Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-30 15:16 UTC

flarum / realtime

[READ ONLY] Subtree split of Flarum realtime extension.

PHP · TypeScriptKeine Lizenz erkannt★ 0 Sterne⑂ 0 Forksseit Dez. 2025Auf GitHub ansehen ↗

flarum/realtime erreicht einen Gesundheitsindex von 54 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (85/100) ab, am schwächsten bei Community & Adoption (32/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

54
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

54
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

FlarumOrganisation
798 Follower53 öffentliche Reposseit Sept. 2013

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
Packagistflarum/realtimev2.0.0-rc.52.68210vor 22 Tagenwebsocketextensionrealtimeflarumtyping-indicator

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

85Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
13.2/36Commit-Rhythmus — 19/52 Wochen mit Commits
15.9/18Commit-Volumen — 58 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year58
human_commit_share0,949
days_since_last_push0
active_weeks_last_year19

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 9 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 21 Tagen
27/27Release-Rhythmus — ein Release etwa alle 25 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count9
latest_release_tagv2.0.0-rc.5
releases_from_tagsnein
days_since_latest_release21
mean_days_between_releases25
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

32Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
0/22.5Lizenz — keine Lizenzdatei erkannt
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licensenein
has_contributingja
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templateja
Wie die Bewertung erfolgt
45.7/80Downloads pro Monat — 2.682 Downloads/Monat über packagist
7.2/20Abhängige in der Registry — 11 Pakete hängen davon ab
Verwendete Eingangsdaten
packagesflarum/realtime
dependents11
ecosystemspackagist
total_downloads9.498
monthly_downloads2.682

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

50Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
9.2/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 59 % der Commits
6.8/13.5Breite der Beitragenden — 5 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled5
top_contributor_share0,589
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
0/38.3PR-Annahme — keine entschiedenen Pull Requests oder keine Daten
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote, PR-Annahme. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
20.9/25Reichweite des Inhabers — 798 Follower von flarum
24.6/25Kontohistorie — 53 öffentliche Repos, Kontoalter ca. 12 Jahre
Verwendete Eingangsdaten
followers798
owner_typeOrganization
is_verified
owner_loginflarum
public_repos53
account_age_days4.690

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf packagist
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 22 Tagen
20/20Versionshistorie — 10 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesflarum/realtime
ecosystemspackagist
any_deprecatednein
min_days_since_publish22

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

43Gefährdet · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
6.4/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfigja
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

56Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
0/10Dangerous-Workflow — keine Daten
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Lizenz — license file not detected
7.5/7.5Maintained — 29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
0/5Pinned-Dependencies — keine Daten
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate5,6
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

55Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 55 von 56 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,982
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — js/tsconfig.json
0/10Reproduzierbare Umgebung
10/10Belegte Agentenpraxis — 3 der letzten 59 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 3 der letzten 59 Commits sind automatisierte Abhängigkeits-Updates
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfiles
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configsjs/tsconfig.json
agent_commit_share0,051
toolchain_manifests
dependency_bot_commit_share0,051
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Pinned-Dependencies. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
27/45Typprüfbarer Code — PHP mit Typprüfungs-Konfiguration (js/tsconfig.json)
55/55Handhabbare Dateigrößen — 0/125 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languagePHP
largest_source_bytes16.345
source_files_sampled125
oversized_source_files0

Eckdaten

0GitHub-Sterne
5Mitwirkende
58Commits, letzte 12 Monate
0Tage seit letztem Push
9Releases
1Bus-Faktor
0offene Issues
npm, PackagistPaket-Ökosysteme

Warnungen zur Datenerhebung

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 5.6 / 10
5.6Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-30 15:16 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
k. A.Dangerous-Workflowno workflows found
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
k. A.Pinned-Dependenciesno dependencies found
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Direkte Abhängigkeiten 5
RegistryPaketVersionsvorgabeManifest
Packagistflarum/core^2.0.0-rc.5composer.json
Packagistplesk/ratchetphpv1.0.4composer.json
Packagistpusher/pusher-php-server^7.2.0composer.json
npmlodash-es^4.18.1js/package.json
npmpusher-js^7.6.0js/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2073,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "PHP": 205019,
        "Less": 3171,
        "JavaScript": 53,
        "TypeScript": 67462
      },
      "pushed_at": "2026-07-30T15:10:34Z",
      "created_at": "2025-12-20T17:26:57Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-30T15:13:32Z",
      "description": "[READ ONLY] Subtree split of Flarum realtime extension. ",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "2.x",
      "license_spdx_raw": null,
      "primary_language": "PHP",
      "significant_languages": [
        "PHP",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "http://flarum.org",
      "name": "Flarum",
      "type": "Organization",
      "login": "flarum",
      "company": null,
      "location": null,
      "followers": 798,
      "avatar_url": "https://avatars.githubusercontent.com/u/5549034?v=4",
      "created_at": "2013-09-26T11:15:45Z",
      "is_verified": null,
      "public_repos": 53,
      "account_age_days": 4690
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.0.0-rc.5",
          "kind": "prerelease",
          "published_at": "2026-07-08T15:54:55Z"
        },
        {
          "tag": "v2.0.0-rc.4",
          "kind": "prerelease",
          "published_at": "2026-06-18T11:59:46Z"
        },
        {
          "tag": "v2.0.0-rc.3",
          "kind": "prerelease",
          "published_at": "2026-06-09T18:53:58Z"
        },
        {
          "tag": "v2.0.0-rc.2",
          "kind": "prerelease",
          "published_at": "2026-06-01T18:17:58Z"
        },
        {
          "tag": "v2.0.0-rc.1",
          "kind": "prerelease",
          "published_at": "2026-04-20T10:23:52Z"
        },
        {
          "tag": "v2.0.0-beta.8.1",
          "kind": "prerelease",
          "published_at": "2026-03-23T08:22:02Z"
        },
        {
          "tag": "v2.0.0-beta.7",
          "kind": "prerelease",
          "published_at": "2026-02-22T17:16:13Z"
        },
        {
          "tag": "v2.0.0-beta.6",
          "kind": "prerelease",
          "published_at": "2026-01-30T09:24:44Z"
        },
        {
          "tag": "2.0.0-beta.5",
          "kind": "prerelease",
          "published_at": "2025-12-20T22:35:39Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a6e19d5828b23306e6c58a1926f7572f2c5b38e8",
          "body": "…858)\n\nThe mapping pointed at a nonexistent directory, so any future\next:flarum/flags import in realtime would fail check-typings with TS2307.\nPoint it at the flags extension's actual dist-typings, matching how\nsticky/tags map ext:flarum/realtime.",
          "is_bot": false,
          "headline": "chore(ts): fix ext:flarum/flags typings path in realtime tsconfig (#4…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-07-30T12:38:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efd58e48511373da61fc7d538cd1175612042eeb",
          "body": "AbstractJob::$onQueue was a static property on the base class. A subclass\nthat does not redeclare a static shares its parent's storage, so routing two\njob classes made the last assignment win for both — silently mis-routing jobs.\n(This pattern dates back to 1.x's $sendOnQueue.)\n\nRoute jobs by class \n[…]\n'instanceof DatabaseQueue' checks unwrap via getDriver().\n\nRemoves AbstractJob::$onQueue; migrates the GDPR and Realtime extensions.\nBreaking: code setting $onQueue must move to Extend\\Queue::route().",
          "is_bot": false,
          "headline": "Route queued jobs at push time via a queue-connection wrapper (#4853)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-07-29T14:17:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2231e0672ff0a088c8cfe7a13bb6a2c636a39830",
          "body": "* docs: add changelog for 2.0.0-rc.5\n\n* docs: add #4806 to rc.5 changelog\n\n* docs: add #4807 to rc.5 changelog\n\n* chore: bump version and dependency constraints to 2.0.0-rc.5",
          "is_bot": false,
          "headline": "[2.x] chore: prepare 2.0.0-rc.5 (#4805)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-07-08T15:08:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f10ba82f85ef549566c65e35838b9ad158e9f059",
          "body": "…e (#4801)\n\nThe monorepo is a Yarn workspaces setup (framework/*/js, extensions/*/js,\njs-packages/*), so the root yarn.lock is authoritative for every workspace\nmember. Every other extension (tags, likes, mentions, flags, ...) correctly\nhas no lockfile of its own.\n\nextensions/gdpr/js and extensions/\n[…]\n A root `yarn install` leaves the root yarn.lock unchanged\n(gdpr/realtime were already resolved as workspace members) and both\nextensions build unchanged, confirming these locks were purely redundant.",
          "is_bot": false,
          "headline": "chore(deps): remove redundant nested yarn.lock files for gdpr/realtim…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-07-07T21:51:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8f30d73fb7c865ac3592577c8746dc0e750a66a",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 036e345e4db3e4b3b0fc1b1a577dff336bf07eab",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-07-07T18:19:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c32cc7c0d88d7c7665864258b7512aa3d83e2864",
          "body": "…h up missed events (#4718)\n\nWebKit suspends hidden pages on desktop Safari just like on iOS, so the\nWebSocket dies silently (often without `close`) while pusher-js's\nforeground-only activity timers cannot notice. The visibilitychange\nrecovery from #4590/#4654 was gated to isIOS() by #4662 and never\n[…]\nbound — and capture end-ness in NewActivity before pushing event\n  payloads, so a gap no longer permanently disables live-append.\n\nFixes #4717.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(realtime): recover desktop tabs after silent socket loss and catc…",
          "author_name": "ekumanov",
          "author_login": "ekumanov",
          "committed_at": "2026-07-07T18:13:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56c7010b172246642e692e782a3b323dbfd314f5",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 63f302e650835977b63df9f5560f079fef2e5796",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-06-17T23:28:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e21ac5a8b0f91fc11e44f2cc7099035b400940c",
          "body": "…st (#4756)\n\n* feat(realtime): ambient typing dots on the index sidebar tag list\n\nExtend the discussion-list ambient typing indicator to the tag list: a tag\nlights up while someone is typing in a discussion carrying it, or composing\na new discussion in it.\n\nBackend (IndexTypingPresence):\n- The index\n[…]\nng channels, subscriptions and dot styling; no\nnew admin settings (the existing public/restricted toggles gate it).\n\n* Apply fixes from StyleCI\n\n---------\n\nCo-authored-by: StyleCI Bot <bot@styleci.io>",
          "is_bot": false,
          "headline": "[2.x] feat(realtime): ambient typing dots on the index sidebar tag li…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-17T23:24:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45c0690b453f7d0d913c25adc00ea11e614526fb",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 6808fc6713fac7df93cf58a867bf6235ac41fe34",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-06-17T16:18:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0d872907b53f408e6ae568cd0f6c4571bbdb07e",
          "body": "…ated (#4752)\n\n* feat(core, realtime): notify browsing users when assets are updated\n\nWhen the forum's JS/CSS is recompiled (extension toggle, cache clear) or a new\ndeployment rolls out, a user already on the page has stale assets until they\nreload. This adds a prompt to reload, delivered two ways:\n\n[…]\new public ForumApplication.checkAssetsRevision().\n- Raise the core JS bundle budget to 160KB; admin.js was already at the 150KB\n  ceiling and this feature's small common-code additions tipped it over.",
          "is_bot": false,
          "headline": "[2.x] feat(core, realtime): notify browsing users when assets are upd…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-17T16:14:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "148dbb5092d3163fe0c91d1ef0317362f805f5da",
          "body": null,
          "is_bot": false,
          "headline": "chore: prep 2.0.0-rc.4 (#4741)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-16T10:05:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "450f1e00db95a468c179bd681d4221b542e20697",
          "body": "Client-originated websocket events were rebroadcast to the channel named\nin the payload without checking the sender. Restrict relaying to client-\nprefixed events on private/presence channels the sender is subscribed to,\nand reject channel subscriptions that present no auth signature.",
          "is_bot": false,
          "headline": "fix(realtime): only relay client events to subscribed channels (#4738)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-15T22:00:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35a1fd39f3a6204f4f30d809bb202db33d1c2b4f",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit e66bb68892a09f929bbeadd9c9011027a23d873b",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-06-13T23:00:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dd6ef26b1afe51c6d8db245e1a38b1b16e5e936",
          "body": "…t (#4731)\n\n* feat(realtime): ambient typing dots on the discussion list\n\nShow a presence-only \"someone is typing here\" dot on discussion list\nrows, fed by a single shared public channel rather than per-discussion\nsubscriptions, so cost stays bounded by viewers (not viewers x\ndiscussions) at any sca\n[…]\n-> 403) and the\n  settings-change restart signal (realtime key -> signaled, other -> not).\n- Ignore .phpunit.cache.\n\n* Apply fixes from StyleCI\n\n---------\n\nCo-authored-by: StyleCI Bot <bot@styleci.io>",
          "is_bot": false,
          "headline": "[2.x] feat(realtime): ambient typing indicators on the discussion lis…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-13T22:56:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3dd1475a508e5b679668b4de735124bc8144dd9f",
          "body": null,
          "is_bot": false,
          "headline": "chore: provide realtime docs link (#4722)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-12T21:22:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f2949c4d8995fede3c55ae176abe302f6d55461",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 952a324e1f477af8424bc6e0b91284080852280a",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-06-12T21:11:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5337aaae7a037086d65684e902ed5ce34ebe4925",
          "body": "Extract the typing indicator into a standalone TypingIndicator component\nbacked by a TypingState, stored on the discussion model as\ndiscussion.typingState. It is added to PostStream endItems under the name\ntypingIndicator, so themes and extensions can remove it and render a fresh\ncomponent elsewhere without relocating a keyed vnode (which threw Mithril\nkeyed/unkeyed fragment errors).\n\nFixes #4619",
          "is_bot": false,
          "headline": "fix(realtime): make the typing indicator reusable and movable (#4721)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-12T21:07:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2faac66540f55f6eb55bb3854280a3c7c5687d0f",
          "body": "… it (#4713)\n\n* [2.x] fix(realtime): broadcast the notification the blueprint produced, not the latest of its type\n\nSendNotificationsJob selected a recipient's newest notification of the blueprint's type via ->latest(), so when a user had multiple notifications of the same type the toast could surfa\n[…]\noast. The listener now matches on the fired blueprint via a single batched\nquery, so the row is guaranteed present.\n\n* Apply fixes from StyleCI\n\n---------\n\nCo-authored-by: StyleCI Bot <bot@styleci.io>",
          "is_bot": false,
          "headline": "fix(realtime): show the correct notification toast, and stop dropping…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-12T16:25:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4067a179c02ecf09ce4016df5838e8016568efb3",
          "body": "* chore: prep rc.3\n\n* chore: bump composer reqs",
          "is_bot": false,
          "headline": "chore: prep `2.0.0-rc.3` (#4698)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-06-09T12:39:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1056acf48af35c521ae50ef9cf69982116da2c9",
          "body": null,
          "is_bot": false,
          "headline": "chore: prep rc2 (#4676)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-05-30T22:29:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fad7d81911149c2e6953f25cfb10aecca3c38b62",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 1932e3ecfa0093f723540e94070142458fbad77e",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-05-13T22:07:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "385487481087f543b55a9ceaf8bb495be3ca4a3e",
          "body": "…662)\n\nPR #4654 added a `visibilitychange` listener that forces a fresh\nPusher instance and refreshes the visible discussion list whenever\nthe tab has been hidden for >5s. That was needed on iOS Safari,\nwhere backgrounding the page silently drops the WebSocket without\nfiring `close`. On every other \n[…]\nowsers use WebKit and share the same\nbackgrounding pathology — iOS Chrome (`CriOS`) and iOS Firefox\n(`FxiOS`) are excluded by `isSafariMobile()` but still need this\nworkaround.\n\nRegression from #4654.",
          "is_bot": false,
          "headline": "[2.x] fix(realtime): only force-reconnect on iOS visibilitychange (#4…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-05-13T22:03:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85efc4e40f24e7424d5100253a8bae75d37671df",
          "body": "…656)\n\n* [2.x] feat(queue): restore per-class queue routing on AbstractJob\n\nReintroduces the `$onQueue` static property + constructor that 1.x jobs\nrelied on for per-class queue routing. Without this, operators have no\nbuilt-in way to send a specific job class to a dedicated queue without\npatching e\n[…]\nr from\n`Flarum\\Realtime\\Push\\Jobs\\Job` — both are now provided by the base\nclass.\n\nIf we're restoring the convention, the standard library should lead\nby example: every shipped job should be routable.",
          "is_bot": false,
          "headline": "[2.x] feat(queue): restore per-class queue routing on AbstractJob (#4…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-05-12T20:33:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed5de942e5cb3654231d33413d912905e895d80a",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 0c4164358c92887727dfdf7a05ce9bb29a47825e",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-05-12T20:13:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "269d96f9565f68767bd2a3ccdb5e4cbc9393b70f",
          "body": "…ves:2 budget (#4654)\n\n* fix(realtime): reconstruct Pusher on iOS reconnect to bypass pusher-js lives:2 kill-switch\n\nPR #4590 fixed the first iOS Safari backgrounding cycle, but the second\ncycle silently dies because pusher-js 7.6's default strategy enforces a\n`lives: 2` budget on its WebSocket tran\n[…]\ne new\n  `RealtimeState.onChannelsReconnected(...)` hook and release it in\n  `onremove`.\n\nCloses #4597.\n\n* Bundled output for commit 63e0b7866874c01017747092052bfdf4584a5e2f\n\nIncludes transpiled JS/TS.",
          "is_bot": false,
          "headline": "[2.x] fix(realtime): reconstruct Pusher on iOS reconnect to bypass li…",
          "author_name": "ekumanov",
          "author_login": "ekumanov",
          "committed_at": "2026-05-12T20:09:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "679a9e90af7496746ae5eb4d95d819988f5a1519",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 413811241472210ab681381ad546542df08e6b81",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-05-09T05:57:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28fbb529c0f8ad4fb8f15fff1e47624e259e5e0f",
          "body": "…r iOS Safari backgrounding (#4590)\n\n* fix(realtime): reconnect WebSocket and catch up on missed events after iOS Safari backgrounding\n\niOS Safari silently drops WebSocket connections when the tab is backgrounded\nor the device sleeps; no `close` event fires, so pusher-js's built-in recovery\nnever tr\n[…]\nresubscription on the new socket and leaves the\nclient receiving no further push events.\n\nFixes #4588.\n\n* Bundled output for commit 8014091e44ebafea21a1e6fb05fd2d5afac3b011\n\nIncludes transpiled JS/TS.",
          "is_bot": false,
          "headline": "fix(realtime): reconnect WebSocket and catch up on missed events afte…",
          "author_name": "ekumanov",
          "author_login": "ekumanov",
          "committed_at": "2026-05-09T05:52:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6483cdada557516799a1a1b7115bea48cc62273",
          "body": "Eloquent's oldest() defaults to a created_at column, but Flarum's users\ntable uses joined_at. The realtime:info command failed with\n\"Unknown column 'created_at' in 'order clause'\".\n\nPass 'joined_at' explicitly to match the schema.\n\nFixes #4617",
          "is_bot": false,
          "headline": "fix(realtime): order users by joined_at in realtime:info (#4630)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-05-06T19:10:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d485768c100203d47d6b45f9a3d7599475e048b2",
          "body": null,
          "is_bot": false,
          "headline": "fix: cast boolean correctly (#4624)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-05-05T14:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3758252e70c9765a2e6f2cd2f426364255b80420",
          "body": null,
          "is_bot": false,
          "headline": "chore: prep rc.1 (#4581)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-04-17T12:43:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa73515cfeeab14dc909edbd97e0336e4e07737d",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 5c5e3ef24be8c691642846723752e48eeef78973",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-04-15T11:19:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06b053c3a97736ffd7e0efead24aa2bc5a62ea66",
          "body": "…573)\n\nAdds `Realtime::authorizePresenceChannel()` to the extender, allowing\nextensions to register per-channel callbacks that gate access to\npresence channel authentication. Closes #4572.",
          "is_bot": false,
          "headline": "feat(realtime): add extension hook to authorize presence channels (#4…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-04-15T07:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77c6b6ba98adbab58b0e167f79de2a2400796026",
          "body": "Bumps [lodash-es](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.\n- [Release notes](https://github.com/lodash/lodash/releases)\n- [Commits](https://github.com/lodash/lodash/compare/4.17.23...4.18.1)\n\n---\nupdated-dependencies:\n- dependency-name: lodash-es\n  dependency-version: 4.18.1\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump lodash-es from 4.17.23 to 4.18.1 (#4517)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-03T12:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aca9d01c582f8c2ce32dd0c4b4af04d69443db52",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 9dc734fef416430932e142caf89fd77f179a79e8",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-03-23T08:19:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9a6fbfb49e38e7180a557cedf4cfb4cf82eb129",
          "body": "…ionToastState (#4500)",
          "is_bot": false,
          "headline": "fix(realtime): guard against undefined app.data.settings in Notificat…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-23T08:15:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f5c4233803714e3ed64ac2858512fdc6ebcf7df",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 186629ca0fd5e797b9a0df34da345b9e43d99309",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-03-22T20:17:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0240566e55281bba01631531187e5dc762c5d78",
          "body": "Replaces the hardcoded 5s dismiss timeout with an admin setting\n(flarum-realtime.notification-toast-dismiss-after), defaulting to 10s.\nSetting the value to 0 disables toast notifications entirely.",
          "is_bot": false,
          "headline": "feat(realtime): make notification toast duration configurable (#4497)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-22T20:14:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "752b8eea2bcbed0c5cf6b49831aa80f692b43d51",
          "body": "* prep for beta.8\n\n* chore: update changelog for beta.8 (#4480, #4481)",
          "is_bot": false,
          "headline": "[2.x] prep for beta.8 (#4478)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-21T22:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a3e7213865addab1ad23b765b6df09dfabfe76b",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 32d9e125da4007dfcaec7650ef2e8aacc18a75ce",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-03-21T22:31:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "443aa43bcc467d0ff7cf7f117f720c0d33501276",
          "body": "…(#4481)\n\nThe DiscussionList-update banner was broken in two ways:\n\n1. The `Button--block` CSS class no longer exists after d2129e63\n   converted it to a parametric LESS mixin. Add `.Button--block()` to\n   `.DiscussionList-update` in forum.less so the button gets\n   `display: flex; width: 100%` agai\n[…]\nks to IndexPage, which is the correct owner since the banner is\n   a page-level concern. Remove the dead `this.addDiscussion` method\n   that was assigned in oninit but never wired to an extend() call.",
          "is_bot": false,
          "headline": "fix(realtime): restore full-width banner and move state to IndexPage …",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-21T22:27:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a49f272547344a1b1f588d4509271e22557eb58d",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit cd4316aac500c74eb8a7bab6d2bff68d42769002",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-03-21T00:01:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9888806e123eec71a81a203fb1d162500a4ca990",
          "body": "…fication toasts (#4473)\n\n* [2.x] feat: realtime extender API + per-extension integrations + notification toasts\n\nIntroduces a `Realtime` extender so each bundled extension wires its own\nrealtime behaviour without realtime having hardcoded knowledge of them.\n\n**flarum/realtime**\n- New `Realtime` PHP\n[…]\nnList/NewActivity,\n  Discussion/NewActivity, and Discussion/TypingIndicator\n\n* chore: remove premium/commercial references from realtime README\n\n---------\n\nCo-authored-by: StyleCI Bot <bot@styleci.io>",
          "is_bot": false,
          "headline": "[2.x] feat: realtime extender API + per-extension integrations + noti…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-20T23:58:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "898ddbd450ac1e42e008f661eed16410c2f770e1",
          "body": "… 3-section sidebar (#4446)\n\n* revert(admin): remove collapsible extension categories, restore 3-section sidebar\n\nThe collapsible category groups introduced in #4392 added too much\nfriction — everything collapsed by default, count badges read like\nnotification counts, and single-item categories (Inf\n[…]\nrestoring\n\"feature\" keeps the data consistent with the rendering logic.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "[2.x] revert(admin): remove collapsible extension categories, restore…",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-14T22:59:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "49c494ebb845f0e6f40a294dd8d206eccec3385d",
          "body": "…abandoned package support (#4392)\n\n* feat(admin): collapsible extension categories, health widget, abandoned package support\n\n- AdminNav: replace static category headers with collapsible groups; each group\n  shows a count badge, category icon, and expand/collapse chevron. Categories\n  default to co\n[…]\ning directly to an\nextension URL (e.g. /admin#/extension/flarum-flags).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "[2.x] feat(admin): collapsible extension categories, health widget & …",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-03-02T06:56:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8cf3263e8a41e434611d91bf40d47d247e252d51",
          "body": null,
          "is_bot": false,
          "headline": "chore: prep for beta.7 (#4377)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-02-21T13:40:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "583034aec33ffb03be8a99bc717d610b22f46888",
          "body": null,
          "is_bot": false,
          "headline": "fix: error when post is not available due to visibility (#4369)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-02-20T16:32:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1c843130005f5f4f4b48fba602f5fa6dfd01eb3",
          "body": null,
          "is_bot": false,
          "headline": "fix: dont use raw db query when bound to external settings cache (#4367)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-02-20T00:28:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e4a11ce29b2c5fbb5843d142009adff405085f9",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 6402e639bb64b06ecdc92ea69e6dacb3655504f7",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2026-02-15T21:46:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ce1bb1b197b30efb78606c30d477ab838e231c",
          "body": "Bumps [webpack](https://github.com/webpack/webpack) from 5.101.0 to 5.104.1.\n- [Release notes](https://github.com/webpack/webpack/releases)\n- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/webpack/webpack/compare/v5.101.0...v5.104.1)\n\n---\nupdate\n[…]\nency-version: 5.104.1\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump webpack in /extensions/realtime/js (#4356)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-15T21:41:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "665467fbbf4c18dd29786af3bf6e300e2ec605eb",
          "body": "Bumps [lodash-es](https://github.com/lodash/lodash) from 4.17.21 to 4.17.23.\n- [Release notes](https://github.com/lodash/lodash/releases)\n- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23)\n\n---\nupdated-dependencies:\n- dependency-name: lodash-es\n  dependency-version: 4.17.23\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump lodash-es from 4.17.21 to 4.17.23 (#4344)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-01-24T13:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "323bb9a68323f2546f06220719bbe97cd7959761",
          "body": null,
          "is_bot": false,
          "headline": "chore: prep for beta.6 (#4343)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2026-01-24T08:00:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e584a98284c62915a3d5cd434bc93f11e5de8046",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 9c1f2ff5ea7a436cefdee69d55adba3a2edbf0f3",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2025-12-29T21:34:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37b1f8c5bf0fb8b2faa4922746c71230133564a4",
          "body": "…g could not work (#4320)\n\n* Update NewActivity.js\n\n* format",
          "is_bot": false,
          "headline": "[2.x] [realtime] Fixed an issue where tag-specified discussion pushin…",
          "author_name": "EdgeInfinity",
          "author_login": "edgeinfinity1",
          "committed_at": "2025-12-29T21:31:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0c7121aafe205b100028b0b34b7ebc1bc35962f",
          "body": "…replies (#4319)\n\n* modified:   extensions/realtime/src/Push/Payload/Generator.php\n\n* format\n\n* format",
          "is_bot": false,
          "headline": "[2.x] [realtime] Fixed an issue causing \"likes\" out of sync after 20 …",
          "author_name": "EdgeInfinity",
          "author_login": "edgeinfinity1",
          "committed_at": "2025-12-24T16:04:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c86104fdb6c8c77ee693624d69629ddff7ec51ff",
          "body": null,
          "is_bot": false,
          "headline": "chore: prep for beta.5 (#4313)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2025-12-20T10:31:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7a7dc5e43ef32950299f3c74a0086c237684c8b",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit 73f9e33a582ef94035c91572749082968fe1e2d1",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2025-12-19T21:43:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a543a58f1700f25382281491b2f226474843f2d3",
          "body": null,
          "is_bot": false,
          "headline": "fix: realtime dist being ignored (#4307)",
          "author_name": "IanM",
          "author_login": "imorland",
          "committed_at": "2025-12-19T21:36:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68bdd7ddfbde8bf2887180aff064ac9c68b3854a",
          "body": "Includes transpiled JS/TS, and Typescript declaration files (typings).\n\n[skip ci]",
          "is_bot": false,
          "headline": "Bundled output for commit c6a90ada34b24d481b2fe83f415ab71189dc083c",
          "author_name": "flarum-bot",
          "author_login": "flarum-bot",
          "committed_at": "2025-12-13T09:30:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6768bae24742a7b75a39b755095e87da8da8cf7",
          "body": "* feat: donating Realtime to Flarum Foundation\n\ntodo:\n\n- migrate settings\n- mark blomstra/realtime as superseded\n- check js and functionality\n- optionally add tests\n\n* Apply fixes from StyleCI\n\n* chore: js changes\n\n* chore: continue adapting to framework\n\n* chore: update framework composer.json\n\n* c\n[…]\nStyleCI\n\n* chore: cleanup composer.json\n\n---------\n\nCo-authored-by: StyleCI Bot <bot@styleci.io>\nCo-authored-by: IanM <ian@morland.me>\nCo-authored-by: IanM <16573496+imorland@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: donating Realtime to Flarum Foundation (#4295)",
          "author_name": "Daniël Klabbers",
          "author_login": "luceos",
          "committed_at": "2025-12-13T09:27:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 9,
      "commits_last_year": 58,
      "latest_release_at": "2026-07-08T15:54:55Z",
      "latest_release_tag": "v2.0.0-rc.5",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 19,
      "days_since_latest_release": 21,
      "mean_days_between_releases": 25
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "flarum/realtime",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "websocket",
            "extension",
            "realtime",
            "flarum",
            "typing indicator"
          ],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/flarum/realtime",
          "is_deprecated": false,
          "latest_version": "v2.0.0-rc.5",
          "repository_url": "https://github.com/flarum/realtime",
          "versions_count": 10,
          "total_downloads": 9498,
          "dependents_count": 11,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2682,
          "first_published_at": null,
          "latest_published_at": "2026-07-08T15:08:06Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 22
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "js/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 16345,
      "source_files_sampled": 125,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json",
        "js/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "packagist"
      ],
      "dependencies": [
        {
          "name": "flarum/core",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.0.0-rc.5"
        },
        {
          "name": "plesk/ratchetphp",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "v1.0.4"
        },
        {
          "name": "pusher/pusher-php-server",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.2.0"
        },
        {
          "name": "lodash-es",
          "manifest": "js/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.1"
        },
        {
          "name": "pusher-js",
          "manifest": "js/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.6.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "imorland",
          "commits": 33,
          "avatar_url": "https://avatars.githubusercontent.com/u/16573496?v=4"
        },
        {
          "type": "User",
          "login": "flarum-bot",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/39334649?v=4"
        },
        {
          "type": "User",
          "login": "ekumanov",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/24654623?v=4"
        },
        {
          "type": "User",
          "login": "edgeinfinity1",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/133833590?v=4"
        },
        {
          "type": "User",
          "login": "luceos",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/504687?v=4"
        }
      ],
      "contributors_sampled": 5,
      "top_contributor_share": 0.589
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a6e19d5828b23306e6c58a1926f7572f2c5b38e8",
        "ran_at": "2026-07-30T15:16:24Z",
        "aggregate_score": 5.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-30T15:10:35Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/flarum/realtime",
    "host": "github.com",
    "name": "realtime",
    "owner": "flarum"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 54,
      "inputs": {
        "security": 56,
        "vitality": 85,
        "community": 32,
        "governance": 50,
        "engineering": 43
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 85,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "commits_last_year": 58,
              "human_commit_share": 0.949,
              "days_since_last_push": 0,
              "active_weeks_last_year": 19
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "19/52 weeks with commits",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 19
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "58 commits in the last year",
                "points": 15.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 58
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 9,
              "latest_release_tag": "v2.0.0-rc.5",
              "releases_from_tags": false,
              "days_since_latest_release": 21,
              "mean_days_between_releases": 25
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "9 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 21 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~25 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 25
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 32,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "packages": [
                "flarum/realtime"
              ],
              "dependents": 11,
              "ecosystems": "packagist",
              "total_downloads": 9498,
              "monthly_downloads": 2682
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,682 downloads/month across packagist",
                "points": 45.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2682,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "11 packages depend on it",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 50,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 5,
              "top_contributor_share": 0.589
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 59% of commits",
                "points": 9.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 59
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "5 contributors",
                "points": 6.8,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "followers": 798,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "flarum",
              "public_repos": 53,
              "account_age_days": 4690
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "798 followers of flarum",
                "points": 20.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 798,
                      "login": "flarum"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "53 public repos, account ~12 yr old",
                "points": 24.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 53
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 12
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "flarum/realtime"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 22
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 22 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 22
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "10 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 43,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 5.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 55,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.982,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "55 of 56 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 55,
                      "sampled": 56
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "js/tsconfig.json"
              ],
              "agent_commit_share": 0.051,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.051
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "js/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "js/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "3 of the last 59 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 3,
                      "sampled": 59
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 59 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 59
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 16345,
              "source_files_sampled": 125,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP with type-check config (js/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "js/tsconfig.json",
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/125 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 125,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T15:16:32.448863Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/flarum/realtime.svg",
  "full_name": "flarum/realtime",
  "license_state": "absent",
  "license_spdx": null
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenPackagist.