\n  • JWTAuth's WebSocket branch validated the token but called next.ServeHTTP\n    WITHOUT setting claims on the request context. The non-WebSocket branch\n    set claims correctly. Downstream WebSocket \n[…]\ns the actual validation\n    reason as a 400, only returning 409 for genuine UNIQUE violations.\n    users_create_error_test.go covers the new sentinels and the response\n    shapes for both error paths.",
          "is_bot": false,
          "headline": "fix(api): propagate JWT claims into WebSocket context, surface Create…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79bab739a0b0310efc3929bb519dcd5b90808d78",
          "body": "  • Delete handlers_ws.go (the old in-memory Hub) entirely — its\n    responsibilities move to pkg/sodp.Server which handles tenant\n    isolation, rate limiting, frame size limits, and per-key fanout.\n  • api/server.go now creates a sodp.Server, wires the engine event\n    channel through pkg/sodp.Bri\n[…]\nributed path with three\n    tests: ForwardsToSODP (bus event → dashboard delta), OrgScopedChannel\n    (per-org dashboard isolation), MalformedEventDoesNotCrash (subscriber\n    survives a bad message).",
          "is_bot": false,
          "headline": "feat(api): replace WebSocket Hub with SODP server",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a55fa626d4c6d60e776c572b88ba710a311de42",
          "body": "  • WORKAROUNDS.md — live list of any in-tree workarounds caused by gaps\n    in @sodp/client. Currently empty (all closed) — entries get added when\n    we hit a client bug and removed when upstream releases the fix.\n  • FEEDBACK_0.2.0.md — original feedback round on @sodp/client@0.1.1.\n    7 issues \n[…]\nd of [value]. Fixed in 0.2.1.\n  • FEEDBACK_0.2.2.md — request for prefix watching (WATCH 'runs.*'),\n    needed by the state-driven UI to discover dynamic key namespaces\n    without an index key. Open.",
          "is_bot": false,
          "headline": "docs(sodp): WORKAROUNDS tracking + SODP team feedback files",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "286382fa9de93c08628a2d2ba558ab0c8842617f",
          "body": "  • integration_test.go — 12 tests using a real httptest server and a\n    gorilla/websocket client: HELLO, WATCH/STATE_INIT, DELTA fanout, full\n    run lifecycle through the bridge, multi-client broadcast, disconnect\n    cleanup, invalid keys, heartbeat echo, CALL mutations, watcher receives\n    del\n[…]\nlity, meta.source semantics (init vs delta), applyOps array\n    operations, the ws.ts baseline pattern, and state.set round-trip.\n    Skipped automatically when node or @sodp/client are not available.",
          "is_bot": false,
          "headline": "test(sodp): integration, resume, and cross-language test suites",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a86e3eacea889b8b0b15df6faced2b0e51dbf92",
          "body": "In-process Go implementation of the State-Oriented Data Protocol (SODP)\nv0.1 — a binary, msgpack-framed WebSocket protocol for streaming state\ndeltas to subscribers.\n\nReplaces the prior in-memory WebSocket Hub. The new package provides:\n\n  • frame.go    — 13-frame wire format (HELLO/WATCH/STATE_INIT\n[…]\ntests covering frames, delta, state store, ring\n                  buffer, fanout, sessions, eviction, body decoders, bridge\n\nDesigned to interoperate with the upstream @sodp/client TypeScript library.",
          "is_bot": false,
          "headline": "feat(sodp): SODP protocol implementation in pkg/sodp",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12d2aa8c094f802fcf6961e70428d075618ff80a",
          "body": "Required by the new pkg/sodp package which implements SODP v0.1\n(MessagePack-framed binary protocol for state synchronization). Pulled\nin as a direct dependency; no other consumers.",
          "is_bot": false,
          "headline": "deps: add github.com/vmihailenco/msgpack/v5 for SODP wire format",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc100fead6bea6c77b70c49e88ccbadcb664d956",
          "body": "  Fixes 7 findings from the CI security scan (gosec):\n\n  - G112 (CWE-400) Slowloris: added ReadHeaderTimeout 10s to http.Server\n  - G124 (CWE-614) Insecure cookie: logout cookie sets Secure + SameSite=Lax\n  - G115 (CWE-190) Integer overflow: bounds check before int->uint32 cast\n    in arrow_transfer\n[…]\nip newlines from URL path in logger\n  - G704 (CWE-918) SSRF: isBlockedHost/validateExternalURL blocks cloud\n    metadata endpoints and private IP ranges in REST fetcher and\n    connection test handler",
          "is_bot": false,
          "headline": "security: fix gosec HIGH and MEDIUM findings",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:46:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9d4065c30ea33427ce83b1dc40d95928210b721",
          "body": "- GET /runs/{id}/logs and /logs/export now accept ?node_id= and ?level=\n  query parameters for server-side filtering. Level is validated against\n  the known enum (debug/info/warning/error); invalid values are ignored.\n- Fixed double-header write in HealthHandler (WriteHeader was called\n  before writeJSON which calls WriteHeader again).",
          "is_bot": false,
          "headline": "feat(api): log filtering by node_id and level, fix health handler",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:43:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7705dde4648ce3585c6facc4ed5e84a5f12609df",
          "body": "Usage:\n  ./lint.sh              # check only, exits non-zero if anything is wrong\n  ./lint.sh --fix        # auto-apply gofmt, then verify\n  ./lint.sh --check      # same as no args (explicit for CI)\n\nIgnores _archive/ and web/dist/ (vendored UI output).",
          "is_bot": false,
          "headline": "chore: add lint.sh for gofmt + go vet with --fix and --check modes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9570fa9821a3521054c3989d97ee0e21c356f95",
          "body": "- Dependency system: rich dependency_rules, trigger mode, cycle detection,\n  smart delete resolver\n- CLI section: login, dev, run --follow, whoami, import/export\n- API reference: dependency endpoints, log filtering query params,\n  delete resolve modes\n- Configuration: CLI credentials, BROKOLI_MAX_CONCURRENT_RUNS env var\n- Architecture: updated cmd/ description",
          "is_bot": false,
          "headline": "docs: update README with dependencies, CLI, log filtering, YAML changes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fa5463be3e6c4e3489d571c62a0192dd163dd5d",
          "body": "…ghts\n\nThe regex-based syntax highlighter was injecting <span class=\"hl-key\">\nHTML fragments that rendered as visible text (hl-key\">name) instead of\ncolored spans. Root cause: the @html directive wasn't reliably rendering\nthe generated HTML across Svelte 5 builds.\n\nFixed by removing the broken highl\n[…]\ncodeText} instead of {@html highlightedCode}. The YAML is\nalready readable in monospace — clean rendering beats broken coloring.\n\nAlso removed the dead CSS classes (.hl-key, .hl-colon, .hl-str, etc.).",
          "is_bot": false,
          "headline": "fix(ui): YAML viewer shows clean text instead of broken syntax highli…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8b41468841c94f44d5de376027892e053c15042",
          "body": "New commands:\n- brokoli login: interactive authentication (server, username, password\n  prompt with hidden input). Stores JWT token in ~/.brokoli/config.json\n  with 0600 permissions. All subsequent commands auto-read credentials.\n- brokoli logout: clears stored credentials.\n- brokoli whoami: shows c\n[…]\nver/token from ~/.brokoli/config.json when\n  --server/--api-key aren't explicitly set.\n- Reports blocked runs with reason instead of hanging.\n\nDependencies: added golang.org/x/term for password input.",
          "is_bot": false,
          "headline": "feat(cli): login/logout/whoami, dev mode with file watcher, run --follow",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f57bb5df3e914ce664c393bf1f32bac9e502929",
          "body": "Import improvements:\n- Validates node types against known enum (rejects unknown types early)\n- Validates required config fields per node type (url for source_api,\n  path for source_file, query for source_db, etc.)\n- Validates edge endpoints reference existing node IDs\n- Rejects self-referencing edge\n[…]\nld for forward compatibility\n- Includes tags in export (was missing)\n\nTests added: StripsInternalKeys, IncludesVersion, ValidatesEdges,\nValidatesNodeType, ValidatesNodeConfig, AutoLayout, SelfRefEdge.",
          "is_bot": false,
          "headline": "feat(yaml): validate on import, auto-layout, strip internals on export",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "97a97aacbe80f8b9b375c283f6d09d91f4557891",
          "body": "- GET /runs/{id}/logs and /logs/export now accept ?node_id= and ?level=\n  query parameters for server-side filtering. Level is validated against\n  the known enum (debug/info/warning/error); invalid values are ignored.\n- Fixed double-header write in HealthHandler (WriteHeader was called\n  before writeJSON which calls WriteHeader again).",
          "is_bot": false,
          "headline": "feat(api): log filtering by node_id and level, fix health handler",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e57b4caa64d8134664ea07059f705d0391f6bb3",
          "body": "  Whitespace alignment in struct tag comments and a trailing blank line,\n  flagged by gofmt after the dependency hardening pass.",
          "is_bot": false,
          "headline": "style: gofmt fixes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T18:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71efa7db159c108bdaf9b7493175568378f2d404",
          "body": "…scade\n\nThis is a hardening pass over the pipeline dependency feature covering both\na multi-tenant security audit and a code-quality rewrite. The two sets of\nchanges touch the same files and ship together.\n\n== Tenant isolation (security audit) ==\n\nFour cross-tenant leaks were found in the initial de\n[…]\ng-scoped.\n- api/dependency_cascade_test.go: transitive cascade (linear + diamond),\n  decouple-only-direct, invalid ?resolve= value.\n\nFull suite (14 packages) passes under go test ./... -count=1 -race.",
          "is_bot": false,
          "headline": "refactor(deps): tenant isolation + batched queries + transactional ca…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T18:08:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c96a707a5d93eb91c2a9ccf4586f3ff2721f599",
          "body": "- DependencyPicker component wires into the Pipeline Editor settings panel:\n  per-rule state/mode/freshness editors, legacy depends_on strings render\n  as dashed chips that can be promoted to first-class rules\n- DeletePipelineDialog catches 409 from the delete API and offers\n  decouple vs cascade ac\n[…]\nadge gains a 'blocked' state (amber) and the RunStatus union\n  picks up the new value\n- Request helper now attaches .status and .body to thrown errors so\n  callers can branch on 409 without re-parsing",
          "is_bot": false,
          "headline": "feat(ui): dependency picker, conflict-aware delete, graph page",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "281860c081d010d57bc5270eb8b306f0c9a17d31",
          "body": "- Create/Update reject dependency cycles with a path-aware 400\n- DELETE /pipelines/{id}?resolve=abort|cascade|decouple:\n  - abort (default): 409 Conflict with the dependent list\n  - cascade: delete this pipeline and all transitive dependents\n  - decouple: strip the reference from each dependent, then delete\n- GET /pipelines/{id}/deps enriched with per-rule state/mode/freshness\n- GET /pipelines/{id}/dependents (reverse lookup)\n- GET /pipelines/dependency-graph (full org graph for visualization)",
          "is_bot": false,
          "headline": "feat(api): dependency cycle detection and delete resolver",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea633f20271ee2a785ec4f928d0c58f5f4cbcd4",
          "body": "- CheckDependencies(store, pipe, now) evaluates state + freshness window\n  and is called from every trigger path (scheduled, manual, webhook)\n- Unsatisfied gates persist a visible Run with status=blocked and the\n  blocker list as the error, instead of silently skipping\n- DetectDependencyCycle() with\n[…]\nnes\n  when an upstream run reaches a terminal state\n- Scheduler now delegates to RunPipeline (blocked-run creation is central)\n- Removes the obsolete deps.go/deps_test.go superseded by dependencies.go",
          "is_bot": false,
          "headline": "feat(engine): cross-pipeline dep enforcement and trigger-mode chaining",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "371a2271e3ead2204af6bf85ec7a133c846b12f1",
          "body": "- New dependency_rules JSON column on pipelines table (sqlite + postgres\n  auto-migration, coexists with legacy depends_on)\n- PipelinesDependingOn(id) interface method for reverse-graph traversal,\n  used by delete resolver and trigger-mode firing",
          "is_bot": false,
          "headline": "feat(store): persist dependency_rules and add reverse-lookup query",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "579d5dd2588f1177411a6e1dcf6c139c3c05cc92",
          "body": "Introduces a rich cross-pipeline dependency model that coexists with the\nlegacy depends_on []string field:\n- DependencyRule{PipelineID, State, WithinSec, Mode}\n- States: succeeded, completed, failed\n- Modes: gate (block), trigger (auto-fire)\n- Pipeline.EffectiveDependencies() merges legacy + rich rules (rich wins)\n- Self-dependency rejection in Validate()\n- RunStatusBlocked for runs that skip due to unsatisfied upstream deps",
          "is_bot": false,
          "headline": "feat(models): add DependencyRule type and blocked run status",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cf4c90bbb18638cb48233749f9c3165c4d1746d",
          "body": "…eaking",
          "is_bot": false,
          "headline": "security: fix cross-tenant breach, CORS, rate limiting, HSTS, error l…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-08T00:21:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b16c1b60bae23a1ec0b0e9536ba903600587cb3",
          "body": "…eaking\n\n  CRITICAL:\n  - C1: WorkspaceMiddleware validates user owns workspace before granting access\n    Prevents cross-tenant data breach via X-Workspace-ID header spoofing\n\n  HIGH:\n  - H1: CORS no longer defaults to wildcard — requires BROKOLI_CORS_ORIGINS\n  - H3: Login rate limit tightened to 3 \n[…]\neaders middleware adds HSTS, X-Frame-Options, CSP headers\n\n  LOW:\n  - L1: System info no longer exposes version, db_size, pipeline count\n  - L3: JSON decode errors no longer leak Go struct field names",
          "is_bot": false,
          "headline": "security: fix cross-tenant breach, CORS, rate limiting, HSTS, error l…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-08T00:18:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "318c4379a0a297212ed18782390090fa338e97eb",
          "body": null,
          "is_bot": false,
          "headline": "docs: Apache 2.0 license, update README, fix stale references",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T21:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "104873660c133fc20d6e258928b1fd5de230c591",
          "body": "… URLs",
          "is_bot": false,
          "headline": "docs: update README for current repo structure, new features, correct…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T21:33:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49b4d263c4b56526acfb0c203d83ad9184809890",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): stage UI build output before GoReleaser to avoid dirty git",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T19:00:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c2faea91f13a98f00dccf764cd99fbd66ca66eb",
          "body": null,
          "is_bot": false,
          "headline": "fix: commit favicon files to web/dist for clean goreleaser builds",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:52:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d6e96ff5628204ca869ca5d20c7043e198a5a2d",
          "body": null,
          "is_bot": false,
          "headline": "fix: commit web/dist placeholder for go:embed in module consumers",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:50:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1feec50b4d02f8f662fbc2acfce4c04ab48fc383",
          "body": null,
          "is_bot": false,
          "headline": "fix: update goreleaser config for current repo structure",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:39:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68df0e2c354bcefbbe38b3d56ebfc0b23ac2327b",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): create ui-dist.tar.gz in /tmp to avoid dirty git state",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:34:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebed6ccda38dd1ee4ca6b0444629a26678e66a79",
          "body": null,
          "is_bot": false,
          "headline": "fix: update install.sh URLs to Tnsor-Labs/brokoli",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:28:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5500ed518c2bebed2d50ed706b3cc0e8ad86f22b",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt all Go files, fix CI workflows",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:18:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a157b8acee2f0ff1476ebee8dea391b578dc14a",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): build UI before tests (go:embed requires web/dist)",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:12:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c06f3ca0117657af637b84effe78cddb1c0b0705",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): update workflow for current repo structure (broked → brokoli)",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:00:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "853ec423281e739409b94497ede2510343edda98",
          "body": "Release:\n- Updated for current repo structure (broked → brokoli)\n- Builds UI and uploads ui-dist.tar.gz to GitHub Release\n- Enterprise repo fetches this artifact instead of cloning OSS\n\nSecurity:\n- Added license compliance scanning (go-licenses)\n- Fails on GPL/AGPL/SSPL dependencies (incompatible with commercial)\n- License summary in GitHub Actions step summary",
          "is_bot": false,
          "headline": "ci: release workflow with UI artifact, license compliance scanning",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T17:56:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cc2645b1cafdc31f387d53344ef730138bb7417",
          "body": "Worker API Store:\n- Workers persist execution data via HTTP (no direct DB access)\n- New server endpoints: node-runs, previews, DLQ, variables\n- Run ID consistency between server and worker\n\nEngine Logging Overhaul:\n- TraceID per run, SpanID per node attempt for distributed tracing\n- Per-attempt Node\n[…]\n view with syntax highlighting\n- Node-stats API for historical duration sparklines\n\nAPI:\n- GET /api/pipelines/{id}/node-stats — historical node durations\n- POST /api/auth/logout — clear session cookie",
          "is_bot": false,
          "headline": "feat: worker API store, distributed tracing, Gantt chart, cookie auth",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T16:09:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c68efd78abdfa656d1a2b7023727a5a9d7caff8",
          "body": "Single Go module: github.com/Tnsor-Labs/brokoli\nBinary renamed: broked → brokoli\nUI source moved: broked-ui/ → ui/\nUI embed moved: broked/ui/ → web/\nMetrics prefix: broked_ → brokoli_\nDefault DB: broked.db → brokoli.db\nlocalStorage: broked-token → brokoli-token\n\nOld BrokoliSQL library code archived in _archive/.\n\nAll imports updated:\n  github.com/hc12r/broked/* → github.com/Tnsor-Labs/brokoli/*\n  github.com/hc12r/brokolisql-go/* → github.com/Tnsor-Labs/brokoli/*",
          "is_bot": false,
          "headline": "refactor: merge broked/ into root, rename broked → brokoli",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T20:25:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d017585a0c1296b9180cc35aafa9edd68af776c",
          "body": "Layout: mobile bottom nav.\nNodeConfigPanel: dbt + notify config panels.\nPagination: simplified component.\nIcons: add dbt, notify, new status icons.\nGlobal CSS: new variables, responsive tweaks.",
          "is_bot": false,
          "headline": "style(ui): component polish, mobile nav, dbt/notify icons, pagination",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e413fb98a35fce555acc2ab1b22bece98d464a11",
          "body": "Pipelines: grid/list toggle, bulk actions, search.\nConnections/Variables: usage tracking display.\nNew API Integrations page.\nCalendar, Lineage, Settings, PipelineRuns improvements.",
          "is_bot": false,
          "headline": "feat(ui): pipeline list redesign, API integrations page, page polish",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "833f020022b4d661c919291bc145037146089a61",
          "body": "Auth: OAuth callback handling, onboarding state in localStorage.\nLogin: GitHub/Google/Keycloak OAuth buttons, setup mode detection.\nNew components: Breadcrumb, EmptyState, RunIndicator, Stepper.",
          "is_bot": false,
          "headline": "feat(ui): OAuth login flow, new components",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b53e52777af52306638cbb4bfcdd15253c249e1a",
          "body": "Replace static welcome hero with reactive onboarding:\n- Track connections, pipelines, runs from actual API data\n- Progress bar with percentage (0/3 → 3/3 complete)\n- Green checkmarks and strikethrough on completed steps\n- Welcome hero visible until all steps done (not just first pipeline)",
          "is_bot": false,
          "headline": "feat(ui): dynamic onboarding with progress bar and step tracking",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee10d0b24ffab050c2eef8d95f6fd7b4df75219b",
          "body": "Remove empty hash from isLoginRoute check. Previously currentHash === \"\"\nbypassed the auth guard, showing the dashboard to unauthenticated users.",
          "is_bot": false,
          "headline": "fix(ui): onboarding screen visible without sign-in",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac4d391556b6663cc8aae801e46ceaf8f75998a1",
          "body": "Add configurable timeout to REST fetcher.\nAdd pkg/common/id.go for ID generation utilities.",
          "is_bot": false,
          "headline": "feat(fetchers): REST fetcher timeout support, common ID generator",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da0ddf963c093f76a813c539c21820143227339b",
          "body": "5 failed attempts in 15min triggers lockout.\nPassword validation: 10+ chars, uppercase, lowercase, digit.\nSuperAdmin/Admin/Editor/Viewer role hierarchy.\nExpand extension interfaces for auth hooks.",
          "is_bot": false,
          "headline": "feat(auth): account lockout, password policy, role enforcement",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6ae39f0a930eb391df45fce797edffd92e8db50",
          "body": "New endpoints:\n- GET/POST pipelines/{id}/dlq, dlq/{id}/resolve\n- POST pipelines/{id}/webhook (external trigger)\n- POST pipelines/{id}/validate-nodes\n- GET pipelines/{id}/deps, pipelines/summary\n- GET connections/{id}/used-by, variables/{key}/used-by\n- GET search, lineage, dashboard, system/info\n- POST system/purge\n- GET runs/calendar, runs/{id}/nodes/{nodeId}/profile",
          "is_bot": false,
          "headline": "feat(api): DLQ, webhook triggers, search, lineage, system info, purge",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f99adeeef6cbdc7c1b2a757c72bb695f2cff743",
          "body": "Add UsedByConnections, UsedByVariables for impact analysis.\nAdd dashboard aggregate query, search endpoint support.\nExpand both Postgres and SQLite stores.",
          "is_bot": false,
          "headline": "feat(store): connection/variable usage tracking, dashboard queries",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9251d310f0fd0c669c752108fb2c3a2a31cbd601",
          "body": "Add description field to connections, expand BuildURI.\nAdd organization model for multi-tenant support.\nAdd variable type metadata.",
          "is_bot": false,
          "headline": "feat(models): expand connection types, add org model, variable metadata",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35124d468f062b3e3cc7659e4711ac12cd320c7b",
          "body": "Expand database engine with better error handling and query support.\nRunner improvements for pipeline execution.\nAdd database tests.",
          "is_bot": false,
          "headline": "feat(engine): database query improvements, runner enhancements",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e758d839e44b2bf0726b966f44fa22e4ffb6b46",
          "body": "Add aliases: rename, filter, function, replace, drop, dedup, agg\n90 new transform test cases covering all rule types.",
          "is_bot": false,
          "headline": "feat(engine): transform rule short aliases, expand test coverage",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75cd8a458c2b44c7c319952de6e71d9d13d12f88",
          "body": "dbt: run/test/build/seed/snapshot/compile/ls with JSON output parsing\nnotify: Slack and webhook with message templates ({{pipeline}}, {{run_id}}, {{rows}})\nBoth registered as NodeTypeDBT and NodeTypeNotify in models.",
          "is_bot": false,
          "headline": "feat(engine): add dbt and notify node types",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab4e940ccb958a9b7e7c04a5c7ee3cdf9feafcde",
          "body": "… (9 tests)\n\n- api/security_test: permissions, workspace validation, error sanitization, password rules\n- engine/security_test: file path whitelist, path traversal, BROKOLI_DATA_DIRS\n- models/security_test: XSS prevention, slug validation, account status, sanitize\n- extensions/distributed_test: pub/sub, pattern matching, FIFO queue, concurrent access",
          "is_bot": false,
          "headline": "test: security suite (55 tests) + distributed EventBus/JobQueue tests…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c36a203a4d704c4b9d8fa150708477bcb1ed6bf4",
          "body": "- Hub.SetEventBus() wires Redis pub/sub for cross-pod broadcasting\n- StartDistributedBroadcasting() publishes local events and subscribes to remote events\n- Server auto-selects distributed mode when EventBus is available\n- UIOverride for enterprise UI injection\n- withSessionCookie fix: always write response body",
          "is_bot": false,
          "headline": "feat(api): WebSocket Hub distributed broadcasting via EventBus",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b21c987a4a5a869a24b456e1c465cfadf9251e31",
          "body": "- Logo redesigned: broccoli florets as pipeline nodes with connection lines\n- 3-color palette: teal (#0d9488), medium green (#16a34a), bright green (#22c55e)\n- Reads as both a broccoli AND a data pipeline graph\n- Updated in Sidebar, Login, and favicon\n- Old monochrome version backed up as favicon-mono.svg",
          "is_bot": false,
          "headline": "style: multicolor broccoli-as-DAG logo",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0defe560ddb3ca44118d84ca4f0ef3a0539e9bb",
          "body": "…ators\n\n- PipelineRuns: Airflow-style run history grid (last 14 days, colored status squares)\n- PipelineRuns: collapsible grid (3 days default, expand to see all)\n- PipelineRuns: run summary bar (started, finished, duration, rows, nodes)\n- PipelineRuns: toolbar buttons icon-only on mobile (<768px)\n- Dashboard: timezone indicator on clock\n- PipelineRuns: formatFullTime shows timezone abbreviation (EDT, CEST, etc.)\n- Types: schedule_timezone added to Pipeline interface",
          "is_bot": false,
          "headline": "feat(ui): run history grid, mobile responsive toolbar, timezone indic…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b353ccea028d2a4e3dd59b3fdfc77881611fb9ee",
          "body": "- RunMode flag: all (default), api (HTTP only), scheduler (cron only), worker (executor only)\n- Worker mode drains engine events to EventBus for cross-pod WebSocket\n- Scheduler mode blocks without HTTP server\n- Purge endpoint scoped by org in multi-tenant mode\n- migrate command: SQLite<->Postgres with type conversion, verification, FK ordering",
          "is_bot": false,
          "headline": "feat(cmd): --mode flag (all/api/scheduler/worker), migrate command",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "999edb8ddd90b6adb78012694605a4b08816d0be",
          "body": "…eline timezone, WebSocket tenant isolation\n\n- RunPipelineAsync enqueues to JobQueue when set (distributed mode)\n- All timestamps now UTC (time.Now().UTC() everywhere)\n- Scheduler defaults to UTC, per-pipeline timezone via tzCronSchedule wrapper\n- Runner emits org_id on all events for WebSocket tenant isolation\n- Catch-up runs respect pipeline timezone",
          "is_bot": false,
          "headline": "feat(engine): RunPipelineAsync with JobQueue, UTC timestamps, per-pip…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c54a2b375cf50c616cfd9566a9b4cfb5b2cbf8f9",
          "body": "…tecture\n\n- EventBus: Publish/Subscribe/Close for cross-pod event distribution\n- JobQueue: Enqueue/Dequeue/Ack/Fail for distributed pipeline execution\n- In-memory defaults (channels) for single-binary mode\n- RunJob struct with pipeline_id, run_id, org_id, params, priority\n- Pattern matching for pub/sub subscriptions\n- Zero behavior change for open source — interfaces unused unless enterprise wires them",
          "is_bot": false,
          "headline": "feat(extensions): EventBus, JobQueue interfaces for distributed archi…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28e59283544a778f79fb7d31fb80f37d41880635",
          "body": "…ormat\n\n- ParsePageParams extracts ?page=1&page_size=25 from query string\n- PaginateSlice returns PageResult envelope {total, page, pages, items}\n- List endpoints return array (no params) or PageResult (with ?page=)\n- Exported wrappers for enterprise handlers\n- OrgIDContextKey for cross-package org context sharing\n- ValidatePassword export for enterprise signup",
          "is_bot": false,
          "headline": "feat(api): server-side pagination with backward-compatible response f…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2a9ac7df1234e6394a4636a1b816a844321fb54",
          "body": "…ostgres production-ready\n\n- Pipeline: pipeline_id (git-sync slug), source (ui/git), workspace_id, org_id, schedule_timezone\n- Event: org_id for WebSocket tenant isolation\n- Store: GetPipelineByPipelineID, PurgeRunsOlderThanByOrg, Count* methods\n- Store: PageParams/PageResult types for server-side p\n[…]\n: all missing tables created (connections, variables, workspaces, settings, etc.)\n- Postgres: workspace filtering fixed (was returning all records)\n- Postgres: proper TIMESTAMPTZ, BOOLEAN, JSONB types",
          "is_bot": false,
          "headline": "feat: pipeline_id, source, workspace/org fields, schedule timezone, P…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b062e04356ec1742804863666ebefddb690fb93",
          "body": "… locking\n\n- TriggerRun now uses RunPipelineAsync (prevents client timeout duplicates)\n- sanitizeRunError strips connection strings and sensitive paths from errors\n- Git-managed pipelines reject UI edits with 403\n- Pipeline create auto-generates pipeline_id slug, sets workspace_id",
          "is_bot": false,
          "headline": "fix(api): async run triggers, error sanitization, git-source pipeline…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a73d85e99d78fa7fff5f2e963e5c4e7c33e28b6",
          "body": "…sking, file path whitelist\n\n- Viewers blocked from write operations in open source (requirePerm fallback)\n- ValidateWorkspaceAccess() helper for cross-workspace protection\n- Connection secrets (Extra field) masked in list responses\n- WebSocket origin validation against BROKOLI_CORS_ORIGINS\n- Webhoo\n[…]\nimiting (1 per 10s)\n- User creation requires admin role after first user\n- File source/sink nodes restricted to allowed dirs (BROKOLI_DATA_DIRS)\n- XSS prevention in org/pipeline names (<>\"'& rejected)",
          "is_bot": false,
          "headline": "security: role-based permissions, workspace validation, connection ma…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8e9dd2bf2a0052406baa3019c6f6743d87140bc5",
          "body": "- App.svelte: hash-based SPA routing, reactive hashchange for layout switching\n- api.ts: 15s timeout, auto-logout on 401\n- auth.ts: token management, permission loading, httpOnly cookie fallback\n- license.ts: community edition stub (enterprise overrides this)\n- workspace.ts: default workspace stub\n- global.css: dark theme with teal accent, CSS variable design system\n- icons.ts: stroke-only SVG icon library",
          "is_bot": false,
          "headline": "feat(ui): app routing, auth lib, design system, and client libraries",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a9c7779306cb064413b54ee162609a19c84e2bc",
          "body": "…omponents\n\n- GlobalSearch: Cmd+K overlay searching pipelines/connections/variables/pages\n- Pagination: reusable with page numbers, ellipsis, page size selector\n- VersionHistory: pipeline version list with rollback\n- Sidebar: stripped to free-tier nav (Dashboard through Settings)\n- Layout: clean shell without enterprise trial banner",
          "is_bot": false,
          "headline": "feat(ui): add GlobalSearch, Pagination, VersionHistory, and improve c…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fae59f16534d7d25426c4306ab760d3d29aaeb19",
          "body": "- Connections: CRUD with type badges, test connection, encryption\n- Variables: key-value store with secret masking, used-by tracking\n- Settings: 4 tabs (General, Users, API & CLI, Integrations)\n- Login: JWT auth with account lockout display, setup flow",
          "is_bot": false,
          "headline": "feat(ui): Connections, Variables, Settings, and Login pages",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c14537b97aaa75320c4da5e8b0000e395a90da34",
          "body": "- Dashboard: 5 KPI cards, 7-day interactive bar chart, 3-column overview grid\n- Pipelines: status/tag filters, sort, search, Ctrl+K hint, pagination, templates\n- PipelineEditor: visual DAG editor with condition nodes, undo/redo, version history\n- PipelineRuns: card-based run list with inline expand, Gantt timeline, data preview",
          "is_bot": false,
          "headline": "feat(ui): redesign Dashboard, Pipelines list, editor, and runs pages",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dffc9ab58aafeb63487c683ce042e5816dfe79d",
          "body": "…rays\n\n- Quality rules: not_null, unique, range, regex, custom expression checks\n- crypto: AES-256-GCM encryption for connection secrets\n- ParseJSONData: handles array-of-objects, single object, and mixed arrays\n  (World Bank API format fix)",
          "is_bot": false,
          "headline": "feat: data quality rules, AES-256 encryption, JSON utils for mixed ar…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3202c6f1a995e6c93b49d73524aa3e407f7d7d0c",
          "body": "…bcommands\n\n- serve: conditional Platform/Team service startup via extensions\n- serve: UIOverride support for enterprise binary UI injection\n- runcmd: CLI pipeline execution (broked run <pipeline-id>)\n- testcmd: CLI pipeline assertions (broked assert <pipeline-id>)",
          "is_bot": false,
          "headline": "feat(cmd): update serve with extension lifecycle, add run and test su…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcae327861b2c00a14e4040b4c5040013334843c",
          "body": "…r open-core\n\n- PlatformProvider: multi-tenant SaaS features (orgs, admin, tickets)\n- TeamProvider: RBAC, workspaces, permission middleware\n- No-op defaults for community edition\n- Existing interfaces: Auth, Audit, GitSync, License, Secrets, Notifier,\n  Contracts, PII, OpenLineage, NodeExecutor",
          "is_bot": false,
          "headline": "feat(extensions): add PlatformProvider and TeamProvider interfaces fo…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 285,
      "latest_release_at": "2026-07-18T23:45:22Z",
      "latest_release_tag": "v0.10.0",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 26,
      "days_since_latest_release": 6,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/Tnsor-Labs/brokoli",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/Tnsor-Labs/brokoli",
          "is_deprecated": false,
          "latest_version": "v0.10.0",
          "repository_url": "https://github.com/Tnsor-Labs/brokoli",
          "versions_count": 18,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T23:33:02Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "ui/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 57127,
      "source_files_sampled": 185,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "ui/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.5"
        },
        {
          "name": "github.com/go-sql-driver/mysql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.3"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.9.1"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.37.1"
        },
        {
          "name": "@sodp/client",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.2.1"
        },
        {
          "name": "@types/prismjs",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.26.6"
        },
        {
          "name": "js-yaml",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.1"
        },
        {
          "name": "prismjs",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.30.0"
        },
        {
          "name": "svelte-spa-router",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        },
        {
          "name": "timeline-arrows",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.8.0"
        },
        {
          "name": "vis-data",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.3"
        },
        {
          "name": "vis-timeline",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 1,
        "open_issues": 1,
        "closed_ratio": 0.5,
        "closed_issues": 1,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "hc12r",
          "commits": 285,
          "avatar_url": "https://avatars.githubusercontent.com/u/66696838?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "dependencies.yml",
        "release.yml",
        "security.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "50 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ee0f93f72ddc44fab3a8b4b1df42aa6257f67aaf",
        "ran_at": "2026-07-25T07:28:08Z",
        "aggregate_score": 2.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T03:19:00Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-18T23:33:03Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": [
        {
          "number": 1,
          "created_at": "2026-05-09T10:58:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Tnsor-Labs/brokoli",
    "host": "github.com",
    "name": "brokoli",
    "owner": "Tnsor-Labs"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 28,
        "vitality": 74,
        "community": 24,
        "governance": 49,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 285,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 26
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "26/52 weeks with commits",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 26
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "285 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 285
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.10.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "merged_prs": 1,
              "open_issues": 1,
              "closed_issues": 1,
              "issue_closed_ratio": 0.5,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "50% of issues closed",
                "points": 23.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 50
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "1/1 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 1,
                      "decided": 1
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "Tnsor-Labs",
              "public_repos": 2,
              "account_age_days": 109
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of Tnsor-Labs",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "Tnsor-Labs"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/Tnsor-Labs/brokoli"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "18 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "data-engineering",
                "data-ops",
                "data-pipeline",
                "data-quality",
                "etl",
                "go",
                "golang",
                "open-source",
                "orchestration",
                "pipeline",
                "self-hosted",
                "single-binary",
                "sqlite",
                "visual-editor",
                "workflow"
              ],
              "has_wiki": true,
              "homepage": "https://brokoli.orkestri.site",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://brokoli.orkestri.site",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "15 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 28,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 28,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 2.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "50 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "ui/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 57127,
              "source_files_sampled": 185,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/185 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 185,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T07:28:15.590806Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/Tnsor-Labs/brokoli.svg",
  "full_name": "Tnsor-Labs/brokoli",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.