Öffentliches Register
Software-GesundheitsberichtSchema 0.30.0 · Metriken 2.3.1 · 2026-08-03 07:51 UTC

delimit-ai / delimit-mcp-server

The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.

Python · JavaScriptMIT★ 21 Sterne⑂ 5 Forksseit März 2026Auf GitHub ansehen ↗
ArtKommandozeilenwerkzeugBibliothekNetzwerkdienstwie das ermittelt wird

delimit-ai/delimit-mcp-server erreicht einen Gesundheitsindex von 78 von 100 und liegt damit im Bereich Gut. Am stärksten schneidet es bei Vitality (87/100) ab, am schwächsten bei AI Readiness (49/100). Zuletzt vor 6 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

78
gesamt / 100
Gut

Software-Gesundheitsindex

Metriken werden auf einer standardisierten Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr gewichtetes Mittel, kalibriert auf die Verteilung des öffentlichen Registers, sodass die Stufen Perzentilbedeutung tragen; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze Gefährdet von 34.

78
Außergewöhnlich93-100Die Spitzengruppe des Registers (≈ obere 5 %); erfüllt im Wesentlichen alle geprüften Kriterien
Exzellent80-92Durchgehend stark; geringfügige Lücken
Gut65-79Gesund; Lücken sind begrenzt und beherrschbar
Mittel50-64Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Schwach35-49Wesentliche Schwächen in mehreren Bereichen
Gefährdet20-34Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-19Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Der gewichtete Gesamtwert 67 wird auf der veröffentlichten Indexskala auf 78 kalibriert (Register-Kalibrierung 2026-08-02).

Eigentümerschaft

Delimit.aiOrganisation
2 Follower17 öffentliche Reposseit März 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

87Exzellent · 21 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 6 Tagen
14.5/36Commit-Rhythmus — 21/52 Wochen mit Commits
18/18Commit-Volumen — 456 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year456
human_commit_share1
days_since_last_push6
active_weeks_last_year21

Release-Disziplin

100Außergewöhnlich
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 45 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 10 Tagen
27/27Release-Rhythmus — ein Release etwa alle 3,9 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count45
latest_release_tagv4.16.4
releases_from_tagsnein
days_since_latest_release10
mean_days_between_releases3,9
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

57Mittel · 17 % des Gesamtindex
Wie die Bewertung erfolgt
21.1/60Stars — 21 Stars
5/25Forks — 5 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks5
stars21
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
readme_badges4
has_contributingja
has_issue_templatenein
has_code_of_conductja
readme_badge_servicesshields.io
has_pull_request_templateja
Wie die Bewertung erfolgt
47.5/80Downloads pro Monat — 3.625 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesdelimit-cli
dependents
ecosystemsnpm
total_downloads
monthly_downloads3.625
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

55Mittel · 23 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
42/42Issue-Lösungsquote — 100 % der Issues geschlossen
28.8/30PR-Annahme — 165/172 entschiedene PRs gemergt
0/13Newcomer PR acceptance — kein PR eines Erstbeitragenden in 30 Tagen entschieden
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs165
open_issues0
closed_issues3
prs_merged_7d1
prs_decided_7d1
prs_merged_30d41
prs_decided_30d42
issue_closed_ratio1
closed_unmerged_prs7
first_time_authors_30d0
first_time_prs_merged_30d0
first_time_prs_decided_30d0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): newcomer_pr_acceptance. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
3.4/25Reichweite des Inhabers — 2 Follower von delimit-ai
9.9/25Kontohistorie — 17 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers2
owner_typeOrganization
is_verified
owner_logindelimit-ai
public_repos17
account_age_days147

Paketpflege

100Außergewöhnlich
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 10 Tagen
20/20Versionshistorie — 237 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesdelimit-cli
ecosystemsnpm
any_deprecatednein
min_days_since_publish10

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

81Exzellent · 19 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 8 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

100Außergewöhnlich
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://delimit.ai
10/10Repository-Beschreibung
10/10Topics — 14 Topics
10/10Wiki
Verwendete Eingangsdaten
topicsapi-governance, breaking-changes, openapi, claude-code, codex, mcp, mcp-server, cursor, ai-governance, cross-model, deliberation, devtools, gemini-cli, model-context-protocol
has_wikija
homepagehttps://delimit.ai
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

57Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 14 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): signed_releases. Die verbleibenden Gewichte wurden renormalisiert.

Abhängigkeits-Advisories

100Außergewöhnlich
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages136
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:delimit-cli@4.16.4 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 136 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Trägt ein bewusst kleines Gewicht (4 %): Agenten-Tooling ist ein echtes Pflegesignal, doch ein Repository ohne jedes Signal kann weiterhin 100/100 erreichen.

49Schwach · 4 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 99 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,99
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 24 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfileja
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,24
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — Python ohne Typprüfungs-Konfiguration
52.2/55Handhabbare Dateigrößen — 11/218 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languagePython
largest_source_bytes709.008
source_files_sampled218
oversized_source_files11
Wie die Bewertung erfolgt
40/40API-Schema (OpenAPI/GraphQL/proto) — api/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_filesapi/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml

Eckdaten

21GitHub-Sterne
1Mitwirkende
456Commits, letzte 12 Monate
6Tage seit letztem Push
45Releases
1Bus-Faktor
0offene Issues
npm, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 5 ⇿
0Sterne
5Forks
6Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

2334455522026-032026-042026-04
Major 0Minor 2Patch 4
OpenSSF Scorecard 4.6 / 10
4.6Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-08-03 07:51 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities14 existing vulnerabilities detected
Direkte Abhängigkeiten 7
RegistryPaketVersionsvorgabeManifest
npmaxios^1.16.0package.json
npmchalk^4.1.2package.json
npmcommander^12.1.0package.json
npmexpress^4.18.0package.json
npminquirer^8.2.0package.json
npmjs-yaml^4.1.0package.json
npmminimatch^5.1.0package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 0

Die Installation von npm:delimit-cli@4.16.4 zieht 136 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "api-governance",
        "breaking-changes",
        "openapi",
        "claude-code",
        "codex",
        "mcp",
        "mcp-server",
        "cursor",
        "ai-governance",
        "cross-model",
        "deliberation",
        "devtools",
        "gemini-cli",
        "model-context-protocol"
      ],
      "is_fork": false,
      "size_kb": 4756,
      "has_wiki": true,
      "homepage": "https://delimit.ai",
      "languages": {
        "Shell": 75636,
        "Python": 2456913,
        "Dockerfile": 1292,
        "JavaScript": 1187074
      },
      "pushed_at": "2026-07-28T03:12:38Z",
      "created_at": "2026-03-09T03:53:35Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-28T03:12:45Z",
      "description": "The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://delimit.ai",
      "name": "Delimit.ai",
      "type": "Organization",
      "login": "delimit-ai",
      "company": null,
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/266560012?v=4",
      "created_at": "2026-03-08T19:47:12Z",
      "is_verified": null,
      "public_repos": 17,
      "account_age_days": 147
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v4.16.4",
          "kind": "patch",
          "published_at": "2026-07-24T02:51:54Z"
        },
        {
          "tag": "v4.16.3",
          "kind": "patch",
          "published_at": "2026-07-18T20:08:55Z"
        },
        {
          "tag": "v4.16.2",
          "kind": "patch",
          "published_at": "2026-07-17T22:45:43Z"
        },
        {
          "tag": "v4.16.1",
          "kind": "patch",
          "published_at": "2026-07-16T06:10:25Z"
        },
        {
          "tag": "v4.16.0",
          "kind": "minor",
          "published_at": "2026-07-14T21:56:44Z"
        },
        {
          "tag": "v4.14.0",
          "kind": "minor",
          "published_at": "2026-06-27T16:19:34Z"
        },
        {
          "tag": "v4.13.1",
          "kind": "patch",
          "published_at": "2026-06-21T01:54:15Z"
        },
        {
          "tag": "v4.13.0",
          "kind": "minor",
          "published_at": "2026-06-21T01:13:02Z"
        },
        {
          "tag": "v4.12.1",
          "kind": "patch",
          "published_at": "2026-06-20T01:16:26Z"
        },
        {
          "tag": "v4.12.0",
          "kind": "minor",
          "published_at": "2026-06-19T03:39:58Z"
        },
        {
          "tag": "v4.11.1",
          "kind": "patch",
          "published_at": "2026-06-17T13:57:12Z"
        },
        {
          "tag": "v4.11.0",
          "kind": "minor",
          "published_at": "2026-06-17T13:17:45Z"
        },
        {
          "tag": "v4.10.0",
          "kind": "minor",
          "published_at": "2026-06-16T22:46:24Z"
        },
        {
          "tag": "v4.9.0",
          "kind": "minor",
          "published_at": "2026-06-15T17:37:50Z"
        },
        {
          "tag": "v4.8.0",
          "kind": "minor",
          "published_at": "2026-06-10T18:26:58Z"
        },
        {
          "tag": "v4.7.10",
          "kind": "patch",
          "published_at": "2026-06-09T19:55:20Z"
        },
        {
          "tag": "v4.7.9",
          "kind": "patch",
          "published_at": "2026-06-09T17:40:39Z"
        },
        {
          "tag": "v4.7.8",
          "kind": "patch",
          "published_at": "2026-06-09T14:51:44Z"
        },
        {
          "tag": "v4.7.7",
          "kind": "patch",
          "published_at": "2026-06-09T04:59:58Z"
        },
        {
          "tag": "v4.7.6",
          "kind": "patch",
          "published_at": "2026-06-09T03:51:22Z"
        },
        {
          "tag": "v4.7.3",
          "kind": "patch",
          "published_at": "2026-06-04T17:08:54Z"
        },
        {
          "tag": "v4.7.2",
          "kind": "patch",
          "published_at": "2026-06-04T11:47:57Z"
        },
        {
          "tag": "v4.7.1",
          "kind": "patch",
          "published_at": "2026-06-04T03:49:38Z"
        },
        {
          "tag": "v4.7.0",
          "kind": "minor",
          "published_at": "2026-06-04T02:15:22Z"
        },
        {
          "tag": "v4.5.13",
          "kind": "patch",
          "published_at": "2026-05-08T18:21:26Z"
        },
        {
          "tag": "v4.5.12",
          "kind": "patch",
          "published_at": "2026-05-08T14:52:37Z"
        },
        {
          "tag": "v4.5.10",
          "kind": "patch",
          "published_at": "2026-05-08T14:19:57Z"
        },
        {
          "tag": "v4.5.9",
          "kind": "patch",
          "published_at": "2026-05-08T02:45:43Z"
        },
        {
          "tag": "v4.5.8",
          "kind": "patch",
          "published_at": "2026-05-08T02:19:19Z"
        },
        {
          "tag": "v4.5.7",
          "kind": "patch",
          "published_at": "2026-05-08T00:35:29Z"
        },
        {
          "tag": "v4.5.6",
          "kind": "patch",
          "published_at": "2026-05-07T21:35:53Z"
        },
        {
          "tag": "v4.5.5",
          "kind": "patch",
          "published_at": "2026-05-07T03:57:17Z"
        },
        {
          "tag": "v4.5.4",
          "kind": "patch",
          "published_at": "2026-05-07T03:47:46Z"
        },
        {
          "tag": "v4.5.3",
          "kind": "patch",
          "published_at": "2026-05-07T03:40:29Z"
        },
        {
          "tag": "v4.3.4",
          "kind": "patch",
          "published_at": "2026-04-23T23:59:07Z"
        },
        {
          "tag": "v4.3.3",
          "kind": "patch",
          "published_at": "2026-04-23T23:30:55Z"
        },
        {
          "tag": "v4.3.1",
          "kind": "patch",
          "published_at": "2026-04-23T17:38:35Z"
        },
        {
          "tag": "v4.3.0",
          "kind": "minor",
          "published_at": "2026-04-23T13:33:28Z"
        },
        {
          "tag": "v4.2.0",
          "kind": "minor",
          "published_at": "2026-04-22T03:02:14Z"
        },
        {
          "tag": "v4.1.38",
          "kind": "patch",
          "published_at": "2026-04-04T21:03:40Z"
        },
        {
          "tag": "v3.10.3",
          "kind": "patch",
          "published_at": "2026-03-21T21:40:22Z"
        },
        {
          "tag": "v3.9.2",
          "kind": "patch",
          "published_at": "2026-03-21T14:29:18Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2026-03-21T04:01:01Z"
        },
        {
          "tag": "v3.6.11",
          "kind": "patch",
          "published_at": "2026-03-21T00:06:35Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-03-18T14:57:59Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ec7ee651640dcd6bb7adc4d4351a45d3c643738a",
          "body": "…(#186)\n\nfix(LED-4078): classify gateway/ai/thinktank_pipeline.py as internal.\n\nDeliberation-as-review (single-contributor org carve-out): operational scope, author infracore, org repo, green CI (13/13 incl. Bundle fail-closed guards). UNANIMOUS APPROVE: /root/.delimit/deliberations/2026-07-27-pr186\n[…]\ne (shipping controlled by package.json files allowlist, which already omits the module). npm publish remains a separate founder-gated hard stop.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(LED-4078): classify gateway/ai/thinktank_pipeline.py as internal …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-28T03:12:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31f50d796a8e8f2b499aacd17c0069a9f39089d7",
          "body": "…allthrough (LED-1964) (#185)\n\nDeliberation-as-review (delimit-ai org, infracore author, operational scope, green CI 14/14): UNANIMOUS APPROVE, quorum 3 panelists / 3 vendors (Anthropic+OpenAI+xAI). Implements the two nits the #183 review flagged (LED-1964). Transcript: /tmp/claude-0/-root/58afc023-0a21-4d52-8df3-76422ba1c3c8/scratchpad/led1964-review.json.",
          "is_bot": false,
          "headline": "fix(chat): time-box migration spawn + reviveSoulForLaunch candidate f…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-24T03:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "739c9cbb5a1e0b921dd13fb201b985f5fc5dbaf8",
          "body": "Release 4.16.4. Founder-approved (classification of 25 LED-1946 mailbox files as INTERNAL + publish, 2026-07-24) — founder approval is the human review. CI dry-run against the branch passed (Pre-publish Validation + npm publish --dry-run). Proprietary prune verified (license_core.py excluded, hard-assert clean).",
          "is_bot": false,
          "headline": "release: v4.16.4 (#184)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-24T02:48:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "befddb0d5aff9009528fd9efc16d26b60da5538a",
          "body": "… (#183)\n\nDeliberation-as-review (delimit-ai org, infracore author, operational scope, green CI 14/14): UNANIMOUS APPROVE, quorum verified 3 panelists / 3 vendors (Anthropic+OpenAI+Google). Two non-blocking nits logged as LED-1964 (migration spawnSync timeout; reviveSoulForLaunch candidate-loop early return) per the merge condition. Transcript: /tmp/claude-0/-root/58afc023-0a21-4d52-8df3-76422ba1c3c8/scratchpad/led1962-chat-review.json. npm publish NOT included — separate founder gate.",
          "is_bot": false,
          "headline": "fix(chat): reliable cross-agent continuity in delimit chat (LED-1962)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-24T01:43:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de4cd930be12b86ec414d0717ed1345807ca5f38",
          "body": "…D-1962) (#182)\n\nDeliberation-as-review (delimit-ai org, infracore author, operational scope, green CI): UNANIMOUS APPROVE after a REJECT→fix→APPROVE cycle. Round 1 (claude+codex) REJECTED a cross-project soul-bleed risk (global-most-recent default-on); fixed in b937cb4 (current-project default + se\n[…]\nle). Transcripts: /tmp/claude-0/-root/58afc023-0a21-4d52-8df3-76422ba1c3c8/scratchpad/led1962-review.json (reject) + led1962-review-v2.json (approve). npm publish NOT included — separate founder gate.",
          "is_bot": false,
          "headline": "feat(setup): auto-revive last soul on session start across agents (LE…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-23T21:49:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "849819b4108c2d0d6229433996bd9a9570a14a6d",
          "body": "…ization guard) (#181)\n\nDeliberation-as-review (LED-1872 carve-out, all 9 conditions verified): SECOND-PASS UNANIMOUS AGREE after first-pass DISAGREE remediation (.sh fail-open gap closed, seeded-violation proof, audited self-annotations). Operational panel claude+codex+grok, quorum met (LED-1908). \n[…]\niberation.md (AGREE) in session 2026-07-20 scratchpad. CI all green incl. the gate passing on its own PR. Admin-merge substitutes REVIEW_REQUIRED per carve-out; gate NOT made required (founder-gated).",
          "is_bot": false,
          "headline": "LED-3799: fail-closed identity-strings content gate (PR-time deanonym…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-20T23:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8edea53852b50bf233b6fa2100528fe6a8ddfb11",
          "body": "…180)\n\nBundle sync for 4.16.3 anti-drift fix. Founder-approved release completion. Both bundle guards green; heartbeat.py (public, #306) synced; license_core.py untracked.",
          "is_bot": false,
          "headline": "chore(bundle): sync gateway bundle for 4.16.3 (heartbeat.py drift) (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T20:05:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8fce005e53641d5c7267302d9e4d2f40b29a724",
          "body": "Release delimit-cli 4.16.3 — founder-approved publish (explicit 'go'). Ships SessionEnd auto-capture hook fix (#178) + author-audit workflow (#177) + bundle-classification (#176). All deploy gates green: test smoke 331/331, security clean, bundle classification + parity green, changelog updated. Zero gateway source-content changes.",
          "is_bot": false,
          "headline": "release: v4.16.3 (#179)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T19:58:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "680c59fcd13d076eda3baeffdf43d898173b5f3d",
          "body": "…session-end handoff (#178)\n\nfix(hooks): install a SessionEnd hook so session handoff auto-captures on real exit (all users).\n\nThe Stop hook fires at end-of-TURN, not on real exit (/exit, window close), so nothing captured a handoff on exit and users had to manually prompt delimit_soul_capture. Inst\n[…]\nlib_sessionend_hook_178.md. All CI green (Test Node 18/20/22, identity-guard, Bundle guards, CodeQL); 7 new tests + setup-no-clobber green. Ships to users only on the next npm publish (founder-gated).",
          "is_bot": false,
          "headline": "fix(hooks): install SessionEnd capture hook in nested shape for auto …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T19:25:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41b3eda0a8ae4e14678c4c8310752f1c69a03ff9",
          "body": "Deliberation-as-Review (all 9 conditions met): UNANIMOUS MERGE, claude+codex+grok = 3 respondents/3 vendors (quorum met). Transcript: scratchpad/delib_opsec_preventive_prs.md. Opsec preventive control LED-3830. Additive CI-only, no runtime/secret change. — always-on scheduled author-email audit, un-bypassable by --admin, fail-closed on empty email.",
          "is_bot": false,
          "headline": "ci(opsec): add always-on scheduled author-audit (LED-3830) (#177)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T13:47:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14bcbd30986393a807df9f8a8586e76a3956be4c",
          "body": "…176)\n\nLED-1938 — classify internal outreach modules for the npm bundle.\n\nDeliberation-as-Review (single-human org; all 9 conditions met):\n- Scope: operational/maintenance (bundle data-file classification; no code/tool-surface change).\n- CI: all green — Bundle fail-closed guards (classification + pa\n[…]\nlic tool; server.py already imported the (already-excluded) outreach_loop_daemon/outreach_substantive, so the public surface was already internal-only.\n\nLedger: LED-3829 (LED-1919 go-live) / LED-1938.",
          "is_bot": false,
          "headline": "fix(bundle): classify outreach_submit + wiring INTERNAL (LED-1938) (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-18T11:03:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ce2d1e427e1ef03087e2416389f7a964d74c605",
          "body": "Classify firewall files internal-exclude (unblocks 4.16.2 publish). Green CI incl. bundle fail-closed guards.",
          "is_bot": false,
          "headline": "fix(bundle): classify firewall files as INTERNAL-EXCLUDE (#175)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T22:41:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca4af141596fef6c2d887a67bb71a298d010f223",
          "body": "Release 4.16.2 (runtime slug fix synced from gateway #301 + onboarding #172 + codex --model fix #173). Green CI incl. bundle fail-closed guards + identity-guard. Tag v4.16.2 triggers publish.yml OIDC publish.",
          "is_bot": false,
          "headline": "release: v4.16.2 (#174)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T22:28:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "644c3a61cb522d7598d10c242fe04a58a3e2ed66",
          "body": "…ure (#173)\n\nMerged on founder authority (npm publish prep, 2026-07-17). Fixes 'delimit chat --model codex' TTY probe false-negative (classify 'stdin is not a terminal' as reachable→proceed, not probe_error). noreply-authored, green CI. Ships in 4.16.2.",
          "is_bot": false,
          "headline": "fix(chat): treat codex TTY probe error as reachable, not a probe fail…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T22:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "325c01aa1d67ac02a85d1a204a5755d24af1455a",
          "body": "…mplate (#172)\n\nMerged on founder authority ('merge B when ready', 2026-07-17) + audit D1. Repoints the dead delimit-api-governance Marketplace slug (404) → delimit-merge-gate-for-ai-written-code in lib/delimit-template.js — the CLAUDE.md onboarding template 'delimit setup' writes into every user repo. noreply-authored, green CI. Companion to delimit-action #42 + gateway #301.",
          "is_bot": false,
          "headline": "fix: repoint dead Marketplace slug in shipped CLAUDE.md onboarding te…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T21:40:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e932924b118c83dd34148b82490c892ae516ab9a",
          "body": "Merged on founder authority ('yes to all', 2026-07-17) + audit deliberation. D1: repoint 3 README Marketplace links off the dead delimit-api-governance slug. Docs-only, green CI.",
          "is_bot": false,
          "headline": "fix(readme): repoint dead Marketplace links to live listing slug (#171)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-17T21:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f106126f2476cbefd2a9cccc50b90d92c20f4db",
          "body": "…t (unblocks 4.16.1) (#170)\n\nMerge basis: founder 4.16.1 release authorization (operational panel below quorum, LED-1915 fail-closed hold). CI infra fix unblocking the authorized publish. CI green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): exclude generated checksums.sha256 from the anti-drift asser…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T06:07:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7df53f6987db5b0fc1614cd0ac7a044ee668d444",
          "body": "Founder-authorized 4.16.1 release chain ('publish 4.16.1 with the phoenix fixes'). All guards green on the release content; leak-prune + marker fixes verified in-commit.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: v4.16.1 (#169)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T01:16:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bde083dd7ca0a11f48bef324db4a4b763b5bd8bd",
          "body": "…r catch #4) (#168)\n\nMerge basis: founder release authorization (4.16.1 chain; operational panel below quorum per LED-1915 fail-closed hold). One-line INTERNAL classification; sync-verifier catch #4; CI green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(bundle): classify ai/schemas/__init__.py INTERNAL (sync-verifie…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T01:08:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5a9bcd137a80db0d3ece960e1c37401b922f7667",
          "body": "…n INTERNAL, changelog, bundle resync (#167)\n\nMerge basis: FOUNDER RELEASE AUTHORIZATION ('publish 4.16.1 with the phoenix fixes', 2026-07-15) — release-prep within the authorized chain, same basis as the 4.16.0 release merges. Review record: two deliberation passes, both 2-respondent (antigravity: \n[…]\nnimous APPROVE on the merits. Transcripts: /root/.claude/jobs/027af2c2/tmp/delib_pr167.md + _v2.md. First live enforcement of canon condition 9.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): prep 4.16.1 — classify audit_stream PUBLIC / custodia…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-16T01:05:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82f9bf9bbf3ce056b231f0b4d84e66fc32b82400",
          "body": "…(LED-3432, LED-3433) (#166)\n\nDeliberation-as-review UNANIMOUS APPROVE (LED-1906, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr166.md). LED-3432 (TTL failover recovery) + LED-3433 (deterministic quota probe, codex probed). Ships to installed users at NEXT publish; delimit doctor mandatory pre-publish.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(chat): TTL-expiring Phoenix failover + deterministic quota probe …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-15T17:11:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "00bc029d9850bec61127e131ef7b2a9b7234477a",
          "body": "…(#165)\n\nDeliberation-as-review basis: mechanical release-blocker fix under the founder's standing publish authorization; third live guard catch (anti-drift assert on marker ordering). CI green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): gateway/VERSION marker must reflect the bumped version …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T21:53:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8453264545bb4f87adcf77984eef60a3e7b7d7de",
          "body": "Founder-authorized release ('publish 4.16.0' + publish.yml re-confirm after the LED-1900 fix). Release commit leak-free (prune+assert active); all guards green on the release content itself.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: v4.16.0 (#164)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T19:47:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b7934d25a4c7ac61f90a23fa856cb303e661a0d5",
          "body": "…epo (LED-1900) (#163)\n\nDeliberation-as-review UNANIMOUS APPROVE (LED-1901, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr163.md). LED-1900 incident fix: release.sh prunes internal-exclude paths + fail-closed hard-assert before commit. Follow-up ledgered: exclude-list canary test. Founder re-confirmed publish via publish.yml.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): never commit proprietary gateway source to the public r…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T19:07:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "aad6bc3956661daa3a9d616bd7f209179a18abf1",
          "body": "Deliberation-as-review UNANIMOUS APPROVE (LED-1899, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr162.md). Spot-check recorded per panel condition: removed-vs-4.14.2 file count verified against the actual packed artifact (140 gateway files removed), both CI guards present. Pack-derived changelog closes the LED-1896 phantom class.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: CHANGELOG 4.16.0 entry (pack-derived, real merged PRs only) (#162)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T17:37:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5a1449b8da032f67076bf88cdd508a347a7dea8f",
          "body": "Deliberation-as-review UNANIMOUS APPROVE (LED-1894, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr161.md). Truth-audit corrections: banned-phrase removal (vocabulary canon enforcement), CHANGELOG phantom-features correction (public-truth), gateway/VERSION marker (parity 137). Merge only — npm publish remains separately gated on the full deploy chain + founder go.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): truth-audit factual corrections (LED-1889) (#161)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T14:53:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1a4ec68386756431b88e635e44bceb9a3fc28277",
          "body": "…#160)\n\nDeliberation-as-review UNANIMOUS APPROVE (LED-1893, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr160.md). SECOND LIVE GUARD CATCH: the anti-drift assert blocked the Gate-5 dry-run on a stale committed bundle — the exact defect that silently shipped in the v4.14.2/v4.15.0 tags. One allo\n[…]\n resynced (memory_bridge.py, LED-1885-approved); transient proprietary license_core.py removed PRE-COMMIT and provably absent (pack==allowlist).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(bundle): resync gateway bundle (memory projection budget fix) (…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T04:26:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4429e840eaa605b5be6fb97dad5048dcdc07331f",
          "body": "Deliberation-as-review UNANIMOUS APPROVE (LED-1892, transcript /root/.claude/jobs/027af2c2/tmp/delib_pr159.md). FIRST LIVE CATCH of the fail-closed classification guard: brand_notes.py (LED-1880 internal brand engine) blocked at the Gate-5 publish dry-run instead of silently shipping — the exact failure class LED-1879 was built to end.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(bundle): classify brand_notes.py INTERNAL (guard catch #1) (#159)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T04:18:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "53d0eff8a86e42479d56f0e39061aa12e19e0e11",
          "body": "…9) (#158)\n\nFounder-directed sequence (\"build the fix, then panel review before publish\") + strategic-panel conditional GO (LED-1888) with all 4 evidence gates closed (CI green incl bundle-guards; extracted-tarball scans clean; clean-env internal-tool no-op invocation; credential scan of removed fil\n[…]\narball; no credentials found in them.\n\nsecurity(bundle): fail-CLOSED allowlist is now the boundary — unclassified gateway files block the build.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security(bundle): invert npm bundle to fail-CLOSED allowlist (LED-187…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-14T03:45:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fcf1e9d324d3b31a2f96c8ebfbb31ba805ed4a2a",
          "body": "…157)\n\nDeliberation-as-review: unanimous (3 models, 3 rounds)\nDeliberation ID: deliberation_20260713_185242_cb11df09\nTranscript: /root/.delimit/deliberations/deliberation_20260713_185355.json\nTranscript SHA-256: 39440e7f66a13d75f656902aae922fe97ef342b8905bc8c157a69a636ff01010\nSource-of-truth merge: delimit-ai/delimit-gateway#290 (41d1f8e)\nVerification: 10/10 GitHub checks; npm 323/323; bundled Python regression 9/9; security/parity/smoke green.\nNo npm publish or @v1 deploy included.",
          "is_bot": false,
          "headline": "fix(handoff): mirror cross-namespace receipt resolution (LED-2451) (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-13T22:54:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c50ebff74fab4058fdea87228f26d341a5fd0e23",
          "body": "… (#156)\n\nDeliberation-as-review (2026-05-11 carve-out): org repo, infracore-authored, operational scope (additive CLI flag), green CI, fresh unanimous operational-panel deliberation over the diff.\n\nVerdict: UNANIMOUS AGREEMENT (round 2) — Codex APPROVE.\nTranscript: /root/.claude/jobs/027af2c2/tmp/d\n[…]\n\nNever-break-installs: adds one `--model <id>` option to `delimit chat`; removes/renames nothing; default behavior byte-identical.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(chat): add `delimit chat --model <id>` per-launch model selector…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-13T19:54:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "35ae9392a9418e2aa2f07beb7dde8c533987d2fd",
          "body": "…(#155)\n\nFable doc-33: delimit-chat launch pre-brief (N approvals/agents/P0s, best-effort 1.5s timeout, degrades silent) + 'phoenix' alias (session was taken; avoids CLI crash) + honest help. chat behavior unchanged; never-break-installs held. 323 tests pass. Founder-approved 2026-07-12 (phoenix alias).",
          "is_bot": false,
          "headline": "feat(chat): launch pre-brief + honest launcher naming (Fable doc-33) …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-12T21:39:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f800d801ba1cf2443e0b85ab25ab10e80de67df3",
          "body": "…json version (#152)\n\nGlama coherence: DELIMIT_TOOLSET=core Docker pin (Glama crawler surface only) + server.json version-sync (LED-3717 drift 4.7.3→4.15.0) + release.sh guard. Reviewed: NON-BREAKING for installs — verified ai/server.py resolves unset/unknown DELIMIT_TOOLSET to 'full' (gating wrapper only installed when !=full), so npm/CLI installs are byte-identical; core applies to the Docker image only. All CI green. Founder-authorized 'review and merge' 2026-07-12.",
          "is_bot": false,
          "headline": "fix(glama): pin Docker crawler surface to core toolset + sync server.…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-12T17:01:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d38ad707ec0f0f4f5fcb6bf6f3accc8d3d49371",
          "body": "…ities) (#154)\n\nFounder-approved merge 2026-07-10 (in-session, explicit 'all yes'). Additive, green CI. CI identity-guard",
          "is_bot": false,
          "headline": "ci: add fail-closed identity-guard (block non-anonymized commit ident…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-10T04:52:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "264efaa30edf420b760473bd98240bc08da22263",
          "body": "…leak prevention) (#153)\n\nProprietary-leak prevention + remediation. Founder-approved (remove-from-HEAD, accept-history) 2026-07-09. (1) sync-gateway.sh exclude list fixed 5/27→27/27, DERIVED from package.json (SSOT) so it can't drift; (2) parity guard (check-bundle-parity.sh) wired into prepublishO\n[…]\n scrub deliberately NOT done (public-repo force-push is disruptive + cannot un-publish already-cloneable code). Node 18/20/22 green. Does NOT affect the published npm package (already excluded these).",
          "is_bot": false,
          "headline": "fix(bundle): sync-gateway exclude parity + parity guard (proprietary-…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-09T22:49:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8b3d9759cd828e401c570e3e3eb44eadb6d0a71",
          "body": "…gest echo + subagent flight-recorder) (#151)\n\nSTR-2202 hook half — 'tools fire tools' SessionStart digest+heartbeat echo + subagent flight-recorder. Founder-directed merge after orchestrator diff review 2026-07-07.\n\nREVIEW (clean): hook code is additive, reversible (removeClaudeHooks strips both), \n[…]\non-promise value from #150 (verified), MERGEABLE = no conflict.\n\nTakes effect for installed users only after a gated npm publish (production deploy); this merge only stages it. No out-of-band publish.",
          "is_bot": false,
          "headline": "feat(hooks): STR-2202 \"tools fire tools\" — HOOK half (SessionStart di…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-08T01:36:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7b7e9241716f0bf5a5345a2fe2465bccaff7896",
          "body": "Founder-directed merge 2026-07-07 (explicit in-session): 'merge PR #150 into the release train.' Public copy founder-ratified (LED-3700, STR-2195). Rebased onto 4.15.0. Rides next regular release publish-gate chain; NOT published out-of-band.",
          "is_bot": false,
          "headline": "docs(npm): on-promise package description (LED-3700, STR-2195) (#150)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-07T20:03:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "874743107511855d0957d2e23415d49f55f8f350",
          "body": null,
          "is_bot": false,
          "headline": "v4.15.0",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-05T05:35:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a7fc60283b9e5cac8e2882a58c55f9fa7609cb4",
          "body": null,
          "is_bot": false,
          "headline": "docs: Update changelog for v4.15.0",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-05T05:35:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cbb9ee551f09a7e3d67e4099d03654c45a3fc44",
          "body": null,
          "is_bot": false,
          "headline": "fix: Revert to NPM token auth for publishing (LED-3262)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-05T00:08:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b62bfee00769d3b58647e276e2ab4ac8450283e",
          "body": null,
          "is_bot": false,
          "headline": "feat: Radar reply lane v2 instrumentation (LED-3222)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:18:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1bd7160ddfcd106072ba24a1be6a1b0a87f8a05",
          "body": "… (LED-3274)",
          "is_bot": false,
          "headline": "feat: Implement delimit_product_lookup for e-commerce spec extraction…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:12:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb0b58cefe8421a6fc5f24418679790d64f4e3a3",
          "body": null,
          "is_bot": false,
          "headline": "feat: Integrate link path checking into delimit_repo_diagnose (LED-3272)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:11:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e95b72cd31e14d7fa0ffd53f8a10100e08c3515",
          "body": null,
          "is_bot": false,
          "headline": "feat: Add delimit_json_validate tool (LED-3271)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T21:11:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ac4f237cb8b79ce50edac14a32454b5aeb5e5ff",
          "body": null,
          "is_bot": false,
          "headline": "docs(strategy): Workstream A deliverables + roadmap (LED-3686..3696)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T19:19:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a15fb6758a87c374aa2a4c00195a453b6e70ba7",
          "body": "… (#149)\n\nMerged via deliberation-as-review carve-out (2026-05-11). UNANIMOUS operational deliberation. Post-publish bookkeeping for live delimit-cli@4.14.2: version→main (closes LED-3684 divergence), CHANGELOG 4.14.2, remove dead test_state_validator.py (tests a class the gateway no longer defines)\n[…]\nved out-of-tree (delimit-private/wip-preserve-2026-07-04/) for a separate finish-and-wire follow-up. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr149-postpublish.md.",
          "is_bot": false,
          "headline": "chore(release): record 4.14.2 on main + stale-test cleanup (LED-3684)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T17:21:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ff77ab52564ca00942b352c570171242cd4b7c5",
          "body": "Merged via deliberation-as-review carve-out (2026-05-11). UNANIMOUS operational deliberation. Fixes clean-tree guard false-positive on the publish-time version bump (allowlist package.json + package-lock.json; stray code still blocks). 6/6 green, 302/302 tests. Unblocks delimit-cli 4.14.2. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr148-guardfix.md. STR-2169.",
          "is_bot": false,
          "headline": "fix(publish): clean-tree guard allows publish-time version bump (#148)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T17:06:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74f720f258b306db9e37fc13f94a4ac51364185d",
          "body": "…es + main clean-tree guard) (#147)\n\nMerged via deliberation-as-review carve-out (2026-05-11). UNANIMOUS operational deliberation. Reconciles the npm 4.14.x release line into main (chat-repl transient-429 fix + clean-tree guard + StateValidator superset; version 4.14.1). Prevents a customer chat regression + version downgrade on the 4.14.2 publish. All CI green. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr147-reconcile.md. STR-2169 / LED-3684.",
          "is_bot": false,
          "headline": "fix: reconcile npm 4.14.x release line (union of published 4.14.1 fix…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T16:56:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1dd56f465ca5f784e385fbf79cdc9246556960dd",
          "body": "Merged via deliberation-as-review carve-out (2026-05-11). Fresh UNANIMOUS operational deliberation over the diff substitutes for the 2nd human reviewer. Conditions: org-owned, infracore-authored, operational (npm publish gate — additive, no customer runtime impact), green CI 9/9, CLI operational panel. Transcript: /home/delimit/delimit-private/deliberations/2026-07-04-review-npm-pr146.md. STR-2169 D2; supersedes closed #145.",
          "is_bot": false,
          "headline": "chore(publish): block npm publish from a dirty tree (STR-2169 D2) (#146)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-07-04T15:44:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b07703e2517018dc41d5dec0f32af82b2a0094db",
          "body": "fix: prevent zombie MCP processes",
          "is_bot": false,
          "headline": "Merge pull request #143 from delimit-ai/fix/issue-142",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-26T05:31:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "356df0632269214076374463c2c99a2c2b4a97e0",
          "body": null,
          "is_bot": false,
          "headline": "fix(mcp): prevent zombie processes on client disconnect (Issue #142)",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-26T05:30:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc41e452da90345c1c7e27368da73fe412ad91fa",
          "body": "- Created StateValidator to check state changes.\n- Added it to ResilientToolCaller to abort retries when state hasn't changed.\n- Added pytest to CI workflow.\n- Created test_state_validator.py covering file_system and command categories.",
          "is_bot": false,
          "headline": "Implement StateValidator logic and test harness (LED-3250)",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-26T04:31:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4847017080af3e6a2ff5af4db14fe5cfca1cff7",
          "body": "'Delimit OS' (and product-as-operating-system framing) is banned EVERYWHERE\nper the vocabulary governance — it's the retired layer-collapse failure mode.\nTwo shipped, customer-facing surfaces still carried it:\n  - bin/delimit-os.sh: header 'the AI developer operating system' + three\n    '[Delimit OS\n[…]\nNote: the marketing-copy-lint does not scan bin/ lib/, which is why these\nslipped through — extending its coverage is a follow-up.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(canon): remove banned 'Delimit OS' framing from shipped CLI strings",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-21T13:34:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eb8d0d6a7d7604df1bb6f27c2f87d69c505993ac",
          "body": "The v4.20 remember/recall suites overrode HOME but not DELIMIT_HOME. The\nmemory path resolves as process.env.DELIMIT_HOME || os.homedir()/.delimit,\nso where DELIMIT_HOME is set (founder box: /root/.delimit) it won —\n'remember' wrote to the REAL store, the tmp memory dir was never created,\nand the te\n[…]\nforced --no-verify);\nit also polluted ~/.delimit/memory. Pin DELIMIT_HOME to the suite's tmp\n.delimit dir. Full npm test: 302/302.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: pin DELIMIT_HOME in remember/recall tests (hermeticity)",
          "author_name": "infracore",
          "author_login": null,
          "committed_at": "2026-06-21T12:30:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9fc0a0d7db3c6e76d93ecc8f3e5bdbe0e262d4f0",
          "body": "4.13.0 shipped the ephemeral v0.2 producer TEST key (fb50eaaa) as\nseal_pubkey.ed25519 (PR #240 mis-commit), so real producer-issued\nattestations failed to verify against the bundled verifier. 4.13.1\nre-syncs the gateway with the authoritative seal-primary 13f6149a +\nits matching constitution signature. No other change from 4.13.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 4.13.1 — correct the bundled Seal verification key (13f6149a)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-21T01:48:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ff65e4d921ceeae6f3c8a5355ef59be9d6bab44",
          "body": "Re-syncs the gateway bundle (stale since 2026-06-09) and ships ~2 weeks\nof accumulated work as a proper minor release. Founder-ratified scope.\n\nHEADLINE (customer-facing): Free/Pro tier realignment (LED-1454/1738/1740/\n1741). 12 zero-marginal-cost tools move to FREE; 16 real-cost tools become\nPro be\n[…]\nr.py (issuance side; not imported by any shipped tool). Kept\nsocial_archetypes.py (the shipped vendor_news_draft tool imports it).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 4.13.0 — Free/Pro tier realignment + Seal v0.2 attestation",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-21T00:32:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8056722ebc7b4bed9ef15e0a70bfc96d8a3d9a66",
          "body": "…141)\n\nFounder-authorized 4.12.1 release (antigravity shim fix + README). Gates: security clean, 245 tests pass, doctor 12 pass, tdqs grade A. Irreversible npm publish gated separately on founder go.",
          "is_bot": false,
          "headline": "release: 4.12.1 — gemini shim → Antigravity (agy) + README refresh (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-20T01:07:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa8b070e8265c13830e4aa07f125925a7fc0c7fe",
          "body": "…(#140)\n\nDeliberation-as-review (2026-05-11 carve-out): a fresh unanimous delimit_deliberate verdict substitutes for the absent human reviewer. Conditions met: org-owned (delimit-ai), infracore-authored, docs scope, green CI, fresh per-diff deliberation, unanimous. Transcript: /home/delimit/delimit-private/deliberations/2026-06-19-docs-freshness-prs-140-28.md",
          "is_bot": false,
          "headline": "docs: document the zero-config `delimit check` command in the README …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-19T22:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dbaa6172beec582561de3a46f05a6ebdf46175f",
          "body": "Deploy-gate security audit (pre-publish) flagged 2 dependency advisories:\n- form-data (transitive): CRLF injection — HIGH\n- js-yaml (direct ^4.1.0): merge-key quadratic DoS — moderate\nnpm audit fix resolves both (0 vulns). js-yaml -> 4.1.1; verified the gate still\nparses YAML and catches breaking ch\n[…]\nnistic breaking-change + secret detection, content-pinned --record.\n\nCo-authored-by: infracore <infracore@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): fix HIGH/moderate dep vulns + bump to 4.12.0 (#139)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-19T03:30:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ad31aaf8fec3e59caec23293323923ee2adcd8aa",
          "body": "…ay move) (#138)\n\n* feat(check): zero-config PR safety gate — no init required\n\n`delimit check` previously errored out without .delimit/policies.yml. It now\nruns with deterministic defaults out-of-the-box on any repo (the zero-config\n30-day-gate wedge). Backward-compatible: when a policy file exists\n[…]\nBy: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: infracore <infracore@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(check): zero-config PR safety gate — no init + secret scan (30-d…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-19T03:21:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "55ac4155ca254ce7a38d9f2e6371b7b17fea4410",
          "body": "…#137)\n\nCo-authored-by: infracore <infracore@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: cross-link all 12 worked-example reports in README (LED-3462) (…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T17:38:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f881f72d0d40ddefb0bbf1b647d7ff03f92e42b5",
          "body": "…D-1454 enforcement) (#136)\n\nFounder-approved 'flip customers' 2026-06-17. Release bump; the v4.11.1 tag triggers the publish. v3.10.0 .so live + Vercel-verified.",
          "is_bot": false,
          "headline": "release: v4.11.1 — proModuleVersion 3.9.0->3.10.0 (binary-customer LE…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T13:51:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1131d39c923568c5de3e281cb0d091b07e3c63",
          "body": "…n-Path README, security_audit dedup, twitter freshness gate (#135)\n\nFounder-directed 'deliberate, build, and ship' + explicit 'Publish 4.11.0' go (2026-06-17). Release bump only; the v4.11.0 tag (separate, next) triggers the publish. Deploy gate: security_audit clean, 51 scoped tests green.",
          "is_bot": false,
          "headline": "release: v4.11.0 — repo_diagnose/test_coverage free (LED-1454), Golde…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T13:12:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24f1742f211df92a46cab7c62791e2f1df3efb4d",
          "body": "…gh (#134)\n\nFounder-ratified (Ship to README) + explicitly directed 'deliberate and merge' 2026-06-17. Unanimous delimit_deliberate verdict (Claude + Codex AGREE, round 2, no blocker). Transcript: /home/delimit/delimit-private/deliberations/2026-06-17-pr235-pr134-merge-review.md. Docs-only, canon-clean, both false claims re-verified at source. npm publish held separately (founder-gated).",
          "is_bot": false,
          "headline": "docs(readme): add Golden-Path \"first 10 minutes\" merge-gate walkthrou…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-17T04:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f295851e35ef8a28edd606919803c05af76783b",
          "body": "…ce), scan_bridge precision, Glama/TDQS/secrets, grace-aware gate (LED-1724/1738/1740/1741) (#133)\n\nMerged on EXPLICIT FOUNDER GO ('go with the push using delimit'). Release vehicle for the founder-ratified pricing publish. Deploy-gate chain: delimit_security_audit CLEAN (ev-1781649113), dry-run ver\n[…]\ned 'cannot republish 4.9.0' guard), CI green (Node 18/20/22 + CodeQL + API Check). Tag v4.10.0 next → publish.yml ships gateway main. 90-day grace = no existing user hard-cut. LED-1724/1738/1740/1741.",
          "is_bot": false,
          "headline": "release: v4.10.0 — Pro tier rebalance (12 free / 12 Pro w/ 90-day gra…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-16T22:43:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c2c2f63a17ea395c32d785174b32cc78c7b09dd",
          "body": "…D-3149) (#132)\n\nReconciles main to the already-published delimit-cli@4.9.0 (live on npm; tag v4.9.0).\n\nMerged under the deliberation-as-review carve-out (2026-05-11): org-owned repo, infracore-authored, operational/release scope, no required status checks failing (Node 18/20/22 pass), fresh UNANIMO\n[…]\n.8.0→4.9.0 (proModuleVersion 3.9.0 unchanged) + CHANGELOG. Already published + verified end-to-end (published verifier validated a real production v0.2 receipt). Founder-authorized publish 2026-06-15.",
          "is_bot": false,
          "headline": "release: v4.9.0 — hardened v0.2 attestation verification (LED-3127/LE…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-15T17:44:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5708b8a309ee3461790b945b074aeefa5fc143d9",
          "body": "…on 3.9.0 (clean ungated Pro engine) (#131)\n\nrelease: v4.8.0 — delimit handoff command (#129) + proModuleVersion 3.9.0 (#130, clean ungated Pro engine). Merged under explicit founder authority following delimit publish protocol; 9/9 CI green; gates: security_audit clean, doctor 9/10, publish.yml dry-run Pre-publish Validation success + clean tarball.",
          "is_bot": false,
          "headline": "release: v4.8.0 — delimit handoff command (LED-1710) + proModuleVersi…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-10T18:24:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06e39786a80abfeea4636c2a50f91b981984f1f4",
          "body": "… published to delimit.ai/releases/v3.9.0) (#130)\n\nchore: bump proModuleVersion 3.8.2 -> 3.9.0 (clean ungated Pro engine live at delimit.ai/releases/v3.9.0). Merged under explicit founder authority; 9/9 checks green. Points delimit setup at the v3.9.0 engine; reaches installs via the next npm CLI publish.",
          "is_bot": false,
          "headline": "chore: bump proModuleVersion 3.8.2 -> 3.9.0 (clean ungated Pro engine…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-10T18:13:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba7637c85021cd9057944cea92526ce86cd8f994",
          "body": "…hoenix (LED-1710 Phase 2) (#129)\n\nLED-1710 Phase 2: wire handoff preflight into both live handoff paths (sending=chat-repl GIT_* scrub + preflight; receiving=SessionStart post-flight) + `delimit handoff [check|fix]` actionable repair + de-hardcode-sync the committed preflight bundle (removes 8 infr\n[…]\ne.md\nFollow-ups tracked LED-1717: npm-CI identity-strings gate + 3 remaining public-repo infracore literals + a `handoff fix` identity-refusal test. No npm publish (publish.yml fires on v* tags only).",
          "is_bot": false,
          "headline": "feat(chat): wire handoff preflight + GIT_* env-scrub into live Auto-P…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T22:09:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15ca2f1d71eeab222c1e7717ae2de3389bf5cf6c",
          "body": "…k (#128)\n\nAutonomous-afternoon batch (LED-1716), founder-approved. Bundle rebuilt from fixed gateway main by sync-gateway at publish.",
          "is_bot": false,
          "headline": "release: v4.7.10 — handoff_preflight + test hygiene + parser tail-see…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:48:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56167b2a97fc4afa0ae833fa893a690c9acf1c76",
          "body": "…cal) (#127)\n\nAutonomous-afternoon LED-1716 item; founder-approved merge+release. Held-PR review-substitute satisfied (transcript + tests in PR body).",
          "is_bot": false,
          "headline": "LED-1710: sync handoff_preflight validator to npm bundle (byte-identi…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:21:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ff580b73fa6805ec43ac1fa5ea34bbebf97424d",
          "body": "…ator (#126)\n\nAutonomous-afternoon LED-1716 item; founder-approved merge+release. Held-PR review-substitute satisfied (transcript + tests in PR body).",
          "is_bot": false,
          "headline": "LED-1714: sync seek-tail transcript read into npm bundle + hook gener…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:21:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20f7162df50c4baa46f9a44ddd2dd93be820bd18",
          "body": "…entinel (#125)\n\nAutonomous-afternoon LED-1716 item; founder-approved merge+release. Held-PR review-substitute satisfied (transcript + tests in PR body).",
          "is_bot": false,
          "headline": "LED-1716: make npm test git subprocesses hermetic + add .git/config s…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T19:21:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ded14ce0b7e6b29e4eff6891a7f178458a943a8",
          "body": "…(#124)\n\nControl plane Phase 0+1: unified queue + interactive CLI + approve/reject via existing inbox ack. Founder-approved ship. Publish via gated tag.",
          "is_bot": false,
          "headline": "v4.7.9 — control plane: delimit control + delimit_control (LED-1709) …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T17:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aa22fbd10ff0b62230a1fe79b1f484a10ee2ed0",
          "body": "Fix hardcoded /home/delimit/delimit-gateway dev-path defaults (reaper/dispatch/loop/continuity/inbox/content-grounding) → portable _paths resolver. Zero behavior change where dev path was correct. Founder-approved ship. Publish via gated tag.",
          "is_bot": false,
          "headline": "v4.7.8 — portable gateway paths (LED-1715) (#123)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T14:35:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1726c537e4eb62996fdcc43b6621cf298abbe42a",
          "body": "delimit chat: fix false 'out of quota' probe (timeout/143 misclassification), fix Auto-Phoenix context-loss (hardcoded dev sys.path → bundled/installed resolution), DELIMIT CHAT dynamic banner. Founder-approved ship. Publish via gated tag.",
          "is_bot": false,
          "headline": "v4.7.7 — delimit chat resilience (probe + Auto-Phoenix + banner) (#122)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T04:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72cb6a929029b395ad90089a5f8bdafbe99c76f7",
          "body": "Docs-only changelog curation preceding the v4.7.6 publish. Founder-approved publish sequence.",
          "is_bot": false,
          "headline": "docs(changelog): 4.7.6 + retroactive 4.7.5 (#121)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T03:41:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7682e466a79b11ce5cc1e2db136c2de2dd0c0171",
          "body": "… (#120)\n\nCompletes the binding follow-up to #119: parse_transcript_tail empty-on-thinking-tail fixed (prefer text, fallback [thinking], widen scan). 24 tests; floor handoffs now carry content. Additive.\n\nDeliberation-as-review unanimous (LED-1714, 7 conditions met). Transcript: /home/delimit/delimit-private/deliberations/2026-06-09-led1713-parser-fix-review.md\nVersion held 4.7.6 (unpublished); publish gated.",
          "is_bot": false,
          "headline": "LED-1713: transcript-tail parser thinking-fallback (folds into 4.7.6)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T03:05:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2d77a2825fc6f363079a0f2d9af4ba081833b35",
          "body": "Customer-facing half of the session-lifecycle loop (gateway side: #217/#218, 5,552 tests). Additive — no tool/CLI removed, no signature changed; degrades safely to the prior no-handoff behavior.\n\nDeliberation-as-review (CLAUDE.md 2026-05-11, 7 conditions met) — re-run with the actual crash-recovery \n[…]\n6-06-09-pr119-led1705-476-review-r2.md\nBINDING FOLLOW-UP (panel condition): parse_transcript_tail completion — ships next.\nPublish HELD: no v4.7.6 tag; npm publish gated behind founder + deploy chain.",
          "is_bot": false,
          "headline": "LED-1705: deterministic session capture + crash recovery (v4.7.6) (#119)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T02:40:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46ed41a3919dd6d2320d1a695d0719b1e60d6792",
          "body": "Byte-identical reconciliation of main to the verified-published delimit-cli@4.7.5 (0 source mismatches vs npm tarball). Operational scope; zero live-customer regression (code already shipped).\n\nDeliberation-as-review (CLAUDE.md 2026-05-11, 7 conditions met): org-owned + infracore-authored + operatio\n[…]\non (LED-1712).\nTranscript: /home/delimit/delimit-private/deliberations/2026-06-09-pr118-reconcile-main-to-475.md\nRetroactive v4.7.5 tag intentionally NOT pushed (avoids publish.yml republish-failure).",
          "is_bot": false,
          "headline": "Reconcile main to published v4.7.5 (orphaned local-only release) (#118)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-09T02:05:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c29394a9bc56bc134ccd82bd7d9eaf34c5d7af4",
          "body": "…e correction (#117)\n\nPhase 3 of the founder-ratified LED-1695 public-surface plan (unanimous strategic deliberation 2026-06-04, transcript .../2026-06-04-public-surface-presentation-plan.md; founder: 'launch all phases now'). Docs+metadata only, CI green, gates clean.",
          "is_bot": false,
          "headline": "release: v4.7.3 — docs/metadata: min-privilege README on npm + 28-typ…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T17:05:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8de02ed269face0e8ba4d12013e136f4c80ee3ec",
          "body": "Item #4 of the founder-ratified 2026-06-04 strategic plan (the plan's strategic deliberation explicitly ranked this item; transcript /home/delimit/delimit-private/deliberations/2026-06-04-post-task-strategic-plan.md). Docs-only README change, CI green. README updates on npm at the next publish; GitHub renders immediately.",
          "is_bot": false,
          "headline": "docs: minimum-privilege adoption path (LED-2305) (#116)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T16:03:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19d1329f79afe8340cae13ec4b2d8c978bf10347",
          "body": "P0 hygiene gate from the ratified 2026-06-04 strategic plan (strategic deliberation, panel-unanimous: 'a P0 security vulnerability isn't a strategic choice to be ranked; it is a mandatory, non-negotiable gate' — transcript .../2026-06-04-post-task-strategic-plan.md; founder ratified the plan). Lockfile-only, express 4.x line, npm audit 0 vulnerabilities after, tests green. Rides the next release; no tag pushed.",
          "is_bot": false,
          "headline": "fix(deps): bump express/qs — resolve transitive qs DoS (LED-1680) (#115)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T12:46:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a564bb2bffb0ffcd75e883fe17424584d816e3b",
          "body": "…(#114)\n\nShips gateway recorder fix (record_call persists to ~/.delimit/tool_usage.jsonl) + tool activation (toolcard usage/dormancy report; additive next-step chains). Gateway code via CI sync-gateway from delimit-gateway main (d905bd4 + 40963df).\n\nAuthorization: founder-directed ship. CI green (No\n[…]\ntry data; 103 insertions/7 deletions). Additive, customer-protection safe. Activation plan LED-1693. Separate live item (not a blocker): LED-1680 transitive qs/express dep DoS (pre-existing in 4.6.2).",
          "is_bot": false,
          "headline": "release: v4.7.2 — tool-usage telemetry fix + dormant-tool activation …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T11:45:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f44162574aa199ec93dfb52a06d95fab55a99588",
          "body": "…ublishing (#113)\n\nv4.7.1 OIDC publish ENEEDAUTH = publish step ran npm 10.x (separate -g upgrade didn't carry over). Node 24 bundles npm >= 11.5.1 -> OIDC-capable npm in the publish step. registry-url stays removed; validate stays Node 20.\n\nCarve-out (7): org-owned; infracore; operational (workflow\n[…]\nodeQL + Delimit API Check); deliberation UNANIMOUS (/home/delimit/delimit-private/deliberations/2026-06-03-oidc-node24-pr113.md, LED-1690); audit=this body. Tags-only trigger -> no merge-time publish.",
          "is_bot": false,
          "headline": "ci(publish): run publish job on Node 24 (npm 11.x) for OIDC trusted p…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T03:36:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e53f479c43203a1ab588cf829c6c98a978e82322",
          "body": "Fixes v4.7.1 OIDC publish E404: setup-node@v4 + registry-url wrote a dummy NODE_AUTH_TOKEN placeholder + always-auth, forcing garbage-token auth instead of OIDC. Removed registry-url; npm defaults to npmjs.org and uses OIDC.\n\nCarve-out (all 7): org-owned; infracore; operational (CI workflow, not shi\n[…]\nff = UNANIMOUS (/home/delimit/delimit-private/deliberations/2026-06-03-oidc-registry-url-fix-pr112.md, LED-1688); audit = this body. publish.yml triggers on v* tags only -> no merge-time publish risk.",
          "is_bot": false,
          "headline": "ci(publish): drop registry-url so OIDC trusted publishing works (#112)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T03:24:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b57959d9ea60ed4bd2666389ea38ccdb2fd4b14",
          "body": "…) (#111)\n\nPatch bump to cut the first release via npm Trusted Publishing (OIDC) -> sigstore provenance (4.7.0 was manually published without it). No functional package changes (.github/ not bundled).\n\nCarve-out (all 7): org-owned; infracore; operational; CI green (Delimit API Check + Node 18/20/22 \n[…]\nimit/delimit-private/deliberations/2026-06-03-v4.7.1-oidc-verify-pr111.md, LED-1687); audit = this body. Founder direct order: publish v4.7.1 to verify. Gates: security_audit clean, test_smoke fail 0.",
          "is_bot": false,
          "headline": "release: v4.7.1 — verify OIDC trusted-publishing pipeline (provenance…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T03:09:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4366ece19b8828a89b4668d4f925aa69d6c80b2",
          "body": "… (#110)\n\nMoves the publish job to npm OIDC Trusted Publishing: npm@^11 (>=11.5.1 for OIDC), NODE_AUTH_TOKEN removed from both publish steps, id-token:write already present, --provenance kept. Fixes the expired-NPM_TOKEN failure that shipped v4.7.0 without provenance (LED-2301).\n\nCarve-out (all 7): \n[…]\n Actions, repo delimit-ai/delimit-mcp-server, workflow publish.yml, BEFORE the next publish, or OIDC auth fails (no token fallback). publish.yml triggers on v* tags only -> no merge-time publish risk.",
          "is_bot": false,
          "headline": "ci(publish): switch npm publish to OIDC Trusted Publishing (no token)…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T02:39:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6eff966b62e7f7267ad3745be73e4902ffbfd65d",
          "body": "…109)\n\nFixes the v4.7.0 publish blocker: nested 'npm pack' under 'npm publish' (npm 10.x) writes no file, so security-check.sh's 'ls $TMPDIR/*.tgz' failed (exit 2). Now enumerates shipped files via write-free 'npm pack --dry-run --json'; grep scan blocks unchanged.\n\nCarve-out (all 7): org-owned; inf\n[…]\npr109.md, LED-1682); audit = this body.\nVerified local: standalone clean; injected-secret negative test FAILS (gate intact); npm publish --dry-run passes nested. npm publish still HELD; no tag pushed.",
          "is_bot": false,
          "headline": "fix(ci): make security-check.sh re-entrancy-safe under npm publish (#…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T02:00:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69570ae00faf20cc9ff954e0606d64f8ca371338",
          "body": "…blocker) (#108)\n\nFixes the v4.7.0 publish dry-run failure: the bundled PUBLIC ed25519 key matched the secrets-scan \\.key$ pattern (false positive). Renamed to seal_pubkey.ed25519 (pilot canon); scan not weakened.\n\nCarve-out (all 7): org-owned; infracore; operational; CI green (Node 18/20/22 + CodeQ\n[…]\nRESOLVED: npm pack confirms seal_pubkey.ed25519 IS bundled (65B), public.key gone; no literal-filename entry in package.json files[] or .npmignore. Mirrors gateway fix 24fa16d. npm publish still HELD.",
          "is_bot": false,
          "headline": "fix(seal): rename bundled public key to seal_pubkey.ed25519 (publish-…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T01:48:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e1e8c425f23014b84aa2f9e6d997a6515ec71c0",
          "body": "Re-land of the seal fold via the compliant carve-out path (prior direct-push bypass reverted in #106).\n\nDeliberation-as-review carve-out (2026-05-11) — all 7 conditions met:\n1. Org-owned: delimit-ai/delimit-mcp-server\n2. Author: infracore\n3. Scope: operational (additive free tool/command; not pricin\n[…]\nr single-contributor org repo). Pre-publish note from the panel: mechanically confirm the verifier's verification_unavailable non-throw path before publish. npm publish remains HELD; no v* tag pushed.",
          "is_bot": false,
          "headline": "feat: delimit seal-verify + open-core Seal verifier (v4.7.0) (#107)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T01:29:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c98a7e2e854682c7a955314f249a978a2054b866",
          "body": "…PR (#106)\n\nReverts 7d723cc, which landed on main via a direct push that auto-bypassed the Protect Main PR ruleset.\n\nAuthorization: direct founder instruction this session (revert + redo as PR). Audit: LED-2297.\nMerged via sanctioned gh pr merge --admin (carve-out mechanism): CI green (Node 18/20/22\n[…]\ndeliberation-as-review carve-out for single-contributor org repos. The seal fold re-lands in the follow-up PR with a fresh deliberation over the diff.\n\nnpm publish remains held; no version tag pushed.",
          "is_bot": false,
          "headline": "Revert v4.7.0 seal fold (landed via ruleset bypass) — re-landing via …",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T01:22:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d723cc9af18009501617d237b12d4d6529d1492",
          "body": "…v4.7.0)\n\nAdd 'delimit seal-verify <receipt.json>' and the free delimit_seal_verify MCP tool. Bundles gateway/ai/seal/ (verifier, content-hashed constitution, public key, sample receipt). The verifier lazy-imports cryptography and fails closed if absent -- it never blocks install or any other tool.\n\n[…]\nligion/secret scans clean; security-check.sh clean; repo diagnose healthy. npm publish intentionally HELD for explicit founder go.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: delimit seal-verify command + bundled open-core Seal verifier (…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-06-04T00:56:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0648d431e6b7b627115f06a35d017174fdbf40de",
          "body": "…er FP; diff-engine context severity; CLI recall fix (#105)\n\nRelease v4.6.2. Founder authorized 'ship it once CI green' (2026-05-27); CI all-green (Node 18/20/22 + CodeQL + API Check). Bundles already-merged+deliberated gateway changes: memory_search/revive/legacy-store (PR #215), scanner FP (LED-2278), diff-engine $ref drift + LED-1600 context-severity (PR #216, deliberation LED-1611). Tag push triggers publish.yml (provenance + secret-scan).",
          "is_bot": false,
          "headline": "release: v4.6.2 — restore memory_search + cross-venture revive; scann…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-27T18:46:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4810c65ea2ae1a1491238c202f597970923f5ef3",
          "body": "LED-1564: pin pytest into the npm-side setup chain so fresh installs auto-provision ~/.delimit/venv with pytest. Single-file change in bin/delimit-setup.js (+7/-3) covering reqFile-branch + inline-fallback + global-pip-fallback. Install-time only; no publish.\n\nCarve-out: merged under delimit-ai/* de\n[…]\nsetup.js only via gh pr diff before merge).\n- Founder explicit override at the moment of merge: 'finish'.\n- Transcript: /home/delimit/delimit-private/deliberations/2026-05-22-pr104-setup-pytest-pin.md",
          "is_bot": false,
          "headline": "fix(setup): LED-1564 — pin pytest into the venv install chain (#104)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-23T01:52:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab73ae9c32edd8f4d78da4dec09f9f47dafb4e0e",
          "body": "… (#103)\n\nDocuments what shipped in 4.6.1 (already published 2026-05-22). Forward-prep for the next customer-visible changelog ship at 4.6.2 — not a retroactive fix to the tarball already on npm. Captures the 7 gateway PRs (cross-post dedup, inline follow-up drafts, STR-195 binding decisions, LED-12\n[…]\ns AGREE (Gemini + Claude + Codex), round 2 ✓\n- Transcript: /home/delimit/delimit-private/deliberations/2026-05-22-pr103-changelog-461.md\n\nNo publish, no tag — rides forward to next functional release.",
          "is_bot": false,
          "headline": "docs(changelog): 4.6.1 entry — bundle hygiene + 7 gateway carry-overs…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-23T00:34:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "76e7ec6bc34ae3f4d770ba5c82b91340b04de3fa",
          "body": "Release reconciliation: post-publish bump + 110-file gateway sync for delimit-cli@4.6.1, which already shipped to https://registry.npmjs.org/delimit-cli/4.6.1 (shasum 8d6807b497487cc5a43f2ed28af4494457f3d0d4, 1.0MB / 202 files).\n\nCarve-out: merged under delimit-ai/* deliberation-as-review pattern (C\n[…]\ny sync transports 7 already-deliberated gateway PRs (#199-205) — not a re-litigation.\n\nPost-merge: tag v4.6.1 + push tag; the GHA publish.yml workflow may fire and will no-op on duplicate npm version.",
          "is_bot": false,
          "headline": "4.6.1 (#102)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-22T20:25:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7881a4cf773be9c289c1e505663efd6a87c42f58",
          "body": "… (#101)\n\nExcludes 3 publish-time-only scripts (build-license-core.sh, security-check.sh, test-license-core-so.sh) from the npm tarball. They stay on the dev machine where prepublishOnly runs them; they no longer ship to customer installs. Closes the meta-leak where the scripts' own leak-detection g\n[…]\npackage.json: 166 → 163 files; 3 scripts gone.\n  - Manifest scan: 0 identity-string hits in shipped files (was 3).\n  - prepublishOnly invocation chain unchanged — scripts still resolve on dev machine.",
          "is_bot": false,
          "headline": "chore(npm): exclude dev-only build scripts from the published tarball…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-22T02:02:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50f91706eae28ad7d3c8d58dd3590a91aff2366b",
          "body": "…or (LED-1207) (#100)\n\nOn some npm-arborist environments `npx delimit-cli` crashes with \"Cannot read properties of\nundefined (reading 'extraneous')\" before reaching the CLI itself. That silently breaks the\npre-commit/pre-push gate and forces --no-verify, violating the no-silent-no-verify rule.\n\nFix:\n[…]\npre-commit-npx-bypass.md\nVerdict: UNANIMOUS AGREEMENT at round 2 (Gemini, Claude Opus 4.7, Codex GPT-5.3-codex).\n\nCloses LED-1207.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): bypass broken npx fallback in pre-commit/pre-push generat…",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-15T05:13:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f2c46edfee297f31e62c23a75fd4ebe3735ef28b",
          "body": "The 4.6.0 entry's \"Known issue (pre-existing, fix tracked)\" line about\ndelimit attest mcp exit codes was incorrect. The original test failure\nthat triggered the note was a phantom — caused by a corrupted local git\nworktree state (LED-1401), not a real CLI bug. On a clean clone, all\nattest-mcp test s\n[…]\nion carve-out. Same direct-push pattern as the 4.6.0 version\nbump (c860c96), which was also implicit in the publish authorization.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): retract incorrect 4.6.0 'known issue' line (LED-1403)",
          "author_name": "infracore",
          "author_login": "infracore",
          "committed_at": "2026-05-15T04:38:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 45,
      "commits_last_year": 456,
      "latest_release_at": "2026-07-24T02:51:54Z",
      "latest_release_tag": "v4.16.4",
      "releases_from_tags": false,
      "days_since_last_push": 6,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 10,
      "mean_days_between_releases": 3.9
    },
    "artifacts": {
      "collected": true,
      "structure": [
        "tree.dockerfile"
      ],
      "declarations": [
        {
          "name": "delimit-cli",
          "path": "package.json",
          "tokens": [
            "npm.bin",
            "npm.entry"
          ],
          "ecosystem": "npm"
        }
      ]
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "readme_badges": {
        "hosts": [
          "shields.io"
        ],
        "total": 4,
        "header": 4,
        "collected": true,
        "has_inspect_badge": false
      },
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "delimit-cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "openapi",
            "swagger",
            "api",
            "breaking-changes",
            "semver",
            "lint",
            "linter",
            "api-governance",
            "api-contracts",
            "ci-cd",
            "github-actions",
            "migration",
            "diff",
            "schema-validation",
            "api-versioning",
            "eslint",
            "delimit",
            "openapi-diff",
            "api-linter",
            "contract-testing",
            "mcp",
            "mcp-server",
            "model-context-protocol",
            "claude-code",
            "codex",
            "gemini-cli",
            "cursor",
            "ai-governance",
            "ai-agents",
            "ai-code-review",
            "ci-governance",
            "merge-gate",
            "attestation",
            "signed-attestation",
            "sigstore",
            "sbom",
            "supply-chain-security",
            "json-schema",
            "json-schema-diff",
            "policy-as-code",
            "audit-trail",
            "ai-coding-assistant",
            "pull-request",
            "pr-comment",
            "developer-tools"
          ],
          "ecosystem": "npm",
          "categories": [],
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/delimit-cli",
          "declared_type": null,
          "is_deprecated": false,
          "latest_version": "4.16.4",
          "repository_url": "https://github.com/delimit-ai/delimit-mcp-server",
          "versions_count": 237,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3625,
          "first_published_at": "2026-03-06T21:16:29.723000Z",
          "latest_published_at": "2026-07-24T02:51:40.136000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        }
      ]
    },
    "popularity": {
      "forks": 5,
      "stars": 21,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-29",
            "count": 2
          },
          {
            "date": "2026-04-15",
            "count": 1
          },
          {
            "date": "2026-04-21",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 5,
        "total_forks": 5
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "api/openapi.yaml",
        "examples/breaking-change-demo/openapi.yaml",
        "examples/monorepo-demo/services/orders/api/openapi.yaml",
        "examples/monorepo-demo/services/users/api/openapi.yaml",
        "examples/openapi-basic/api/openapi.yaml",
        "examples/safe-change-demo/openapi.yaml"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 709008,
      "source_files_sampled": 218,
      "oversized_source_files": 11,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "gateway/requirements.txt",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 136,
        "malicious_count": 0,
        "assessed_package": "npm:delimit-cli@4.16.4",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "axios",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.16.0"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.2"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "express",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.0"
        },
        {
          "name": "inquirer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.2.0"
        },
        {
          "name": "js-yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "minimatch",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 165,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 3,
        "closed_unmerged_prs": 7
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "infracore",
          "commits": 269,
          "avatar_url": "https://avatars.githubusercontent.com/u/266558014?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "api-governance.yml",
        "author-audit.yml",
        "ci.yml",
        "claude.yml",
        "identity-guard.yml",
        "identity-strings-gate.yml",
        "publish.yml",
        "weekly-tweet.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "14 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ec7ee651640dcd6bb7adc4d4351a45d3c643738a",
        "ran_at": "2026-08-03T07:51:05Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "recent_prs": {
        "merged_7d": 1,
        "decided_7d": 1,
        "merged_30d": 41,
        "authors_30d": 1,
        "decided_30d": 42,
        "sample_size": 60,
        "window_days": 30,
        "sample_exhausted": false,
        "authors_probed_30d": 1,
        "newcomer_merged_30d": 0,
        "bot_prs_excluded_30d": 0,
        "newcomer_authors_30d": 0,
        "newcomer_decided_30d": 0
      },
      "ci_last_run_at": "2026-08-02T08:36:57Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-28T03:12:39Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/delimit-ai/delimit-mcp-server",
    "host": "github.com",
    "name": "delimit-mcp-server",
    "owner": "delimit-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": "The weighted overall 67 is calibrated to 78 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 67,
            "calibrated": 78,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 78,
      "inputs": {
        "security": 57,
        "vitality": 87,
        "community": 57,
        "governance": 55,
        "calibration": "2026-08-02",
        "engineering": 81,
        "ai_readiness": 49,
        "weighted_overall_raw": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 87,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 456,
              "human_commit_share": 1,
              "days_since_last_push": 6,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "456 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 456
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 45,
              "latest_release_tag": "v4.16.4",
              "releases_from_tags": false,
              "days_since_latest_release": 10,
              "mean_days_between_releases": 3.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "45 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 45
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 10 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 57,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "forks": 5,
              "stars": 21,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "21 stars",
                "points": 21.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "5 forks",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": 4,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [
                "shields.io"
              ],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "delimit-cli"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3625
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,625 downloads/month across npm",
                "points": 47.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3625,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 81,
            "inputs": {
              "merged_prs": 165,
              "open_issues": 0,
              "closed_issues": 3,
              "prs_merged_7d": 1,
              "prs_decided_7d": 1,
              "prs_merged_30d": 41,
              "prs_decided_30d": 42,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 7,
              "first_time_authors_30d": 0,
              "first_time_prs_merged_30d": 0,
              "first_time_prs_decided_30d": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "165/172 decided PRs merged",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 165,
                      "decided": 172
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "delimit-ai",
              "public_repos": 17,
              "account_age_days": 147
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of delimit-ai",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "delimit-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "17 public repos, account ~0 yr old",
                "points": 9.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 17
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "delimit-cli"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 10
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 10 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "237 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 237
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "exceptional",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "api-governance",
                "breaking-changes",
                "openapi",
                "claude-code",
                "codex",
                "mcp",
                "mcp-server",
                "cursor",
                "ai-governance",
                "cross-model",
                "deliberation",
                "devtools",
                "gemini-cli",
                "model-context-protocol"
              ],
              "has_wiki": true,
              "homepage": "https://delimit.ai",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://delimit.ai",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "14 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 57,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "14 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:delimit-cli@4.16.4 runtime dependency closure — what installing the published package pulls in — 136 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:delimit-cli@4.16.4",
                  "assessed": 136
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 136,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 136,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "weak",
        "name": "AI Readiness",
        "value": 49,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "weak",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.24,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "24 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 24,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 709008,
              "source_files_sampled": 218,
              "oversized_source_files": 11
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "11/218 source files over 60KB",
                "points": 52.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 218,
                      "oversized": 11
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "excellent",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "api/openapi.yaml",
                "examples/breaking-change-demo/openapi.yaml",
                "examples/monorepo-demo/services/orders/api/openapi.yaml",
                "examples/monorepo-demo/services/users/api/openapi.yaml",
                "examples/openapi-basic/api/openapi.yaml",
                "examples/safe-change-demo/openapi.yaml"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "api/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "api/openapi.yaml, examples/breaking-change-demo/openapi.yaml, examples/monorepo-demo/services/orders/api/openapi.yaml, examples/monorepo-demo/services/users/api/openapi.yaml, examples/openapi-basic/api/openapi.yaml, examples/safe-change-demo/openapi.yaml"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "cli",
        "library",
        "network-service"
      ],
      "scores": {
        "cli": 16,
        "library": 14,
        "mcp-server": 2,
        "network-service": 7
      },
      "primary": "cli",
      "evidence": [
        {
          "tier": "declared",
          "label": "cli",
          "source": "npm.bin",
          "weight": 10
        },
        {
          "tier": "declared",
          "label": "library",
          "source": "npm.entry",
          "weight": 8
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:npm",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:commander",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "network-service",
          "source": "dep:express",
          "weight": 4
        },
        {
          "tier": "structure",
          "label": "network-service",
          "source": "api_schema",
          "weight": 3
        },
        {
          "tier": "description",
          "label": "cli",
          "source": "description:cli",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "mcp-server",
          "source": "tag:mcp-server",
          "weight": 2
        }
      ],
      "artifacts": [
        {
          "path": "package.json",
          "labels": [
            "cli",
            "library"
          ],
          "ecosystem": "npm"
        }
      ],
      "confidence": "high",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-03T07:51:23.236512Z",
  "schema_version": "0.30.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/delimit-ai/delimit-mcp-server.svg",
  "full_name": "delimit-ai/delimit-mcp-server",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v2.3.1, Schema v0.30.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.