JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 8540,
"has_wiki": false,
"homepage": null,
"languages": {
"C": 6659,
"C#": 626931,
"Go": 292523,
"C++": 538403,
"CSS": 13727,
"PHP": 350929,
"Dart": 517797,
"HTML": 447,
"Java": 622348,
"Ruby": 165470,
"Rust": 338271,
"CMake": 21561,
"Scala": 37091,
"Shell": 41210,
"Swift": 468704,
"Elixir": 60889,
"Kotlin": 604989,
"Python": 318948,
"Svelte": 629149,
"Dockerfile": 3587,
"JavaScript": 417077,
"PowerShell": 3298,
"TypeScript": 9170822,
"Go Template": 4771,
"Objective-C++": 15873
},
"pushed_at": "2026-07-19T13:48:31Z",
"created_at": "2026-03-15T08:14:59Z",
"owner_type": "Organization",
"updated_at": "2026-07-17T00:14:29Z",
"description": null,
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "Organization",
"login": "edge-base",
"company": null,
"location": null,
"followers": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/268324515?v=4",
"created_at": "2026-03-15T08:07:20Z",
"is_verified": null,
"public_repos": 8,
"account_age_days": 128
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.4.9",
"kind": "patch",
"published_at": "2026-07-17T00:15:22Z"
},
{
"tag": "v0.4.8",
"kind": "patch",
"published_at": "2026-07-16T00:21:10Z"
},
{
"tag": "v0.4.7",
"kind": "patch",
"published_at": "2026-07-15T15:24:35Z"
},
{
"tag": "v0.4.6",
"kind": "patch",
"published_at": "2026-07-14T12:39:06Z"
},
{
"tag": "v0.4.5",
"kind": "patch",
"published_at": "2026-07-14T05:28:07Z"
},
{
"tag": "v0.3.5",
"kind": "patch",
"published_at": "2026-07-08T20:49:35Z"
},
{
"tag": "v0.3.3",
"kind": "patch",
"published_at": "2026-07-08T02:43:59Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2026-07-07T12:17:28Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-07-03T09:05:06Z"
},
{
"tag": "v0.2.9",
"kind": "patch",
"published_at": "2026-04-08T23:06:18Z"
},
{
"tag": "v0.2.8",
"kind": "patch",
"published_at": "2026-04-04T06:52:31Z"
},
{
"tag": "v0.2.7",
"kind": "patch",
"published_at": "2026-03-29T13:52:34Z"
},
{
"tag": "v0.2.4",
"kind": "patch",
"published_at": "2026-03-24T23:27:33Z"
},
{
"tag": "v0.2.3",
"kind": "patch",
"published_at": "2026-03-24T01:52:17Z"
},
{
"tag": "v0.2.2",
"kind": "patch",
"published_at": "2026-03-23T09:15:57Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-03-23T07:10:37Z"
}
],
"recent_commits": [
{
"oid": "38e0ba236bb395a079f0fc42ff1a513a710263a7",
"body": null,
"is_bot": false,
"headline": "release: prepare 0.4.9",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-17T00:07:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f27bc14e65fdde54b002e138cd0639757bece16",
"body": null,
"is_bot": false,
"headline": "release: prepare 0.4.8",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T23:48:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca773bbc89a13b04a07783e0541ecee97e263a78",
"body": null,
"is_bot": false,
"headline": "Merge 0.4.7 server fixes",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T15:21:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6f5a4cf661d2425eb674fbd942d7c0b2163d87f0",
"body": null,
"is_bot": false,
"headline": "fix(server): reconcile SQLite uniqueness and signed HEAD",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T15:21:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9528017dccde3a0bb5d5a41ffdedf1a65658b354",
"body": null,
"is_bot": false,
"headline": "test: make local CI opt-in and responsive",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T15:17:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05877bdfe8cefc91a930e12b682166e902a59b4c",
"body": null,
"is_bot": false,
"headline": "test: keep app bundle checks responsive",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T13:15:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "afb5a7ba6cd554a1d16484ab41a186ef57c7272d",
"body": null,
"is_bot": false,
"headline": "ci: add focused npm release gate",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T11:45:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e726a82e6d62d06fb90d399defe2a919e70811a",
"body": null,
"is_bot": false,
"headline": "test: keep CLI telemetry checks nonblocking",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T11:29:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c515aaa50d70156bdccbb50af0d3128d42c3a581",
"body": null,
"is_bot": false,
"headline": "test: keep CLI workers responsive during packaging",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T10:38:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "90320e7d2c5d8cf15c163cc84fb0d1dbcbd34650",
"body": null,
"is_bot": false,
"headline": "test: extend local CLI packaging timeout",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T09:50:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a3af133cc7fa4f8b6dd6f913f4a45e5a0921e51",
"body": null,
"is_bot": false,
"headline": "test: allow slow local CLI packaging",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T09:48:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3ac68298b2e8e47efa417f3a5a2074e8853b159",
"body": null,
"is_bot": false,
"headline": "test: extend isolated local CI timeouts",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T09:44:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70745ef7ecee67372bca546c4e03bfd9e3a914ee",
"body": null,
"is_bot": false,
"headline": "perf(ci): cache pnpm stores in Docker volumes",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T08:59:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a18f318761c51608a9044b7ef4332e6f7243e08",
"body": null,
"is_bot": false,
"headline": "fix(ci): keep release gates operational",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T08:46:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "509b98b4250ab7669676d264735a975722a3481d",
"body": null,
"is_bot": false,
"headline": "test: tolerate slow isolated Linux checks",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T06:44:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce47b0ea56b7d0d7666b6e3ff2a77a2d3429c5f7",
"body": null,
"is_bot": false,
"headline": "Release EdgeBase 0.4.7",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T04:23:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8ab5607e84d5937b03ffd774e1a2fd50de36127d",
"body": null,
"is_bot": false,
"headline": "docs(functions): document background work context",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T04:20:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bd4d204ddef56649803c0a52b7916f0d53097daf",
"body": null,
"is_bot": false,
"headline": "feat(server): enrich function runtime contracts",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T04:19:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f2f2026596a832798f0d83abeb411b473dea7aa",
"body": null,
"is_bot": false,
"headline": "fix(web): coalesce same-tab session refreshes",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T04:19:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de41c621944de8b3289a65e197e776cd9ee96449",
"body": null,
"is_bot": false,
"headline": "fix(cli): harden live refresh and slow startup",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-15T04:19:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97cffd805b74d769e7c68f8c256ca45a923f6b2b",
"body": null,
"is_bot": false,
"headline": "refactor(web): model room connection lifecycle",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T23:47:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71344a672fee186acc638d7acee7c093ad543a76",
"body": null,
"is_bot": false,
"headline": "fix(web): preserve room reconnect backoff until sync",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T20:54:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0367ca2091d2b055e461c85f9ce0865afcdbb62",
"body": null,
"is_bot": false,
"headline": "Release EdgeBase 0.4.6",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T12:37:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24dd2e6f4c03d497548f492634f68618f4810563",
"body": "Release EdgeBase 0.4.5",
"is_bot": false,
"headline": "Merge pull request #81 from edge-base/codex/edgebase-0.4.5-release-ci",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T05:26:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e811f8d8bc70f4292f6d31e889b5eda7202383d9",
"body": null,
"is_bot": false,
"headline": "Align mutation checks with configured targets",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T03:56:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fba85707fdb3f3e9cb83c7ea12355e27f4e0ece1",
"body": null,
"is_bot": false,
"headline": "Preserve mutation coverage in the local gate",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T03:46:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9ccdac6af128f41124ac81807f7f41b3bd6ffdfe",
"body": null,
"is_bot": false,
"headline": "Keep the local Linux gate sequential",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T03:27:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7643fb798ba3e2ca79f36b0d0fe7f9c9179684c2",
"body": null,
"is_bot": false,
"headline": "Scale server test deadlines under local emulation",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T03:08:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "94e8a536321a6d9cb2c0389e3fddba57d4f3d515",
"body": null,
"is_bot": false,
"headline": "Use native Trivy under local emulation",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T02:59:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0aad074b88c5c3698e7e31e510dbb8f06d2c122f",
"body": null,
"is_bot": false,
"headline": "Make local Trivy scans tokenless",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T02:46:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad171072de3e8be503e5d49318601045477ddbd2",
"body": null,
"is_bot": false,
"headline": "Document additional EdgeBase 0.4.5 changes",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T02:29:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8da3f19d1455e520784787e208eefd13e6434413",
"body": null,
"is_bot": false,
"headline": "Add request deadlines and live fan-out safeguards",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T02:29:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "feadb110c9c214a1e7863e99cd94cc1ca518bdc3",
"body": null,
"is_bot": false,
"headline": "Fix local release gate isolation",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T02:08:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "984a908cdef45ba228567f26783ff5b875339efe",
"body": null,
"is_bot": false,
"headline": "Prepare EdgeBase 0.4.5 release",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-14T01:45:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7014cf2912cb419230483c97df83de487497bed0",
"body": "* Release EdgeBase 0.4.4 Docker self-hosting\n\nAdd context-only Docker packaging, project docker-context support, public CA and automatic data volume defaults, and an explicit self-hosted localhost cookie opt-in. Synchronize the 0.4.4 release graph and changelogs.\n\n* Harden Dependabot update cooldown\n[…]\n\n\n* Drop Windows runners from hosted CI\n\n* Remove stale Win64 CI dependencies\n\n* Fix cookie refresh lock takeover\n\n---------\n\nCo-authored-by: june lee <21379657+melodysdreamj@users.noreply.github.com>",
"is_bot": false,
"headline": "Release EdgeBase 0.4.4 Docker self-hosting (#79)",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-13T13:40:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ca5b50af2ec6a19d12b564a33a600561d17abf6",
"body": "The only shipped-code change: the C++ SDK's AuthClient::adoptAuthTokens rejected\nany auth response carrying an accessToken without a refreshToken as an\n\"incomplete replacement token pair\" (ok=false). But the server legitimately\nreturns access-token-only on a displayName change — the name is embedded\n[…]\nRemaining red CI is Windows-only (Node/JS/Python e2e on Windows,\npack smoke, C++ Unreal Win64) plus the two contract gates that aggregate them.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Version 0.4.3: fix C++ SDK updateProfile access-token-only adoption",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T22:37:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4af7338dabbed0c9a46cf591d1d64dc1f1c3339f",
"body": "…sessions\n\nThe test revoked sessionsAfterSecondSignIn.last(), which can be this client's own\nsession (changePassword had re-issued exactly one session for it) — revoking it\ninvalidates the caller's token, so the follow-up listSessions threw EdgeBaseError.\nCapture the client's own session id and revoke a different one, matching the JS\nand Flutter SDK fixes. (Verified via CI — local Gradle reproduction was blocked.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-kotlin): revoke a non-current session in changePassword_and_…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T14:52:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c5e39840fc0c10f977ccfe79edae9a1fc48eacb0",
"body": "IosUnitTests.swift used `XCTAssertEqual(await ...)` etc. in 13 places, but Swift\nautoclosures (which XCTAssert* take) cannot contain `await`, so the ios test\ntarget failed to compile (\"await in an autoclosure that does not support\nconcurrency\"). Bind each awaited value to a `let` first, then assert. Mechanical\nfix; verified no XCTAssert-with-await lines remain. (Verified via CI — full Xcode\nis unavailable locally.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-swift): extract awaited values before XCTAssert (compile fix)",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T14:52:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b742103e6ed380434a889b956f973b3b84456a2a",
"body": "…storage\n\nThe anonymous → link-with-email e2e used MemoryTokenStorage, but anonymous\naccount upgrades require a DurableTokenStorage (0.4.0: replacement tokens must\nsurvive a lost response), so linkWithEmail threw \"Anonymous account upgrades\nrequire durable ... storage\" — correct SDK behavior, wrong \n[…]\nhat the server accepts an anon token on /auth/link/email, confirming this is a\ntest-config issue, not an SDK/server bug. Flutter e2e now 62/62.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-flutter): back the anonymous-upgrade e2e with durable token …",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T14:46:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "84b346c58667743466e48260dfcfb8f53f98dc01",
"body": "The Flutter revokeSession e2e revoked sessions.last, which can be this client's\nown session — revoking it invalidates the caller's token, so the follow-up\nlistSessions failed with TOKEN_INVALID. Capture the client's own session id up\nfront and revoke a different one, matching the JS SDK fix. Also document the\nverified flutter test:e2e command in dev/testing/sdk-e2e.md.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-flutter): revoke a non-current session in the revokeSession e2e",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T14:34:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4e2df6708092a16e059c7fc36924c08a76fe9f15",
"body": "Document the per-language SDK E2E harness — run-with-services commands, the\ntoolchain matrix, the EDGEBASE_E2E_REQUIRED / gradle-daemon / localhost-vs-\n127.0.0.1 gotchas, and the Windows-only jobs that cannot be reproduced off a\nWindows runner. Allowlist dev/testing/ in .gitignore (like dev/release/) and\nlink the doc from AGENT.md (Testing) and CONTRIBUTING.md (Development).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add dev/testing/sdk-e2e.md for local SDK E2E reproduction",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T14:21:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2eeabe259cada06dd01293df9b608cd7d60be3eb",
"body": "…ting them\n\nAuthClient::adoptAuthTokens rejected any response that carried an accessToken\nwithout a refreshToken as an \"incomplete replacement token pair\", setting\nok=false. But the server legitimately returns access-token-only on a displayName\nchange (the name is embedded in the JWT, so it re-issue\n[…]\nefresh token for access-only responses; still reject a refresh-only response.\n\nVerified: C++ core e2e 64/64 pass (was 63/1), unit 132/132 pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sdk-cpp): adopt access-token-only auth refreshes instead of rejec…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T14:20:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d6ad4731740ef9fe74731496658e536cb3aa657c",
"body": "The AsyncStorage restore E2E persisted the refresh token under the legacy\n'edgebase:refresh-token' key, but 0.4.0 namespaced storage keys as\n'edgebase:<encoded baseUrl>:refresh-token' and deliberately does not migrate\npre-namespace keys. TokenManager.restore() therefore found nothing and left the\nuser null. Persist under the namespaced key the manager actually reads.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-rn): restore session from the namespaced refresh-token key",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T13:31:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "26171db2de3f4ecc46c2fcf61cc6684340e4210f",
"body": "…h callback\n\nTwo cookie-auth-transport unit tests captured the refresh resolver inside a\ngetAccessToken callback, then relied on a fixed setTimeout(45ms) before calling\nit. On slow CI runners (Windows) the callback had not run yet, so resolveRefresh\nwas undefined (\"resolveRefresh is not a function\") — a flaky failure. Await a\nsignal fired from inside the callback instead of guessing a delay.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-js): make in-flight-refresh cookie tests wait for the refres…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T13:26:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9008ba16aa507663cccab6054872326a2f2cbb3d",
"body": "Two web.e2e.test.ts cases asserted pre-0.4.0 semantics (dead since the file's\ntransform error) and failed once revived:\n- revokeSession revoked the caller's own only session and expected to stay\n authenticated; revoke a second account session instead.\n- handleOAuthCallback fed a hand-crafted JWT an\n[…]\n and exchanges the refresh\n token server-side; drive the real flow with a genuine session's tokens.\nAlso drop the now-unused fake-JWT helpers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(sdk-js): rewrite stale web e2e auth tests for current behavior",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T13:05:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2d4a50b0cd40d5eb6c8647d036c20be51a9389da",
"body": "The E2E config runs in release mode, where auth redirect flows (magic link,\npassword reset, email verify/change) require an explicit\nauth.allowedRedirectUrls allowlist since 0.4.0. The config never set one, so the\nweb auth-verify-loop E2E tests hit \"redirect_url requires auth.allowedRedirectUrls\nin release mode\". Add a same-origin localhost:4173 wildcard covering the test\napp's callback routes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(server): allow localhost redirect URLs in the E2E config",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T13:05:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b61ccfc577d026a6bad2e5fa86e5068054072fe6",
"body": "resolve-options.test.ts asserted the secrets-file spy was called with a\nhardcoded POSIX path, but resolveOptionalServiceKey builds it via\njoin(projectDir, '.edgebase', 'secrets.json'), which yields backslashes on\nWindows — failing the spy assertion on windows-latest. Build the expected path\nwith join() so it matches on every platform.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli-test): compare resolved secrets path with join() for Windows",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T12:40:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2e6ed7dc8839fec2274870cf7356837f8b526f74",
"body": "Two `it(...)` blocks in web.e2e.test.ts used `await client.auth.signInWithOAuth`\ninside a non-async arrow, so esbuild failed the whole suite transform with\n\"await can only be used inside an async function\" (pre-existing since 0.4.0).\nAdd the missing `async`.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sdk-js-test): mark web OAuth e2e cases async so await is valid",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T12:29:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2a52c6133f06681331dbe03cdd4e06742de531ca",
"body": "The version-bound managed-deploy-secrets tests asserted\n`statSync(path).mode & 0o777 === 0o600`, but NTFS cannot represent POSIX\npermissions and Node reports 0o666 (438) there, failing 5 tests on\nwindows-latest. Skip the owner-only mode assertion on win32, matching the\nexisting guard used for the deploy-manifest permission check.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli-test): guard POSIX 0600 secret-file mode assertions on Windows",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T12:29:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "20bc4669a7b2116d3f2f708a562beadb3afde7ff",
"body": "…ures\n\nThe 0.4.2 release commit added a version-bound managed-deploy-secrets CLI test\nwhose SERVICE_KEY/JWT_USER_SECRET/JWT_ADMIN_SECRET fixtures are synthetic\n\"<16-hex>\".repeat(4) values. Gitleaks flags them as generic-api-key. Add their\nexact fingerprints per the file's fingerprint-specific policy so a genuinely new\ncredential in the same file still fails CI.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(secret-scan): allowlist deterministic hex deploy-secret test fixt…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T12:10:25Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "695c5be0051fe8ed58fd170dfa88214e091c30f8",
"body": "…e integrity hardening\n\nSecurity hardening release across auth, config export, and the release runtime\nboundary. No public HTTP or SDK API break; language SDKs are metadata-synced to\n0.4.2 only.\n\n- Password sign-in no longer leaks account existence: absent, passwordless, and\n wrong-password users s\n[…]\nd Content-Length\n and while streaming.\n\nVerified locally: server unit 2666 passed, CLI 943 passed, release:preflight\n32/32 with no advisories.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Version 0.4.2: auth enumeration, backup redaction, and release runtim…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T11:33:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "af1d32826d0ae58e375d2ab51f274e531c2b36da",
"body": "The secret-scan workflow and .gitleaksignore added in 0.4.0 missed a fixture in\ntheir own commit: a hand-crafted \"header.<base64 test payload>.signature\" JWT in\npackages/sdk/swift/packages/ios/Tests/IosUnitTests.swift (token-restore unit\ntest). It is a deterministic test value, not a real credential. Add its exact\nfingerprint per the file's fingerprint-specific policy so a genuinely new\ncredential in the same file still fails CI.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(secret-scan): allowlist deterministic fake-JWT iOS test fixture",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T06:03:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4e9196007d4e88c6262050d4fb8876353f76da0d",
"body": "Realtime rooms rewrote Durable Object storage on every socket heartbeat: the\nper-room ephemeral-timer blob was persisted unconditionally several times per\nalarm, and the socket liveness check re-armed itself every ~5s while persisting\nan ever-advancing socketHeartbeatCheckAt. An active room therefor\n[…]\ntate\nchanges; a dead socket is still reaped within roughly one stale window. No\npublic API / SDK change. Guarded by room-auth-state-loss tests.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Version 0.4.1: fix RoomsDO per-heartbeat storage write storm",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T05:40:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b93d1781d29f1b6ef77ce447d79840e17dab60a0",
"body": "Bump EdgeBase 0.3.8 -> 0.4.0. A minor (not patch) bump because this release\ncarries backward-incompatible behavior; a patch number would understate the\nupgrade risk for downstream SDK consumers.\n\nBreaking changes:\n- React Native signInWithOAuth() is now async; callers using its { url } must await it\n[…]\n).\n\nVersion stamped across all file-backed SDK targets and doc references; per-SDK\nCHANGELOG headings relabeled to 0.4.0. release:check passes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "Version 0.4.0: security hardening with breaking SDK auth/storage changes",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-12T04:42:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d7c094206190e1998e1a662662a4a5129d91c8d3",
"body": null,
"is_bot": false,
"headline": "docs: codify the fast verification loop",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-10T05:38:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd15fc4910aa35e10066e9cbfdef121912744bb7",
"body": null,
"is_bot": false,
"headline": "fix: align release assets with the CLI server graph",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-10T05:13:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64c854c8062eac2e922eaf1fcc9fb86e78c79004",
"body": null,
"is_bot": false,
"headline": "release: harden packaged runtimes for EdgeBase 0.3.8",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-10T05:04:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98d963867d908caf1c0bd71374d39cfaef9c8d4b",
"body": null,
"is_bot": false,
"headline": "release: fix packaged runtimes for EdgeBase 0.3.7",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-10T03:47:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9bd79dd4acc9941bdafe8b6ef1d84d5f547ecf8",
"body": null,
"is_bot": false,
"headline": "ci: install dependencies for release contract checks",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-10T02:05:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c55b13e8d407dd7f078db82065e0ca2ebeaaae39",
"body": null,
"is_bot": false,
"headline": "release: prepare EdgeBase 0.3.6",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-10T02:03:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1efbdbc8bc6f35245b1bed9d88cb5ba2e5d762bf",
"body": "Full-repo review remediation across server, SDKs, admin, CLI, and infra, plus release 0.3.5.\n\n- Server: room anonymous-auth hardening, schemaless SQL identifier escaping, OAuth redirect wildcard fix + warning, admin login rate-limit + timing, CORS credentials only on exact-origin match, validated Se\n[…]\ns, non-root Docker.\n- CI: pinned all GitHub Actions to SHAs, explicit workflow secrets, shell-injection fix, pnpm supply-chain settings.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "Security & correctness hardening + release 0.3.5 (#69)",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T20:47:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d076aea8fa35df947ee80b0171db03fc6f88dd5c",
"body": "…ky crash)\n\ntest_room_unified_surface_sends_signal_member_and_admin_frames used a fixed\n`Task.sleep(20ms)` and then read `fakeSocket.messages[0/1/2]` by index. The\nsend is async and appends on a different executor, so on a slow/loaded CI runner\nthe append had not landed within 20ms and the index rea\n[…]\nthe message exists (2s cap)\n and replace the three sleep-then-index reads with it, making the test\n deterministic regardless of runner speed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sdk-swift): make room send-frame test wait deterministically (fla…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T04:41:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d5844cc5f94ac2a05db637a5cd6fd8e98162ca4b",
"body": "…e it\n\nThese modules were previously untested (listed in UNTESTED_LIBS and excluded\nfrom the coverage gate). Add hermetic unit tests (all network/bindings mocked):\n- totp.ts: verifyTOTP window tolerance + invalid/expired codes, recovery codes,\n encrypt/decrypt round-trips\n- email-provider.ts: facto\n[…]\n/email/sms\nfrom the coverage exclude so the gate now enforces them: branch coverage is\n99% / 100% / 90.6% respectively, global stays at 85.87%.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(server): cover auth-critical TOTP/email/SMS providers and enforc…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T04:08:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "11e7785ec629d85e7e71bb67190ec747f4f60fbf",
"body": "…tles\n\nThe clamp in _scheduleNextAlarm() stops a past-due setAlarm from wedging the DO,\nbut it does not make the loop terminate: alarm steps 5 (_stateSaveAt, not-dirty\nbranch) and 7 (_socketHeartbeatCheckAt) cleared their ephemeral scalar in memory\nWITHOUT calling syncEphemeralTimersToStorage() — un\n[…]\n a past-due scalar and\nthe room settles to idle.\n\nVerified: all 10 room integration files pass (127 tests) with zero \"Alarm\nexceeded\" warnings.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(room): persist cleared ephemeral timers so the past-due alarm set…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T04:08:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "accb730c160f63d4d955d814352c4db0c3d0e7d9",
"body": "Bundles the create-edgebase bin restore, the room DO alarm fix, and the\nCI integration-runner timeout. Bumps version to 0.3.3 across all packages,\nSDKs, and versioned references.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: release 0.3.3",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T02:43:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b028ea4b729635df7fde9aeba3d9271ed2a5a94e",
"body": "_scheduleNextAlarm() called ctx.storage.setAlarm(earliest) with no lower\nbound. When earliest <= now (a timer restored from storage after hibernation,\nor re-armed during alarm() processing), workerd re-fires the alarm immediately\nwithout yielding the DO input gate. That spins into a tight loop — sur\n[…]\ns pass (127 tests), zero \"Alarm exceeded\"\nwarnings (was 26 on room-hooks alone), and session.onReconnect passes 5/5\nconsecutively with no hang.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(room): never schedule a Durable Object alarm in the past",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T02:07:50Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2a69b8776ae40f3821b7d67c3589af60ea8e9171",
"body": "…d test\n\nA flaky pre-existing hang in room-hooks.test.ts (a Room Durable Object alarm\nthat breaks the workerd runtime so vitest can never exit) left a shard's\nprocess idle forever. The runner's `wait` loops had no timeout, so one wedged\nshard blocked the whole job until GitHub's 6h cap — which is ex\n[…]\n: happy path still 43s/PASS; a forced low timeout fails with exit 1\n(no false pass); ❯ extraction pinpoints the hung file on a real wedged log.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): stop integration shard runner from hanging for 6h on a wedge…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-08T00:32:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3a92ab1717d11cf9e4be9fd0bf85ca6f67c9d901",
"body": "The bin entrypoint (./bin/create-edgebase.js) was caught by the blanket\n`bin/` rule in .gitignore, so it was never committed. It happened to exist\non disk through 0.2.9 but was absent from 0.3.0 onward — every release since\nshipped with no bin, breaking `npm create edgebase@latest`.\n\n- Restore the l\n[…]\n-to-end against the current CLI.\n- Add a .gitignore exception so this hand-written file stays tracked and can\n never be silently dropped again.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(create-edgebase): restore missing bin entrypoint and track it in git",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T23:22:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3b7a5235d18e71cb6c1ca38f903a502ad731b24b",
"body": "The regenerated smoke report now counts the two transact endpoints;\nupdate the inline snapshot to match (skippedRouteCount stays 0).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: update smoke skip-report snapshot for transact routes (191→193)",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T07:13:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "43cd91dff288c428c686975834932d982c934fe8",
"body": "The openapi.json list operations gained an includeTotal query parameter;\nregenerate the checked-in smoke tests to match (SDK codegen output is\nunchanged — the param does not alter the generated wrappers).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: regenerate smoke tests for includeTotal list param",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T06:53:59Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ed43f3d47c817bd18620c9ee861112f377db6d51",
"body": "…ted provider handlers from the unit coverage gate\n\nAdds mocked-executor unit tests for the PostgreSQL list/get/insert/count/search\nand batch-by-filter update/delete paths.\n\nExcludes d1-handler.ts and postgres-handler.ts from the vitest.unit coverage\ninclude set. Both are provider request handlers v\n[…]\ndo.ts handler already sits outside src/lib/. This aligns the unit\ncoverage gate with genuinely unit-tested code without weakening the threshold.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(server): cover PostgreSQL handler paths; exclude integration-tes…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T06:50:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "faf2619326f33082add6b83d13fd8beeffb52fff",
"body": "Bump version to 0.3.2 across all packages, SDKs, and versioned references.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: release 0.3.2",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T06:25:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4565a77bf31b88644855e3711b28d8b00a217f96",
"body": "Document which of the 15 SDKs are fully supported (Tier 1), maintained\nbest-effort (Tier 2), or experimental, with a tier table on a new docs page,\nsidebar entry, and a Support column in the README SDK table.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add SDK support tiers",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T06:25:05Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "069011e64fa076223d5b70702e22e68a3075e741",
"body": "…ontracts\n\nSecurity: the D1 batch endpoints skipped access-rule evaluation entirely —\nbatch updates ran no update rule, batch deletes evaluated the delete rule once\nagainst an empty row, and batch-by-filter ignored auth/service-key context —\nallowing authenticated clients to bypass row-level authori\n[…]\nook rejection no longer\nleaves a stale pending email/phone registration.\n\nAdds focused unit and integration coverage for every aligned behavior.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(server): enforce batch access rules and align D1/PG/DO provider c…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-07T06:25:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a108d37b5e772a3d3b31291483f6cc3535d88323",
"body": "…tion registry\n\nFiles exporting only named defineFunction consts (e.g. DB trigger maintainers)\nwere silently dropped by the registry codegen, so their triggers never fired.\ndetectExports now collects such exports and generateFunctionRegistry registers\neach as '<route>#<exportName>'; HTTP-method and default exports are unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): register named defineFunction exports in the generated func…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-05T23:24:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "060a92b2d1ad9ba3787d736101df501c5b348860",
"body": "…ace)\n\nFirst dynamic-block integration coverage: needsCreate 2-RTT bootstrap on\nfirst transact, per-instance isolation, expect-based 409 rollback, and\nper-row rule enforcement without a Service Key, all through the worker\n/{ns}/{instanceId}/transact route.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: dynamic per-instance transact integration coverage (txws namesp…",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-05T20:55:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f857fe07f24438840170c421de90f33813c17a0b",
"body": "- handlePgRequest routes POST /transact before table validation; ops run\n on the request's single connection inside BEGIN/COMMIT with ROLLBACK on\n any failure\n- expect assertions run real SELECTs inside the transaction (409 when\n unmet); per-row update/delete rules and expect read rules evaluated\n[…]\nc); core dist\n rebuilt\n- unit tests: postgres-transact.test.ts (BEGIN/COMMIT ordering, 409\n rollback, sidecar 501, pre-transaction validation)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: PostgreSQL transact support via session-scoped BEGIN/COMMIT",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-05T05:04:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "027877d25a83e4dda819f97e1401603ccbffb184",
"body": "- POST /api/db/{ns}[/{instanceId}]/transact: ordered insert/update/delete\n ops across tables applied all-or-nothing, plus expect assertions that\n verify row state at commit time and abort with 409 when unmet\n- DO provider: single transactionSync with batch-parity rule evaluation,\n database-live e\n[…]\nw, FAQ update\n- Tests: transact integration suite (14) across D1 shared and new\n provider-pinned txdo DO namespace; batch/crud regression green\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: add multi-table atomic transact API (DO + D1 providers)",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-05T04:44:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "21a9115072d4741275e714dba487e914a06b907f",
"body": null,
"is_bot": false,
"headline": "fix: include metadata in signed storage URLs",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T08:32:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "228b115d7b64ff2ec194dadfabe49d14b08bab0b",
"body": null,
"is_bot": false,
"headline": "fix: use wrangler boolean env for ci watcher",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T08:05:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be4b0d52b7c46fddc00109b5e4948164aef02747",
"body": null,
"is_bot": false,
"headline": "fix: stabilize windows portable pack smoke",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:59:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "12b52f057aea17a4096e9ed13e9ce320ae14c47f",
"body": null,
"is_bot": false,
"headline": "ci: install elixir hex from github",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:47:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8325856049285cfb75eaeced96422527fd246fd0",
"body": null,
"is_bot": false,
"headline": "ci: skip unused elixir rebar setup",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:40:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c1c0c856971b292d7ff16afb7754a57d1cad4de",
"body": null,
"is_bot": false,
"headline": "fix: pass storage query map in rust sdk",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:32:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a1ce27d4b63f6b5517c3412db595dc157a1b8d18",
"body": null,
"is_bot": false,
"headline": "fix: pass storage query map in go sdk",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:20:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45f4574e96ec4df64f902973c097dcf3897273f2",
"body": null,
"is_bot": false,
"headline": "fix: align storage wrappers with query-aware core",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:17:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a237d2dfd7318c6d09325b4824496b547c0a2cda",
"body": null,
"is_bot": false,
"headline": "fix: stabilize auth smoke ci",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T07:14:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0ed6ead93dd28b65aec93e65740fee4d798333d1",
"body": null,
"is_bot": false,
"headline": "chore: release 0.3.1 with storage updates",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T06:58:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3af07afda808c594b3eb255a06a6a0f04fce88f5",
"body": null,
"is_bot": false,
"headline": "chore: bump release version to 0.3.0",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T06:46:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f66a8d8d6493aadcbbf51283953e063f8700d03f",
"body": null,
"is_bot": false,
"headline": "Fix cross-tab auth refresh coordination",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T06:42:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "148df2bcfba54fdfa44bb9ef020ccf4885ecc075",
"body": null,
"is_bot": false,
"headline": "Harden auth tokens and sync SDK contracts",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-07-03T00:49:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5429683ae6266748b1cf3ca50cfce7d9d98ca36f",
"body": null,
"is_bot": true,
"headline": "chore: bump release version to 0.2.9",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-08T22:58:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5cb6bdf8e910d1d495e3f60155d64900f0c02fcc",
"body": "[codex] Add server-blind room.collab Yjs surface",
"is_bot": false,
"headline": "Merge pull request #68 from edge-base/codex/room-collab-yjs-surface",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-04-08T22:41:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8942288267c38bc40042c3ac8b95233a406aa3a7",
"body": null,
"is_bot": true,
"headline": "add anonymous room auth integration coverage",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-08T22:11:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ccda34cd210103d99ab95dd639fff2424005ac31",
"body": null,
"is_bot": true,
"headline": "add room.collab yjs surface",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-08T21:26:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20524d8cf7d8e3b2f4384c2a49ff22795060c5bf",
"body": "Fix CodeQL PR summary category matching",
"is_bot": false,
"headline": "Merge pull request #67 from edge-base/codex/codeql-summary-check",
"author_name": "june lee",
"author_login": "melodysdreamj",
"committed_at": "2026-04-04T08:38:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a2653579a38531c9097f2459d3f6709c970579c0",
"body": null,
"is_bot": true,
"headline": "ci: align codeql categories with pipeline workflow",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-04T08:09:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbe0560b7ab46290fe3552be4b5552198c6114ab",
"body": null,
"is_bot": true,
"headline": "ci: stabilize codeql analysis categories",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-04T08:05:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc704ae938dbed0c20330fe2c9366220509f06c6",
"body": null,
"is_bot": true,
"headline": "docs: remove meta separation wording",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-04T07:38:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3605ca1044902d3bf6de8500a84e36da01d3b4f9",
"body": null,
"is_bot": true,
"headline": "docs: simplify static frontend docs wording",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-04T07:36:37Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 16,
"commits_last_year": 397,
"latest_release_at": "2026-07-17T00:15:22Z",
"latest_release_tag": "v0.4.9",
"releases_from_tags": false,
"days_since_last_push": 2,
"active_weeks_last_year": 7,
"days_since_latest_release": 4,
"mean_days_between_releases": 11
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": false,
"has_contributing": true,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "@edge-base/cli",
"exists": true,
"license": "MIT",
"keywords": [
"edgebase",
"cli",
"baas",
"backend",
"cloudflare-workers"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@edge-base/cli",
"is_deprecated": false,
"latest_version": "0.4.9",
"repository_url": "https://github.com/edge-base/edgebase",
"versions_count": 31,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 2620,
"first_published_at": "2026-03-18T10:50:05.468000Z",
"latest_published_at": "2026-07-17T00:20:50.176000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
},
{
"name": "@edge-base/server",
"exists": true,
"license": "MIT",
"keywords": [
"edgebase",
"runtime",
"server",
"cloudflare-workers"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@edge-base/server",
"is_deprecated": false,
"latest_version": "0.4.9",
"repository_url": "https://github.com/edge-base/edgebase",
"versions_count": 31,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 2699,
"first_published_at": "2026-03-18T10:49:25.609000Z",
"latest_published_at": "2026-07-17T00:20:07.754000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
},
{
"name": "@edge-base/shared",
"exists": true,
"license": "MIT",
"keywords": [
"edgebase",
"shared",
"config",
"functions"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@edge-base/shared",
"is_deprecated": false,
"latest_version": "0.4.9",
"repository_url": "https://github.com/edge-base/edgebase",
"versions_count": 31,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 3819,
"first_published_at": "2026-03-18T10:49:05.882000Z",
"latest_published_at": "2026-07-17T00:19:30.752000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
},
{
"name": "create-edgebase",
"exists": true,
"license": "MIT",
"keywords": [
"edgebase",
"create-edgebase",
"scaffold",
"cli"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/create-edgebase",
"is_deprecated": false,
"latest_version": "0.4.9",
"repository_url": "https://github.com/edge-base/edgebase",
"versions_count": 32,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 2283,
"first_published_at": "2026-03-18T08:18:03.941000Z",
"latest_published_at": "2026-07-17T00:20:54.478000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
}
]
},
"popularity": {
"forks": 2,
"stars": 7,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-03-18",
"count": 1
},
{
"date": "2026-03-20",
"count": 1
}
],
"complete": true,
"collected": 2,
"total_forks": 2
},
"star_history": {
"days": [
{
"date": "2026-03-18",
"count": 4
},
{
"date": "2026-03-19",
"count": 1
},
{
"date": "2026-03-30",
"count": 1
},
{
"date": "2026-05-19",
"count": 1
}
],
"complete": true,
"collected": 7,
"total_stars": 7
},
"open_issues_and_prs": 9
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"example"
],
"has_llms_txt": true,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [
"packages/server/openapi.json"
],
"has_devcontainer": false,
"typecheck_configs": [
"docs/tsconfig.json",
"packages/admin/tsconfig.json",
"packages/cli/tsconfig.json",
"packages/plugins/core/tsconfig.json",
"packages/sdk/js/packages/admin/tsconfig.json",
"packages/sdk/js/packages/auth-ui-react/tsconfig.json",
"packages/sdk/js/packages/core/tsconfig.json",
"packages/sdk/js/packages/ssr/tsconfig.json",
"packages/sdk/js/packages/web/tsconfig.json",
"packages/sdk/js/tsconfig.json",
"packages/sdk/react-native/tsconfig.json",
"packages/server/tsconfig.json",
"packages/shared/tsconfig.json"
],
"toolchain_manifests": [
"packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj",
"packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj",
"packages/sdk/csharp/packages/core/EdgeBase.Core.csproj",
"packages/sdk/csharp/packages/unity/EdgeBase.Unity.csproj",
"packages/sdk/csharp/packages/unity/tests/EdgeBase.Unity.Tests.csproj",
"packages/sdk/csharp/src/EdgeBase.csproj",
"packages/sdk/csharp/tests/EdgeBase.Tests.csproj",
"packages/sdk/elixir/packages/admin/mix.exs",
"packages/sdk/elixir/packages/core/mix.exs",
"packages/sdk/go/go.mod",
"packages/sdk/java/build.gradle",
"packages/sdk/java/packages/admin/build.gradle",
"packages/sdk/java/packages/android/build.gradle",
"packages/sdk/java/packages/core/build.gradle",
"packages/sdk/kotlin/admin/build.gradle.kts",
"packages/sdk/kotlin/build.gradle.kts",
"packages/sdk/kotlin/client/build.gradle.kts",
"packages/sdk/kotlin/core/build.gradle.kts",
"packages/sdk/rust/Cargo.toml",
"packages/sdk/rust/packages/admin/Cargo.toml",
"packages/sdk/rust/packages/core/Cargo.toml",
"packages/sdk/scala/build.gradle.kts",
"packages/sdk/scala/packages/admin/build.gradle.kts",
"packages/sdk/scala/packages/core/build.gradle.kts"
],
"largest_source_bytes": 205754,
"source_files_sampled": 1183,
"oversized_source_files": 28,
"agent_instruction_files": [
"AGENT.md",
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 5111
},
"dependencies": {
"manifests": [
"docs/package.json",
"package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@edge-base/server",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@edge-base/shared",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "chalk",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.0"
},
{
"name": "commander",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.0"
},
{
"name": "esbuild",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^0.28.1"
},
{
"name": "jose",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
},
{
"name": "ora",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^9.3.0"
},
{
"name": "pg",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^8.16.3"
},
{
"name": "tsx",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^4.20.6"
},
{
"name": "ts-morph",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^27.0.2"
},
{
"name": "wrangler",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "4.103.0"
},
{
"name": "@edge-base/cli",
"manifest": "packages/create-edgebase/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@edge-base/core",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@edge-base/shared",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@hono/zod-openapi",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "^1.2.2"
},
{
"name": "@simplewebauthn/server",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "^10"
},
{
"name": "bcryptjs",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.3"
},
{
"name": "hono",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "4.12.25"
},
{
"name": "jose",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
},
{
"name": "pg",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "^8.16.3"
},
{
"name": "zod",
"manifest": "packages/server/package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.6"
},
{
"name": "tsx",
"manifest": "tools/sdk-codegen/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.0"
},
{
"name": "tsx",
"manifest": "tools/smoke-gen/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 8,
"merged_prs": 53,
"open_issues": 1,
"closed_ratio": 0.909,
"closed_issues": 10,
"closed_unmerged_prs": 10
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "melodysdreamj",
"commits": 243,
"avatar_url": "https://avatars.githubusercontent.com/u/21379657?v=4"
},
{
"type": "User",
"login": "edgebase1952",
"commits": 21,
"avatar_url": "https://avatars.githubusercontent.com/u/269032722?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.92
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"agent-skills-sync.yml",
"ci.yml",
"codeql.yml",
"go-split-sync.yml",
"npm-publish.yml",
"php-split-sync.yml",
"pipeline.yml",
"secret-scan.yml",
"semgrep.yml",
"swift-split-sync.yml",
"test.yml"
],
"has_docs_dir": true,
"linter_configs": [
"eslint.config.js"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"mix.lock",
"pnpm-lock.yaml",
"yarn.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 9,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/24 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 8,
"reason": "dependency not pinned by hash detected -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 8,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "30 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "38e0ba236bb395a079f0fc42ff1a513a710263a7",
"ran_at": "2026-07-21T16:42:00Z",
"aggregate_score": 7.3,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/edge-base/edgebase",
"host": "github.com",
"name": "edgebase",
"owner": "edge-base"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"security": 73,
"vitality": 81,
"community": 54,
"governance": 53,
"engineering": 72
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 81,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"commits_last_year": 397,
"human_commit_share": 0.93,
"days_since_last_push": 2,
"active_weeks_last_year": 7
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 2 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 2
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "7/52 weeks with commits",
"points": 4.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 7
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "397 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 397
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 16,
"latest_release_tag": "v0.4.9",
"releases_from_tags": false,
"days_since_latest_release": 4,
"mean_days_between_releases": 11
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "16 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 16
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 4 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 4
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~11 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 11
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 54,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"forks": 2,
"stars": 7,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "below_threshold"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "7 stars",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 7
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "2 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 2
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 68,
"inputs": {
"packages": [
"@edge-base/cli",
"@edge-base/server",
"@edge-base/shared",
"create-edgebase"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 11421
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "11,421 downloads/month across npm",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 11421,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 53,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 14,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.92
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 92% of commits",
"points": 1.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 92
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"merged_prs": 53,
"open_issues": 1,
"closed_issues": 10,
"issue_closed_ratio": 0.909,
"closed_unmerged_prs": 10
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "91% of issues closed",
"points": 42.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 91
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "53/63 decided PRs merged",
"points": 32.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 53,
"decided": 63
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/24 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 41,
"inputs": {
"followers": 2,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "edge-base",
"public_repos": 8,
"account_age_days": 128
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "2 followers of edge-base",
"points": 3.4,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 2,
"login": "edge-base"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "8 public repos, account ~0 yr old",
"points": 7.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 8
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@edge-base/cli",
"@edge-base/server",
"@edge-base/shared",
"create-edgebase"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 4
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "4 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 4,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 4 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 4
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "32 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 32
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 72,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "11 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 11
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.js",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 73,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 73,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 7.3
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/24 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 4,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "30 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 93,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"has_llms_txt": true,
"legible_history_share": 0.839,
"agent_instruction_files": [
"AGENT.md",
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 5111
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENT.md, AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENT.md, AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": "llms.txt present",
"points": 15,
"status": "met",
"details": [
{
"code": "llms_txt_present",
"params": {}
}
],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "78 of 93 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 78,
"sampled": 93
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"mix.lock",
"pnpm-lock.yaml",
"yarn.lock"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"docs/tsconfig.json",
"packages/admin/tsconfig.json",
"packages/cli/tsconfig.json",
"packages/plugins/core/tsconfig.json",
"packages/sdk/js/packages/admin/tsconfig.json",
"packages/sdk/js/packages/auth-ui-react/tsconfig.json",
"packages/sdk/js/packages/core/tsconfig.json",
"packages/sdk/js/packages/ssr/tsconfig.json",
"packages/sdk/js/packages/web/tsconfig.json",
"packages/sdk/js/tsconfig.json",
"packages/sdk/react-native/tsconfig.json",
"packages/server/tsconfig.json",
"packages/shared/tsconfig.json"
],
"agent_commit_share": 0.37,
"toolchain_manifests": [
"packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj",
"packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj",
"packages/sdk/csharp/packages/core/EdgeBase.Core.csproj",
"packages/sdk/csharp/packages/unity/EdgeBase.Unity.csproj",
"packages/sdk/csharp/packages/unity/tests/EdgeBase.Unity.Tests.csproj",
"packages/sdk/csharp/src/EdgeBase.csproj",
"packages/sdk/csharp/tests/EdgeBase.Tests.csproj",
"packages/sdk/elixir/packages/admin/mix.exs",
"packages/sdk/elixir/packages/core/mix.exs",
"packages/sdk/go/go.mod",
"packages/sdk/java/build.gradle",
"packages/sdk/java/packages/admin/build.gradle",
"packages/sdk/java/packages/android/build.gradle",
"packages/sdk/java/packages/core/build.gradle",
"packages/sdk/kotlin/admin/build.gradle.kts",
"packages/sdk/kotlin/build.gradle.kts",
"packages/sdk/kotlin/client/build.gradle.kts",
"packages/sdk/kotlin/core/build.gradle.kts",
"packages/sdk/rust/Cargo.toml",
"packages/sdk/rust/packages/admin/Cargo.toml",
"packages/sdk/rust/packages/core/Cargo.toml",
"packages/sdk/scala/build.gradle.kts",
"packages/sdk/scala/packages/admin/build.gradle.kts",
"packages/sdk/scala/packages/core/build.gradle.kts"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj, packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj, packages/sdk/csharp/packages/core/EdgeBase.Core.csproj (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj, packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj, packages/sdk/csharp/packages/core/EdgeBase.Core.csproj"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.js",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "docs/tsconfig.json, packages/admin/tsconfig.json, packages/cli/tsconfig.json, packages/plugins/core/tsconfig.json, packages/sdk/js/packages/admin/tsconfig.json, packages/sdk/js/packages/auth-ui-react/tsconfig.json, packages/sdk/js/packages/core/tsconfig.json, packages/sdk/js/packages/ssr/tsconfig.json, packages/sdk/js/packages/web/tsconfig.json, packages/sdk/js/tsconfig.json, packages/sdk/react-native/tsconfig.json, packages/server/tsconfig.json, packages/shared/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/tsconfig.json, packages/admin/tsconfig.json, packages/cli/tsconfig.json, packages/plugins/core/tsconfig.json, packages/sdk/js/packages/admin/tsconfig.json, packages/sdk/js/packages/auth-ui-react/tsconfig.json, packages/sdk/js/packages/core/tsconfig.json, packages/sdk/js/packages/ssr/tsconfig.json, packages/sdk/js/packages/web/tsconfig.json, packages/sdk/js/tsconfig.json, packages/sdk/react-native/tsconfig.json, packages/server/tsconfig.json, packages/shared/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "37 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 37,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "dependency automation configured, none observed in the sampled commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "dependency_bot_config_only",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 205754,
"source_files_sampled": 1183,
"oversized_source_files": 28
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "28/1183 source files over 60KB",
"points": 53.7,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 1183,
"oversized": 28
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"example"
],
"has_mcp_signal": false,
"api_schema_files": [
"packages/server/openapi.json"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "packages/server/openapi.json",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "packages/server/openapi.json"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "example",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "example"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"deps.dev does not index npm:@edge-base/cli@0.4.9; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-21T16:42:10.255297Z",
"schema_version": "0.23.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/edge-base/edgebase.svg",
"full_name": "edge-base/edgebase",
"license_state": "standard",
"license_spdx": "MIT"
}