Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-25 03:29 UTC

agora-oss-org / agora-server

Self-hosted open-source backend for community & social apps (posts, comments, reactions, follows, spaces, realtime chat, semantic search). API-compatible with the Replyke SDK. Built on Supabase.

TypeScriptAGPL-3.0★ 4 Sterne⑂ 0 Forksseit Mai 2026Auf GitHub ansehen ↗

agora-oss-org/agora-server erreicht einen Gesundheitsindex von 59 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (76/100) ab, am schwächsten bei Community & Adoption (42/100). Zuletzt vor 3 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

59
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

59
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Agora OSS OrgOrganisation
0 Follower5 öffentliche Reposseit Juni 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
npm@agora-server/contract0.22.03.46519vor 5 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

76Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 3 Tagen
6.2/36Commit-Rhythmus — 9/52 Wochen mit Commits
18/18Commit-Volumen — 827 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year827
human_commit_share1
days_since_last_push3
active_weeks_last_year9

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 26 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 5 Tagen
27/27Release-Rhythmus — ein Release etwa alle 1,8 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count26
latest_release_tagv0.22.0
releases_from_tagsnein
days_since_latest_release5
mean_days_between_releases1,8
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

42Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
7.7/60Stars — 4 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars4
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (AGPL-3.0)
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
47.2/80Downloads pro Monat — 3.465 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packages@agora-server/contract
dependents
ecosystemsnpm
total_downloads
monthly_downloads3.465
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

50Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
38.2/38.3PR-Annahme — 2/2 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs2
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
0/25Reichweite des Inhabers — 0 Follower von agora-oss-org
5.8/25Kontohistorie — 5 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers0
owner_typeOrganization
is_verified
owner_loginagora-oss-org
public_repos5
account_age_days30

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 5 Tagen
20/20Versionshistorie — 19 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packages@agora-server/contract
ecosystemsnpm
any_deprecatednein
min_days_since_publish5

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

76Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 6 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.

Dokumentation

100Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://demo.agora-oss.org
10/10Repository-Beschreibung
10/10Topics — 20 Topics
10/10Wiki
Verwendete Eingangsdaten
topicsbackend, comments, community, drizzle-orm, moderation, nodejs, open-source, pgvector, postgres, realtime, replyke, self-hosted, semantic-search, social-network, socketio, supabase, typescript, replyke-sdk, replyke-server, sublay
has_wikija
homepagehttps://demo.agora-oss.org
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

46Gefährdet · 16 % des Gesamtindex

Sicherheitslage

32Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 23 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,2
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages1
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:@agora-server/contract@0.22.0 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 1 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

73Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 93 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,93
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes45.604
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — apps/admin/tsconfig.json, apps/api/tsconfig.json, apps/secure-chat/tsconfig.json, packages/contract/tsconfig.json, packages/core/tsconfig.json
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 48 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespnpm-lock.yaml
has_dockerfileja
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configsapps/admin/tsconfig.json, apps/api/tsconfig.json, apps/secure-chat/tsconfig.json, packages/contract/tsconfig.json, packages/core/tsconfig.json
agent_commit_share0,48
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/542 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes38.991
source_files_sampled542
oversized_source_files0

Eckdaten

4GitHub-Sterne
1Mitwirkende
827Commits, letzte 12 Monate
3Tage seit letztem Push
26Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch pypi package 'agora-scorer' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 3.2 / 10
3.2Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-25 03:29 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities23 existing vulnerabilities detected
Direkte Abhängigkeiten 72
RegistryPaketVersionsvorgabeManifest
npm@agora-server/contractworkspace:*apps/admin/package.json
npm@radix-ui/react-avatar^1.1.12apps/admin/package.json
npm@radix-ui/react-dialog^1.1.16apps/admin/package.json
npm@radix-ui/react-dropdown-menu^2.1.17apps/admin/package.json
npm@radix-ui/react-separator^1.1.9apps/admin/package.json
npm@radix-ui/react-slot^1.2.5apps/admin/package.json
npm@radix-ui/react-tabs^1.1.14apps/admin/package.json
npm@radix-ui/react-toast^1.2.16apps/admin/package.json
npm@radix-ui/react-tooltip^1.2.9apps/admin/package.json
npm@tanstack/react-query^5.101.0apps/admin/package.json
npmclass-variance-authority^0.7.1apps/admin/package.json
npmclsx^2.1.1apps/admin/package.json
npmlucide-react^1.17.0apps/admin/package.json
npmreact^18.3.1apps/admin/package.json
npmreact-dom^18.3.1apps/admin/package.json
npmreact-router-dom^7.17.0apps/admin/package.json
npmtailwind-merge^3.6.0apps/admin/package.json
npmzod^3.25.76apps/admin/package.json
npm@agora-server/contractworkspace:*apps/api/package.json
npm@agora/coreworkspace:*apps/api/package.json
npm@aws-sdk/client-s3^3.901.0apps/api/package.json
npm@hono/node-server^1.19.14apps/api/package.json
npm@jenova-marie/wonder-logger^2.1.4apps/api/package.json
npm@node-rs/argon2^2.0.2apps/api/package.json
npm@opentelemetry/api^1.9.0apps/api/package.json
npm@socket.io/redis-adapter^8.3.0apps/api/package.json
npm@supabase/supabase-js^2.107.0apps/api/package.json
npmdotenv^17.4.2apps/api/package.json
npmdrizzle-orm^0.45.2apps/api/package.json
npmhono^4.12.23apps/api/package.json
npmioredis^5.11.1apps/api/package.json
npmjose^5.10.0apps/api/package.json
npmneo4j-driver^6.1.0apps/api/package.json
npmpostgres^3.4.9apps/api/package.json
npmsharp^0.34.5apps/api/package.json
npmsocket.io^4.8.3apps/api/package.json
npmweb-push^3.6.7apps/api/package.json
npmzod^3.25.76apps/api/package.json
npm@agora-server/contractworkspace:*apps/secure-chat/package.json
npm@agora/coreworkspace:*apps/secure-chat/package.json
npm@hono/node-server^1.19.14apps/secure-chat/package.json
npm@jenova-marie/wonder-logger^2.1.0apps/secure-chat/package.json
npmdotenv^17.4.2apps/secure-chat/package.json
npmdrizzle-orm^0.45.2apps/secure-chat/package.json
npmhono^4.12.23apps/secure-chat/package.json
npmioredis^5.11.1apps/secure-chat/package.json
npmjose^5.10.0apps/secure-chat/package.json
npmpostgres^3.4.9apps/secure-chat/package.json
npmsocket.io^4.8.3apps/secure-chat/package.json
npmzod^3.25.76apps/secure-chat/package.json
npmzod^3.25.76packages/contract/package.json
npm@agora-server/contractworkspace:*packages/core/package.json
npm@jenova-marie/wonder-logger^2.1.0packages/core/package.json
npmdrizzle-orm^0.45.2packages/core/package.json
npmhono^4.12.23packages/core/package.json
npmioredis^5.11.1packages/core/package.json
npmjose^5.10.0packages/core/package.json
npmpostgres^3.4.9packages/core/package.json
npmzod^3.25.76packages/core/package.json
PyPIfastapi>=0.110services/scorer/pyproject.toml
PyPIuvicorn>=0.29services/scorer/pyproject.toml
PyPIpydantic>=2.6services/scorer/pyproject.toml
PyPIhttpx>=0.27services/scorer/pyproject.toml
PyPIasyncpg>=0.29services/scorer/pyproject.toml
PyPIpyjwt>=2.8services/scorer/pyproject.toml
PyPIneo4j>=5.19services/scorer/pyproject.toml
PyPIopentelemetry-sdk>=1.27.0services/scorer/pyproject.toml
PyPIopentelemetry-exporter-otlp-proto-http>=1.27.0services/scorer/pyproject.toml
PyPIopentelemetry-exporter-prometheus>=0.48b0services/scorer/pyproject.toml
PyPIopentelemetry-instrumentation-fastapi>=0.48b0services/scorer/pyproject.toml
PyPIopentelemetry-instrumentation-asyncpg>=0.48b0services/scorer/pyproject.toml
PyPIopentelemetry-instrumentation-httpx>=0.48b0services/scorer/pyproject.toml
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 0

Die Installation von npm:@agora-server/contract@0.22.0 zieht 1 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "backend",
        "comments",
        "community",
        "drizzle-orm",
        "moderation",
        "nodejs",
        "open-source",
        "pgvector",
        "postgres",
        "realtime",
        "replyke",
        "self-hosted",
        "semantic-search",
        "social-network",
        "socketio",
        "supabase",
        "typescript",
        "replyke-sdk",
        "replyke-server",
        "sublay"
      ],
      "is_fork": false,
      "size_kb": 6269,
      "has_wiki": true,
      "homepage": "https://demo.agora-oss.org",
      "languages": {
        "CSS": 1728,
        "HTML": 806,
        "Shell": 11404,
        "Python": 181778,
        "PLpgSQL": 78532,
        "Dockerfile": 9610,
        "JavaScript": 247642,
        "TypeScript": 2181533
      },
      "pushed_at": "2026-07-21T09:32:13Z",
      "created_at": "2026-05-23T01:41:21Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T09:32:58Z",
      "description": "Self-hosted open-source backend for community & social apps (posts, comments, reactions, follows, spaces, realtime chat, semantic search). API-compatible with the Replyke SDK. Built on Supabase.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "root",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Agora OSS Org",
      "type": "Organization",
      "login": "agora-oss-org",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/296750678?v=4",
      "created_at": "2026-06-25T03:22:31Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 30
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-19T06:04:45Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-18T04:31:02Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-07-18T02:21:31Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-07-08T03:12:18Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-07T06:45:08Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-07-05T11:12:32Z"
        },
        {
          "tag": "v0.16.5",
          "kind": "patch",
          "published_at": "2026-07-04T11:06:32Z"
        },
        {
          "tag": "v0.16.4",
          "kind": "patch",
          "published_at": "2026-07-04T05:37:09Z"
        },
        {
          "tag": "v0.16.3",
          "kind": "patch",
          "published_at": "2026-07-03T08:42:19Z"
        },
        {
          "tag": "v0.16.2",
          "kind": "patch",
          "published_at": "2026-07-03T02:24:51Z"
        },
        {
          "tag": "v0.16.1",
          "kind": "patch",
          "published_at": "2026-07-03T01:26:15Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-02T02:34:59Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-06-16T18:44:09Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-08T08:16:22Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2026-06-08T08:22:20Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-06-07T02:32:19Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-06-07T00:58:47Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-06-05T07:21:56Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-03T08:15:54Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-31T08:59:26Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-31T05:27:22Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-06-07T01:07:52Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-05-28T04:09:31Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-05-28T01:20:58Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-05-27T05:33:38Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-05-24T09:02:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9ceb3fe8edb50190e2ebfe988f07bfbe6aa3230a",
          "body": null,
          "is_bot": false,
          "headline": "cheat-sheet",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T09:32:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97a4397590accd5e14e9b4891b162a35a7bed3bc",
          "body": "Events (migration 0053) had been invisible to every search surface since\nthey shipped: nothing embedded an event, and match_content had no branch\nthat could return one. Adds \"event\" as a fourth source type.\n\nEvents embed on create and re-embed on update (title, description, venue\nname, address — ven\n[…]\nunit.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_011DQQwcpFWHJWyQEdmfTCgP\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "✨ feat(search): make events searchable via /search/content",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T09:31:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "759b614cd1b6036bd62be2c0c47be703322a17f8",
          "body": "Propagate the widened seam into every mirror, and correct the claims the\nfirst pass made that this change falsifies.\n\n- apps/admin/README.md: full table of all eight keys with the type each is\n  validated as, the boolean spellings, and two subsections on the settings\n  that look like security contro\n[…]\nat runtime\" and framed the VITE_* flags as\nruntime-unreachable. Both were true when written and are now wrong — every\nadmin setting is runtime-resolved.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
          "is_bot": false,
          "headline": "📝 docs: document the AGORA_ADMIN_* runtime settings",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T04:37:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d46120d7217660e4d5441d9e13f7d44094b006e5",
          "body": "Wire the container side of the admin's fully runtime-resolved config, so a\npulled image can be retargeted without a rebuild.\n\n- Emit all seven new keys from the proxy entrypoint alongside publicAppUrl;\n  each is optional, and an unset var is omitted so the SPA keeps its\n  build-time default\n- Relay \n[…]\n comments that this makes false: the build args are\nnow only DEFAULTS, not the sole way to set these, and the admin SPA does\nhave a runtime config seam.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
          "is_bot": false,
          "headline": "🚀 deploy(proxy): relay the AGORA_ADMIN_* settings into /config.js",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T04:37:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25c60fd11e99bf86582317a1cb0e64d63b832b1f",
          "body": "The seam landed with one key; move the rest of the admin's config onto it\nso a PULLED agora-proxy image has no build-time-only setting left. One\npublished image can now serve a different project, API origin, or feature\nset with no rebuild.\n\nMigrated: projectId, apiBaseUrl, moderatorBaseUrl, socialGr\n[…]\nuard, NOT a boundary. It disables Save\n  controls but the API still authorizes by token. Real enforcement is the\n  server's OPERATOR_RO_EMAILS allowlist\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
          "is_bot": false,
          "headline": "✨ feat(admin): resolve every setting through the runtime config seam",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T04:37:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7f922237e03df21b192268d20dbe3f830b75ca4",
          "body": "Propagate the new runtime setting into every mirror the propagation map\nflags for a deploy-surface change, so an operator can discover it from\nwhichever entry point they start at:\n\n- apps/admin/README.md: new \"Runtime configuration\" section with the\n  precedence rule, the env-to-key table, the retar\n[…]\n seam\n\nEach spells out why it matters: unset, the admin's \"Open in app\" links\npoint at the local demo dev server, which is wrong on any real deployment.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
          "is_bot": false,
          "headline": "📝 docs: document AGORA_PUBLIC_APP_URL and the /config.js seam",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T02:26:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e98975504364a14e654d53f28116028481d061c",
          "body": "Wire the setting the admin's new /config.js seam consumes, so the \"Open in\napp\" deep links land on a deployment's real community front end instead of\nthe local demo dev server they silently defaulted to.\n\nAGORA_PUBLIC_APP_URL was reachable from nowhere before this: it lived only\nas VITE_DEMO_URL ins\n[…]\n proxy\n\nNote it is inert in docker-compose.dev.yml, where the admin is served from\nthe host vite server; host-side dev uses VITE_PUBLIC_APP_URL instead.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
          "is_bot": false,
          "headline": "🚀 deploy(proxy): relay AGORA_PUBLIC_APP_URL into the admin at runtime",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T02:26:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a34735487de9584a3ce08fc834a528999071d42",
          "body": "The admin SPA is a static Vite build baked into the agora-proxy image, so\nevery VITE_* var is inlined at BUILD time. A deployment that PULLS the\npublished image (docker-compose.prod.yml) could never change them, which\nleft the \"Open in app\" deep links on reports, AI flags, and steward cases\npermanen\n[…]\n existing builds are unaffected\n\nFirst key is publicAppUrl, fed by AGORA_PUBLIC_APP_URL (wired up in the\nproxy image and compose in a following commit).\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>",
          "is_bot": false,
          "headline": "✨ feat(admin): add /config.js runtime config seam and PUBLIC_APP_URL",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-21T02:26:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fcb1bd2b4a8f93606fc23cb018f6d50f3dc7902",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.22.0",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T06:04:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bec1b0b09f0d9da6dce9146e6be2896695e126d",
          "body": "04-seed-homepage-comments now rewrites the anchor's copy to explain the\nmechanism to both its audiences — a signed-out homepage visitor reading the\nthread, and an operator finding it in the admin panel as an ordinary entity.\nThe seeded thread follows suit, discussing how the surface works rather tha\n[…]\no it\nworks regardless of env config. Only if both fail does it warn and leave the\nanchor unpublished rather than failing the seed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(seeds): self-explaining public anchor + two-route publish authority",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T06:02:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9b1c380366b9d0821ee3d8d600b14f0c42e279d",
          "body": "…rface guide\n\nThree strands of the same thread — making the internet-public surface actually\nusable by an embed — landed together because their CHANGELOG entries interleave.\n\n1. GET /v7/:projectId/public/entities/by-foreign-id\n\nThe anonymous mirror of the walled by-foreign-id lookup, so an embed can\n[…]\nolicy matching the uuid route. Full suites green (576 unit, 619\nintegration).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(public): anonymous by-foreign-id lookup, seed coverage, and a su…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T04:27:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "76f135e5eff683a7136fc844ca70c9ed3f621224",
          "body": "…ated\n\n/public/* exists to be embedded by third-party sites, but shipped uncacheable,\nso every embed impression hit the origin.\n\nSuccess responses now carry `public, max-age=0, s-maxage=300, must-revalidate`\nplus an ETag (lib/public-cache.ts); a matching If-None-Match returns a bodyless\n304. Orderin\n[…]\naking onto the walled\nsurface. Full suites green (576 unit, 611 integration).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "perf(public): make the anonymous surface CDN-cacheable + ETag-revalid…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T03:25:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bf8afea4f2f29f20a37b45ed1ffc623ce252e58b",
          "body": "The internet-public-entities work landed migration 0065_entity_internet_public,\nso both parked plans' 0065 targets are stale.\n\nRenumber space-scoped-stewards and store-phase1 to 0066 throughout (file paths,\njournal entries, DDL headers, git commands, and the store plan's journal-append\nscript). Both\n[…]\nmes doesn't have to hunt for it.\n\nDocs only — neither plan has been executed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "📝 docs(plans): renumber parked migrations to 0066 (0065 is taken)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T03:24:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14b7bc953200cd5dc10f13f147d081b93bc29870",
          "body": "…ic/* read surface\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge: internet-public entities — visibility ladder + anonymous /publ…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T01:40:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "01d944271c085dd07edf8dea9a8ffc5471e2224c",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "fix(api): redact anonymous user PII on the public comment routes too",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T01:34:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc65dc864c8afb555b08ddccf9cab154d1957fbc",
          "body": "…ty route\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "fix(api): final-review hardening for the /public/* surface + visibili…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T01:24:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb36105bbd4cedb61451a33493c6b8e5fd199f41",
          "body": "…gelog)\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs: internet-public entities contract (§public, Entity.public, chan…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a704c260cc8155d89ba5801823b1ffa50c7f933e",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(api): anonymous /public/* internet-public read surface",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:42:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b67fc571b1872f8731ba0a0a330b01bdd70035b",
          "body": "… ladder)\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(api): privileged PATCH /entities/:id/visibility (internet-public…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:27:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52ce0bf824140f5912f5b441911abab4ced8eb26",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(api): internet-public ladder gate (lib/public-access)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:18:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0192357af2bda57181bbf28a9cb67e6f142febab",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(contract): Entity.public field + entityVisibilitySchema",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:13:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4836a3af4c526298e57cf075ecceeeb71714b762",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(db): entities.is_public internet-visibility flag (0065)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:06:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3d56dd9985acea1789018f605693ebc54ca299e",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs: internet-public entities spec + implementation plan",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-19T00:04:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02925ff71981b6378de0ddfbddfca0f1879ec119",
          "body": "The admin login's one-click \"Log in as admin\" button is gated on\nVITE_DEMO_EMAIL + VITE_DEMO_PASSWORD, inlined at `vite build` time (the\nadmin SPA has no runtime config seam). The proxy Dockerfile never declared\nthese ARGs and the deploy workflow never passed them, so production builds\nbaked them em\n[…]\nred\nas a Secret (so it silently resolved empty) — source it from secrets too.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "ci(admin): bake demo operator credentials into the admin build",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T07:42:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a8e184b257b4735595a83eabf0098f741ebc9ad",
          "body": "Rework the admin LoginPage to match the demo login: a welcome blurb, an\n\"or\" divider, and a one-click \"🛠️ Log in as admin\" button that signs in\nwith the seeded operator credentials. Drop the credential prefill (the\none-click button covers it now, so the form is unambiguously \"your own\naccount\"). No \n[…]\no\nreal deployments that leave those unset see only the ordinary sign-in form.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(admin): restyle login to mirror the demo screen",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T06:58:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "adfc55cacce9a95d0d4344690ad4b9879bdf0d39",
          "body": "…designs)",
          "is_bot": false,
          "headline": "merge: store marketplace spec + phase 1 plan + ROADMAP index (parked …",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T06:09:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39075de6682f8117692a1e2d106bcf0b79a3466e",
          "body": "Introduce the living roadmap and index the two parked initiatives:\n\n- ROADMAP.md (repo root): pointers + status only — ready-to-execute\n  spec+plan pairs (space-scoped stewards, store Phase 1), committed\n  follow-ons (store Phase 2, store admin-SPA/SDK surfaces, stewardship\n  Watch, secure-chat diag\n[…]\n landing\n\nNothing here changes runtime behavior; both initiatives await a future\nexecution session.\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "📝 docs: add ROADMAP index, space-scoped-stewards plan, changelog entry",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T05:45:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab76ccaffe847cff911b557a1c1b83282372877b",
          "body": "Executable TDD plan for the approved marketplace spec's Phase 1\n(coins + digital cosmetics), parked for a later session:\n\n- 13 tasks: contract types/zod, core schema, migration 0065 (ledger\n  trigger + serialized purchase/gift/earn/stipend SQL fns), settings,\n  shapers, store router, purchase/equip/\n[…]\nase 2 (Stripe + merch), and SDK/demo surfaces are\n  explicitly out of scope (tracked in ROADMAP.md)\n\nAuthored-By: Jenova Marie <jenova-marie@pm.me>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "📝 docs(store): store Phase 1 implementation plan",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T05:45:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46c2dcabd8445f9c8c640043b82144375de5d14c",
          "body": "…ed merch)\n\nApproved brainstorm output: per-project store domain (Approach A — in-core\nrouter + append-only coin ledger), Phase 1 digital cosmetics / Phase 2\nStripe + fulfilled merch.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01G5F4pcgLie2XF5HS9rzp2w\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs(store): marketplace design spec (coins + digital cosmetics, phas…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T04:57:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "605c0ba8e25ffd1c358d3e908dfb3089e78fdc6a",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.21.0",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T04:27:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "300792063f21fadf46038b1ac1c2afd1af39bb8a",
          "body": "Resolve the admin email+password once (shared resolve-admin-creds.mjs) and\npropagate via child env so a typed password reaches every post-seeder.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_0176Aqcz3FiTyL2cDrLWzzZA",
          "is_bot": false,
          "headline": "merge: seed admin-credential propagation to post-seeders",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T04:25:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "16c00e90c7edbd867812d62ac9e6dc4ff96e88cf",
          "body": null,
          "is_bot": false,
          "headline": "Seed: a custom admin password now propagates to the post-seeders.",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T04:24:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8af30553979bb7821b6ff615ce7d78ed54c2c77e",
          "body": null,
          "is_bot": false,
          "headline": "spec",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T04:23:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "537c175056dc2e69120ecec6ce83209064e711ee",
          "body": "PATCH /admin/social/read-receipts/spaces/:spaceId mutates settings\n(spaces.readReceiptsEnabled) but lacked assertSettingsWritable, so a\nsettings-read-only principal holding the operator claim could flip it.\nAdd the guard after the operator check; it now 403s settings/read-only\nlike the other five se\n[…]\nd the scope/handler\ncomments were updated to match. No behavior change there.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "fix(settings): gate read-receipts toggle behind settings-read-only cap",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T03:16:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aec88c05bd45d04cee5c376f9c6c3f1923e25427",
          "body": null,
          "is_bot": false,
          "headline": "agora admin rename",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T03:03:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8e7543819754055eb490d0752b5030efeced7a8",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.20.0",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T02:20:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8a6101d363d49af439498d452826b832811012c",
          "body": "Adds SETTINGS_READONLY_EMAILS — a shared demo login (demo-admin@agora-oss.org) gets\nthe full operator view but is server-blocked (403 settings/read-only) from the five\nsettings-save endpoints (PATCH /settings/feed|moderator|steward|social, /webhooks/config).\nNon-destructive actions and ordinary memb\n[…]\n each reviewed clean; whole-branch review (Opus) verified no bypass path,\nclaim on every mint path, fail-closed, correctly scoped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge: settings-read-only demo operator + default admin email rename",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T02:17:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "91927b885e86d9642d6e05d6843c58d62a2aa6c9",
          "body": "…ngsReadonly in token JSDoc (review follow-up)",
          "is_bot": false,
          "headline": "test(settings): valid steward notifyPolicy for a true 200; note setti…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T02:04:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd6fa7bbbfbba7e9dabcb50d0b6249edda393bcd",
          "body": "… admin email",
          "is_bot": false,
          "headline": "chore(demo): enable settings-read-only demo operator + rename default…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T01:52:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2344dfe6c57b62f0805f3a51752edd9b0831342",
          "body": "… endpoints",
          "is_bot": false,
          "headline": "feat(settings): block settings-read-only principal from the five save…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T01:37:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0270c341340d3cb66d5ec6aba84e21f6e525020",
          "body": null,
          "is_bot": false,
          "headline": "feat(auth): settingsReadonly allowlist → JWT claim → c.var.auth pipeline",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T01:23:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d2c02de3a4a8ebe3c4863a04add9896b3001977",
          "body": null,
          "is_bot": false,
          "headline": "docs: demo read-only admin — spec + implementation plan",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-18T01:17:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "606b7b953449f1044c7d8d0558f266988994f3c7",
          "body": "Every /v7/:projectId/* request now requires an authenticated account. authWall\n(packages/core) replaces optionalAuth at the project-group mount; AUTH_WALL_ALLOWLIST\nis the API's entire anonymous surface. Migration 0064 revokes the 0008 anon\npublic-read RLS so the DB states the same posture. Tokens are bound to their project\nat the wall. Ships in 0.20.0.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge: auth wall — private by default (BREAKING)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T09:21:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2ca3a1e4c919d3e05a2507cefab0ebf28aade7a4",
          "body": "…lock skew\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "fix(auth): bind tokens to their project at the wall; fix suspension c…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T09:10:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4654707c7e680b156f13d9504631f943894f461f",
          "body": null,
          "is_bot": false,
          "headline": "PENTEST.md",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T08:34:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8b7b364441b4346be3f9d2f59d1c71a8c241b11",
          "body": "…wrap SECURITY bullet\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "test(api): pin STORAGE_PROVIDER in the integration hermetic block; re…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T08:33:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8aae1110a45988c47583b57bbf4a6d27ec5a3732",
          "body": "\"Ships in the next MAJOR version.\" was written while the entry sat under\n[Unreleased]. Stamped into a dated 0.20.0 section it reads as \"not this\nrelease\" — the opposite of the truth. Pre-1.0 the minor bump is the\nbreaking vehicle (SemVer §4), so say so plainly.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): the auth wall lands in 0.20.0, not a later major",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T08:13:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "905fab654e2374720f91b59617ed9ad17da49beb",
          "body": "…rences\n\nDocument demo-admin@agora-oss.org / DemoAdmin123! alongside the existing\nagora-admin@gmail.com login, since the two come from different layers and are\neasy to confuse:\n\n  • agora-admin@gmail.com  — 00-seed-auth-admin, ALWAYS seeded (runs before the\n    gate), privileged only if added to OPE\n[…]\nSWORD compose defaults),\nwhich should keep pointing at the always-seeded account rather than one that\nonly exists behind the gate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(seed): document the two seeded admins; fix stale seed:graph refe…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T07:58:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ef3b4ce35ddaa77d164c50d7a5ac9ebe006a49ea",
          "body": "Declare demo-admin@agora-oss.org (DemoAdmin123!) in the seed manifest, granted\n`owner` on the seed project.\n\nTwo new manifest fields drive it:\n  • per-user `password` — overrides meta.defaultPassword\n  • `roles` array (owner|admin|steward)\n\nA new `roles` phase in 03-seed-engine.mjs applies them. It \n[…]\n clean; unit suite 540 passed.\n\nAlso carries a pre-existing untracked change: the `migrate` script alias in\napps/api/package.json.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(seed): seed a demo admin as project owner via manifest role grants",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T07:54:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cc9b6d31a1f4bc635166745f76f4dcde18b4c828",
          "body": "… + supersede search spec\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs: private-by-default posture — MANIFEST/MODELS/SECURITY/CHANGELOG…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T07:07:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b059ddd20e7d59b3f847fc2d98fe580aa55e386a",
          "body": "…the auth wall\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(db): revoke 0008 anon public-read policies — DB posture matches …",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T06:59:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c551f812bf8b7e3553fe572166509002975f93dd",
          "body": "…y tokens\n\nEvery existing integration test that exercised a project-scoped read\nanonymously now mints/passes a fixture user's token, per the wall mounted in\nTask 2. Tests that asserted anonymous access as the behavior under test were\ninverted (anonymous -> 401, authed -> the previous expectation), n\n[…]\nRAGE_PROVIDER=s3 in dev .env routing through an unreachable MinIO) and\nwere left untouched.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "test(api): sweep integration suite for the auth wall — reads now carr…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T06:50:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "68b320c11b69a9cc0bb5187f48f82142cd627cb4",
          "body": null,
          "is_bot": false,
          "headline": "#5 match docs",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T06:48:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bd046ed350c261fb132c4ac788a46ce8ef95952",
          "body": "…ALLOWLIST\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(api): mount the auth wall — private by default behind AUTH_WALL_…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T06:15:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8098f17d9675e30ca2370ebf2ed822e0b442cb9d",
          "body": "…gn-in allowlist\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(core): authWall middleware — private-by-default gate with pre-si…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T06:03:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1450b647012d794fe951af9b64b3cc2bf49463b8",
          "body": "Also tracks the 2026-07-16 search-auth spec it supersedes, so Task 5's\nsupersession lands as a one-line diff rather than a new file.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs(specs): auth wall — private-by-default design + implementation plan",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T06:00:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0721b68ecde88b74fa43db2f0514fd2b51cfd66d",
          "body": "Enforce the space `visibility` axis (public/unlisted/private, migration 0060,\npreviously persist-only) on discovery reads: filter listings/search/children,\n404 hidden private spaces on direct fetch, truncate breadcrumb ancestors, and\ngate sub-resource reads. Closes a hole where private spaces were f\n[…]\nstranger.\n\nOpus whole-branch review: READY TO MERGE. No migration/contract change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n# Conflicts:\n#\tCHANGELOG.md\n#\tdocs/MANIFEST.md",
          "is_bot": false,
          "headline": "merge: space-visibility discovery filtering (SDK v7.8.2 #3)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T05:41:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "723f7d32c5b7837c8274c0b9aea0502fa33cdd38",
          "body": "…space (M1)\n\nThe Thorough visibility gate 404'd /membership/me for a PENDING applicant on a\nprivate space, so \"apply -> can't check status\" was a dead end. Exempt the\ncaller's own row: a caller who already holds a membership row (pending/rejected/\nbanned) knows the space exists, so they may read the\n[…]\nsed];\nreleased sections are immutable history).\n\nIntegration 24/24 (2 new: pending reads own row; exemption unlocks nothing else).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(spaces): let a member read their OWN membership row on a private …",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T05:39:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "516dcca6f2788174b211132f6c1bff8f608c46d2",
          "body": null,
          "is_bot": false,
          "headline": "plans & specs",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-17T02:47:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "648cc2cf37173368c907fe3e2451acb0fd3e437e",
          "body": "Activate chat-message push notifications: fan out dispatchChatMessagePush to\nother active conversation members after the socket emit (sender excluded),\nhonoring per-conversation mute and the global chat-push opt-out. Row-less,\nPII-free, fire-and-forget (message still 201). No contract/model/migratio\n[…]\nange. Opus whole-branch review: READY, 0 blocking.\n\nGate: typecheck clean (5 pkgs), unit 525/525, integration affected-area 17/17.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge: chat-message push fan-out (SDK v7.8.2 #2)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-10T03:55:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3aaefb6680e65decb7b7e3720049e3b04fa4093a",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs(spaces): document the space-visibility discovery gate",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-10T03:51:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "643468578a2b9f9eb32960767863e8e43cae20be",
          "body": "…am/rules/membership)\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(spaces): gate space sub-resource reads by visibility (members/te…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T10:00:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b0f840bc2f49d8323ce81f18a2fded790a31715",
          "body": "…adcrumb ancestors\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(spaces): 404 hidden private spaces on direct fetch; truncate bre…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T09:55:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3871f875285ac212c7fb83c95137d87ab25d239e",
          "body": "…nd children\n\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(spaces): filter unlisted/private spaces from listings, search, a…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T09:50:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75d96f7d3a9ee7740deb79cf00b5a45590a3f4a3",
          "body": "…view follow-up)",
          "is_bot": false,
          "headline": "test(chat): assert cleanup status in chat-message-push beforeEach (re…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T09:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f503a9816e118e2f4609b0e41045a2c44a355ae",
          "body": "Signed-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(spaces): add space-visibility discovery authority + unit tests",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T09:02:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7aa7f85a5aa14933011a01415e09355ed806afc",
          "body": null,
          "is_bot": false,
          "headline": "docs: chat-message push fan-out (CHANGELOG + MANIFEST)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T08:55:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b8e2576b409c4cb3bc64c0ba3edbf0bfd183397",
          "body": "…ors mute + opt-out)\n\nExtract awaitable sendChatMessagePush (decision testable at the webpush\nboundary); dispatchChatMessagePush stays fire-and-forget. Wire the per-member\nfan-out after the socket emit in POST /conversations/:id/messages, excluding\nthe sender. Integration-tested: dispatch when clear, suppressed on\nforever-mute, future timed-mute, and global opt-out; route smoke 201.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(chat): fan out push to conversation members on message send (hon…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T08:51:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "156ad45bdfc8132a8afd2356dfe061b2087b2721",
          "body": null,
          "is_bot": false,
          "headline": "feat(push): register 'message' as a push-worthy type (New message)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T08:45:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "339c826002b1dadd5b056ab38fcb048d7371e739",
          "body": "… #2)\n\nThree bite-sized TDD tasks: register the \"message\" push title; extract an\nawaitable sendChatMessagePush + wire the per-member fan-out after the socket\nemit; docs. Gates = mute + global opt-out; row-less; PII-free; no\ncontract/model/migration change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(plan): chat-message push fan-out implementation plan (SDK v7.8.2…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T08:44:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7d89faf86240e372f320e05248d68d869a777c7a",
          "body": "Activate the unreachable chat-message push path: register the \"message\"\npush title and fan out dispatchChatMessagePush to other conversation\nmembers after the socket emit. Row-less (honors per-conversation mute),\ngates = mute + global opt-out only. No contract/model/migration change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(spec): chat-message push fan-out design (SDK v7.8.2 #2)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-09T08:38:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ffa3a3fa57b59827bfde06fc63d9ebb6ede01af",
          "body": "Emit a space-scoped spaceReputation on returned/embedded users when the SDK requests it\n(spaceReputationId uuid|none + spaceReputationDescendants), via a per-router spaceRepGate\nmiddleware + a centralized post-shape enrichSpaceReputation pass. Covers users, entities,\ncomments, chat, spaces (team/mem\n[…]\nn store). Additive/backward-compatible.\nVerified: typecheck clean (5 pkgs), unit 524/524, full integration 506 pass/7 skip/0 fail.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge: space-reputation enrichment (SDK v7.8.2 #6)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T07:10:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e6a1a53090858beee668532c2989399dc9fd6973",
          "body": "…intent)\n\nAdds logger.debug({ err }, …) in enrichSpaceReputation's space-read-gate catch so a\ntransient gate error is distinguishable from an expected members-only denial. Debug-level\nkeeps the common denial out of info/error noise. Behavior-preserving (still fails closed).\n\nPer final whole-branch review follow-up.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(space-rep): debug-log the fail-closed read-gate skip (log-with-…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T07:08:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6c8a16a8b1b1ad9cc4e47f112e80111008ecfde1",
          "body": null,
          "is_bot": false,
          "headline": "plans and specs",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T07:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b899ff5f475121399cbcbbb9f0337f151136e07",
          "body": "… and access gate",
          "is_bot": false,
          "headline": "docs(space-rep): document spaceReputation enrichment param, coverage,…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T06:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e7fdf68466bf8b6ced26a473d718fba3edcdb8f",
          "body": null,
          "is_bot": false,
          "headline": "feat(space-rep): enrich embedded users on follows + connections",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T06:38:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91935e279931806e4670064bc7c8db433e2684ac",
          "body": null,
          "is_bot": false,
          "headline": "feat(space-rep): enrich embedded users on spaces/search/reports",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T06:28:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80820b5300b4b6df2063511d5382c2fb1ee77a0c",
          "body": "…iews)",
          "is_bot": false,
          "headline": "feat(space-rep): enrich embedded users on chat (members/messages/prev…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T06:16:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f047be0c62f3083325fbc6ec98a273f92e2b229",
          "body": null,
          "is_bot": false,
          "headline": "feat(space-rep): enrich embedded users on entities + comments",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T06:09:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47e9e3158084ed45b3ed4abe2262ced2bc0fb49b",
          "body": "…n (private-space oracle)",
          "is_bot": false,
          "headline": "fix(space-rep): fail-closed space-read gate on space-scoped reputatio…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T06:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "716085ab2c624af05d43560cb150052f6abb3fd0",
          "body": "…nd-to-end",
          "is_bot": false,
          "headline": "feat(space-rep): spaceRepGate middleware + wire users (user-direct) e…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T05:43:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d82d33ce9ddb278e52fa6cabb39c435520420f86",
          "body": "…ollect/resolve/stamp)",
          "is_bot": false,
          "headline": "feat(space-rep): contract field + Variables + pure enrichment core (c…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T05:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3de2910528bc166714acaa16a693270187e3665a",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.19.0",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T03:11:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c6f71fcfff2e9777e72335b6d14c0867334c30f",
          "body": null,
          "is_bot": false,
          "headline": "merge: map unreachable tenant DB to a retryable 503 (api + secure-chat)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T03:10:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea15350104a31c725b1acb0c523ac8d4381b89d3",
          "body": "A per-tenant request routing to a well-formed but unreachable Postgres DSN\n(host down, connection refused, DNS failure, connect timeout, dropped socket)\nsurfaced as 500 common/internal — mislabelling a transient infra outage as an\napplication bug, paging the app team and telling clients not to retry\n[…]\nan app-level wire test per service asserting\nconnection→503 and FK-error→500.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "fix: map unreachable tenant DB to a retryable 503, not 500",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T03:00:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "af3134e8f5f0f6335043674de8d4609152b3385b",
          "body": "… visibility, follows/connections search, search includeChildSpaces (+ match/space-rep scaffolds)\n\nSecond merge after the space-scoped reputation engine. This branch's four migrations were renumbered 0058-0061 -> 0060-0063 (journal when 658-661, strictly above root's max 657) to clear the collision \n[…]\n.muted_forever + match_content(9-arg); full integration suite green (exit 0).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "merge: v7.8.2 SDK sync — notification prefs, conversation mute, space…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T01:20:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e9ab2488e80b1e663eeca217511c531ab84709f",
          "body": "…ith root space_reputation 0058/0059)\n\nRoot merged the space-scoped reputation engine (0058_space_reputation, 0059_space_reputation_trigger) first. This branch is the second merge, so its four migrations are renumbered to 0060-0063 with journal when 1781934611658-661 (strictly above root's max 657).\n[…]\nents + journal entries + CHANGELOG number refs; no SQL body or schema change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "chore(migrations): renumber 0058-0061 -> 0060-0063 (avoid collision w…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T01:11:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e84a3ed96ca0093e83a722529e950c45a1f833a",
          "body": "Cleanup pass on feat/sdk-v7.8.2-sync from the final review: escape\n%/_/\\ in the follows/users search query so it can't act as a SQL LIKE\nwildcard, dedup disabledTypes on PUT /preferences before persisting and\nechoing it, add missing boundary-case unit tests (mute exact-expiry,\nspace-reputation absen\n[…]\nfor space-reputation\nvalidation to match the handlers it's actually wired on.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "fix: harden user-search LIKE escaping, dedup push prefs, close test gaps",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T00:52:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "565b8780487f3c5e0c716362977d6b8b9439faef",
          "body": "…endant CTE rollup\n\nTrigger-maintained per-(user,space) reputation (the space-partitioned twin of profiles.reputation) plus loadSpaceReputations read batcher with recursive-CTE subtree rollup. Migrations 0058/0059. Forward-only; feed-level & message reactions contribute to no space. The storage/read\n[…]\n.2 space-reputation enrichment (wire contract owned by feat/sdk-v7.8.2-sync).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "merge: space-scoped reputation engine — space_reputation store + desc…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-08T00:48:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "349dd146e6850c296b24cd2daf9055f7f1744de5",
          "body": "… CTE with CYCLE guard\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "test(reputation): pin content_space_id message branch; harden subtree…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T14:00:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "231ee8f6e925e2f694bcc8190441e3d91897da07",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(reputation): descendant rollup via recursive CTE + changelog",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T13:48:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fee3d42cbbcf515560592e0473da7b2dbf391a05",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(reputation): loadSpaceReputations single-space read + map-fill",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T13:36:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9c4fbbc42b54dbf2d22647518da30fa43b17f260",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(reputation): maintain space_reputation from the reaction trigger",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:55:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9c5c757773889bfebbce518d19efe8bb4cdd6ab8",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(reputation): add space_reputation table + RLS",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:49:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1d87cbc9b3b4ff5a3379aade3e13aea21b4db04c",
          "body": "Documents the seven v7.8.2 server-side features against the shipped code:\nnotification preferences, conversation mute (with the not-yet-wired\nmessage-push suppression noted), space visibility (persist+emit only, no\ndiscovery filtering), follows/connections text search (post-pagination\nfilter caveat)\n[…]\n surfaces (match,\npush-notification preferences) per the propagation checker.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "docs: MANIFEST/MODELS/CHANGELOG for v7.8.2 SDK sync",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:47:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b4e8728b40ffa9094b560e39d54608e2402b5b07",
          "body": "…n user-direct)\n\nAdd validateSpaceReputationParams as a pure, unit-tested guard for the\nspaceReputationId/spaceReputationDescendants SDK params, and wire it onto\nevery user-direct (/users/*) handler so a spaceReputationId=context there\n400s (space-reputation/context-not-allowed) instead of silently \n[…]\nrollup) is a\nfuture spec — this cycle only ships the shared validation shape.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(users): space-reputation param validator scaffold (context 400 o…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:35:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "091f52dd976e3ae6c95e8d9695054ac00201bf77",
          "body": "Ships the v7.8.2 useMatchUsers request contract only; the facet/embedding\nengine is a separate future spec. requireAuth-gated, body validated by\nmatchUsersSchema (directed mode without a non-empty query -> 400), always\nresolves { results: [] } so the SDK hook settles cleanly.\n\nMounted in routes/inde\n[…]\n wires createApp() plumbing\nand mounts the whole /v7 tree via mountRoutes()).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(match): POST /match/users stub (validated, returns empty results)",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:28:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e6e9525af67593bb1c95da93733b97f894851037",
          "body": "match_content gains p_space_ids uuid[] (default null) so a resolved\n{self ∪ descendants} space set can scope semantic search, instead of\njust a single space. retrieveContent (routes/search.ts) resolves the\nsubtree via lib/space-tree.ts resolveSpaceSubtree when the caller\npasses includeChildSpaces al\n[…]\ne-set arg through.\nNull p_space_ids preserves today's behavior byte-for-byte.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(search): includeChildSpaces via match_content space-set arg",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:16:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ab858b72c2efdfeefc7acc9df5edf11852c3ea0e",
          "body": "Adds resolveSpaceSubtree(projectId, spaceId), a recursive CTE over\nspaces.parent_space_id returning the space id plus all live descendant\nids (self included). Scoped by project_id and deleted_at is null at\nboth the anchor and recursive steps; fully parameterized (::uuid\ncasts, no string interpolation). Consumed by the upcoming search\nincludeChildSpaces support (Task 11).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(spaces): recursive space-subtree resolver",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:06:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c28f9f75d801dbb2f2beaa93f1bb8506e68bfa40",
          "body": "…ession\n\nAdds POST /conversations/:id/mute (self-scoped mutedUntil/mutedForever\nupdate via muteDurationToState) and isConversationMutedForUser /\ndispatchChatMessagePush push-layer helpers that gate a chat \"message\"\npush on the recipient's per-conversation mute, after the existing\nglobal opt-out. No \n[…]\nMessagePush is\nready for a future task to wire into the message-send fan-out.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nSigned-off-by: Jenova Marie <jenova@recoverysky.org>",
          "is_bot": false,
          "headline": "feat(chat): POST conversations/:id/mute + per-conversation push suppr…",
          "author_name": "Jenova Marie",
          "author_login": "jenova-marie",
          "committed_at": "2026-07-07T12:00:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 26,
      "commits_last_year": 827,
      "latest_release_at": "2026-07-19T06:04:45Z",
      "latest_release_tag": "v0.22.0",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 1.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@agora-server/contract",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@agora-server/contract",
          "is_deprecated": false,
          "latest_version": "0.22.0",
          "repository_url": "https://github.com/agora-oss-org/agora-server",
          "versions_count": 19,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3465,
          "first_published_at": "2026-06-07T09:07:42.467000Z",
          "latest_published_at": "2026-07-19T06:04:56.746000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 4,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "apps/admin/tsconfig.json",
        "apps/api/tsconfig.json",
        "apps/secure-chat/tsconfig.json",
        "packages/contract/tsconfig.json",
        "packages/core/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 38991,
      "source_files_sampled": 542,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 45604
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 1,
        "malicious_count": 0,
        "assessed_package": "npm:@agora-server/contract@0.22.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@agora-server/contract",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@radix-ui/react-avatar",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.12"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.16"
        },
        {
          "name": "@radix-ui/react-dropdown-menu",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.17"
        },
        {
          "name": "@radix-ui/react-separator",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.9"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.5"
        },
        {
          "name": "@radix-ui/react-tabs",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.14"
        },
        {
          "name": "@radix-ui/react-toast",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.16"
        },
        {
          "name": "@radix-ui/react-tooltip",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.9"
        },
        {
          "name": "@tanstack/react-query",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.101.0"
        },
        {
          "name": "class-variance-authority",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "lucide-react",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.17.0"
        },
        {
          "name": "react",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        },
        {
          "name": "react-dom",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        },
        {
          "name": "react-router-dom",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.17.0"
        },
        {
          "name": "tailwind-merge",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.0"
        },
        {
          "name": "zod",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "@agora-server/contract",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@agora/core",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@aws-sdk/client-s3",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.901.0"
        },
        {
          "name": "@hono/node-server",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.19.14"
        },
        {
          "name": "@jenova-marie/wonder-logger",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.4"
        },
        {
          "name": "@node-rs/argon2",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.2"
        },
        {
          "name": "@opentelemetry/api",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.0"
        },
        {
          "name": "@socket.io/redis-adapter",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.3.0"
        },
        {
          "name": "@supabase/supabase-js",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.107.0"
        },
        {
          "name": "dotenv",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "drizzle-orm",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.45.2"
        },
        {
          "name": "hono",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.23"
        },
        {
          "name": "ioredis",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.11.1"
        },
        {
          "name": "jose",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.10.0"
        },
        {
          "name": "neo4j-driver",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "postgres",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.4.9"
        },
        {
          "name": "sharp",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.34.5"
        },
        {
          "name": "socket.io",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.8.3"
        },
        {
          "name": "web-push",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.7"
        },
        {
          "name": "zod",
          "manifest": "apps/api/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "@agora-server/contract",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@agora/core",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@hono/node-server",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.19.14"
        },
        {
          "name": "@jenova-marie/wonder-logger",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.0"
        },
        {
          "name": "dotenv",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "drizzle-orm",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.45.2"
        },
        {
          "name": "hono",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.23"
        },
        {
          "name": "ioredis",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.11.1"
        },
        {
          "name": "jose",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.10.0"
        },
        {
          "name": "postgres",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.4.9"
        },
        {
          "name": "socket.io",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.8.3"
        },
        {
          "name": "zod",
          "manifest": "apps/secure-chat/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "zod",
          "manifest": "packages/contract/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "@agora-server/contract",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@jenova-marie/wonder-logger",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.0"
        },
        {
          "name": "drizzle-orm",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.45.2"
        },
        {
          "name": "hono",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.23"
        },
        {
          "name": "ioredis",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.11.1"
        },
        {
          "name": "jose",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.10.0"
        },
        {
          "name": "postgres",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.4.9"
        },
        {
          "name": "zod",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.25.76"
        },
        {
          "name": "fastapi",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.110"
        },
        {
          "name": "uvicorn",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.29"
        },
        {
          "name": "pydantic",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.6"
        },
        {
          "name": "httpx",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.27"
        },
        {
          "name": "asyncpg",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.29"
        },
        {
          "name": "pyjwt",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.8"
        },
        {
          "name": "neo4j",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=5.19"
        },
        {
          "name": "opentelemetry-sdk",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.27.0"
        },
        {
          "name": "opentelemetry-exporter-otlp-proto-http",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.27.0"
        },
        {
          "name": "opentelemetry-exporter-prometheus",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.48b0"
        },
        {
          "name": "opentelemetry-instrumentation-fastapi",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.48b0"
        },
        {
          "name": "opentelemetry-instrumentation-asyncpg",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.48b0"
        },
        {
          "name": "opentelemetry-instrumentation-httpx",
          "manifest": "services/scorer/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.48b0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 2,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "jenova-marie",
          "commits": 827,
          "avatar_url": "https://avatars.githubusercontent.com/u/202562814?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "dco.yml",
        "docker-publish.yml",
        "npm-publish.yml",
        "release.yml",
        "wiki-sync.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "23 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9ceb3fe8edb50190e2ebfe988f07bfbe6aa3230a",
        "ran_at": "2026-07-25T03:29:13Z",
        "aggregate_score": 3.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T09:37:20Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-06-10T08:13:20Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/agora-oss-org/agora-server",
    "host": "github.com",
    "name": "agora-server",
    "owner": "agora-oss-org"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 46,
        "vitality": 76,
        "community": 42,
        "governance": 50,
        "engineering": 76
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 827,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "827 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 827
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v0.22.0",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 1.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 42,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 8,
            "inputs": {
              "forks": 0,
              "stars": 4,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "4 stars",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "@agora-server/contract"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3465
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,465 downloads/month across npm",
                "points": 47.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3465,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 50,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 2,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2/2 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "agora-oss-org",
              "public_repos": 5,
              "account_age_days": 30
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of agora-oss-org",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "agora-oss-org"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 5.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@agora-server/contract"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "19 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 76,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "backend",
                "comments",
                "community",
                "drizzle-orm",
                "moderation",
                "nodejs",
                "open-source",
                "pgvector",
                "postgres",
                "realtime",
                "replyke",
                "self-hosted",
                "semantic-search",
                "social-network",
                "socketio",
                "supabase",
                "typescript",
                "replyke-sdk",
                "replyke-server",
                "sublay"
              ],
              "has_wiki": true,
              "homepage": "https://demo.agora-oss.org",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://demo.agora-oss.org",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 32,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "23 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@agora-server/contract@0.22.0 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@agora-server/contract@0.22.0",
                  "assessed": 1
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 1,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 1,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 73,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.93,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 45604
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "93 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 93,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "apps/admin/tsconfig.json",
                "apps/api/tsconfig.json",
                "apps/secure-chat/tsconfig.json",
                "packages/contract/tsconfig.json",
                "packages/core/tsconfig.json"
              ],
              "agent_commit_share": 0.48,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "apps/admin/tsconfig.json, apps/api/tsconfig.json, apps/secure-chat/tsconfig.json, packages/contract/tsconfig.json, packages/core/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "apps/admin/tsconfig.json, apps/api/tsconfig.json, apps/secure-chat/tsconfig.json, packages/contract/tsconfig.json, packages/core/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "48 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 48,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 38991,
              "source_files_sampled": 542,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/542 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 542,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch pypi package 'agora-scorer' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T03:29:23.774832Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agora-oss-org/agora-server.svg",
  "full_name": "agora-oss-org/agora-server",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.