JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 1240,
"has_wiki": true,
"homepage": "https://obsigna.dev",
"languages": {
"Go": 409182,
"HTML": 261682,
"Shell": 3903,
"Makefile": 207
},
"pushed_at": "2026-07-20T03:28:37Z",
"created_at": "2026-04-02T09:28:46Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T03:28:38Z",
"description": "Centralized audit dashboard for Agent Receipts / Obsigna — collect, view, and verify receipts from any SDK or proxy",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go",
"HTML"
]
},
"owner": {
"blog": "https://agentreceipts.ai",
"name": "Agent Receipts",
"type": "Organization",
"login": "agent-receipts",
"company": null,
"location": null,
"followers": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/272751690?v=4",
"created_at": "2026-04-01T08:01:33Z",
"is_verified": null,
"public_repos": 9,
"account_age_days": 112
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.13.1",
"kind": "patch",
"published_at": "2026-07-20T03:30:10Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-07-17T08:40:07Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-07-15T09:57:45Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-07-15T01:09:52Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-07-02T09:07:40Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-06-23T04:53:42Z"
},
{
"tag": "v0.9.0-alpha.5",
"kind": "prerelease",
"published_at": "2026-06-22T23:47:36Z"
},
{
"tag": "v0.9.0-alpha.4",
"kind": "prerelease",
"published_at": "2026-06-20T04:38:33Z"
},
{
"tag": "v0.9.0-alpha.3",
"kind": "prerelease",
"published_at": "2026-06-19T23:34:31Z"
},
{
"tag": "v0.9.0-alpha.2",
"kind": "prerelease",
"published_at": "2026-06-19T04:43:00Z"
},
{
"tag": "v0.9.0-alpha.1",
"kind": "prerelease",
"published_at": "2026-06-19T00:21:02Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-06-12T10:56:55Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-06-10T23:45:09Z"
},
{
"tag": "v0.7.0-alpha.5",
"kind": "prerelease",
"published_at": "2026-06-10T06:26:39Z"
},
{
"tag": "v0.7.0-alpha.4",
"kind": "prerelease",
"published_at": "2026-06-09T10:05:38Z"
},
{
"tag": "v0.7.0-alpha.3",
"kind": "prerelease",
"published_at": "2026-06-09T02:45:26Z"
},
{
"tag": "v0.7.0-alpha.2",
"kind": "prerelease",
"published_at": "2026-06-09T02:23:47Z"
},
{
"tag": "v0.7.0-alpha.1",
"kind": "prerelease",
"published_at": "2026-06-09T00:13:49Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-06-08T22:27:39Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-06-08T06:18:47Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-06-03T02:10:12Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-06-03T01:53:43Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-06-02T23:32:31Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-05-22T05:17:58Z"
},
{
"tag": "v0.2.2",
"kind": "patch",
"published_at": "2026-05-20T06:59:47Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-05-20T05:38:18Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-05-20T05:29:22Z"
},
{
"tag": "v0.1.6",
"kind": "patch",
"published_at": "2026-05-19T10:08:10Z"
},
{
"tag": "v0.1.5",
"kind": "patch",
"published_at": "2026-05-18T08:16:35Z"
},
{
"tag": "v0.1.4",
"kind": "patch",
"published_at": "2026-05-16T00:58:37Z"
},
{
"tag": "v0.1.3",
"kind": "patch",
"published_at": "2026-05-01T04:44:02Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2026-04-24T10:42:43Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2026-04-24T05:22:53Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-04-05T09:13:57Z"
}
],
"recent_commits": [
{
"oid": "e1f5a50284b93bbef74da74a2b9565af4e12a565",
"body": "Bumps the go group with 2 updates: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) and [obsigna.dev/sdk/go](https://github.com/agent-receipts/obsigna).\n\n\nUpdates `modernc.org/sqlite` from 1.53.0 to 1.54.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https\n[…]\nte-type: version-update:semver-minor\n dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the go group with 2 updates (#177)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T03:28:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb2ba3c7199d4f019e8a55e14d5cd5d8aabbcab3",
"body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.5.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356f\n[…]\nsion-update:semver-major\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go in the github-actions group (#176)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T03:27:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5952245622e5416f644eccc8e185d2881d4fa7a0",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.13.1 (#180)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-20T03:27:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9996a862efef29cc0aa79a0c61742ac193f180b",
"body": "* fix(fleet): stack receipt preview in front of the Session Graph modal\n\nSelecting a row (or a chain cell) in the Session Graph modal opened the\nreceipt/chain detail modal behind the graph: every .modal-backdrop shared\none z-index (50), and the graph modal sits later in the document, so on a\ntie it \n[…]\n the closer registry), so a new modal is\n registered in exactly one place.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Fix modal stacking so receipt previews appear above Session Graph (#178)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-20T03:23:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "25520b9eb5e5dbad04cd7ec9e9e177bc95e1f21c",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.13.0 (#175)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-17T08:36:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5b0a6d9b884774bc20fac63d60ef2fc56761e34",
"body": "* feat(enrichment): add Cost column to Overview and Sessions views\n\nOverview's recent-receipts mini-table gets the same per-row running-total\nCost column as the Receipts tab (small, session-bounded list, so a\nclient-side per-session fetch is fine).\n\nThe Sessions tab gets a session-total Cost column.\n[…]\nntSessionEnrichment=8 via a\nsemaphore channel; goroutine creation itself stays unbounded (cheap) but\nonly 8 run their Enrich() call at once. New test verifies peak concurrency\nnever exceeds the bound.",
"is_bot": false,
"headline": "feat(enrichment): add Cost column to Overview and Sessions views (#174)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-17T08:31:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "907fd5526b61e148f517e4eb3eacfc8d2501a2a7",
"body": "…e agent graph (#173)\n\n* fix(enrichment): surface local enrichment in the Receipts tab's inline agent graph\n\nThe Session Graph modal and Fleet view (#172) both got a tokens/cost\nenrichment line, but the third session-scoped surface — the \"Agent graph\"\npanel shown above the receipts table when filter\n[…]\nd view) fetches each visible\nsession's enrichment once and patches a Cost column in per row via\nbinary search over its CostPoints curve, right of Time. Flat\n(non-session-grouped) tables are unchanged.",
"is_bot": false,
"headline": "fix(enrichment): surface local enrichment in the Receipts tab's inlin…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-17T05:30:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a4ff06603cc46fb6910f37b3de3bbcedb16f7e05",
"body": "…raph and Fleet views (#172)\n\n* feat(enrichment): surface session-level local enrichment in Session Graph and Fleet views\n\nLocal session enrichment (token usage, estimated cost) was previously only\nfetched and rendered once per receipt, inside the single-receipt detail\nmodal, even though enrich.Enri\n[…]\ns a goroutine per session when no\n enricher is configured — the common \"no local data\" deployment skips\n the wg.Add/Wait entirely instead of paying setup for calls that would\n each just return nil.",
"is_bot": false,
"headline": "feat(enrichment): surface session-level local enrichment in Session G…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-17T04:42:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a21328fba35c0ce8a042694e3e7811617e289930",
"body": "Corrects a misfiled CHANGELOG entry: the local session enrichment bullet\nlanded under the already-tagged [0.11.0] heading in #170 instead of\n[Unreleased], so it never shipped in a version. Moves it to its own\n[0.12.0] section.",
"is_bot": false,
"headline": "chore(release): bump to v0.12.0 (#171)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-15T09:55:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f866a2bf0f30c627bf5f8600f413cb9ba0af965",
"body": "* feat(enrich): local session enrichment as unverified sidecar\n\nAdd display-only enrichment of the receipt-detail view with locally\navailable agent session data (token usage, context-window %, estimated\ncost) when the dashboard runs on the same host/user as the agent.\n\nThe enrichment is an explicit,\n[…]\no skip\nfiles above a 128 MiB cap (real transcripts are a few MiB), and wrap the\nreader in io.LimitReader as a hard bound that also covers a 0-stat-size\ndevice file or a file that grows after the stat.",
"is_bot": false,
"headline": "Add local session enrichment for display-only unverified data (#170)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-15T09:52:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0e16bb756af60e48dd66650bc7a217d056351f57",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.11.0 (#169)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-15T01:04:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64d929511bd4fed93c0963783079ffd2a83a8a1e",
"body": "…use limit (#157) (#167)\n\n* feat(attribution): base temporal_overlap on edge-proximity; document path-reuse limit\n\nTwo refinements to cross-session collision detection (#157), both pre-release\nso they build on the unreleased FleetAttribution feature rather than changing\nshipped behaviour.\n\n157-a — p\n[…]\nonFarApartNoTemporalOverlap asserting that a\n single-session edge whose touches are 90 min apart reports temporal_overlap\n =false (the deliberate change from the old \"always true within a session\").",
"is_bot": false,
"headline": "fix(attribution): event-proximity temporal_overlap + document path-re…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-15T00:58:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "318ca3af2fbb4eb6c879e5fa9813ac14df5d94e6",
"body": "Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.45.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.45.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n dependency-version: 0.52.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.52.0 (#168)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T04:26:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe629ea7279f2deb9aea55898a6c151759125791",
"body": "* docs: document forensic-key endpoint security model\n\nAdd a SECURITY.md section covering POST /api/forensic-key and\nPOST /api/forensic-key/path: the guards in place (loopback-only bind,\nHost-header/DNS-rebinding validation, cross-origin rejection, the\napplication/json Content-Type CSRF guard, and t\n[…]\no, internal/store/reader.go).\n- CHANGELOG.md: clarify that the application/json CSRF guard and the\n \"..\"/NUL path allowlist apply only to POST /api/forensic-key/path,\n not to POST /api/forensic-key.",
"is_bot": false,
"headline": "docs: document forensic key endpoint security model (#166)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-09T06:57:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32cb661ccbb4fb03b69254557ca5c84530fc4c36",
"body": "* feat(attribution): add FleetAttribution data layer and endpoint\n\nAdd FleetAttribution([]sessionID) and GET /api/fleet/attribution?limit=N,\ncomputing one combined ADR-0029 §4 attribution payload across the N most\nrecently-active sessions (default 6, capped 12). Agent keys are namespaced\n<session_id\n[…]\no main pulled in #162's seedFleetDB (returns *store.Reader,\nfleet signatures) alongside this branch's own seedFleetDB (returns *Server,\nfleet attribution). Rename the latter to seedFleetAttributionDB.",
"is_bot": false,
"headline": "feat(attribution): fleet attribution data layer and endpoint (#157)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-09T06:57:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "86ef2bae3ec55c6d19d8c923613fe2163f4b1ce1",
"body": "Path-derived state-dependency edges are inferred from shared\naction.target.resource path strings. Path identity is not file\nidentity, so these edges are evidential — they suggest two agents\ntouched the same resource — not proof of causal order.\n\nReword the README session-attribution section and the \n[…]\nwith a tooltip clarifying that\nBash/MCP/spawn receipts are signed but carry no resource path.\n\nStrings, README prose, and tooltip markup only — no behaviour change and\nno internal identifiers renamed.",
"is_bot": false,
"headline": "docs: remove overclaiming language from session dependency graph (#165)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-09T06:45:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81e1032285d4658d2d48299ef873416ddb475b7c",
"body": "Bumps the github-actions group with 1 update: [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `goreleaser/goreleaser-action` from 7.2.2 to 7.2.3\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/gorel\n[…]\nsion-update:semver-patch\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump goreleaser/goreleaser-action (#164)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-07T08:29:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ae0a0cfcbf36487d2af364a373001b13eff899e3",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.10.0 (#163)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-02T07:33:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0fa0678aba9d09908c19510a7d092c721590933",
"body": "* feat(fleet): add experimental activity-signature view\n\nAdds an experimental, flag-gated Fleet tab that renders the N most recently-\nactive sessions as 'universes': orchestrator sized by receipt volume, a\ndiscretionary activity-mix ring (bash demoted to a thin inner gauge arc),\nagent-type satellite\n[…]\no `fleetFp` to avoid\n collision with other helpers in the shared inline script.\n- Add a keyboard focus indicator for universe cards: highlight the cell\n boundary via `.fleet-universe:focus-visible`.",
"is_bot": false,
"headline": "feat(fleet): experimental activity-signature view (#162)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-07-02T06:50:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a745ed7e62c6119981e3e7e142105611a9b02bd",
"body": "* feat(fleet): add --experimental flag and activity-signature data layer\n\n- Add `-experimental` bool CLI flag (default false) wired into Config.Experimental\n- Expose experimental field in GET /api/config JSON response\n- Add SessionSignature type and activityCategory() helper in internal/store\n- Add \n[…]\nkeyword precedence (mcp/bash first, edit before read), not 'file.modify'\n falling through to read (it never matches read).\n- CHANGELOG: use single-dash -experimental consistently (matches -db/-port).",
"is_bot": false,
"headline": "feat(fleet): --experimental flag + activity-signature data layer (#161)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-30T10:35:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4e3ec0217d6b49277bf15aa6f14b7ca0f4731159",
"body": "Bumps the go group with 1 update: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `modernc.org/sqlite` from 1.52.0 to 1.53.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.52.0...v1.53.0)\n\n---\nupdated-de\n[…]\nte-type: version-update:semver-minor\n dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump modernc.org/sqlite in the go group (#160)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T08:06:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8ce9b34f0dceb1e4963d9617899182ff734a922b",
"body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.4.0 to 6.5.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e3721\n[…]\nsion-update:semver-minor\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go in the github-actions group (#159)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T08:06:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6473835bdff88ba16c88ae27cede09c124d3bac0",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.9.0 (#155)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-23T04:51:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1732fc3ad1b93e93cb85d2b2b3eb13b2157b6060",
"body": null,
"is_bot": false,
"headline": "chore(deps): migrate Obsigna SDK to obsigna.dev/sdk/go v0.23.0 (#154)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-23T04:40:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0af2613a1f3f68fd27501493717ad0b97f352033",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.9.0-alpha.5 (#153)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-22T23:29:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fd5285a80e4c7ca733a404c685a13a9302f8631e",
"body": "Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).\n\n\nUpdates `actions/checkout` from 6.0.3 to 7.0.0\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits\n[…]\nsion-update:semver-major\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout in the github-actions group (#150)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T23:19:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4f991cc4955b282db7343dce5661fed5e4fc62a",
"body": "… (#151)\n\nBumps the go group with 1 update: [github.com/agent-receipts/ar/sdk/go](https://github.com/agent-receipts/ar).\n\n\nUpdates `github.com/agent-receipts/ar/sdk/go` from 0.21.0-alpha.1 to 0.22.0-alpha.1\n- [Release notes](https://github.com/agent-receipts/ar/releases)\n- [Commits](https://github.c\n[…]\nte-type: version-update:semver-minor\n dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/agent-receipts/ar/sdk/go in the go group…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T23:18:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6535f1dfa4e9cd47a8b202432f2df78b0899ce7d",
"body": "Update the page title, header brand, action-type reference description,\nand the empty-database CLI hint to read \"Obsigna\". GitHub URLs, Go\nimport paths, and on-disk agent-receipts paths are left unchanged.",
"is_bot": false,
"headline": "feat: rebrand dashboard UI from Agent Receipts to Obsigna (#152)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-22T23:15:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91019088467ba3f64b14c75bd3d18c1b062645f6",
"body": null,
"is_bot": false,
"headline": "docs(changelog): add v0.9.0-alpha.4 SDK bump entry (#149)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-20T04:58:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ffad8cc9507249fe0d459ce9c6a32f2ca9aadcf6",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.9.0-alpha.4 (#148)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-20T04:36:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "627fbbe601d81bbe58ee536893e9789b4aa77a9e",
"body": null,
"is_bot": false,
"headline": "chore(deps): bump obsigna SDK to v0.21.0-alpha.1 (#147)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-20T03:58:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "301620224ef270227f603e92d9cb2de4196169bd",
"body": "* docs: refresh README screenshots to reflect current dashboard\n\nReplace the stale 8-receipt overview screenshot with three current\nscreenshots captured from a live store with 29k+ receipts:\n\n- docs/screenshot.png — Overview tab: activity timeline, risk/status/\n action distribution panels, Receipts\n[…]\nt texts to match the new screenshots and move the detail\nscreenshot to the Forensic decryption section where it belongs.\n\n* docs: rename session-attribution-detail.png → forensic-decryption-detail.png",
"is_bot": false,
"headline": "docs: refresh README screenshots to reflect current dashboard (#146)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-20T00:27:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "996c4e20fac17d94e64e2249013ba8bc81b56b20",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.9.0-alpha.3 (#145)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T23:31:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e3ea7a1ce157908cbc9db50268838eb598db7cb7",
"body": "…144)\n\nPOST /api/forensic-key and DELETE /api/forensic-key had no CSRF\nprotection: a cross-origin page could issue a CORS-simple text/plain\nPOST to replace the operator's loaded forensic key, or a DELETE to\nclear it, without triggering a preflight. Add an Origin allowlist\nguard (rejectCrossOrigin) mirroring the existing Host-header DNS-rebind\nguard, and apply it to all three forensic write endpoints. Requests\nwithout an Origin header (curl, SDK clients) are unaffected.\n\nCloses #79",
"is_bot": false,
"headline": "fix(forensic): reject cross-origin requests to key write endpoints (#…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T23:23:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a9c0e9847bef3a4d370843c46dc514e2012368e",
"body": "… oversize buffer, return 413 (#143)\n\n* fix(forensic): harden key file reads against non-regular files and oversize\n\nReject non-regular files (symlinks, FIFOs, devices, directories) in\nreadFileLimited via Lstat before opening, so a FIFO at ForensicKeyPath\ncannot hang startup and a device cannot be r\n[…]\no operator-\nsupplied input can no longer reach an arbitrary file, resolving the\nCodeQL go/path-injection alert. The startup auto-load (operator-set\nconfig, not an HTTP source) is unaffected.\n\nRefs #78",
"is_bot": false,
"headline": "fix(forensic): harden key file reads — reject non-regular files, zero…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T23:16:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b32d635351ac3611ed03611a973e2e61aef8188",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.9.0-alpha.2 (#142)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T04:38:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e12e3ca7754f07efa92510d3379d2d34d9eace6",
"body": "VerifyChainLinks checked each Ed25519 signature with receipt.Verify on the\nparsed Go struct, which re-marshals and canonicalizes a struct that drops any\nfield a newer SDK signed over but nested inside the payload (e.g. under\ncredentialSubject). The signature then verifies over different bytes than w\n[…]\nT /api/chains/{id}/verify?public_key=...\n\nSwap to receipt.VerifyRaw(cr.Raw, ...), the signature-side twin of\nHashRawReceipt, so both paths verify the verbatim wire bytes. Requires SDK\nv0.20.0-alpha.2.",
"is_bot": false,
"headline": "fix(verify): verify chain signatures from raw wire bytes (#73) (#141)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T04:35:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "641bef3e95f2feb5d5df3791b2992c8f07dafe4d",
"body": "The project layout described internal/store as \"multi-DB\", but it was\nnever implemented — OpenReadOnly opens exactly one database. Describe\nwhat the package actually does.",
"is_bot": false,
"headline": "docs: correct internal/store description (not multi-DB) (#140)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T02:29:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3586e5bb75da5162b1e4a27bac96ac8349c51247",
"body": "* feat(ui): render structured issuer and principal details\n\nSurface the issuer's type, top-level model, and operator (name + id), and\nthe principal's type as a badge in the receipt detail view. Previously these\nfields were only visible in the raw JSON blob. All new fields render\nconditionally and de\n[…]\n not omitempty, so a present-but-empty\noperator could render a stray 'operator' label. Render the row only when at\nleast one of name/id is non-empty, and emit each span only when its value is\npresent.",
"is_bot": false,
"headline": "feat(ui): render structured issuer and principal details (#139)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T02:15:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "442ce30c14ff3c1eca43ecada77a10fe9738923e",
"body": "* feat(taxonomy): surface action-type taxonomy in the dashboard\n\nAdd GET /api/taxonomy serving the SDK's built-in action-type registry\n(every known type with its description and default risk level, grouped\nby category). The frontend uses it to:\n\n- render a collapsible \"Action type reference\" card in\n[…]\ncard for\n the whole page lifetime after a transient boot-time error.\n- Fail TestTaxonomyEndpoint if an action type appears in more than one\n category, rather than silently overwriting the map entry.",
"is_bot": false,
"headline": "feat(taxonomy): surface action-type taxonomy in the dashboard (#138)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T01:17:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8539cacefe3c5b16834e52f1a25197e32f8cfa39",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.9.0-alpha.1 (#137)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T00:13:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b9634d7548b127147318ae487ae6a03b9714e75",
"body": "* feat(graph): highlight connected component on node click\n\nClicking an agent-graph node now highlights its entire state-dependency\nconnected component (all agents reachable via shared-resource contention\nedges), dims everything outside it, and emphasizes the in-component\nstate-dep edges. Delegation\n[…]\nible on\nhighlighted nodes. Use --text instead of --accent for the rings so the\nclicked node reads clearly on the blue root node as well as green\nsub-agents.\n\nAddresses Copilot review feedback on #136.",
"is_bot": false,
"headline": "feat(graph): highlight connected component on node click (#136)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-19T00:07:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "36326f9aec23a9de25246786b0b28546e46bb333",
"body": "… (#134)\n\nBumps the go group with 1 update: [github.com/agent-receipts/ar/sdk/go](https://github.com/agent-receipts/ar).\n\n\nUpdates `github.com/agent-receipts/ar/sdk/go` from 0.17.0-alpha.1 to 0.20.0-alpha.1\n- [Release notes](https://github.com/agent-receipts/ar/releases)\n- [Commits](https://github.c\n[…]\nte-type: version-update:semver-minor\n dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github.com/agent-receipts/ar/sdk/go in the go group…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-18T07:09:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8fb46a018e16fe79c4637f24808a9fdc08fd8d2b",
"body": null,
"is_bot": false,
"headline": "docs: add agentreceipts.ai and obsigna.dev to the ecosystem table (#133)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-13T12:14:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "80374245b8e113bbf89a9dbba9050f0fdc627170",
"body": "… and security model (#132)\n\n* docs(readme): document forensic decryption, analytics, full HTTP API, and security model\n\nThe README lagged the shipped feature set (v0.8.0). Make it the canonical\nreference by adding what was missing:\n\n- Forensic decryption — default-path auto-load (~/.local/share/age\n[…]\ncosystem: the monorepo is now agent-receipts/obsigna (was agent-receipts/ar);\n rename the entry, add an obsigna-daemon row, and repoint the mcp-proxy/spec\n tree links and the intro links to obsigna.",
"is_bot": false,
"headline": "docs(readme): document forensic decryption, analytics, full HTTP API,…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-13T10:10:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b6ef00f7f6731d50ced290dc41ee1f745dbcc4ba",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.8.0 (#131)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-12T10:54:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5d0313966920689832eb12c5c0a22aa315d4839",
"body": "* feat: ADR-0029 §4 attribution and blast-radius view\n\nExtends the existing session graph panel with cross-agent state-dependency\nedges, a blast-radius attribution panel, risk rings on nodes, and a coverage\nfraction in the modal header.\n\nBackend:\n- New `SessionAttribution` method on store.Reader: qu\n[…]\nrom_agent/to_agent in the API response could flip\nbetween requests for identical data.\n\nISO-8601 timestamps sort lexicographically, consistent with the\nORDER BY timestamp ASC in the attribution query.",
"is_bot": false,
"headline": "Add session attribution analysis with state-dep edges (#130)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-12T10:51:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "713c05cab00e78cbdc8ddb589795c6704bd00ccb",
"body": "* feat: surface transcript-derived model and token usage from issuer.runtime\n\nAdds dashboard support for the enrichment fields introduced in obsigna\nPR #779: issuer.runtime.{model,capture_method,usage}.\n\nStore layer:\n- Four new fields on ReceiptRow: RuntimeModel, RuntimeCaptureMethod,\n RuntimeUsage\n[…]\n RuntimeModel extraction only; notes that capture_method and usage\n surface via the detail endpoint's raw JSON passthrough, not ReceiptRow.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "Surface transcript-derived model and token usage in receipts (#129)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-11T09:04:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "836333a01e48aff7a44879dd9e6c03a06d5a68c9",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.7.0 (#128)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-10T23:43:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dcabf891012202323d5d129a4b1b74d91a595ac2",
"body": "Extract issuer.model from receipt JSON ($.issuer.model) into ReceiptRow.IssuerModel\nand expose it as issuer_model in the API response. The session graph renders\nthe model name as a third label line below each agent node, visible in both\nthe inline receipts-view graph and the session-detail modal graph.\n\nOlder receipts that predate the daemon stamping issuer.model degrade gracefully\n— the model line is simply absent from those nodes.",
"is_bot": false,
"headline": "feat: surface issuer.model in session graph nodes (#127)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-10T20:24:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4a162c6102bbd10dc76fe2517e92bfcccf0a3d8",
"body": "* feat: node-link session graph view for agent delegation (#122)\n\nAdds a per-session agent delegation graph to the Sessions table. Each\nsession row gets a \"Graph\" button that opens a modal showing an SVG\nnode-link diagram: the orchestrator (root) at the top, sub-agents in a\nrow below, connected by d\n[…]\nb-agents → 1120 px wide viewBox instead of 800 px)\n- Inline graph collapse button: drop icon-btn class (fixed 28×28 box was\n squishing ▾ to a dot); use bare button style matching session-collapse-btn",
"is_bot": false,
"headline": "feat: node-link session graph view for agent delegation (#122) (#126)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-10T20:22:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d60be0fd52ab711ea62a618a70fce6d19046a08a",
"body": "bytes.TrimSpace was used to handle raw keys uploaded with a trailing\nnewline, but TrimSpace strips any whitespace byte including 0x0A and\n0x0D. X25519 keys are random bytes, so ~2% of keys end in such a byte;\nin those cases TrimSpace consumed a real key byte and the input no\nlonger matched any recognised encoding.\n\nReplace with bytes.TrimRight(raw, \"\\r\\n\") on the raw-key path so only\nactual line endings are stripped.",
"is_bot": false,
"headline": "fix: use TrimRight for raw forensic key line-ending stripping (#125)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-10T06:24:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ce781f698539541a2aad08dc06caa6bf8eaaddc",
"body": "The Receipts tab only synced ?q= into the URL; session_id was set by\napplySessionFilter/filterBySession but never removed when the filter was\ncleared. A stale ?session_id= would then be re-applied by the deep-link\nboot logic on the next reload, making the session filter sticky and\nforcing users to h\n[…]\nthe URL to widen the view.\n\nloadReceipts() now owns URL sync for session_id too (set when present,\ndelete when empty), and the redundant URL writes in applySessionFilter /\nfilterBySession are removed.",
"is_bot": false,
"headline": "fix: clear session_id from URL when session filter is cleared (#124)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-10T06:12:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e89fb2b3e64defedaac5fdc4fd503dff3122a535",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.7.0-alpha.4 (#123)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T10:03:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f8e4a1a602168ad8a23c2fb7f10de43a742be4c",
"body": "The dashboard read the sub-agent id from a flat `issuer.agent_id`, but the\ndaemon never emitted it there — and as of protocol v0.5.0 / daemon\nv0.18.0-alpha.1 it lives under the open `issuer.runtime` sub-object\n(ADR-0026). So `issuer.agent_id` always resolved to NULL and sub-agent\ngrouping never lit \n[…]\neal receipts; add an agent_type assertion.\n\nVerified against the live receipts.db: /api/sessions agent_count resolves\nsub-agents, /api/receipts surfaces agent_id + agent_type on all 33\nsub-agent rows.",
"is_bot": false,
"headline": "feat: read sub-agent identity from issuer.runtime (ADR-0026) (#121)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T09:58:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41158da6dfae42405dbbd48b68651515d5f4f25a",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.7.0-alpha.3 (#120)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T02:41:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbee21179a4c8cde9a7f6f821a6e84e9351a1cdd",
"body": "issuer.agent_id is a Layer 3 extension field not yet produced by any\ncurrent daemon version, so the agent count was always 0. Falling back\nto issuer.id gives a correct count (≥ 1) for current receipts; once\nthe daemon starts emitting agent_id the correct subagent count appears\nautomatically.",
"is_bot": false,
"headline": "fix: fall back to issuer.id for Sessions tab agent count (#119)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T02:38:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24d724c35cd4c36ee5bafbee68b6bc368c73bcdd",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.7.0-alpha.2 (#118)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T02:21:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "79df7624820bcdfad847f6697eb360f943bfa4fd",
"body": "* feat: add Sessions tab with GET /api/sessions endpoint\n\nAdds a dedicated Sessions tab that lists all agent sessions extracted\nfrom stored receipts. Each row shows session ID, receipt count, distinct\nagent count, and first/last seen timestamps. Clicking a row navigates to\nthe Receipts tab pre-filte\n[…]\nagate errors in seedSessionsDB helpers\n\nMarshal/unmarshal and hash/insert errors were silently discarded,\ncausing later test failures with confusing messages instead of\na clear t.Fatalf at the source.",
"is_bot": false,
"headline": "feat: Sessions tab (#117)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T02:19:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1dc06e56505367b4bdc6772ab5d31b23ad1480cd",
"body": "* feat: jump to session from Overview recent receipts (#111)\n\nAdd a small session pill to each receipt row in the Overview recent-receipts\nmini-table when the receipt carries a session_id. Clicking the pill switches\nto the Receipts tab and applies a session filter. Supports a ?session_id=\nURL deep l\n[…]\nregardless of merge order.\n\n* fix: data-session-id attribute on pill; call loadReceipts() in fallback branch\n\n* fix: single loadReceipts call; bookmarkable URL in both paths; focus-visible; aria-label",
"is_bot": false,
"headline": "feat: jump to session from Overview recent receipts (#111) (#115)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T01:51:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3e22345926fc8071ad055b5a0e1cc31068d8a11e",
"body": "* feat: filter receipts by session_id (#110)\n\nAdd a Session ID filter to the Receipts tab. Typing in the new input\nrestricts the list to receipts whose issuer.session_id matches exactly.\nClicking a session header in the grouped view pre-fills the input and\nreloads. Clear filters / chip-clear also re\n[…]\n no session_id is present.\n\n* fix: use data-session-id attribute on session header span (avoid JSON.stringify in onclick)\n\n* fix: trim session_id param; session header as button; fix changelog wording",
"is_bot": false,
"headline": "feat: filter receipts by session_id (#110) (#114)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T01:49:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4d901d2432b45077235d21c367b563b231b00eb",
"body": "* feat: keyboard navigation between receipts in detail view (#112)\n\nWhen the receipt detail modal is open, j/↓ opens the next receipt in\nthe current list and k/↑ opens the previous one. Navigation stops at the\nends (no wrap). Session/agent header rows in grouped mode are skipped via\nthe [data-receipt-id] selector. Keyboard shortcuts help modal updated.\n\n* fix: serialize keyboard navigation; clarify shortcut help labels",
"is_bot": false,
"headline": "feat: keyboard navigation between receipts in detail view (#112) (#113)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T01:39:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e5a4cf0eaca871e9d8b0cf370e4245e07574731a",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.7.0-alpha.1 (#109)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T00:12:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a7e1aff4661180e6e7e025cd6b139dbbabdd1b3",
"body": "…lation pairs, delegation edges) (#108)\n\n* feat: add Layer 3 attribution rendering (session groups, swimlanes, correlation pairs, delegation edges)\n\nReceipts from daemon ≥ v0.17.0 / hook ≥ v0.14.0 carry three new JSON\nfields: issuer.agent_id, issuer.session_id, credentialSubject.correlation_id,\nand \n[…]\ner augmentation and switch to HashRawReceipt.\n\nAlso expose collapse state to assistive tech: add aria-expanded=\"true\"\nto the session collapse button on render and keep it in sync inside\ntoggleSession.",
"is_bot": false,
"headline": "feat: Layer 3 attribution rendering (session groups, swimlanes, corre…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-09T00:09:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a9e6a4e5d3a621fbd651249c7757e9539c4c281",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.6.1 (#107)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T22:25:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba9f83831e0f91ed5f6cd758592124e63d509b46",
"body": "* fix: return [] instead of null for empty API result sets\n\nStore functions initialised their output as a nil slice which JSON-encodes\nas null. When the selected time range contains no receipts the /api/receipts\nendpoint returned null, causing the frontend to crash with\n\"Cannot read properties of nu\n[…]\n\n- Add receipts || [] guard to loadReceipts in the frontend\n- Remove dead nil-guards from handleTimeseriesStats, handleActionStats,\n handleServerStats now that the store always returns non-nil slices",
"is_bot": false,
"headline": "fix: return [] instead of null for empty API result sets (#106)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T22:23:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee062932d0657ccc7a8711cd1caac8490c9e57d2",
"body": "Adds skip_upload: auto to the stable formula (consistent with daemon/hook/\nmcp-proxy) and a new dashboard-alpha formula that publishes on every\nrelease — stable and pre-release alike.\n\nInstall the latest cut (including alphas/betas) with:\n brew install agent-receipts/tap/dashboard-alpha\n\nconflicts_with the stable formula; livecheck regex extended to match\npre-release suffixes.",
"is_bot": false,
"headline": "feat(release): add alpha-track Homebrew formula for dashboard (#104)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T20:19:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bd569af8b43263d8ade8bbb5f2b5c8cdf6377e6",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.6.0 (#103)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T06:14:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6dabf90c9ccf5ebedbf47708d1f9a36c9fb5d5c2",
"body": "A GitHub icon next to the shortcuts button opens the project repo in a new tab,\nso operators can browse the source or report an issue.",
"is_bot": false,
"headline": "feat: add a GitHub link to the header (#102)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T05:42:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac6ebe7583b33ec470f34de955c2a9342224b17c",
"body": "The stacked bars rendered as thin spikes because the inter-bar gap was 2x the\nbar width. The gap is now a small fraction (0.06) of the bar width, so the\ncontiguous time buckets read as a continuous histogram rather than spaced-out\nspikes. Genuine zero-activity buckets remain visible as gaps.",
"is_bot": false,
"headline": "fix: render activity timeline as a tight stacked bar chart (#101)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T05:34:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f25aaca88e20559629e3518eb3989c8ee9fa248",
"body": "* feat: add error-rate sparkline and throughput stat card\n\nAdds two new panels to the Overview tab driven by the active time range:\n\n- Error-rate sparkline (data-card=\"error-rate\"): collapsible card with an\n inline SVG polyline of failure % per timeseries bucket. Null/zero-total\n buckets render as\n[…]\n)\n- recompute throughput from live stats.total in renderStats (no stale value\n during polling); cache only rangeHours + prev per-hour as context\n- add aria-label/role=img to the sparkline trend arrow",
"is_bot": false,
"headline": "feat: add error-rate sparkline and throughput stat card (#100)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T04:31:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0922a406893facf1f8cbb2d5bc12da916f40ea0",
"body": "* feat: add activity timeline chart to overview\n\nAdds a collapsible \"Activity timeline\" card to the Overview tab,\npositioned between the stats summary cards and the 3-column\ndistribution grid. The card renders an inline SVG stacked bar chart\nof receipt counts per timeseries bucket, with success (gre\n[…]\ntal so success+failure+other sum\n exactly to the bar total (no per-segment 1px min); keeps the hit-rect\n covering the full bar\n- show a distinct error state on fetch failure instead of 'No activity'",
"is_bot": false,
"headline": "feat: add activity timeline chart to overview (#99)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-08T04:14:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd7d98731e320cc0f5064c77e892dceefdcc7e10",
"body": "* feat: add time range picker and timeseries stats endpoint\n\nAdd a persistent 1h/6h/24h/7d/30d/All range picker to the Overview tab\nthat drives every panel — stat cards, distributions, top actions, server\nactivity, and recent receipts — via after= on /api/stats and /api/receipts.\nThe active preset i\n[…]\nedge)\n- render bucket_duration cleanly (\"1h\" not \"1h0m0s\") via formatBucketDuration\n- use second-resolution RFC3339 for the frontend after= watermark\n- add tests for to-alone and clean bucket_duration",
"is_bot": false,
"headline": "feat: add time range picker and timeseries stats endpoint (#98)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-07T20:15:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "575480f9bcb5a9b9d95a437198c7bdcd62af74a9",
"body": "Each Overview card (distribution charts, Top actions, Server activity, Recent\nreceipts) gets a chevron that collapses it to just its header. The collapsed\nstate is persisted per card in localStorage so hidden cards stay hidden across\nreloads.",
"is_bot": false,
"headline": "feat: collapsible Overview cards with remembered state (#97)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-07T08:57:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ef24b867482957524d8c2d6ea0c2ab4be101025",
"body": "Bumps the go group with 1 update: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `modernc.org/sqlite` from 1.51.0 to 1.52.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.51.0...v1.52.0)\n\n---\nupdated-de\n[…]\nte-type: version-update:semver-minor\n dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump modernc.org/sqlite in the go group (#96)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-07T08:55:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b9a87c11f342596cb02a90774e89b7e660646bd6",
"body": "Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).\n\n\nUpdates `actions/checkout` from 6.0.2 to 6.0.3\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits\n[…]\nsion-update:semver-patch\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout in the github-actions group (#95)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-07T08:55:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b35dcffd8359a4341b86e18035d2d2c66412de62",
"body": "* fix: overview summary cards no longer hang on skeletons\n\nBoth the Top actions and Server activity summary fetches ran after\nstartPolling(), which bumps poller.generation, so their gen guard always\nbailed and the skeletons never rendered. Move the fetches before startPolling\nwhile keeping each isol\n[…]\nng /api/stats/* delay recent-receipts polling and keyboard nav.\nStart polling + nav first, then load the cards guarded by a fresh generation\ncaptured after startPolling (which increments the counter).",
"is_bot": false,
"headline": "fix: overview summary cards no longer hang on skeletons (#94)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-07T08:50:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3244a5b67ea51c8689fb8f693af5bcc5d7c48f20",
"body": "* feat: add server/tool breakdown panel and endpoint\n\nAdds GET /api/stats/servers which groups receipts by\ncredentialSubject.action.target.system and tool_name, computing\ntotals, failure counts, and failure rates at both levels. Rows with\nno server value are folded into an \"Unknown\" bucket placed af\n[…]\nzes as server:\"\" instead of\nthe literal \"Unknown\", so a real server named \"Unknown\" stays distinguishable.\nThe frontend renders \"\" as the \"Unknown\" label and keys the missing bucket off\nserver === ''.",
"is_bot": false,
"headline": "feat: add server/tool breakdown panel and endpoint (#93)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-07T05:44:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fac128525f05474f1b25032646b6172c16b6e3d2",
"body": "* feat: add free-text search to receipts\n\nAdds a search box to the Receipts tab filter bar that searches across\nthe full raw receipt JSON via GET /api/receipts?q=<term>. The active\nterm is synced to the URL so searches are bookmarkable; loading the\ndashboard with ?q=<term> pre-fills the box and open\n[…]\nfix: populate header stats on ?q= deep-link boot\n\nAddresses Copilot review: the deep-link path skipped loadOverview, leaving the\nheader receipt-count/latest-timestamp blank until Overview was visited.",
"is_bot": false,
"headline": "feat: add free-text search to receipts (#92)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-07T05:36:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe89e6ed2549ab95db16b6270ccefbfb88d57153",
"body": "* feat: add top actions by failure rate table and endpoint\n\nAdd GET /api/stats/actions returning per-action-type failure statistics\n(total, success, failure, failure_rate). Action types with fewer than 5\nreceipts are excluded via HAVING. An optional `range` query param\n(Go duration string) restricts\n[…]\nd the issue examples; frontend renders it as a percent\n- sortable Actions column headers are now real <button>s with aria-sort\n- Overview summary rows are keyboard-operable (role/tabindex/Enter/Space)",
"is_bot": false,
"headline": "feat: add top actions by failure rate table and endpoint (#91)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-07T04:37:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba0d61839e1d02faefffb2de35ab7f8679afa0ae",
"body": "The collector architecture already solves the multi-machine problem —\nagents POST receipts to a central collector, the dashboard reads that\nstore from any browser. A native desktop wrapper is not needed and\nwould have locked the frontend into a local-only shape.\n\nCloses #38",
"is_bot": false,
"headline": "docs: supersede ADR 0001 (Wails desktop wrapper) (#89)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-06T00:01:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "496a337d7dc4c7465f01bf698ee63366a80593b1",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.5.1 (#82)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-03T02:07:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "222a15c0065a9ffd91ccf5b5cc708cbc9d25eb8d",
"body": "v0.5.0 only read .input and .output from the decrypted parameters when\npopulating the row tooltip cache, so disclosures that capture other\ntop-level keys — for example MCP tool wrappers writing command /\narguments / result — looked the same as before decryption: the\nfallback \"Additional disclosure f\n[…]\n the schema\nmatches the server's preview convention.\n\nWhen the decrypt succeeded but every value is empty, the tooltip now\nsays \"🔓 Decrypted (empty parameters)\" instead of pretending nothing\nhappened.",
"is_bot": false,
"headline": "fix: show decrypted row preview for arbitrary disclosure schemas (#81)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-03T02:04:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3433ce4582ea370fd111f890fa5ccdd60880a2ae",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.5.0 (#80)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-03T01:50:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f360175ecfd1e2648d8220e2150dcc69f0c0d1f",
"body": "* feat: load forensic key from path and auto-probe default location\n\nAdd a file-path input to the forensic key modal (pre-filled with the\nXDG default ~/.local/share/agent-receipts/forensic.key) so operators\ncan load their key by pasting or editing a path instead of using the\nfile picker. A new POST\n[…]\nth.Join discarding the home\nprefix when joined with \"/file\") does not apply to Go; verified that\nfilepath.Join(\"/home/alice\", \"/file\") returns \"/home/alice/file\" — the\nbehaviour is Python's, not Go's.",
"is_bot": false,
"headline": "feat: load forensic key from path and auto-probe default location (#77)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-03T01:38:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "acd3ed40806b15cb707642c7fcd95a512e62381b",
"body": null,
"is_bot": false,
"headline": "chore(release): bump to v0.4.0 (#76)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-02T23:29:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a9312037de3036adb896cd35c8f56b621951f680",
"body": "* feat: decrypt HPKE parameter disclosure envelopes in the dashboard\n\nOperators can now load their X25519 forensic private key into the\ndashboard and view decrypted parameters_disclosure envelopes inline in\nthe receipt detail view, closing the detail-view decryption follow-up\ndeferred in 0.3.0.\n\nThe\n[…]\n now re-syncs from the authoritative status on a non-OK or\n failed DELETE instead of optimistically applying the error body, so the UI\n can't show the key as cleared while the server still holds it.",
"is_bot": false,
"headline": "feat: decrypt HPKE parameter disclosure envelopes in the dashboard (#75)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-02T22:59:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ce616d18a6446d4122e88280fe2bf4036b981655",
"body": "* fix(verify): recompute chain hashes from raw wire bytes (#719)\n\nChain verification reported valid chains as broken. The hash-linkage\nrecompute round-tripped each receipt through the Go struct via\nreceipt.HashReceipt, which drops any forward-compat fields a newer SDK\nwrote before hashing. The resul\n[…]\nthe single allocation.\n\n* docs(verify,store): tidy ChainReceipt/VerifyChainLinks comments\n\nAdd the missing 'that' in two doc comments for readability, per PR\nreview. Comment-only; no behaviour change.",
"is_bot": false,
"headline": "Fix chain verification false negative with forward-compat fields (#74)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-06-02T07:40:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ebc75c264d56c9ac81db348002b83e58f887b11",
"body": "Bumps the go group with 2 updates in the / directory: [github.com/agent-receipts/ar/sdk/go](https://github.com/agent-receipts/ar) and [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `github.com/agent-receipts/ar/sdk/go` from 0.11.0 to 0.13.0\n- [Release notes](https://github.com/agen\n[…]\nte-type: version-update:semver-minor\n dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the go group across 1 directory with 2 updates (#72)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-02T05:51:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "66754b6f8d07d83fa16e7d4bdda6371ddcfb2ba9",
"body": "Bumps the github-actions group with 1 update: [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `goreleaser/goreleaser-action` from 7.2.1 to 7.2.2\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/gorel\n[…]\nsion-update:semver-patch\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump goreleaser/goreleaser-action (#70)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-02T05:50:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dde25a1264632ebef9e5de85b10d6d670c8c9bb1",
"body": "CHANGELOG entry for the v0.3.0 cut: brings the dashboard onto sdk/go v0.11.0 (envelope-shape parameters_disclosure per ADR-0012) via #67/#68, and backfills the missing 0.2.x compare links.\n\nAfter merge, push tag v0.3.0 to trigger release.yml → goreleaser → binaries + GitHub Release + homebrew-tap formula update.",
"is_bot": false,
"headline": "chore(release): bump to v0.3.0 (#69)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-22T05:16:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e581b9f3cb852468967318d7d64a73d038420437",
"body": "…est (#68)\n\n* test(store): remove double-close on raw sqlite handle in legacy-shape test\n\nThe previous patch (#67) used both `defer db.Close()` and an explicit\n`db.Close()` to release the writer before opening the reader. That\ndouble-closes the handle and can mask the inner-Close error. Drop the\ndef\n[…]\n; the explicit close is required (and now error-checked) so the\nreader sees a quiesced file.\n\nPer Copilot review on #67 (landed after merge).\n\n* test(store): t.Cleanup as failure-path Close safety net",
"is_bot": false,
"headline": "test(store): drop double-close on raw sqlite handle in legacy-shape t…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-22T04:53:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5a926242e41f317d5f6c94aa828647084e591ce9",
"body": "- Bumps github.com/agent-receipts/ar/sdk/go from v0.9.0 to v0.11.0.\n- Refactors internal/store/reader_test.go for the v0.3.0 envelope-shape parameters_disclosure (*receipt.DisclosureEnvelope).\n- Adds TestReader_ListReceipts_OutputStatusMismatch_LegacyShape to keep coverage of the SQL mismatch detect\n[…]\npre-v0.3.0 flat-map disclosures (per Copilot review on #67).\n\nPhase 6 of the v0.3.0 release in agent-receipts/ar (#280). Production code unchanged; envelope-shape UI rendering is a separate follow-up.",
"is_bot": false,
"headline": "chore(deps): bump sdk/go to v0.11.0 (v0.3.0 envelope migration) (#67)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-22T04:39:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "93744dac74df2b79e8e6aa407986f9ebe103b5f1",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.2 (#66)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T06:57:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d40ee1de2358b4738d133cf52b654b8cd9cdd420",
"body": null,
"is_bot": false,
"headline": "fix(ui): truncate long action type labels in distribution chart (#65)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T06:54:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20104ff31270c9f97d04a09400193619d81a4497",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.1 (#64)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T05:36:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2131c51e17964c5e1fb5cd87b9bc704bfc0b3d0d",
"body": "…act (#63)",
"is_bot": false,
"headline": "fix(ui): cap action distribution chart to top 5 to keep overview comp…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T05:35:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5c9b800a7cd9738252d1394098ebf71132058506",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.0 (#62)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T05:27:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45e5fe4fd5f5faf4759b61a7ad79215eccdd41d4",
"body": "…t detail (#61)\n\n* feat(ui): render structured Intent and Authorization fields in receipt detail (#6)\n\nExpand the Intent section to show conversation_hash and reasoning_hash\nas truncated monospace with tooltip, plus a \"(truncated)\" note on the\nprompt preview when prompt_preview_truncated is true.\n\nA\n[…]\nce with NaN guard; use join('') for scopes badges\n\n* fix(ui): guard granted_at against invalid date before formatTime\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(ui): render structured Intent and Authorization fields in receip…",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T05:20:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d81c92ffaadfc33065b284a00ce3998245cb0c8a",
"body": "* fix: cap overview recent-receipts fetch to 20 rows (#58)\n\nThe overview loadOverview() call was fetching /api/receipts with no\nlimit, pulling up to 10k rows to display only a handful. Add ?limit=20\nto that specific fetch; the full receipts view is unchanged.\n\nCloses #58\n\nCo-Authored-By: Claude Sonn\n[…]\np limit param at 10000; fix CHANGELOG row count\n\n* fix: use maxLimit constant in error message; add limit param tests\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: cap overview recent-receipts fetch to 20 rows (#59)",
"author_name": "Otto Jongerius",
"author_login": "ojongerius",
"committed_at": "2026-05-20T05:20:02Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 34,
"commits_last_year": 179,
"latest_release_at": "2026-07-20T03:30:10Z",
"latest_release_tag": "v0.13.1",
"releases_from_tags": false,
"days_since_last_push": 3,
"active_weeks_last_year": 16,
"days_since_latest_release": 3,
"mean_days_between_releases": 3.4
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/agent-receipts/dashboard",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/agent-receipts/dashboard",
"is_deprecated": false,
"latest_version": "v0.13.1",
"repository_url": "https://github.com/agent-receipts/dashboard",
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-20T03:27:32Z",
"latest_version_yanked": null,
"days_since_latest_publish": 3
}
]
},
"popularity": {
"forks": 0,
"stars": 2,
"watchers": 1,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 3
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 122868,
"source_files_sampled": 15,
"oversized_source_files": 2,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 5388
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.52.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 15
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 13,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.54.0"
},
{
"name": "obsigna.dev/sdk/go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.24.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "modernc.org/sqlite",
"direct": true,
"version": "v1.54.0",
"ecosystem": "go"
},
{
"name": "obsigna.dev/sdk/go",
"direct": true,
"version": "v0.24.0",
"ecosystem": "go"
},
{
"name": "github.com/cloudflare/circl",
"direct": false,
"version": "v1.6.4",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/ncruces/go-strftime",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/remyoudompheng/bigfft",
"direct": false,
"version": "v0.0.0-20230129092748-24d4a6f8daec",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.52.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.46.0",
"ecosystem": "go"
},
{
"name": "modernc.org/libc",
"direct": false,
"version": "v1.74.1",
"ecosystem": "go"
},
{
"name": "modernc.org/mathutil",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "modernc.org/memory",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 13,
"direct_count": 2,
"indirect_count": 11
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 138,
"open_issues": 3,
"closed_ratio": 0.925,
"closed_issues": 37,
"closed_unmerged_prs": 2
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "ojongerius",
"commits": 159,
"avatar_url": "https://avatars.githubusercontent.com/u/1726055?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"publish.yml",
"release.yml",
"shellcheck.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/22 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 3 contributing companies or organizations -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "e1f5a50284b93bbef74da74a2b9565af4e12a565",
"ran_at": "2026-07-23T07:27:42Z",
"aggregate_score": 6.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-20T03:29:16Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-20T03:28:33Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 90,
"created_at": "2026-06-06T00:02:10Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 156,
"created_at": "2026-06-25T03:58:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 179,
"created_at": "2026-07-20T02:56:20Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/agent-receipts/dashboard",
"host": "github.com",
"name": "dashboard",
"owner": "agent-receipts"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"security": 73,
"vitality": 81,
"community": 36,
"governance": 58,
"engineering": 77
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 81,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"commits_last_year": 179,
"human_commit_share": 0.87,
"days_since_last_push": 3,
"active_weeks_last_year": 16
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "16/52 weeks with commits",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 16
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "179 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 179
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 34,
"latest_release_tag": "v0.13.1",
"releases_from_tags": false,
"days_since_latest_release": 3,
"mean_days_between_releases": 3.4
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "34 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 34
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.4 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.4
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 36,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 2,
"watchers": 1,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "2 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 2
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "1 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 1
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 58,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"merged_prs": 138,
"open_issues": 3,
"closed_issues": 37,
"issue_closed_ratio": 0.925,
"closed_unmerged_prs": 2
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "92% of issues closed",
"points": 43.2,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 92
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "138/140 decided PRs merged",
"points": 37.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 138,
"decided": 140
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 46,
"inputs": {
"followers": 11,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "agent-receipts",
"public_repos": 9,
"account_age_days": 112
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "11 followers of agent-receipts",
"points": 7.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 11,
"login": "agent-receipts"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "9 public repos, account ~0 yr old",
"points": 7.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 9
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/agent-receipts/dashboard"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 3
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 3 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 3
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "34 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 34
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 77,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://obsigna.dev",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://obsigna.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 73,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 6.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 13 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 13
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 13,
"unassessed_packages": 0,
"affected_by_severity": "unknown 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 13,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 87,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 5388
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 87,
"sampled": 87
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 87,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.04,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0.13
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "4 of the last 100 commits agent-authored or agent-credited",
"points": 8,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 4,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "13 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 13,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 93,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 122868,
"source_files_sampled": 15,
"oversized_source_files": 2
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "2/15 source files over 60KB",
"points": 47.7,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 15,
"oversized": 2
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-23T07:28:00.720371Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agent-receipts/dashboard.svg",
"full_name": "agent-receipts/dashboard",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}