JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [
"agent-orchestration",
"bun",
"mcp",
"opencode",
"plugin",
"typescript"
],
"is_fork": false,
"size_kb": 671,
"has_wiki": false,
"homepage": "https://www.npmjs.com/package/@fro.bot/space-bus",
"languages": {
"CSS": 9461,
"TypeScript": 676331
},
"pushed_at": "2026-07-25T03:51:27Z",
"created_at": "2026-07-03T01:21:11Z",
"owner_type": "User",
"updated_at": "2026-07-24T06:06:47Z",
"description": "Space Bus — workspace agent bus for OpenCode. One control agent tasking per-project agents over the OpenCode server API, with an MCP facade for Claude Desktop.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "fro.bot",
"name": "Fro Bot",
"type": "User",
"login": "fro-bot",
"company": null,
"location": null,
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/80104189?v=4",
"created_at": "2021-03-05T11:46:20Z",
"is_verified": null,
"public_repos": 7,
"account_age_days": 1967
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2026-07-19T08:38:41Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2026-07-18T18:34:56Z"
},
{
"tag": "v0.13.1",
"kind": "patch",
"published_at": "2026-07-13T08:21:20Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-07-13T05:24:16Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-07-12T08:12:51Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2026-07-11T23:12:18Z"
},
{
"tag": "v0.10.1",
"kind": "patch",
"published_at": "2026-07-11T20:27:22Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-07-11T17:05:47Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-07-11T03:11:19Z"
},
{
"tag": "v0.8.1",
"kind": "patch",
"published_at": "2026-07-10T23:42:06Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-07-10T21:45:41Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-07-06T05:12:04Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-07-05T19:20:01Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-07-05T13:38:57Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-07-04T18:44:36Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-07-04T15:32:14Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-07-04T15:04:08Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-07-04T14:02:43Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-07-04T02:57:01Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-07-04T00:21:24Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-07-03T20:17:25Z"
}
],
"recent_commits": [
{
"oid": "7fa38ad1023c9adbca43fd05fb22add34ef0bc3b",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#114)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-19T08:37:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5f0a3aa261cce593a4148371412963c335f2e7ce",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(dev): update dependency @changesets/cli to v2.31.1 (#108)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-19T08:30:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe0cc42fbd11c201edfd0d11319ba5b07007ea0a",
"body": "caller-generated OpenCode message IDs plus typed partial-failure handles enable safe reconciliation",
"is_bot": false,
"headline": "feat: add dispatch message correlation (#113)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-19T08:16:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "747d33745ca613c634e73987a0434036fbe2e989",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(dev): update dependency @opencode-ai/plugin to v1.17.19 (#105)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-18T19:55:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "303e8a9d6083f18a5d9d3138f1162fb5b29f84f4",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update bfra-me/.github to v4.16.37 (#103)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-18T18:54:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9aede7357762cd63a47348c64b101d0111f7615b",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update GitHub Actions (#101)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-18T18:47:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "778311fed4f513d8690d21b0003972339dd4d896",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#111)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-18T18:33:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "88023385c852c10557bfb8c14bb240b034a4a12e",
"body": "Add bounded message reads, structured pending-question access, and explicit question replies with validation. Extend dispatch with a safe fail-closed blocked mode that returns blocked state instead of mutating when policy is set, while preserving default question-reply behavior.",
"is_bot": false,
"headline": "feat: add explicit session interaction APIs (#109)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-18T18:30:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f59950560d52830934f217c98e6c0876a7377680",
"body": "Pass explicit --config via resolveRosterPath override instead of mutating process.env.SPACE_BUS_CONFIG.\n\nAdd regression tests in cli/config to pin behavior: --config resolves only for that invocation, keeps SPACE_BUS_CONFIG precedence/isolation intact when pre-set, and leaves ambient env untouched after command parsing.",
"is_bot": false,
"headline": "fix: avoid leaking CLI roster config (#110)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-18T18:19:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e20e01775918a01855eb5aba64d04bf966f4d51",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.88.0 (#98)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-13T21:09:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "387f9c8df8ff7a184d237608b277deaa4603238c",
"body": "chore: load local development plugin",
"is_bot": false,
"headline": "chore: load the local development plugin (#99)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-13T09:26:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98c6a29fcb13c959c4068b1cd4feacbf1cb4d4aa",
"body": "docs: capture MCP response-envelope contract",
"is_bot": false,
"headline": "docs: document MCP response-envelope contract (#97)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-13T09:09:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fbd1109521a332a96b20da5ffeea3d9938db4fcb",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#96)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-13T08:19:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b35b8394bfc51d48856cf6c1e35b1eb9393cf21a",
"body": "fix(mcp): return structured registry mutation results",
"is_bot": false,
"headline": "fix(mcp): preserve successful registry mutations (#95)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-13T08:17:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "69c1cec5af7b6430242969b5a8a136107e02ff31",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#91)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-13T05:22:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "721000dc4335c00a7c0b7c213eca38cd30dbdaa1",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(dev): update dependency @opencode-ai/plugin to v1.17.16 (#85)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-13T05:20:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8dc0794ddbe012dd6df45514c0ade79f655d07b1",
"body": null,
"is_bot": false,
"headline": "ci(renovate): skip artifacts update for bun and npm (#92)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-13T05:07:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e954643a75559570fc417b42a29d5444e63b8ead",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.87.1 (#94)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-13T04:21:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37b5adecbff361bf113f7619064453d065731f05",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.87.0 (#90)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-13T03:20:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d475e91bdf25774fc23034a4830beafb8a5180f1",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update bfra-me/.github to v4.16.36 (#89)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-12T23:11:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7444781080cc74ba6f777976da2a55566c588c1e",
"body": "…session default (Phase B) (#88)\n\n* feat: per-call roster addressing — registry loader + roster param + result echo\n\n* feat: bus_registry management tool + MCP session default\n\n* chore: changeset for multi-roster addressing (Phase B)\n\n* fix: apply Phase B review findings — once-resolved paths, strict actions, session hygiene, registry-default routing\n\n* fix: build plugin-facing bus_registry args with tool.schema (zod version reconciliation)",
"is_bot": false,
"headline": "feat: multi-roster addressing — roster param, bus_registry tool, MCP …",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-12T22:40:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05aa9f7c8d2370f42dc5d61c57a7802f43e83d9c",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#87)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-12T08:11:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "989797672d4d65fbc3df1ff75978b12cd3f2af79",
"body": "…ubpath (#86)\n\n* docs: multi-roster support brainstorm + plan\n\n* feat: roster registry — schema, node module, test isolation\n\n* feat: roster mutation module — create/edit spacebus.json\n\n* feat: discovery rosterPath + /registry library subpath\n\n* chore: changeset for multi-roster substrate (minor)\n\n*\n[…]\n because ensureServer had keyed its state dir/discovery\n write off the uncanonicalized symlink path instead). Restored the fix\n immediately after confirming.\n\n* docs: check off Phase A units in plan",
"is_bot": false,
"headline": "feat: multi-roster substrate — registry, mutation module, /registry s…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-12T07:44:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c1264a93219d4731c79377350acb9669c1125567",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.85.1 (#76)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-12T05:26:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "033db105310789e56e18fae822e1995ada545c79",
"body": "docs: compound service-persistence learnings (launchd env, TOCTOU, probe fallback)\n\nThree learnings from the 0.11.0 service-persistence arc (#80):\n- new: pin ambient env (PATH + XDG_STATE_HOME) into generated launchd units\n — launchd's sparse env breaks shim-resolved binaries and splits state roots\n[…]\nx lstat-then-open with atomic O_NOFOLLOW + fchmod\n- update: fold the printJob probe (failure-conflated-with-absence) into the\n reused-kill-helper-fallbacks doc as a second instance of the same family",
"is_bot": false,
"headline": "docs: compound service-persistence learnings (#83)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-12T04:15:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e3a788f7f406fad5b0c98664c5de119bf2977403",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#82)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-11T23:10:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e1718a51c43a389f2e37091a73b1dc7ed39b169f",
"body": "…daemon (#80)\n\n* docs: service-persistence requirements + implementation plan\n\n* feat: launchd provider — plist generation + launchctl runner (unit 1)\n\nImplements Unit 1 of the service-persistence plan: pure-ish Node-only\nplist generation, atomic owner-only writes, tamper-refusal checks, and\na seam-\n[…]\nO_WRONLY|O_APPEND|O_CREAT|O_NOFOLLOW) so the kernel refuses a\nsymlinked final component at open time, and fchmod the resulting fd\ninstead of chmod-by-path. ELOOP maps to the 'refusing symlink' result.",
"is_bot": false,
"headline": "feat: service persistence — launchd agent for reboot-durable managed …",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T23:06:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4fefad7d3732212fb114bd359fa9b4f306b48bd3",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#79)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-11T20:26:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3afbbb69894c2b2444450e26862b8a6e82ed89a1",
"body": "…s dist) (#78)\n\n* docs: second same-day instance of the packaged-artifact blind spot\n\nThe browser-safety gate bundled from src/ and passed while the published\ndist/{core,contract,format}.js carried a node:module createRequire prelude\nthat broke Vite downstream (mothership#22; fixed in 0.10.1). Adds the\ndist-level-twin prevention rule.\n\n* docs: state the dist-prelude fix as proposed (#77 open), not shipped",
"is_bot": false,
"headline": "docs: second instance of the packaged-artifact blind spot (src gate v…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T20:23:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3b2631b9dbecd9233f251fcb340bed23b8c7f65",
"body": "fix: build browser-safe subpaths (core/contract/format) with browser target\n\nThe published npm artifacts for dist/core.js, dist/contract.js, and\ndist/format.js carried Bun's node-target createRequire(node:module)\nprelude, breaking Vite bundling for consumers like Mothership (which had\nto ship a work\n[…]\nevel gate that runs\nbun run build and scans the published dist/*.js files directly for\nnode: imports -- the existing test only bundled from src/ and couldn't\ncatch a build.ts regression like this one.",
"is_bot": false,
"headline": "fix: browser-safe subpath artifacts must not carry a Node prelude (#77)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T20:21:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2464d843b8bec3b4a33450b85d723221fd0b383c",
"body": "…pot (#75)\n\ndocs: capture OpenCode reserved-subpath loader collision + dogfooding blind spot\n\nTwo solutions docs from the 0.9.0 plugin-load failure (fixed in 0.10.0, #73):\n- integration-issues: exports[\"./server\"] is OpenCode's reserved plugin\n entrypoint (resolved before main); publishing a librar\n[…]\nhain + guard.\n- workflow-issues: a source-file plugin ref bypasses npm entrypoint\n resolution, masking the packaging bug for 0.6.0-0.9.0.\nCross-linked into the plugin tool-registration best-practice.",
"is_bot": false,
"headline": "docs: OpenCode reserved-subpath loader collision + dogfooding blind s…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T18:48:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1240d336af3871f24aa49434637ac50e8924373",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#74)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-11T17:04:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cb9245d2379511eb2a3dbf0621301a4140055f0",
"body": "…on (#73)\n\n* fix: remap ./server subpath to plugin entry — OpenCode loader collision\n\n* fix: bump changeset to minor + automate negative-control guard test\n\n- ./server repoint is a shape change to a published subpath; README's\n stability contract ships shape changes as minor. Migration note added\n for direct /server importers (silent-failure warning).\n- Negative control is now an automated test: dist/server.js must fail\n the loader's V1 shape check, proving the guard discriminates.",
"is_bot": false,
"headline": "fix: remap ./server subpath to plugin entry — OpenCode loader collisi…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T17:02:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d4ccb3b38a7844b72e770a6f7a5708f472f490b",
"body": "…aims) (#71)\n\ndocs: capture async-foundation learnings (blocking-wait primitive + verify-claims)\n\nTwo best-practices learnings from the 0.9.0 async-delegation work:\n\n- NEW: blocking-wait-primitive-on-stateless-surface — designing a\n block-until-attention primitive when the surface is stateless (no\n\n[…]\n status() behavior as new P0 bugs. 'Is this\n a NEW bug?' is as empirically checkable as 'is this endpoint authed?' —\n read what the base branch already did before accepting the diff\n introduced it.",
"is_bot": false,
"headline": "docs: async-foundation learnings (blocking-wait primitive + verify-cl…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T04:01:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c79b8ff9ae46d31619e1979f653fee19476c1dc7",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#70)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-11T03:10:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "51d0154f26b91545c9dec1715772428615589e28",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.85.0 (#69)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-11T03:07:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6e57bffd785b4d3658b4817793a6342d511c1fdf",
"body": "…it (0.9.0) (#68)\n\n* feat(core): normalized session state enum + deriveSessionState (#49 async foundation)\n\nAdd a single normalized lifecycle enum (running|blocked|complete|failed|\nnot_found) derived once in core and exported browser-safe on /contract, so\ncallers stop inferring state from raw busy/b\n[…]\nt #10). init was never used\nby the double; drop it from both the wrapper param and the inner call to\nmatch makeWaitFetch's one-param shape. The test still proves\ndeadline-independence (pollCount > 1).",
"is_bot": false,
"headline": "feat: async-delegation foundation — normalized session state + bus_wa…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-11T03:02:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f0782b58d02c11ed7627880c5939bb1c48c4495c",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#64)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-10T23:41:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "930d6983b355da7aae81de79af30f90a8623d8ce",
"body": "fix(server): reap orphaned child on stopServer's dead-wrapper branch (#63)\n\nstopServer's dead-wrapper branch (verifyIdentity fails — the recorded\nwrapper pid is gone/recycled) removed the discovery record but never\nsignaled the process group. Same orphan gap the supervision died-path\nreap closed: if\n[…]\nity). Half 2 (the\nzombie-leader tri-state guard) stays tracked in #63. Real wrapper+child\ntest: wrapper-only death, stop reaps the surviving child; 202 tests,\n10x isolation clean, negative-controlled.",
"is_bot": false,
"headline": "fix: reap orphaned child on stopServer's dead-wrapper branch (#63) (#66)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T23:38:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b1fcd026685f81f770e5c7c0968c706bb2a4166b",
"body": "docs: capture the reused-kill-helper fallback-audit learning (#62)\n\nNew best-practice doc from the died-path orphan-reap review: when reusing\na shared signaling/kill helper in a new caller, audit its fallback\nbehavior against the NEW caller's (often weaker) preconditions. signalGroup's\nbare-pid fall\n[…]\ne-leader edge as a follow-up (#63) rather than\nover-building.\n\nCross-linked into the stop→hung→died group-signaling lineage, with a\nreciprocal died-path-sibling pointer added to the stop-leak bug doc.",
"is_bot": false,
"headline": "docs: capture the reused-kill-helper fallback-audit learning (#65)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T23:25:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb5bc474f9f57f0247604cc3e9fe4b8722ce160c",
"body": "* fix(server): reap orphaned daemon child on the supervision died path (#49)\n\nThe managed daemon is a harness wrapper + opencode child in one detached\nprocess group. The --foreground supervisor's died path exited fail-closed\nwhen the wrapper pid went away, but never signaled the group — so a\nwrapper\n[…]\ntion reap test (STUB_IGNORE_SIGTERM child\n ignores SIGTERM), negative-controlled; annotate the died-path seam test\n to document the reap wiring.\n\n201 tests, 10x isolation clean, no leaked processes.",
"is_bot": false,
"headline": "fix: reap orphaned daemon child on the supervision died path (#49) (#62)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T23:08:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40f3f9e61dd6991f0a2fedada31c1fea7b278a4d",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#58)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-10T21:44:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbb1059af040d379e5c450fc76b768d9675bb712",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update GitHub Actions (#51)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-10T21:41:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "209a3e03bdc2027379f7dcb34eb4327eb0552d27",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update bfra-me/.github to v4.16.35 (#53)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-10T21:38:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "679c449136d35527be3c45c07c2610f55fc7d287",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(dev): update dependency @opencode-ai/plugin to v1.17.15 (#55)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-10T21:29:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "52105dce702d0c5ce908d3c15e86188f2f658b96",
"body": "Two process/testing learnings from the foreground-supervision thread:\n\n- New best-practice doc: seam/mock-injected tests prove only promise-\n level behavior; a claim about process-level behavior (exit latency,\n timer/handle cleanup, signal handling) needs a negative-controlled\n real-subprocess te\n[…]\nh. This standard supersedes the\n narrower 'git show main:<path>' existence check — this session's flake\n genuinely existed on main (~33% in isolation), which the existence\n check would have missed.",
"is_bot": false,
"headline": "docs: capture review-gap learnings from #49 Layer B supervision (#61)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T21:25:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c9b10b142405b58f62c49cd79de68bf8636036dc",
"body": "* test(server): fix zombie-reap flake in SIGKILL-escalation test\n\nThe escalation test asserted isAlive(pid)===false instantly after\nstopServer returned. After the group SIGKILL, waitForGroupDeath\ncorrectly sees the group gone, but the specific child pid can briefly\nlinger as a reapable zombie (kill(\n[…]\nression),\nit just tolerates the microsecond reaping window. 25/25 in isolation.\n\nPre-existing flake, split from #49 Layer B per focused-PR discipline.\n\n* chore: empty changeset for test-only flake fix",
"is_bot": false,
"headline": "test: de-flake the SIGKILL-escalation test (zombie-reap race) (#60)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T20:57:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "869a003a9506dbb54f837d01759c58b2295d1321",
"body": "…r B) (#59)\n\n* feat(cli): active --foreground supervision with fail-closed exit (#49 Layer B)\n\nspace-bus serve --foreground was a passive signal-waiter — it never\nchecked whether the managed daemon was still alive. A crash or host\nexit left the daemon gone, its discovery.json stale, and attachers\ndi\n[…]\nery cleaned' (may not hold\nunder EPERM on the hung path).\n\nAll prior signal tests injected a noop sleep, so none exercised a real\ntimer — this class of bug had zero coverage until the subprocess test.",
"is_bot": false,
"headline": "feat: active --foreground supervision with fail-closed exit (#49 Laye…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T20:46:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d85b7d373776642dc657c6367845fca57917c2c8",
"body": "* fix(server): clean up stale discovery records on dead-pid reads (#49 Layer A)\n\nA managed daemon that dies by crash or host-process exit (not an\nexplicit stop) left discovery.json on disk pointing at a dead pid.\nEvery later resolver read that stale record and handed attachers a dead\nendpoint — the \n[…]\n Add the plan-required config.ts loadContext integration test: a stale\n dead-pid record makes loadContext fail actionably AND removes the\n file, proving the direct-attachLive caller path is cleaned.",
"is_bot": false,
"headline": "fix: clean up stale managed-daemon discovery records (#49 Layer A) (#57)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-10T17:28:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a94ef1550be4f6cd1755d6452ab53b0054ac2b32",
"body": "The Library surface section listed only /core, /config, /contract, and\n/format, omitting two exports that already ship: /server (the Node-only\nmanaged-server lifecycle) and /attach (the browser-safe resolveManagedServer\nresolver added in 0.7.0). Add both, and include /attach in the browser-safe\nset to match what CI bundle-tests.",
"is_bot": false,
"headline": "docs: document /server and /attach subpath exports in README (#48)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-06T21:05:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce374f570fb55b11451b46397136e0c43d5aeb4d",
"body": "…#47)\n\ndocs(solutions): capture the verify-claims-not-assertions orchestration lesson\n\nTwo misses this session, one meta-learning: the orchestrator acted on\nunverified claims and had to walk both back. A subagent called a\ngenuinely 1-in-3-flaky test 'pre-existing/unrelated' (a test added on\nthe bran\n[…]\nof checking the ground truth. Guidance: reproduce 'flaky', refute\n'pre-existing' with git, re-query PR/release state at each continuation\nboundary. Cross-links the empirical-claims and stop-leak docs.",
"is_bot": false,
"headline": "docs: capture the verify-claims-not-assertions orchestration lesson (…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-06T05:36:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd1c70fe4b457725906e0ccde728c9493b5acef5",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#45)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-06T05:11:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5dd75b9fd045d989156c4ffbbc92c10abed4ede9",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.83.1 (#41)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-06T04:42:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9338a6116ed9935d5a25774bfc055f24ce38276e",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update bfra-me/.github to v4.16.34 (#40)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-06T04:38:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e3b901334980fe5dbf033e72972a6240812ceae6",
"body": "docs(solutions): capture the managed-stop wrapper/child leak as a bug doc\n\nspace-bus stop signaled the harness WRAPPER pid and reported\nstopped:true while the opencode CHILD kept holding the port (a ~164MB\nuntracked orphan). Bug-track doc: symptoms, the wrapper/child process\ntopology root cause, the\n[…]\nal an unverified pid, and don't\naccept a flaky test (the zombie-reap race). Cross-links to the\nlifecycle best-practice doc (whose stop section now points back here)\nand the empirical-verification doc.",
"is_bot": false,
"headline": "docs: capture the managed-stop wrapper/child leak (#46)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-06T04:15:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b02aae760e5f4b97a749f4529c41935447b02d7",
"body": "…naling) (#44)\n\n* fix(server): stop signals the process group so the wrapped server child dies\n\nharness/opencode serve is a thin node wrapper that spawns the real\nserver as a child holding the port; the managed lifecycle tracked and\nsignaled only the wrapper pid. stopServer SIGTERM'd the wrapper, sa\n[…]\n\nalready-gone are absorbed internally with a bare-pid fallback), so\nstopServer's catch never sees ESRCH — the old comment claiming an\nESRCH path reached it was stale. Comment-only; behavior unchanged.",
"is_bot": false,
"headline": "fix: managed-server stop leaked the opencode child (process-group sig…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-06T04:06:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "430e0f94b7dfabc0798fa4cd0bd61c8f27a93c47",
"body": "…#43)\n\n* docs(solutions): capture four learnings from the managed-server + attach work\n\nFour best-practice/process learnings from this session, cross-linked:\n\n- managed-server-lifecycle-first-caller-spawns — the review-hardened\n daemon supervision pattern (O_EXCL spawn lock, pid-identity kills,\n t\n[…]\n\n'docs/solutions/best-practices/' while every existing doc uses the\nbare 'best-practices' — a mismatch that would make category-filtered\nlearning lookups silently miss them. Aligned to the convention.",
"is_bot": false,
"headline": "docs: compound four learnings from the managed-server + attach work (…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-06T02:56:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "82d6e37ddff74fb8c33f8bca68bc64ae0f0cfaec",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#39)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-05T19:19:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9f74fa32e83e18990ee3cff4240aab42ba1db6c",
"body": "* feat(attach): browser-safe managed-server resolver (/attach subpath)\n\nExternal attachers (a Mothership webview) can resolve the managed\nserver's discovery file without any node:* imports: resolveManagedServer\n(workspaceDir, seams) reads the same on-disk discovery contract as\ndiscovery.ts through i\n[…]\ntics (leading slash preserved from the first part,\nslash runs collapsed, empty segments dropped). The discovery-path\nparity test against discovery.ts still passes; added 6 direct\nposixJoin unit tests.",
"is_bot": false,
"headline": "feat: browser-safe managed-server resolver (/attach) (#38)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-05T17:00:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "337a6a578ab3ad2c891f74ce11cef615cd75a039",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#36)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-05T13:37:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a456d734d5b21121047b26edf01dbac8e1c20ad",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.83.0 (#34)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T19:33:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f338abbc361193ba2e7d686ebecef44a238f6ed4",
"body": "test: isolate XDG_STATE_HOME so the suite stops leaking real state dirs\n\nThe managed-server tests randomize roster paths but stateDirFor keys\noff XDG_STATE_HOME ?? ~/.local/state — so every run that wrote\ndiscovery/lock/provisional state hashed a fresh dir into the real home\n(791 accumulated in one \n[…]\nnever cleaned). A Bun test\npreload now forces XDG_STATE_HOME to a per-run temp dir and cleans it\nup on exit. Proof: real ~/.local/state/space-bus stays empty across a\nfull suite run. Test-only; patch.",
"is_bot": false,
"headline": "test: isolate XDG_STATE_HOME to stop state-dir leaks into $HOME (#35)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T19:02:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e98aff5eb843c290b67b70feba8854f660fa827",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#33)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T18:43:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c6544439e3d2f0f929a4ff9d29ada199bb802ed5",
"body": "* docs: managed-server brainstorm + plan\n\n* feat(discovery): roster schema split + discovery/lock/pid-identity primitives\n\nRoster server config becomes baseUrl XOR managed (existing rosters\nparse unchanged); new Node-only src/discovery.ts provides the\nstate-dir layout (keyed by roster-path hash), at\n[…]\n range,\nand rebuild the URL from a hardcoded 127.0.0.1 literal — no\nfile-derived string reaches the outbound request. The host was already\nregex-pinned; this closes the static-analysis taint path too.",
"is_bot": false,
"headline": "feat: managed bus server — lifecycle in the plugin (#32)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T18:41:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7e17809f40db4078b932cbd0028158c393fb81a7",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#31)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T15:31:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4dfd57c71555a4f30fac513a4c50f72b9b49fdbb",
"body": "feat(deps)!: zod v4\n\nContract schemas are now zod-4 (looseObject replaces the deprecated\npassthrough — unknown-field semantics unchanged and test-pinned;\nz.url() replaces z.string().url()). MCP raw-shape registration rides\nthe SDK's native zod-4 path. Full lockfile regeneration was required:\nincremental install kept a stale nested zod@3 under the MCP SDK,\nbreaking tsc with AnySchema mismatches despite the SDK allowing ^4.",
"is_bot": false,
"headline": "feat: upgrade to zod v4 (#30)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T15:29:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "182ff452d4aaa81a1437b71160546a7906164550",
"body": "docs(solutions): browser-safe library boundary cut pattern\n\nInjected-context validation (zod parse copies — validate-then-mutate\ncan't bypass), guards traveling from loader to consuming boundary,\nfilesystem facts as load-time flags, sentinel-pinned credential\nhygiene, and the Bun browser-target testing trap: builtins stub\nsilently and Node globals dodge import guards — safety tests count\nonly after negative controls prove they fire.",
"is_bot": false,
"headline": "docs(solutions): browser-safe boundary-cut pattern (#29)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T15:09:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe37b45a2d63585604a5f191b442db6aa0211012",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#28)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T15:03:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fda974ceb6f3491f5c159b25335dcd30ad1a327",
"body": "* feat(tools): structured dispatch metadata on bus_task results\n\n{sessionId, project, mode} rides the plugin ToolResult metadata\nchannel and MCP structuredContent alongside the unchanged formatted\ntext, built by one shared helper so the surfaces can't drift.\nRenderers get the session id machine-read\n[…]\ndContent worked without it, but clients keying off\noutputSchema for discoverability couldn't see the fields; isError\npaths skip SDK validation so error returns stay schema-free.\n\n* style: biome format",
"is_bot": false,
"headline": "feat: structured dispatch metadata on bus_task (#27)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T15:00:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c175893587c66216233e709d916cba72fa659349",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#26)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T14:01:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83013cd67fa114451c97cdd1c25ff84dd83616ad",
"body": "…) (#25)\n\n* feat(contract): extract OpenCode API schemas into src/contract.ts\n\nThe 19 zod schemas the bus maintains for the server API move to a\nzod-only module (experimental-labeled), preserving names, passthrough\nposture, and provenance comments; core imports from contract. First\ncut of the librar\n[…]\n: correct loadContext comments — no cwd fallback exists\n\nREADME example implied a current-directory default; mcp.ts gains the\nsingle-directory-per-process note so nobody 'fixes' it with\nprocess.cwd().",
"is_bot": false,
"headline": "feat: library surface — subpath exports, browser-safe core, snapshot(…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T13:57:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8de33f47dbe6874017ca25fc3c61278ded49f34",
"body": "docs(plan): library-surface implementation plan (reviewed)\n\nFive units: contract extraction, core boundary cut (validated\nper-call context injection with parse-copy guard travel), snapshot\ncomposite, subpath packaging with a CI browser-safety probe (core/\ncontract/format bundle + config-isolation as\n[…]\nings integrated: single validation gate with copying parse,\nper-call context contract, fail-fast ordering pinned, smoke migrates\nlast, snapshot bypasses sequential probing, credential-scrubbed\nerrors.",
"is_bot": false,
"headline": "docs(plan): library-surface implementation plan (#24)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T10:19:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "885dbbf8518619e7ba9c8f4b7e7766bcf9240133",
"body": "docs: ideation + reviewed requirements for the library surface\n\nIdeation pass (Mothership-support focus, 37 candidates, 5 survivors)\nand the brainstorm it seeded: subpath exports of a browser-safe core\n(roster + credentials injected, validated at the boundary), Node-side\nconfig module, bounded-concu\n[…]\nted:\nboundary validation + guard-travel requirements, R5 softened to\nwhere-practical migration, snapshot cap/error-sanitization rules,\nbyte-equivalence claim corrected, packaging follow-through named.",
"is_bot": false,
"headline": "docs: library-surface ideation + requirements (#23)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T10:04:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ca3e2d9dcc27d3298c6d369f3c96262e4f322279",
"body": "docs(solutions): template CI from the org's own repos, not adjacent ones\n\nWorkflow learning from the conversion's correction round: org-identity\nmarkers (renovate preset, review-bot inputs/pins, settings shape,\nnaming) must come from the org's own repos; outside templates only for\nwhat the org genuinely lacks. Convention drift passes every automated\ngate — the fix is sourcing discipline plus asking about provisioned\nsecrets instead of guessing.",
"is_bot": false,
"headline": "docs(solutions): org-template sourcing lesson (#22)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T03:29:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c414cf171fbaa187daf21eb8643e946402a24ebe",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#18)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T02:56:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83bdc757fc6ca73497b18ccda91f05086e433aee",
"body": "useLiteralKeys off (bracket-notation env access is the repo\nconvention), noImportantStyles off for design-token assets, schema\nmigrated to the installed 2.5.2 (preset key). Zero diagnostics on a\nclean tree — lint output is now purely regression signal.",
"is_bot": false,
"headline": "chore(lint): signal-only biome output (#20)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T02:39:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "235deb53aabc68dee3237ae6cbc6d8569fcff438",
"body": "Consumer-first section order (install → configure → tools → Claude\nDesktop → development), a field-by-field spacebus.json reference,\nthree badges, and the version-pin note generalized to lockstep-upgrade\nguidance.",
"is_bot": false,
"headline": "docs: shape the README for the npm listing (#19)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T01:08:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac6dc8f548e4d378ec367d3c98fd3219a93774e7",
"body": "* refactor: shared toDispatchArgs validator; e2e version-injection test\n\nBoth adapters (MCP handler and plugin tool) narrow through one\nvalidator instead of casting past DispatchArgs' exclusivity —\nzero 'as DispatchArgs' remains. New test builds for real and asserts\ndist/mcp.js carries the shebang, \n[…]\nobservable error-precedence change. MCP handler\nfail-fast stays covered by the parity source-text guard — no stdio\nharness for one branch.\n\nVerified: typecheck clean; bun test 60/60; lint at baseline.",
"is_bot": false,
"headline": "refactor: shared dispatch-args validator + version-injection test (#17)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-04T00:46:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "991c9adb25155deab15b8e7a29ee512f607b1454",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#16)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-04T00:20:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cfe5b4633a28e930d3298632986f23afc409d4ef",
"body": "* chore: deferred-items sweep — real MCP version, stricter dispatch args\n\n- space-bus-mcp reports the package version (build-time define with a\n 'dev' fallback for direct-source runs) instead of a static 0.0.0\n- DispatchArgs is a discriminated union: bare {prompt} is a compile\n error; project may \n[…]\nhe MVP build; the README and\nAGENTS.md now carry everything a contributor needs, and the planning\nhistory lives in docs/brainstorms and docs/plans.\n\n* chore: add changeset for the deferred-items sweep",
"is_bot": false,
"headline": "chore: deferred-items sweep (#15)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T22:33:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ef5a36fcc1dbc3746812e3044f81a9fbefdb766",
"body": "…ngs (#14)\n\ndocs(solutions): npm trusted-publishing bootstrap + plugin scoping learnings\n\nTwo knowledge-track docs from the conversion: the new-package bootstrap\nconstraint (manual first publish before a trusted publisher can be\nconfigured; OIDC mechanics verified on the 0.1.0 release) and the\nOpenCode plugin registration/directory-scoping rules (tool map,\nctx.directory vs process.cwd(), lazy config, double-registration\nhazard — all probe-verified on the shared server).",
"is_bot": false,
"headline": "docs(solutions): trusted-publishing bootstrap + plugin scoping learni…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T21:12:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4bf187ba68cb89510d56a35e9201416937db27c9",
"body": "* docs: apply Fro Bot branding\n\nAdd branded social banner, styleguide, and design tokens; restyle README header with brand badges and banner while preserving all repo-specific content.\n\n- assets/banner.svg: parametric 1280x640 banner (title sized down to clear the avatar portal for the longer repo n\n[…]\n-bus\"\n- add <title> element to banner.svg for a11y (noSvgWithoutTitle)\n- format tokens.css quote style to satisfy biome\n\n---------\n\nCo-authored-by: fro-bot[bot] <fro-bot[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "docs: apply Fro Bot branding (#12)",
"author_name": "Fro Bot",
"author_login": "fro-bot",
"committed_at": "2026-07-03T20:52:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9696b44106a196416a35a2727a2a13439f0bcc8c",
"body": null,
"is_bot": false,
"headline": "ci(renovate):enable automerge for fro-bot/agent in GitHub Actions (#13)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T20:43:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4d8f6cdd04c8b9e4990631605c9ef983075f917",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update fro-bot/agent to v0.82.0 (#10)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-03T20:34:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c0a65fa5d01208c254c8744570b804330baa572",
"body": "docs(plan): plugin conversion complete — all seven units verified\n\nAE4 (operator workspace round-trip via file-path plugin), AE5 (0.1.0\npublished through CI trusted publishing with SLSA provenance), and AE6\n(npm-name resolution under harness, live round-trip) all passed.",
"is_bot": false,
"headline": "docs: mark plugin conversion plan complete (#11)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T20:26:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a7fd8ae2dac7f2781d6ef16584c63669a5cf1968",
"body": "chore(changesets): version packages\n\nCo-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(🦋📦): version packages (#8)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-03T20:16:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e84b2562062684134c6513af0af83b93b9ad2d2e",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(dev): pin dependencies (#3)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-03T20:13:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc8129bf9eb6c27a0a26685de65626714385bacb",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update dependency npm to v11.18.0 (#5)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-03T20:03:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df3dc2d3c9a42757e078c99903523bcecb86a920",
"body": "- Added 'Analyze' and 'CodeQL' to required status checks\n- Ensured stricter validation for branch merges",
"is_bot": false,
"headline": "feat: add required status checks for branches (#9)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T20:00:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cdba36b7821bb3e8798d97c520d54253694b3f1c",
"body": "Co-authored-by: fro-bot[bot] <109017866+fro-bot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): update GitHub Actions (#4)",
"author_name": "fro-bot[bot]",
"author_login": "fro-bot[bot]",
"committed_at": "2026-07-03T19:50:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1744b88db2c474da07de770b88824cc6065bb815",
"body": "feat(cutover): repo sheds control-board hosting — plugin is the only tool source\n\nThe operator workspace passed its live end-to-end gate through the\nplugin, so the transitional surfaces go: .opencode/tools wrappers,\nroot workspace.json/spacebus.json, and the MCP facade's repo-root\nfallback (SPACE_BU\n[…]\nnor).\n\nVerified: typecheck clean; bun test 51/51; lint clean; build OK;\nfixture-based smoke 11/11 PASS; MCP bin probe with and without\nSPACE_BUS_CONFIG (four tools / actionable error, protocol-clean).",
"is_bot": false,
"headline": "feat: complete the control-board cutover (#7)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T19:41:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78c85cb25658b29ed945e351b46c99b3ac61c0e3",
"body": "…gin (#2)\n\n* feat(config): lazy per-call roster resolution from spacebus.json\n\nsrc/config.ts owns roster discovery: SPACE_BUS_CONFIG override (absolute\nor ~ only; URLs and bare-relative rejected; canonicalized) falling back\nto <directory>/spacebus.json, localhost guard and zod parse included.\ncore.t\n[…]\nity drift-guard asserting the plugin tool map matches the shared\ndescription constants and arg schemas (with a source-text check on the\nMCP registrations).\n\n51 tests, 0 fail; typecheck and lint clean.",
"is_bot": false,
"headline": "feat: convert space-bus into the distributable @fro.bot/space-bus plu…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T13:23:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad8eefe00c467ba342353d5bbd3d8cc6fbb61fc5",
"body": "…trap\n\nExact copilot-delegate contracts inlined (release/ci workflow shapes,\nchangesets + package scripts, biome, renovate automerge guard, App-token\nrelease auth). Corrected Unit 7 against current npm docs: a trusted\npublisher can't be configured for a nonexistent package — first publish\nis a manual bootstrap, AE5 is satisfied by the second release. Fixed\nthe bin invocation (bunx --package=@fro.bot/space-bus space-bus-mcp).",
"is_bot": false,
"headline": "docs(plan): deepen with verified template contracts and publish boots…",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T06:24:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37b3fdd29779932aac945e39ed7be73324dc2623",
"body": "Seven units: lazy roster resolution, plugin entry, packaging/build,\nCI workflow set, docs rewrite, reversible control-board cutover, first\npublish. Document review (coherence, feasibility, scope-guardian,\nadversarial, security-lens) findings integrated: no-caching roster\nreads, exact-path discovery, node build target, main-branch publish\ngate, fixture generation script, npm rollback + offline fallback.",
"is_bot": false,
"headline": "docs(plan): plugin conversion implementation plan (reviewed)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T06:20:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04e100f5c028805e1c7954531ce515d517e68ba2",
"body": "Live probe on harness ee55e157: file-path plugin entries load and\nregister tools; per-session input.directory tracks the request's\nworkspace on a shared server (process.cwd() does not). The two P1\nunknowns from document review are settled empirically.",
"is_bot": false,
"headline": "docs(brainstorm): record verified plugin-loading probe results",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T06:06:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "293ccb760eb4320b0aaeaf392c0baad9b99a2b62",
"body": null,
"is_bot": false,
"headline": "docs(brainstorm): plugin conversion requirements (reviewed)",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T06:01:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e9c933834a3e136d116e37b95a9319219d415024",
"body": "loadManifest rejects non-loopback baseUrl hosts at startup — Basic auth\nnever leaves the machine even if workspace.json is tampered with.\nfindSessionDirectory now errors when a session's directory matches no\nmanifest project instead of silently attributing it to the probing\nproject (wrong label + wrong directory header downstream).\n\nVerified: typecheck clean; smoke 11/11 PASS; negative probe with a\ntampered manifest fails fast naming the offending host; workspace.json\nrestored byte-identical.",
"is_bot": false,
"headline": "fix(security): localhost guard on baseUrl; refuse to guess session owner",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T05:40:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cc9166e2435db0179bd1e20b3c1c785b6646f09",
"body": "- api(): never-throw choke point (synthetic 599 on network failure) +\n 30s AbortSignal timeout so a hung server fails fast\n- encodeURIComponent on all caller-supplied URL path segments\n- .opencode tools throw on core errors (plugin ToolResult has no\n isError channel; thrown errors surface as tool \n[…]\nrrected\n\nVerified: typecheck clean; smoke 11/11 PASS; MCP stdio probe (four\ntools, isError path intact, stdout protocol-clean); dead-port probe\nconfirms status() degrades to ok:false without throwing.",
"is_bot": false,
"headline": "fix(review): apply validated safe-auto findings from review pass",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T05:36:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "64146a6d582b994af867cc5a407a5a16adefcb01",
"body": "bus_task now takes optional sessionId: absent → new session (project\nrequired); present → steer the existing session (answer its pending\nquestion, else follow-up prompt), with a mismatch guard when a project\narg disagrees with the session's owner. One mechanism for start-vs-\ncontinue instead of two tools.\n\nVerified live: new dispatch, follow-up steer, question-reply steer, and\nmismatch guard; MCP tools/list shows exactly four; typecheck clean;\nsmoke PASS.",
"is_bot": false,
"headline": "refactor(bus): fold bus_reply into bus_task — four tools again",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T05:08:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b507b533786569373e46f51cf59323e1c856aa5",
"body": "A delegate blocked on a question was indistinguishable from a working\none (busy: true either way) — dogfooding hit this twice. status() now\nchecks /question for the session and reports a preview + option labels;\nformatStatus renders a 'blocked: waiting on a question' line.\n\nVerified live: question-asking session shows blocked line with options,\nreply unblocks it and the field clears; typecheck clean; smoke PASS.",
"is_bot": false,
"headline": "feat(status): surface pending interactive questions in bus_status",
"author_name": "Marcus R. Brown",
"author_login": "marcusrbrown",
"committed_at": "2026-07-03T05:04:41Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 21,
"commits_last_year": 111,
"latest_release_at": "2026-07-19T08:38:41Z",
"latest_release_tag": "v0.15.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 4,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.9
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@fro.bot/space-bus",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@fro.bot/space-bus",
"is_deprecated": false,
"latest_version": "0.15.0",
"repository_url": "https://github.com/fro-bot/space-bus",
"versions_count": 22,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 2,
"monthly_downloads": 4190,
"first_published_at": "2026-07-03T19:44:51.948000Z",
"latest_published_at": "2026-07-19T08:38:39.441000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 0,
"stars": 1,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 8
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 95488,
"source_files_sampled": 54,
"oversized_source_files": 1,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 6683
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "@hono/node-server",
"direct": false,
"version": "1.19.15",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.9,
"advisory_ids": [
"GHSA-frvp-7c67-39w9"
],
"fixed_version": "2.0.5",
"advisory_count": 1,
"oldest_advisory_days": 3
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"moderate": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 95,
"malicious_count": 0,
"assessed_package": "npm:@fro.bot/space-bus@0.15.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@modelcontextprotocol/sdk",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "1.29.0"
},
{
"name": "zod",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.4.3"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@modelcontextprotocol/sdk",
"direct": true,
"version": "1.29.0",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": true,
"version": "^4.4.3",
"ecosystem": "npm"
},
{
"name": "@biomejs/biome",
"direct": false,
"version": "2.5.2",
"ecosystem": "npm"
},
{
"name": "@changesets/cli",
"direct": false,
"version": "2.31.1",
"ecosystem": "npm"
},
{
"name": "@opencode-ai/plugin",
"direct": false,
"version": "1.18.2",
"ecosystem": "npm"
},
{
"name": "@types/bun",
"direct": false,
"version": "1.3.14",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.9.3",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 7,
"direct_count": 2,
"indirect_count": 5
}
},
"maintainership": {
"issues": {
"open_prs": 4,
"merged_prs": 92,
"open_issues": 4,
"closed_ratio": 0.846,
"closed_issues": 22,
"closed_unmerged_prs": 1
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "marcusrbrown",
"commits": 68,
"avatar_url": "https://avatars.githubusercontent.com/u/831617?v=4"
},
{
"type": "User",
"login": "fro-bot",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/80104189?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.986
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yaml",
"codeql-analysis.yaml",
"fro-bot.yaml",
"release.yaml",
"renovate.yaml",
"scorecard.yaml",
"update-repo-settings.yaml"
],
"has_docs_dir": true,
"linter_configs": [
"biome.json"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 5 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 8,
"reason": "dependency not pinned by hash detected -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 8,
"reason": "2 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "7fa38ad1023c9adbca43fd05fb22add34ef0bc3b",
"ran_at": "2026-07-25T05:37:32Z",
"aggregate_score": 7.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T03:51:30Z",
"oldest_open_prs": [
{
"number": 72,
"created_at": "2026-07-11T10:03:40Z",
"last_comment_at": "2026-07-11T10:03:45Z",
"last_comment_author": "fro-bot"
},
{
"number": 115,
"created_at": "2026-07-19T17:34:14Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 116,
"created_at": "2026-07-19T21:28:25Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 118,
"created_at": "2026-07-20T18:31:27Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-19T08:37:20Z",
"ci_last_conclusion": "SKIPPED",
"oldest_open_issues": [
{
"number": 6,
"created_at": "2026-07-03T14:56:32Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 63,
"created_at": "2026-07-10T23:04:27Z",
"last_comment_at": "2026-07-10T23:05:55Z",
"last_comment_author": "fro-bot"
},
{
"number": 81,
"created_at": "2026-07-11T22:09:48Z",
"last_comment_at": "2026-07-11T22:11:38Z",
"last_comment_author": "fro-bot"
},
{
"number": 123,
"created_at": "2026-07-25T01:46:24Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/fro-bot/space-bus",
"host": "github.com",
"name": "space-bus",
"owner": "fro-bot"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"security": 81,
"vitality": 74,
"community": 33,
"governance": 59,
"engineering": 86
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 74,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 57,
"inputs": {
"commits_last_year": 111,
"human_commit_share": 0.58,
"days_since_last_push": 0,
"active_weeks_last_year": 4
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "4/52 weeks with commits",
"points": 2.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 4
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "111 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 111
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 21,
"latest_release_tag": "v0.15.0",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "21 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 21
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.9 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 33,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 1,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "1 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 1
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"packages": [
"@fro.bot/space-bus"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 4190
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "4,190 downloads/month across npm",
"points": 48.3,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 4190,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 59,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 22,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.986
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 99% of commits",
"points": 0.3,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 99
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 5 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"merged_prs": 92,
"open_issues": 4,
"closed_issues": 22,
"issue_closed_ratio": 0.846,
"closed_unmerged_prs": 1
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "85% of issues closed",
"points": 39.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 85
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "92/93 decided PRs merged",
"points": 37.8,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 92,
"decided": 93
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 37,
"inputs": {
"followers": 1,
"owner_type": "User",
"is_verified": null,
"owner_login": "fro-bot",
"public_repos": 7,
"account_age_days": 1967
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of fro-bot",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "fro-bot"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "7 public repos, account ~5 yr old",
"points": 17.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 7
}
},
{
"code": "account_age_years",
"params": {
"years": 5
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@fro.bot/space-bus"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "22 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 22
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 86,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "7 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 7
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "biome.json",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"agent-orchestration",
"bun",
"mcp",
"opencode",
"plugin",
"typescript"
],
"has_wiki": false,
"homepage": "https://www.npmjs.com/package/@fro.bot/space-bus",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.npmjs.com/package/@fro.bot/space-bus",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "6 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 6
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 81,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 79,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 7.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 5 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 4,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "2 existing vulnerabilities detected",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Matched the npm:@fro.bot/space-bus@0.15.0 runtime dependency closure — what installing the published package pulls in — 95 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@fro.bot/space-bus@0.15.0",
"assessed": 95
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 88,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 95,
"unassessed_packages": 0,
"affected_by_severity": "moderate 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
"points": 13.2,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "@hono/node-server 1.19.15 (moderate 5.9)"
}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory has been public longer than 90 days",
"points": 40,
"status": "met",
"details": [
{
"code": "advisories_none_stale",
"params": {
"days": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 95,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 1
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 64,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 6683
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "58 of 58 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 58,
"sampled": 58
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 52,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "biome.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "biome.json"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 95488,
"source_files_sampled": 54,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/54 source files over 60KB",
"points": 54,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 54,
"oversized": 1
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "critical",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-25T05:37:49.504072Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/fro-bot/space-bus.svg",
"full_name": "fro-bot/space-bus",
"license_state": "standard",
"license_spdx": "MIT"
}