Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-27 17:09 UTC

brightman-ai / deepwork-browser

GoMIT★ 0 Sterne⑂ 0 Forksseit Mai 2026Auf GitHub ansehen ↗

brightman-ai/deepwork-browser erreicht einen Gesundheitsindex von 39 von 100 und liegt damit im Bereich Gefährdet. Am stärksten schneidet es bei Vitality (68/100) ab, am schwächsten bei Security (15/100). Zuletzt vor 5 Tagen aktualisiert.

39
gesamt / 100
Gefährdet

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

39
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

brightman-aiOrganisation
0 Follower6 öffentliche Reposseit Apr. 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/brightman-ai/deepwork-browserv0.9.0-9vor 8 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

68Mittel · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 5 Tagen
4.8/36Commit-Rhythmus — 7/52 Wochen mit Commits
14.3/18Commit-Volumen — 38 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year38
human_commit_share1
days_since_last_push5
active_weeks_last_year7
Wie die Bewertung erfolgt
16.2/27Liefert Releases aus — 9 Versions-Tags (keine GitHub-Releases)
36/36Release-Aktualität — letztes Release vor 8 Tagen
27/27Release-Rhythmus — ein Release etwa alle 7,9 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count9
latest_release_tagv0.9.0
releases_from_tagsja
days_since_latest_release8
mean_days_between_releases7,9
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

24Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

42Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
0/38.3PR-Annahme — keine entschiedenen Pull Requests oder keine Daten
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote, PR-Annahme. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
0/25Reichweite des Inhabers — 0 Follower von brightman-ai
6.7/25Kontohistorie — 6 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers0
owner_typeOrganization
is_verified
owner_loginbrightman-ai
public_repos6
account_age_days100

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 8 Tagen
20/20Versionshistorie — 9 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/brightman-ai/deepwork-browser
ecosystemsgo
any_deprecatednein
min_days_since_publish8

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

34Gefährdet · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.

Dokumentation

40Gefährdet
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
0/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmeja
has_docs_dirnein
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

15Kritisch · 16 % des Gesamtindex

Sicherheitslage

15Kritisch
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
0/10Dangerous-Workflow — keine Daten
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — keine Daten
0/5Pinned-Dependencies — keine Daten
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
0/7.5Vulnerabilities — 15 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate1,5
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

66Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 36 von 38 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,947
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — go.mod (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Go (statisch typisiert)
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 35 der letzten 38 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesgo.sum
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,921
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Pinned-Dependencies. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
53.5/55Handhabbare Dateigrößen — 5/184 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes149.855
source_files_sampled184
oversized_source_files5

Eckdaten

0GitHub-Sterne
-Mitwirkende
38Commits, letzte 12 Monate
5Tage seit letztem Push
9Releases
-Bus-Faktor
0offene Issues
GoPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Contributor list unavailable
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 1.5 / 10
1.5Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-27 17:09 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
k. A.Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
k. A.Packagingpackaging workflow not detected
k. A.Pinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
0Vulnerabilities15 existing vulnerabilities detected
Direkte Abhängigkeiten 6
RegistryPaketVersionsvorgabeManifest
Gogithub.com/brightman-ai/kitv0.1.0go.mod
Gogithub.com/chromedp/cdprotov0.0.0-20260321001828-e3e3800016bcgo.mod
Gogithub.com/chromedp/chromedpv0.15.1go.mod
Gogithub.com/mattn/go-sqlite3v1.14.37go.mod
Gogolang.org/x/cryptov0.48.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 986,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1697939,
        "HTML": 25381,
        "Shell": 8624,
        "Swift": 20090,
        "JavaScript": 26080,
        "Objective-C": 39023
      },
      "pushed_at": "2026-07-22T12:36:54Z",
      "created_at": "2026-05-17T08:04:55Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T12:38:20Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "brightman-ai",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/277260871?v=4",
      "created_at": "2026-04-18T12:47:04Z",
      "is_verified": null,
      "public_repos": 6,
      "account_age_days": 100
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-19T12:37:19Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-18T16:34:23Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-18T06:39:30Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-08T17:49:12Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-08T06:00:08Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-04T13:26:24Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-03T10:59:19Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-06-18T18:53:47Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-05-17T08:04:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "5ad958f866075dc7c4e6366e622d78e4f1085017",
          "body": "- open: 视口事实 fail-loud 建立(install 单点注册, 防 AddScript 跨连接无界堆积—评审实测 8 连接 8 份);\n  attach 每命令幂等重放 + SessionInfo.Keyboard 推回页面\n- act: keyboard show|hide 输出 + 焦点自动同步的 keyboard/keyboard_hint(弹起/收起双文案)\n- observe browser_chrome 机读块扩展: keyboard{visible,inset_css,top_y}, viewport_units\n  {svh/lvh/vh/dvh_residua\n[…]\n如实声明), zones 键盘态感知\n- persona|personas 子命令直达人格表(零提示 Witness 实测会先试这个拼法, 原 unknown+全量 help=误导)\n- help: keyboard op 两行 + browser_chrome_hint 补视口事实说明\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): keyboard 接线 + persona 子命令 + observe 视口事实机读块 (0.8.0 → 0.9.0)",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-19T12:37:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9aec4d6862d2320ba059627d7e1bd70f8a21a9ca",
          "body": "另一 session 真机实测抓获双向缺陷: vv 自适应健康页被误判遮挡(假阳) + 键盘 bug 类完全不可见(假阴)。\n根因: chrome 只画像素、不改变页面感知的视口。\n\n- 视口事实四通道对齐: visualViewport.height/innerHeight 走 shim(patch getter+派发真 resize,\n  __dwViewportFacts); 100svh/env(safe-area-inset-bottom) 走 CDP 原生 override\n  (setSmallViewportHeightDifferenceOverride 跨导航复位→open\n[…]\n态仅 vvH→457; opus 零提示 Witness 四夹具判定全对; 对抗评审 5 findings 全处置。\nspec: docs/product/browser-chrome/ (delta 20260719-192107-browser-chrome-vv-fidelity)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(browser): 视口事实对齐 + 软键盘态 — chrome 仿真从画像素升级为变视口 (REQ-BC-11/12)",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-19T12:36:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e8fc61efae70d4219884fb664295df9d09e68955",
          "body": "…e 接线 + 裸移动视口硬拦 (0.7.0 → 0.8.0)\n\n- --persona mobile = iPhone 15 Pro 保真全家桶(含 chrome 仿真 auto); --persona desktop = 平台默认桌面指纹保真姿态; 列表首位+help 金句配方\n- --browser-chrome auto|on|off 旗标(auto 默认: 移动预设带几何即开; on 无数据/叠显式 viewport fail-loud; safari 引擎拒 on)\n- 裸 --viewport 宽<500 无 persona = \"假手机\" error 硬拦(文案给 --pers\n[…]\nctions/coordinate_space/dpr) + --annotate 证据截图出口\n- act zoom 后 PageScale 镜像落 session 并跨调用 CDP 重放(不依赖 sim 开关); printPersonas fidelity/stealth 分组标注\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): AI-native 入口 — persona mobile/desktop 意图别名 + browser-chrom…",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-18T16:34:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "548b8799a168e6ab0ded2fbc30d0ed51f3207f1b",
          "body": "顶层 const __params 驻留页面全局词法环境, 第二次 evaluate 即 \"already been\ndeclared\" 全体失败(独立 Witness 复跑实测抓获的存量 bug)。\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(audit): __params 注入 IIFE 包裹零全局残留 — 同会话第二次 audit 不再全体 SyntaxError",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-18T16:34:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bd915c6235187b417dcdba45859364016af158f4",
          "body": "…ct/browser-chrome/)\n\n- devices.json 增 browserChrome 几何字段(iphone-14/15-pro, 载入期 Validate fail-fast) = 唯一 SSOT\n- 仿真会话视口开到大视口 lvh, 底部 [svh,lvh) 为遮挡带 — 100vh 布局 bug 与真机同构显形\n- observe 截图 Go 侧合成 Safari 底栏(页面外绘制/零 DOM 注入/逐像素恒定/随 theme-color 取色/annotate 红描边)\n- act 遮挡守卫: 投影 ≥svh fail-loud(带内 occluded/越界 bel\n[…]\nDeviceMetricsOverride 踩回)\n- audit browser-chrome-occlusion check(error/warn/protected 三级压假阳)\n- 单测: 几何自洽/auto-on-off 判定/合成不变性与确定性/取色/投影数学/zoom 解析\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(browser): Safari chrome 仿真 — 双视口显形 + 三嘴共享 SSOT (spec: docs/produ…",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-18T16:33:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "baad8b228de965f2bcfae5e589bd2954ccdc3d6f",
          "body": "…ll fail-loud/降噪 + browser-cli profile 清理 发布)\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(cli): bump version 0.6.0 → 0.7.0 (checkbox 修复 + observe 模态排序/fi…",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-18T06:39:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "886dbcaf1d8fe7271b321b227812cd88c72f31b9",
          "body": "⚠ **整文件提交 (用户 2026-07-17 授权)**: 本 commit 含**两批**改动 —— 下面 §1-4 是本轮做的,\n§5 是同工作树上另一 session 在飞的 WIP (cli_profile_cleanup 那批, 约 380 行)。二者在\ncmd/dw-browser/main.go 里混着, 无法干净拆分。全量 go build/vet/test ./... 均 rc=0。\n\n## 1. observe 看不见模态/抽屉里的元素 (本轮主因)\n\n**现象**: agent 拿着 observe 结果一路点空气 —— act 返回 success:true / p\n[…]\nor, 而 resolveCanonicalSelector 把 nth 当**匹配集内下标**解析 ⇒ 同名按钮在 @r5/@r9/@r20\n  会生成 [nth=5] 而报 \"out of range (matched 3)\"。本来就坏, 与本次改动无关。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(observe): 模态优先排序 + fill 语法 fail-loud + visible_errors 降噪 + 快速失败",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-17T10:41:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84225850db2ead03ba57d31309ef949f21dfa144",
          "body": "- executeToggleCheckbox 曾把语义 locator 解析出的节点 ref(eN/@rN)直接塞进\n  document.querySelector → isChecked 恒 false → uncheck 永不点击且报 success(no-op),\n  check 恒点击(已勾选时误反转)。重写:CSS 与 ref 两路径共用同源节点解析\n  (resolveBackendNodeID → ResolveNode → CallFunctionOn)读真实 checked/aria-checked,\n  仅状态不符时复用 executeClick(可信事件链不变);读取\n[…]\nacebar/\" \" 映射。\n- 回归:action_engine_checkbox_test.go(headless 5-phase:uncheck 修复/check/\n  防双跳幂等/div fail-loud/Space toggle,修前 RED)+ mapKeyName 单测。\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(action): checkbox toggle 对语义 locator 假阳 + press Space 键映射",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-11T09:50:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a0f97347e9581e6f9e7e0fe8ce6a3dac57233aa8",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(cli): bump version 0.5.0 → 0.6.0 (fillsecret 特性发布)",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-08T17:49:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7dcce84a484a944d22368eafdafb4cad55c07cb5",
          "body": "… inputs via CDP insertText\n\n`fillsecret <selector> '<value>'` fills a password/controlled input through the trusted\nCDP Input.insertText channel (real input events → penetrates Vue/React controlled inputs\nthat swallow programmatic value sets). Default fill/type still REFUSE password fields\n[IR-03];\n[…]\nue is never echoed to logs or the\naction result. +TestParseFillSecret; +help entry.\n\n(go-sqlite3 1.14.33→1.14.37 via go mod tidy.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(action): fillsecret op — opt-in safe fill for password/sensitive…",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-08T16:48:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f10fb41fee4d3c49455f862a367782b5387d6c41",
          "body": "docs/ 带斜杠只匹配目录,抓不到 docs 符号链接;改 docs 同时匹配符号链接与目录。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: 硬化 .gitignore 让 docs 符号链接真被忽略(防误提交私有 docs 进 public 仓)",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-08T06:50:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6acdbc13d92143d8b53dc970a2225927765017e6",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(cli): bump version 0.4.0 → 0.5.0 (Persona 特性发布)",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-08T06:00:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "96ab808d94cc7edc35572ddc19a922909f2bec1d",
          "body": "Persona = compose(Fingerprint, Shell, Network, Env) + Posture(stealth):\n身份轴唯一一等组合对象,subsume 旧 DevicePreset(删)+ FingerprintPreset(=Fingerprint facet)。\nheadless 忠实还原微信/企业微信 webview、移动端、暗色、断网,触发被测 app 自身适配逻辑\n(微信遮罩/响应式/touch/暗色),替代真机。\n\n- 身份 SSOT 收敛:删 DevicePreset + --device flag(破坏变更);stealth 降为 posture\n[…]\n-tags personacheck)\n\n活规格 SSOT: docs/product/browser-persona/spec.md (REQ-01..11 + INV-1..3)\nREQ-01/02 真微信遮罩 live 验交独立 Witness(未自证)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(browser)!: 可组合测试保真 Persona — 身份 SSOT 收敛 + facet 保真",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-08T05:50:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "773880769e991c5de3368dff455bda58d012901f",
          "body": "…策略开关\n\nBREAKING: 会话行为由业务场景声明,不再由技术开关拼。\n\n- --scenario 必选,所有建会话命令(open/once/act-oneshot/journey-oneshot/test/layout/session-start/safari)强制;--id 操作命令继承会话场景。场景→SessionPolicy+render+kind(scenario.go)。\n- 删裸开关 --remote-writes/--deterministic/--kind/--commit(传入显式报错,防误用);--allow-host 仅 webvisit 有效。\n- policy.go/evidence.go/record.go 用户面串不再引用已删 flag。\n- liveview 不受影响(走 muxhost/htr 独立入口)。经 codex 两轮对抗 review + 单测 + 真 Chrome 冒烟。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli)!: 场景做必选主入口 (app-test-explore/app-test-baseline/webvisit),删裸…",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-04T13:26:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "875b62998a02427ef4565c3a1ab203a8c4700a77",
          "body": "同步内建 version 常量到 v0.3.0 (历史 v0.1/v0.2 tag 未同步 const, 一并治理)。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(cli): bump version 0.1.0 → 0.3.0 (SessionPolicy 特性发布)",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-03T10:59:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2e50d439f431bea64fb8cb4e220062b0f4c93145",
          "body": "…s REJECT\n\ndw-browser 加 per-session、per-act 强制的安全/确定性策略 (browser/policy.go = SSOT):\n- 远程写门控: --remote-writes deny(默认)|confirm|allow + --allow-host;按顶层 origin 分类, 读 & localhost 写恒放行, 公网写 default-deny (safe-by-default, 零 flag 不破存量)。强制点 checkActPolicy(取 live URL) + safari executeAction, Act/ActWithSess\n[…]\n 降级)。\n- domain-neutral: 测试分类学留 harness DSL, 工具零产品测试相名。\n- 单测 + 真 Chrome 运行时冒烟通过; 经 codex 双路 review。completions/_dw-browser: zsh 补全。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(browser,cli): 域中立 SessionPolicy — 远程写门控 + LLM 确定性锁 + oracle-clas…",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-07-03T08:18:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5acbdb890e72bffbce8d0a6c53f56d1f580292a",
          "body": "executePress 此前把所有按键(含组合键)都丢给 chromedp.KeyEvent,\n而后者将 Selenium 风格的 PUA 修饰符 rune 编码成未知可打印字符 —— Chrome\n把它当文本插入、从不置 ctrlKey/metaKey,导致 \"press Control+b\" 实际向\n输入框写入一个字面 'b'。\n\n修复:新增 parseKeyCombo 识别含修饰符的按键串,组合键改走\ndispatchModifierCombo —— 派发带 Modifiers 位掩码(Alt=1/Ctrl=2/Meta=4/\nShift=8)的真实 CDP keyDown→keyUp\n[…]\nrl+b 回归、多修饰符、未知 token 不\n误判)、TestCodeForKey;更新 TestMapKeyNameIsCaseInsensitiveForCommonKeys\n反映组合键不再走 mapKeyName。browser 包构建 + 测试均绿。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(browser): 修饰键组合走 CDP keyDown/keyUp,Ctrl+B 不再插入字面字符",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-06-21T06:54:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "605228e9397c3c1dfe66227b1f2d156abcefa9a7",
          "body": "零上下文 AI 可读 + token 瘦的 CLI 重设计,两场景驱动:\n- A 探索(Claude agent): open→observe→act→close;observe 单感知动词,瘦默认 ~3K + 加法 flag(--out/--health/--tree),取代 view/snap/observe 三重叠。\n- B 基线(测试脚本/CI): journey + check 确定性 pass/fail,CLI 零 LLM。\n删 view/snap/screenshot/explore/get/plan/do/batch/state/--session。\n顶层 help 重写为单一连贯故事(95 行,无矛盾弃用)。\n引擎改动纯加法零删除 → liveview(Pool/Mux/AcquireTab)不受影响;引擎测试 + deepwork-pro liveview 路由运行时测试均绿。\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): dw-browser Agent-First 两场景 SSOT 收敛",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-06-18T18:53:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bbb0e302b7aa074d38a27ccd9cd14ea183e6e4ba",
          "body": null,
          "is_bot": false,
          "headline": "Constrain virtual display bridge to darwin",
          "author_name": "st",
          "author_login": null,
          "committed_at": "2026-05-31T14:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cac64828d1f1b5e174f59f810059a4c427683abf",
          "body": null,
          "is_bot": false,
          "headline": "feat(cli): baseline browser agentic testing flows",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-28T08:39:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fe079fa65ee0911253932a54053203da96ed705",
          "body": "…le path\n\nAddresses 3 verified findings from codex review of HEAD~3..HEAD:\n\n1. [HIGH] Ensure() concurrency race (virtual_display_darwin.go): display/\n   displayID were published before bounds were set (w==0), then vdm.mu was\n   released during the 1s registration + 500ms mirror-exit sleeps. A\n   con\n[…]\nlerance (intentional/documented), rescue @autoreleasepool\n(LOW slow-leak; full-body re-indent risk not worth it under this scope).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(virtual-display,cli): codex review MUST-FIX — Ensure race + profi…",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-27T05:33:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "165a7802ea8e971c92d85969b93359467fe4b5dc",
          "body": "… rescue\n\n- dw_vd_rescue_foreign_windows: replace CGDisplayBounds(virtualID) with\n  dw_vd_physical_union_from_current + DW_VD_QUARANTINE_GAP for correct\n  virtual display bounds (CGDisplayBounds always returns main screen rect\n  for CGVirtualDisplay — macOS bug)\n\n- dw_vd_inspect_windows_for_pid_boun\n[…]\nr.\n\nVerified: 16/16 engine-core tests pass; headed Chrome containment\ncheck passes in <100ms; rescue fires at 30s and moves 1 foreign window.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(virtual-display): correct bounds, containment tolerance, periodic…",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T18:10:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8d97070bf3422699975d98b557e84167bbf74193",
          "body": "P0 — view reading --format plain|list|table\n  Structured extraction via JS querySelector. list returns li items,\n  table returns matrix of table rows. Works in both session (view reading)\n  and zero-session (once --view reading) paths. Output: {items:[...]} or\n  {tables:[[[...],...],...]}. --wait <m\n[…]\nied to all\n  headless instances (removes navigator.webdriver). Stealth adds the UA\n  masking on top. headed/CGVirtualDisplay mode unaffected.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): P0-P3 improvements — format, profile, stealth, SPA retry",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T17:03:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a83d269ea3c00b32812ae462bacfa48ba5f2e756",
          "body": "Three-part fix for CGVirtualDisplay window containment:\n\n1. Fast path now calls refreshBoundsLocked() instead of displayBoundsLocked().\n   displayBoundsLocked() is query-only — it does NOT update vdm.x/y/w/h.\n   Stale (0,0) coords from a failed initial Ensure() would persist across all\n   subsequent\n[…]\nways had this race. The issue\nbecame visible when macOS became more consistently async about propagating\nquarantine-placement bounds changes.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(virtual-display): prevent headed Chrome leaking to main screen",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T16:48:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aaacc8f299329555a9d047e2de32a857ca5efa28",
          "body": "…to Chrome\n\nChrome does not inherit HTTP_PROXY/HTTPS_PROXY automatically. Without this fix\nall external-site sessions silently fail (navigation timeout) in proxy\nenvironments, while Python/curl succeed. Now Chrome picks up the proxy from\nthe same env vars that the rest of the system uses.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(launcher): auto-detect HTTP(S)_PROXY env and pass --proxy-server …",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T16:21:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "06a593c51fa7a19914b59e4e3a32ac884ac06961",
          "body": "refs are persisted to session state file for act \"@rN\" lookup; echoing the\nfull array to stdout was negating the token-efficiency goal. Now state output\nis url+title+compact_text+refs_count only (~1.5KB vs ~10KB snap). Verified:\n6.7x smaller than snap --compact, BrowserAct parity achieved.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): state cmd omits refs array from stdout — 85% token reduction",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T15:59:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b1b64c8da32e1c3ada8f95b142e4413f6d7d49c6",
          "body": "…ol+test operation\n\nPrime-offset sequence (25137+offset) gives 50 candidates. Prevents \"no available\nCDP port\" exhaustion when app Chrome pool and journey runner both need ports.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(pool): expand CDP port candidates from 10 to 50 for concurrent po…",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T10:48:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "381f7f4f32fccd31c6d88b18c2ef55ff1f52abc0",
          "body": "…rowserAct-inspired)\n\nAdds `dw-browser state --session <id>` command that outputs only the indexed\ninteractive elements for the current page, not the full page text dump.\n\nInspired by BrowserAct's `state` command design: agents get compact\n`[@r1 button 'Nav'] [@r2 input]` output and operate by ref d\n[…]\nput: {url, title, state: \"@r1...\", refs: [...], refs_count, skill_hint?}\nRefs are saved to session for subsequent `act \"click @r1\"` commands.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): dw-browser state — compact indexed interactive elements (B…",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T10:37:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d528b7b167ff3d20053c10e01987e1ec30546bdc",
          "body": "- autoLoadLLMEnv: auto-sources ~/.deepwork/testing-llm.env for OpenRouter API key\n- isNLGoal: detects free-form NL do: steps vs structural commands\n- cliActionExecutor/oneshotActionExecutor: route NL goals via Planner (skill-first, then LLM decomposition)\n- assert.go: remove early return from unparseable DSL so visual oracle handles NL assertions\n- assert.go: evalConsoleErrorsCount only counts level=error (not warnings)\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(testing): NL planner + vision oracle wiring for journey runner",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T10:29:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3f3b3c3000d12517653913228b6924c5512fd096",
          "body": "…on CGVirtualDisplay\n\nPhase-C only fixed the followProgrammaticNav path. target_created_auto_follow,\ntarget_destroyed_fallback, and manual_switch all still called activateBrowserTarget\nwhich triggers [NSWindow makeKeyAndOrderFront:] on macOS, causing Chrome on\nCGVirtualDisplay to escape to the user'\n[…]\nivateBrowserTargetNoFront. Wired in pool.go for both ModeHeaded paths\n(BrowserMuxHost and direct VirtualDisplay) and in browser_core_impl.go.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(browser): SetNoFrontMode — skip BringToFront for all activations …",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-26T10:28:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "694dbceb585d578792ffa80935f43e8291967adf",
          "body": "…prevent CGVirtualDisplay escape\n\nfollowProgrammaticNav path was calling activateBrowserTarget which\ntriggers page.BringToFront -> [NSWindow makeKeyAndOrderFront:] on macOS.\nThis caused Chrome running on CGVirtualDisplay to escape to the main Space\nwhenever the AI research browser navigated to a rea\n[…]\nes this instead.\nUser-gesture paths (pendingSwitch/opener/gesture) still use the full\nactivateBrowserTarget with Page.bringToFront as before.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(liveview): skip Page.bringToFront for programmatic nav follow to …",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-25T05:46:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4e3501708a55f39546557b7ebe0ecddf6adfb9d8",
          "body": "…+ journey runner)\n\n- transcript oracle: TranscriptBinding/State, transcript_tool_count/has/error_count/text_contains/format_v1/done_count, file_glob_count\n- journey runner: transcript_has wait condition (waitTranscriptCondition), BLOCKED semantics, mutations, viewport ResizeViewport, Chrome-leak re\n[…]\n\n- browser_core_impl: remove dead-code syntax error (Chinese curly-quote literal)\n- testdata: sample transcript fixture for oracle unit tests\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(testing): Phase-C deep CUJ-16 BDD test infra (transcript oracle …",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-25T04:56:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1dac53e6b55b05996577a72a8801cd55d45151cf",
          "body": "Make this the single superset browser engine — deepwork-pro now depends\non this module and deleted its duplicate internal/browser. Port the\napp-side RefreshTargets serialization fix (refreshMu + TryLock, prevents\nCDP GetTargets flooding) into target_tracker.\n\nAdd browser/skills: a reusable SKILL.md \n[…]\ndout domain field.\n\nHonor DDC-I-10: the skills layer is mechanical-only (zero LLM);\ndistillation/NL planning stay in deepwork-pro.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(browser): unify engine + shared skills library (CHG-012)",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-24T12:14:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b5257f3bab7f813d99a11d304c89bee8215f2c2c",
          "body": "Trailing-slash pattern only matches directories; evolve_history is now a\nsymlink, so drop the slash.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: fix evolve_history ignore pattern to match the symlink",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-24T09:23:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8c749786c9a699bd99cd9eab1914caa81f979640",
          "body": "evolve_history real content lives in deepwork-pro; this public repo only\nholds a gitignored symlink, same scheme as docs/.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: gitignore evolve_history (symlinked from private repo)",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-24T09:22:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ad5639d6e6ddf399694721d0b81645d65dd8978f",
          "body": "Adds the spec-driven BDD + multi-perception testing engine under\nbrowser/testing/ (observe / diff / check / journey / do / get / explore with\nstructural, behavior, telemetry, visual and layout oracles), a CDP\nconsole/network telemetry collector, and the dw-browser testing CLI; plus the\nsupporting an\n[…]\neferences scrubbed from code comments.\nThe evolve_history/ design notes are intentionally not included (kept in the\nprivate repo).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dw-browser): AI-native testing engine + browser-pkg updates",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-24T09:16:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0b389c8f8f1ccde8c0f3974f05ab54ba63a2ddb",
          "body": "Strip all internal design identifiers (BS-09, DDC-I-xx, BRR-xx, TH-xxxx,\nCAP-BS09, T5/T6/BP refs, IR-xx, TC-xx) from Go source comments across the\nentire browser package before public release.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "clean: remove private design refs from Go file comments",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-17T09:33:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "47fc13acf3c342cd6535e150d520322b76c55cb9",
          "body": "…w, snapshots, and CLI",
          "is_bot": false,
          "headline": "deepwork-browser: browser automation engine with Chrome pool, LiveVie…",
          "author_name": "Anthony",
          "author_login": null,
          "committed_at": "2026-05-17T08:04:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 9,
      "commits_last_year": 38,
      "latest_release_at": "2026-07-19T12:37:19Z",
      "latest_release_tag": "v0.9.0",
      "releases_from_tags": true,
      "days_since_last_push": 5,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 7.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/brightman-ai/deepwork-browser",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/brightman-ai/deepwork-browser",
          "is_deprecated": false,
          "latest_version": "v0.9.0",
          "repository_url": "https://github.com/brightman-ai/deepwork-browser",
          "versions_count": 9,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-19T12:37:19Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 149855,
      "source_files_sampled": 184,
      "oversized_source_files": 5,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/brightman-ai/kit",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.0"
        },
        {
          "name": "github.com/chromedp/cdproto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260321001828-e3e3800016bc"
        },
        {
          "name": "github.com/chromedp/chromedp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.15.1"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.37"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.48.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": null,
      "bot_contributors": 0,
      "top_contributors": [],
      "contributors_sampled": null,
      "top_contributor_share": null
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "15 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "5ad958f866075dc7c4e6366e622d78e4f1085017",
        "ran_at": "2026-07-27T17:09:13Z",
        "aggregate_score": 1.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/brightman-ai/deepwork-browser",
    "host": "github.com",
    "name": "deepwork-browser",
    "owner": "brightman-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 39,
      "inputs": {
        "security": 15,
        "vitality": 68,
        "community": 24,
        "governance": 42,
        "engineering": 34
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 68,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "commits_last_year": 38,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "38 commits in the last year",
                "points": 14.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 38
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 9,
              "latest_release_tag": "v0.9.0",
              "releases_from_tags": true,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 7.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "9 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~7.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 7.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 42,
        "weight": 0.24,
        "metrics": [
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 37,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "brightman-ai",
              "public_repos": 6,
              "account_age_days": 100
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of brightman-ai",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "brightman-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "6 public repos, account ~0 yr old",
                "points": 6.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 6
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/brightman-ai/deepwork-browser"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "9 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 34,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 15,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 15,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 1.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "15 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 66,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.947,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "36 of 38 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 36,
                      "sampled": 38
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 73,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.921,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "35 of the last 38 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 35,
                      "sampled": 38
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 149855,
              "source_files_sampled": 184,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/184 source files over 60KB",
                "points": 53.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 184,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Contributor list unavailable",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T17:09:17.203301Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/brightman-ai/deepwork-browser.svg",
  "full_name": "brightman-ai/deepwork-browser",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.