Öffentliches Register
Software-GesundheitsberichtSchema 0.26.0 · Metriken 1.13.0 · 2026-07-22 15:32 UTC

iterate / capnweb

JavaScript/TypeScript-native, low-boilerplate, object-capability RPC system

TypeScriptMIT★ 0 Sterne⑂ 0 Forksseit Juni 2026ForkAuf GitHub ansehen ↗

iterate/capnweb erreicht einen Gesundheitsindex von 48 von 100 und liegt damit im Bereich Gefährdet. Am stärksten schneidet es bei Vitality (77/100) ab, am schwächsten bei Engineering Quality (29/100). Zuletzt vor 5 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

48
gesamt / 100
Gefährdet

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

48
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

iterate.comOrganisation
27 Follower20 öffentliche Reposseit Aug. 2010

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
npm@iterate-com/capnweb0.10.069.2592vor 5 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

77Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 5 Tagen
22.8/36Commit-Rhythmus — 33/52 Wochen mit Commits
18/18Commit-Volumen — 175 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year175
human_commit_share0,83
days_since_last_push5
active_weeks_last_year33
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 1 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 41 Tagen
12.6/27Release-Rhythmus — Rhythmus unbekannt (nur ein Release)
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count1
latest_release_tagv0.8.0-websocket.1
releases_from_tagsnein
days_since_latest_release41
mean_days_between_releases

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

29Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
0/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmenein
has_licensenein
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
64.5/80Downloads pro Monat — 69.259 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packages@iterate-com/capnweb
dependents
ecosystemsnpm
total_downloads
monthly_downloads69.259
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

60Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
8.1/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 64 % der Commits
13.5/13.5Breite der Beitragenden — 28 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled28
top_contributor_share0,638
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
30.6/38.3PR-Annahme — 4/5 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs4
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
10.4/25Reichweite des Inhabers — 27 Follower von iterate
21.6/25Kontohistorie — 20 öffentliche Repos, Kontoalter ca. 15 Jahre
Verwendete Eingangsdaten
followers27
owner_typeOrganization
is_verified
owner_loginiterate
public_repos20
account_age_days5.820

Paketpflege

92Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 5 Tagen
12/20Versionshistorie — 2 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packages@iterate-com/capnweb
ecosystemsnpm
any_deprecatednein
min_days_since_publish5

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

29Kritisch · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 4 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

1Kritisch
Wie die Bewertung erfolgt
0/30README
0/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
0/10Repository-Beschreibung
0/10Topics
0/10Wiki
Verwendete Eingangsdaten
topics
has_wikinein
homepage
has_readmenein
has_docs_dirnein
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

35Gefährdet · 16 % des Gesamtindex

Sicherheitslage

35Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — keine Daten
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 15 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3,5
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): packaging. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

57Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 80 von 83 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,964
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — __tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
8/10Belegte Agentenpraxis — 4 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 3 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs__tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json
agent_commit_share0,04
toolchain_manifests
dependency_bot_commit_share0,03
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
53.9/55Handhabbare Dateigrößen — 2/97 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes130.907
source_files_sampled97
oversized_source_files2
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

0GitHub-Sterne
28Mitwirkende
175Commits, letzte 12 Monate
5Tage seit letztem Push
1Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Community profile unavailable
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@iterate-com/capnweb@0.10.0; advisories assessed against the repository dependency graph instead

Weitere Details

OpenSSF Scorecard 3.5 / 10
3.5Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-22 15:32 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
k. A.Packagingpackaging workflow not detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities15 existing vulnerabilities detected
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 955,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "JavaScript": 5587,
        "TypeScript": 847165
      },
      "pushed_at": "2026-07-17T13:31:47Z",
      "created_at": "2026-06-03T15:45:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T13:32:22Z",
      "description": "JavaScript/TypeScript-native, low-boilerplate, object-capability RPC system",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://iterate.com",
      "name": "iterate.com",
      "type": "Organization",
      "login": "iterate",
      "company": null,
      "location": "United Kingdom",
      "followers": 27,
      "avatar_url": "https://avatars.githubusercontent.com/u/364663?v=4",
      "created_at": "2010-08-14T23:00:46Z",
      "is_verified": null,
      "public_repos": 20,
      "account_age_days": 5820
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.0-websocket.1",
          "kind": "prerelease",
          "published_at": "2026-06-10T19:56:22Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "6cd9dc89f53ee8420be0c69fe6c5d1be563954f4",
          "body": "Bonk (Cloudflare's AI PR reviewer) requires Cloudflare AI Gateway secrets\nthis repo doesn't have, and its PR-opened trigger is not gated on the\ncloudflare org, so every iterate PR would get a failing check. The CLA\nassistant runs on pull_request_target and would demand Cloudflare CLA\nsignatures from iterate contributors. Both are upstream-internal; drop\nthem. semgrep.yml and test.yml are kept — they run without secrets.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove Cloudflare-internal CI workflows from the fork",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T13:19:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fdf04f5e14ad22b249162219223732aad225dae3",
          "body": null,
          "is_bot": false,
          "headline": "Sync package-lock name to @iterate-com/capnweb",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T13:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "291c19170a8d2d976a2a47ac5e54fc9eaff45538",
          "body": "Rename the package so Iterate can ship the fork (WebSocket-over-RPC +\nonCall + Provider type fix) on npm without colliding with upstream\ncapnweb. Wire pkg.pr.new for main/PR previews and a tag-based npm\nrelease workflow for real registry publishes.",
          "is_bot": false,
          "headline": "Publish as @iterate-com/capnweb with pkg.pr.new and npm release CI",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T13:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11b103c38e0c6e35a3f9f1961ae59e57b049b468",
          "body": null,
          "is_bot": false,
          "headline": "Add a server-side per-call RPC hook",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T12:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37740d3858a5604a4310443d9efd61a033642b92",
          "body": "Installing capnweb directly from git (e.g. \"capnweb\": \"github:...\")\notherwise produces a package without dist/, since only prepublishOnly\ntriggers the build and package managers don't run it for git deps.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a prepare script so git dependencies get a build",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T12:57:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dd78944e223584029e91e66094b27ec8a5e19602",
          "body": "…de Response.\n\nWhen a Response has a webSocket property -- the Cloudflare Workers\nextension, as produced by a fetch() that performs a WebSocket upgrade --\nit can now be passed over RPC, in arguments or return values, with the\nsocket's messages tunneled over the RPC session. Bare WebSockets remain\nno\n[…]\nfor now; and on\nplatforms whose sockets don't buffer pre-accept (e.g. Node ws), messages\narriving before the Response is serialized are dropped.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add support for sending WebSockets over RPC, as part of a fetch upgra…",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T12:57:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bc4bc45a6f54b6a4ea211e746c4d545df0d8c1b3",
          "body": "Bump vitest, @vitest/browser, vite, and ws to clear critical/high\ndev-server advisories, and refresh patched transitives in range.",
          "is_bot": false,
          "headline": "chore: patch relevant audit vulnerabilities (#218)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-16T15:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cca1a212da1e8bc4f807725d96702f0b78207e1",
          "body": "…RPC payloads (#212)\n\n* test: add tests for streaming RpcTarget over RPC\n\n* feat: support streaming WritableStream writes with lifecycle-managed RPC payloads\n\n* chore: add changeset for RpcTarget streaming support\n\n* fix: dispose capability-free stream chunks immediately after write\n\n- Only defer payload disposal when the chunk owns hooks or promises\n- Avoid attaching disposers to pure data object chunks",
          "is_bot": false,
          "headline": "feat: support streaming WritableStream writes with lifecycle-managed …",
          "author_name": "Neko Hz",
          "author_login": "codehz",
          "committed_at": "2026-07-16T12:17:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f790b59d5e6692d93ff382c2acabe5eacb64d54",
          "body": null,
          "is_bot": false,
          "headline": "ci: prevent Bonk from pushing (#217)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-16T01:16:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7325f9d5c80dd57fea896bb4696d22a102cf10a8",
          "body": "* feat: Support buffer views serialization\n\n* docs: list bytes type markers\n\n* Always serialize in little endian, check length multiples.\n\n* feat: Enhance byte container support and error handling in serialization",
          "is_bot": false,
          "headline": "feat: Support ArrayBuffer and Buffer Views serialization (#201)",
          "author_name": "ttmx",
          "author_login": "ttmx",
          "committed_at": "2026-07-16T00:10:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a02db961460c222b0643a92483255613c7f78d5",
          "body": "The BaseType union types readable streams as ReadableStream<any>, mirroring WritableStream<any>, so an RpcTarget signature can carry a readable stream of any RPC-compatible chunk type. The runtime pipes each chunk through the generic RPC serializer, so the type surface matches runtime behavior; the \n[…]\nrough the Stubify/Unstubify mapped types unchanged.\n\nType-tests cover string and object chunk streams, assert the chunk type is preserved rather than collapsed to any, and retain byte-stream coverage.",
          "is_bot": false,
          "headline": "Widen ReadableStream RPC chunk type to any RPC-compatible value (#214)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-15T15:24:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee7ca6f5f15dfc238c8d877e23ad396de67d68ab",
          "body": "* Tidy the error-type map and WebSocket close-reason limit\n\n- serialize.ts: use a null-prototype object literal for ERROR_TYPES instead of\n  Object.assign(Object.create(null), ...).\n- websocket.ts: derive the close-reason cap from the RFC 6455 Close-frame size\n  (125 - 2) rather than a bare 123, and\n[…]\nn the\n\"import not found\" path and never calls resolve() a second time. Its test also\npassed with the guard removed. Remove both, and drop the changeset since this\nis a cleanup with no behavior change.",
          "is_bot": false,
          "headline": "Tidy the error-type map and WebSocket close-reason limit (#209)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-09T17:27:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92baaed467e2cefb7f89916516ebdb7b88d043c6",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#208)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T01:21:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e5c5622a326540e14602304da84fccf00b2d62d",
          "body": "…port handling (#190)\n\n* Fix four correctness issues in serialization and transport handling\n\n- serialize.ts: filter inherited Object.prototype keys (and toJSON) out of an\n  error's own-property bag during deserialization, matching the plain-object\n  path. Prevents keys like __proto__/toString/value\n[…]\n--\n\nCo-authored-by: taylorodell <172618523+taylorodell@users.noreply.github.com>\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>\nCo-authored-by: Dimitri Mitropoulos <dimitrimitropoulos@gmail.com>",
          "is_bot": false,
          "headline": "Fix five correctness and robustness issues in serialization and trans…",
          "author_name": "taylorodell",
          "author_login": "taylorodell",
          "committed_at": "2026-07-07T01:16:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b20ec655bc244072f78382b22ef295228b1d259",
          "body": "Deserializing messages from an untrusted peer could exhaust CPU, memory,\nor the stack:\n\n- A long [bigint,...] digit string fed straight to BigInt() blocks the\n  event loop, because BigInt()'s decimal parse is superlinear.\n- A deeply nested message could overflow the stack during evaluation.\n- An arb\n[…]\nandalone\ndeserialize() path stays protected by the defaults. Limits are purely local\n(the protocol has no negotiation step); exceeding one throws, which aborts\nthe session via the existing abort path.",
          "is_bot": false,
          "headline": "Add receiver-side resource limits for untrusted peers (#184) (#185)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-06T22:54:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47df6970ed155868e40504a171374ff8b50f46b9",
          "body": "* ci: bump checkout/setup-node to v5 for Node 20 deprecation\n\nGitHub Actions warns that Node.js 20 is deprecated and actions/checkout@v4 + actions/setup-node@v4 are forced onto Node.js 24 (actions run 28813638276, PR #185). Upgrade these workflows to v5 to align with the new runtime.\n\n* ci: move wor\n[…]\nsteps from v5 to v7 for consistency.\n\n* ci: upgrade setup-node action to v6\n\nBump actions/setup-node from v5 to v6 across workflows to stay on the latest major while keeping node-version pinned to 24.",
          "is_bot": false,
          "headline": "ci: upgrade GitHub Actions to Node 24-compatible versions (#207)",
          "author_name": "Dimitri Mitropoulos",
          "author_login": "dimitropoulos",
          "committed_at": "2026-07-06T21:52:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "610ab3ab6c187a5bafc24f321c27ae957d7206e5",
          "body": null,
          "is_bot": false,
          "headline": "ci(cla): report dispatched CLA pass via commit status (#206)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-06T16:24:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fcc52a3e69861f0b36b52911aed9e2ad3a8fb65",
          "body": "* Version Packages\n\n* docs(changelog): credit @ashkalor for #186",
          "is_bot": true,
          "headline": "Version Packages (#205)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-04T14:10:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78744ca99df8c93443556351b5849329765a930c",
          "body": "…sponse (#195)\n\nWithout response.end() and return, non-POST requests fell through into the\nRPC pipeline and crashed with ERR_HTTP_HEADERS_SENT. Forward options.headers\non the 405 path so cross-origin browser clients receive CORS headers.",
          "is_bot": false,
          "headline": "fix(batch): return 405 immediately for non-POST in nodeHttpBatchRpcRe…",
          "author_name": "Lê Minh Quân",
          "author_login": "aleister1102",
          "committed_at": "2026-07-04T13:51:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a9f19d1c957215c0cc84058c64324feea8ff9c5",
          "body": "The global test server called `httpServer.listen(0)` with no host, so on\ndual-stack hosts Node binds the IPv6 wildcard `::`. That address is then\nprovided to clients verbatim as `testServerHost`, so tests connect to\n`http://[::]:PORT` / `ws://[::]:PORT`.\n\nChromium tolerates connecting to the wildcar\n[…]\n synchronous).\n\nVerified on macOS: Firefox and WebKit go from failing those two tests to\npassing; node and workerd are unaffected.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bind test server to loopback so Firefox/WebKit can connect (#200)",
          "author_name": "SamJB123",
          "author_login": "SamJB123",
          "committed_at": "2026-07-03T19:29:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "79bc29639f2fb73882d119987c5bc97a9f3cb933",
          "body": null,
          "is_bot": false,
          "headline": "ci(cla): dispatch CLA check for generated release PRs (#204)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-02T16:44:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5161d97cfd9a6374d6bd0485e9ce1851495c5e18",
          "body": "* Version Packages\n\n* chore: empty commit to trigger required CLAssistant check",
          "is_bot": true,
          "headline": "Version Packages (#203)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-02T14:06:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf633f81972cb6cb1d9bf6d1c8be711d9ec9878",
          "body": "Add \".\" to workspaces so the root package is treated as a workspace\nmember (releasable), and set onlyUpdatePeerDependentsWhenOutOfRange so\nbumping capnweb does not force a major bump of capnweb-validate.\n\nFixes the Release workflow failing on the first changeset that targets\nthe root capnweb package (regression from #169).",
          "is_bot": false,
          "headline": "fix: allow changesets to release root capnweb package (#202)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-01T14:27:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c70bbb77ee5b25672f77d7befef7e711f4a98836",
          "body": "Add transport encoding levels so custom RPC transports can work with `jsonCompatible` values, `jsonCompatibleWithBytes` values, or `structuredClonable` messages instead of always receiving JSON strings.\n\nNote: `MessagePort` sessions now post structured-clonable objects over the port instead of JSON \n[…]\n This changes the wire format between the two ends of the port, so both ends of a `MessagePort` session must upgrade to this version together.\n\nOriginal design and implementation by @ashkalor in #144.",
          "is_bot": false,
          "headline": "Finish RPC transport encoding levels from #144 (#186)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-01T03:24:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "952a541afbfb7c051b8b1f17fb84d3587300cb4c",
          "body": "…call (#198)\n\nBoth Bonk workflows previously authorized the triggering user with a\ndedicated step that called the GitHub API at\n/orgs/cloudflare/members/{user}. That required provisioning and storing a\nREAD_ONLY_ORG_GITHUB_TOKEN secret and cost an extra API round-trip on\nevery invocation.\n\nThe webho\n[…]\nout, since these jobs run with contents/issues/\npull-requests write and the Cloudflare AI Gateway secrets.\n\nREAD_ONLY_ORG_GITHUB_TOKEN is no longer referenced by any workflow and\ncan be deprovisioned.",
          "is_bot": false,
          "headline": "ci: gate Bonk on author_association instead of an org-membership API …",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-19T22:09:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c9ef01e028185e4feadea552978d43205a6af68",
          "body": null,
          "is_bot": true,
          "headline": "Version Packages (#199)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-16T16:38:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "040982108c4c35820f61292819a276a495aa982d",
          "body": "…ypoint and DurableObject. (#197)\n\nThese are invoked by the Workers runtime, not over RPC, so they pass\nthrough unvalidated instead of being treated as RPC methods. The same\nplatform-passthrough filtering now runs on the server-marker path\n(newWorkersRpcResponse) as well as the @validateRpc decorator, so both\nagree on which members are validated.",
          "is_bot": false,
          "headline": "Skip validation for fetch and connect lifecycle methods on WorkerEntr…",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-16T14:57:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc8601e0cd430627ab1f5708a42e2a3c6275e7c0",
          "body": "* Version Packages",
          "is_bot": true,
          "headline": "Version Packages (#196)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-12T20:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4093556c84ab7193a289c62bce6fd75996840cda",
          "body": "…(#194)\n\n- Replace constructor-returns-Proxy in __validateRpcClass with in-place\n  prototype method wrapping, idempotent via a WRAPPED_METHOD symbol\n- Decorated classes extending decorated classes now resolve subclass-only\n  methods against the subclass validator instead of refusing them\n- Instances\n[…]\nl branded RpcTargets, removing the Proxy-serialization\n  hazard over native workerd RPC\n- Reword refusal errors to distinguish instance-property access from\n  methods not declared on the RPC interface",
          "is_bot": false,
          "headline": "fix(validate): support decorated classes extending decorated classes …",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-12T20:00:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d6b2ff40ea4138c4487b94e196bbe4bb087e1c8",
          "body": "Adds the same Bonk (ask-bonk/OpenCode) setup used in cloudflare/workers-sdk:\n\n- bonk-pr-review.yml: auto-reviews newly opened PRs from Cloudflare org\n  members using the prompt in .github/bonk_reviewer.md\n- bonk.yml: interactive agent triggered by /bonk or @ask-bonk comments,\n  using the agent defin\n[…]\nss-runtime support.\n\nRequires repo access to secrets: CF_AI_GATEWAY_ACCOUNT_ID,\nCF_AI_GATEWAY_NAME, CF_AI_GATEWAY_TOKEN, READ_ONLY_ORG_GITHUB_TOKEN,\nplus the ask-bonk GitHub App installed on the repo.",
          "is_bot": false,
          "headline": "ci: add Bonk AI code review workflows (#193)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-12T09:46:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd220554cb2fa401feca7e533679e511cbfed5ec",
          "body": null,
          "is_bot": true,
          "headline": "Version Packages (#191)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-09T01:58:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d5a0478c3a6d283c66182f8031214906a5ad36a",
          "body": "Changesets 'Version Packages' PRs are authored by github-actions[bot], which isn't in the CLA allowlist, so the required CLAssistant check can never pass on them: the bot can't sign, and recheck reports against main rather than the PR head. Add it alongside dependabot[bot]/workers-devprod.",
          "is_bot": false,
          "headline": "ci(cla): allowlist github-actions[bot] for changesets release PRs (#192)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-09T01:48:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cb51eb4c6424ef38132daa0e473f48ec7e14271",
          "body": "* Add capnweb-typecheck RPC validators\n\nAdd the capnweb-typecheck package, marker transform, plugin adapters, CLI, runtime validators, tests, and Worker React debug example.\n\n* rename capnweb-typecheck to capnweb-validate\n\n* Add decorator-based RPC validation\n\n* Stabilize capnweb-validate fast bailo\n[…]\nexercises a server-side validation failure.\n\n* fix(validate): require TypeScript >=5.7 (SharedArrayBuffer view typing)\n\n* Add changeset\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Add capnweb-validate RPC validators (#169)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-09T00:58:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d17ba1afc3613cb02a832c5c88eda338dd32dfe",
          "body": "Use tsdown's explicit tsx config loader so older Node 22 builds can still load tsdown.config.ts.\n\nReplace deprecated external config with deps.neverBundle and update the config type to UserConfig.",
          "is_bot": false,
          "headline": "Update tsdown to latest version (#183)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-05-22T17:55:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5eb7701f74ee7783455e3ea17ea65d5200ded496",
          "body": null,
          "is_bot": false,
          "headline": "Switch build tool from tsup to tsdown (#50)",
          "author_name": "Kingsword",
          "author_login": "kingsword09",
          "committed_at": "2026-05-20T16:53:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b9f85997fe554cd986bb02ab16afb3375e515b6",
          "body": null,
          "is_bot": false,
          "headline": "docs: add info about Blob serialization to protocol.md (#171)",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2026-05-15T01:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31adae850abdba0e0735aa60cd5fa31f2814c09c",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#167)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-05-11T18:20:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7413e43b251a0db79e9c59e67d37f01c725818fe",
          "body": "…ialization (#166)\n\nCloses #87.\n\nToday the wire format for `Error` only carries `name`, `message`, and (optionally) `stack`. Anything a user attaches to the error — `code`, `details`, a `cause`, the inner errors of an `AggregateError` — is lost the moment the error crosses an RPC boundary.\n\nThis PR \n[…]\ne any if needed.\n\nThe `error` expression in protocol.md now documents the optional `props` element, the lossy-fallback semantics.\n\n---------\n\nCo-authored-by: aron-cf <aron-cf@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Preserve own properties of Error instances across serialization/deser…",
          "author_name": "Aron",
          "author_login": "aron-cf",
          "committed_at": "2026-05-08T15:21:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25baebf7facfcdafb8cd46ea20b982cbc05557a4",
          "body": "_This fix is actually #154 from @VastBlast, but I removed the middle commit and squashed the other two. (The middle commit of #154 was addressing an unrelated problem and is more controversial -- see my comments there.)_\n\nThis fixes a memory leak in long sessions. It turns out that due to the implem\n[…]\nsh to fix it, at least in V8: https://chromium-review.googlesource.com/c/v8/v8/+/7646250\n\nBut this won't fix the `Promise.race` leak (first point above), so we should still land this fix to Cap'n WEb.",
          "is_bot": false,
          "headline": "Fix memory leak from long-lived cancellation promise (#168)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-05-07T17:27:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e499e2ac38dd4b57403d7e3d3294412bfbace14",
          "body": "* fix serialization of Invalid Date values and handle NaN/null timestamps\n\n* Create proud-melons-stare.md\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Fix serialization for Invalid/NaN dates (#152)",
          "author_name": "VastBlast",
          "author_login": "VastBlast",
          "committed_at": "2026-05-07T16:25:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f4d495ef66e947612e80f36f4f9570b439e407",
          "body": "* feat: add Blob serialization support over RPC\n\nBlobs can now be passed as RPC call arguments and return values, with\nMIME type preserved across the wire.\n\nWire format: [\"blob\", type, [\"readable\", pipeId]]. Bytes always stream\nthrough a pipe — reading a Blob's bytes is inherently async, so there's\n\n[…]\nequires a session).\n\n* Apply suggestions from code review\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>\n\n* Inline blob constant\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "feat: add Blob serialization support over RPC (#155)",
          "author_name": "Gabriel Massadas",
          "author_login": "G4brym",
          "committed_at": "2026-05-07T16:05:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4b0aab6e6a59562188a6ac59f68b79804434526",
          "body": "## Summary\n\nAdds Semgrep Community Edition (OSS) scanning to this repository as part of the App&ProdSec team's migration from Semgrep Pro to Semgrep CE.\n\n## What it does\n\n- Runs on every PR, on `push` to the main/master branch, and monthly on a staggered schedule.\n- Uses `actions/cache@v5` so `pip i\n[…]\nrmational; the job does not block on findings.\n- First PR after merge installs Semgrep; subsequent PRs skip that step.\n\nSee the internal App&ProdSec email for migration context, or ping us internally.",
          "is_bot": false,
          "headline": "ci: add Semgrep OSS scanning workflow (#164)",
          "author_name": "Hrushikesh Deshpande",
          "author_login": "hrushikeshdeshpande",
          "committed_at": "2026-05-06T19:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4a17cf1695837e2238cffffa07b5761fa7dd149",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#163)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-27T22:37:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cb91326387bea52a4dab889ed01a46f30ce4af0",
          "body": "* Add Bun ServerWebSocket support\n\nBun uses callback-based WebSocket handlers registered on `Bun.serve()`\nrather than the standard `addEventListener` interface. Passing a Bun\nServerWebSocket to `newWebSocketRpcSession()` errors because the\n`addEventListener` method does not exist (#61).\n\nA new BunWe\n[…]\nREADME.md\n\nRemove example of custom Bun websocket transport\n\n* Add changeset\n\n---------\n\nCo-authored-by: aron-cf <aron-cf@users.noreply.github.com>\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Add bun support (#159)",
          "author_name": "Aron",
          "author_login": "aron-cf",
          "committed_at": "2026-04-20T16:40:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cfa1b959ebf4cf24c3ea8277f424118306ffff2e",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#149)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-09T23:03:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "189fa799f6ef26d0704b355c1e11a9ed9a362247",
          "body": "…nto capnweb's public interface. (#148)\n\nThese type overrides were meant for type-checking Cap'n Web's own code, but the TS compiler \"helpfully\" shlepped them into the public `index.d.ts` for the capnweb package, affecting dependent builds. Oops!",
          "is_bot": false,
          "headline": "Fix type overrides for Uint8Array's toBase64 and fromBase64 leaking i…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-03-09T21:48:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03c82e877efcd1cfed1bee91d20140870bd07a27",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#147)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-09T20:19:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60be60d504f6d6984e88a6ef558b91dee5afb97b",
          "body": "…ore accurate. (#142)\n\nThis PR rewrites type definitions to fix a ton of issues. I believe this closes all the open & confirmed type issues/bugs reported. Based on my testing, I did not find any new issues, but please let me know if anything slipped.\n\nMy motivation for this stemmed from the current \n[…]\n different base/edge cases. I then tested it against the current types, before using AI to both rewrite the types. After many hours, feedback loops, and handwritten rewrites, I finally landed on this.",
          "is_bot": false,
          "headline": "Major improvements to type definitions, fixing bugs and making them m…",
          "author_name": "VastBlast",
          "author_login": "VastBlast",
          "committed_at": "2026-03-09T20:08:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5667226688fad4e28508f7779d49c1c89e53f102",
          "body": "* Fix base64 handling and also support Buffer.\n\n* base64 encoding of large arrays no longer throws on any platform.\n* When toBase64 is unavailable, but Buffer is, this uses Buffer.\n* Also, we now accept Buffer for serialization and treat it like Uint8Array.\n* Also, when decoding, if Buffer is availa\n[…]\nencode.cloudflare.dev/share/VwnZjojz\n\n* Add changesets for base64 and Buffer changes.\n\n* Don't strip padding in the toBase64() case that already omits it.\n\nAlso add a test verifying padding-stripping.",
          "is_bot": false,
          "headline": "Fix base64 handling and also support Buffer. (#145)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-03-09T19:19:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "686da4465b0f42b4f2a30ba93c2b52424a67ba0b",
          "body": "…ing in commands (#138)",
          "is_bot": false,
          "headline": "refactor: move build format config to tsup config rather than hardcod…",
          "author_name": "VastBlast",
          "author_login": "VastBlast",
          "committed_at": "2026-03-07T23:13:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "844e2ece215712e8e0f0537f3655eef2152fe331",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#130)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-18T23:07:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0d2f1ddf188cf2f3633c58a9c7141b1e5fa8392",
          "body": "There are some ugly hacks to work around Firefox not supporting `request.body`. Ugh.\n\n(I started out asking Claude to do this but it actually failed in a bunch of ways and I ended up rewriting most of it.)",
          "is_bot": false,
          "headline": "Implement support for serializing Headers, Request, and Response. (#135)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-02-18T21:27:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b42835387ba6053d70351a2bea6bb5dc3e6ec5c8",
          "body": "* docs: add info about transport/framing to protocol.md\n\n* Apply suggestions from code review\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "docs: add info about transport/framing to protocol.md (#137)",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2026-02-18T21:18:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2bb17b940b23eb8ab89be1e85538493cb4552ad",
          "body": "…ith automatic flow control. (#132)\n\n* Refactor: RpcPayload.stubs -> hooks\n\nInstead of storing an array of RpcStub, we now store an array of the underlying StubHooks.\n\nThis will make it easier to add support for new types like streams, which aren't RpcStubs, but they will wrap / be wrapped in StubHo\n[…]\npletes. This makes sense and solves the case seen in the tests.\n2. I also just made it skip the cancel() call if the stream is locked. Throwing the exception and ignoring it is just a waste of cycles.",
          "is_bot": false,
          "headline": "Add support for sending ReadableStream and WritableStream over RPC, w…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-02-13T01:42:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e3fa09394c0c50c0901c98782936f4ef3df963fc",
          "body": "* Update dependencies.\n\n* Test proxying an RPC stub all the way to Durable Objects.\n\nIn particular, the DO keeps a dup() of the stub and uses it later, after the original subscription call has returned. This requires the `rpc_params_dup_stubs` compat flag, which became default as of 2026-01-20, hence the compat flag update.\n\nFixes #110.",
          "is_bot": false,
          "headline": "Test proxying an RPC stub all the way to Durable Objects. (#122)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-02-05T22:40:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10abaf35dbf4de32ad1d91d4c3482dcba72f3e30",
          "body": "Use key remapping to filter out symbol keys instead of mapping to never.\nFixes Disposable compatibility issue with RPC types.\n\nRef: cloudflare/workerd#5804",
          "is_bot": false,
          "headline": "fix(types): filter symbol keys in RpcCompatible mapped type (#129)",
          "author_name": "Dillon Mulroy",
          "author_login": "dmmulroy",
          "committed_at": "2026-01-21T17:52:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a64e42529987d4ace65ed752bcca5ff074b9b63d",
          "body": "* updates dependencies\n\n* adds a tsconfig to fix type error\nExecutionContext was missing in worker.ts.  it's actually unused, but I was thinking that it was probably here (since this is an example) to show it, so instead of deleting it to remove the type error I fixed the problem by adding a tsconfi\n[…]\nale both)\n\n* comparison bar\nin the summary, it would be nice to have a side-by-side horizontal histogram\n\n* spell out initialism\n\n---------\n\nCo-authored-by: dimitropoulos <dmitropoulos@cloudflare.com>",
          "is_bot": false,
          "headline": "refresh `worker-react` example (#127)",
          "author_name": "Dimitri Mitropoulos",
          "author_login": "dimitropoulos",
          "committed_at": "2026-01-12T16:41:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34ce42c915737374e5d8c760fe157e4ec6fd18e8",
          "body": null,
          "is_bot": false,
          "headline": "fix type error in tests stub (#124)",
          "author_name": "Dimitri Mitropoulos",
          "author_login": "dimitropoulos",
          "committed_at": "2026-01-05T18:17:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db952ec5aefe49f4235e83f064d6f37d013262ef",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#123)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2025-12-24T14:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32e362fd1ee465d3adfe810ba135bbea224ce32b",
          "body": "This matches behavior introduced in workerd in: https://github.com/cloudflare/workerd/pull/5733\n\nThis plus the workerd change together should allow full end-to-end proxying between Cap'n Web and native workerd RPC to work correctly (provided workerd has enabled the `rpc_params_dup_stubs` compat flag, at least).",
          "is_bot": false,
          "headline": "If an RpcTarget passed in params has a dup() method, use it. (#121)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-12-23T17:11:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76fdff109d561b66025ee693920a34b23e74f317",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#109)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2025-12-16T21:33:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c87560efe1b042f133e978f7a60ecd52f69a549",
          "body": "* Mention @hono/capnweb in readme.\n\nFixes #60\n\n* Support serializing async functions.\n\nThere's a hidden `AsyncFunction` type which they implement.\n\nFixes #115.\n\n* Update dependencies.\n\n... Except for playwright because Firefox starts giving opaque NetworkErrors on some tests that connect to localhost and I don't want to debug it right now.",
          "is_bot": false,
          "headline": "Three small updates, in particular fixing async functions (#120)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-12-16T21:29:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89a706f1a1c484eb199f09b01688a30433d7a441",
          "body": "* fix(worker-react): jsrpc -> capnweb\n\n* fix(worker-react): import server type\n\n* fix: last remnants of jsrpc",
          "is_bot": false,
          "headline": "fix(worker-react): jsrpc -> capnweb (#35)",
          "author_name": "Aries",
          "author_login": "ariesclark",
          "committed_at": "2025-12-16T20:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d21e4cacfa1305e271e89657f8167bc688ade438",
          "body": "* Enhance Stubify and Unstubify for tuple types\nfixes #116\n\n* Add changeset for \"Enhance Stubify and Unstubify for tuple types\"",
          "is_bot": false,
          "headline": "Enhance Stubify and Unstubify for tuple types (#117)",
          "author_name": "Neko Hz",
          "author_login": "codehz",
          "committed_at": "2025-12-16T20:36:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a470458dd152a66d473be638626f668f8be47d9",
          "body": "* Changes the name of the type `Serializable` to the more correct\n`RpcCompatible` and exports it.\n\nThis is needed to aide integration with other libraries. For instance,\nif you want to make a generic function that will make use of an RpcStub,\nyou will need to declare a constraint of `RpcCompatible<T\n[…]\ncopy the entire type definition and declare it\nlocally, which works, but this is much simpler.\n\n* Add changeset for `RpcCompatible<T>`.\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Export the `Serializable` type from the package. (#78)",
          "author_name": "Ian Taylor",
          "author_login": "itaylor",
          "committed_at": "2025-11-06T15:19:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85fde1b90f25956ac0a820fa3e5be41a321fc34f",
          "body": null,
          "is_bot": false,
          "headline": "Add explicit build step to release workflow (#108)",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-05T14:45:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d805d4b6c60fa3e182bcbc7ce169b428cb92d7a",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#104)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2025-11-05T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa4fe305f8037219bce822f9e9095303ff374c4f",
          "body": "- generate both ESM and CommonJS outputs and adjust package exports\n- upgraded some devDependencies\n- removeds the sample changeset I'd added\n- update workflow to not explicitly call build (since we do that with prepublish anyway)",
          "is_bot": false,
          "headline": "Add CommonJS build output and update dependencies (#107)",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-05T14:15:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e38f80505f5024e20d9eead0b0a45d8d0688b76",
          "body": "Sorry, the lawyers insist.\n\n(This is the same bot we use on the workerd repo.)",
          "is_bot": false,
          "headline": "Add CLA signature enforcement bot. (#106)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-05T14:14:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4275f5531472003fa8264e6434929c03eb54448",
          "body": "* Add changeset for past PR #82.\n\n* Throw an error when attempting to access RpcTarget instance properties.\n\nThis helps people learn why instance properties are not accessible over RPC, whereas returning `undefined` leaves them confused.\n\nFixes #55\n\n* Implement toString() for RpcStub and RpcPromise.\n[…]\n, so I didn't want to install it.\n\nMight help with #91, though I won't declare that one \"fixed\" until we actually have tests proving it.\n\n* Document missing expression types in protocol.md.\n\nFixes #48",
          "is_bot": false,
          "headline": "Grab bag of issue fixes! (#105)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-05T14:12:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2fcb34ba17f2d9e979fa9d3ac3e12a61c384870",
          "body": null,
          "is_bot": false,
          "headline": "Release automation take 4. (#103)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-04T20:21:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99ecb6ba6b12580e7de168e2ed591d050a3811db",
          "body": "* Fix changeset version command, attempt 2.\n\nSince this isn't parsed by a shell, the quotes don't work. 🤦\n\n* Add missing version-script.ts file.\n\nThis was referenced from the prerelease job but didn't make it into the original PR.",
          "is_bot": false,
          "headline": "Release automation, take 3. (#102)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-04T20:12:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46180b9922ef447d721e2ebe1661d2a4e2fa996f",
          "body": "Apparently it's not run through a shell by default, so my `&&` was misinterpreted.",
          "is_bot": false,
          "headline": "Fix changeset version command. (#101)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-04T19:49:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "032de6b17d86098619d5e09e5ec4895aaa031d97",
          "body": "This sets up some stuff for release automation, built around github actions, changesets, and pkg.pr.new. \n- pkg-pr-new.yml: For every pull request, we publish a version to their registry, and a comment will popup in the PR comments showing how to use it (eg: https://github.com/cloudflare/workers-oau\n[…]\ncluded (or if they're not). This will also have a link to generate and add a changeset to the PR directly (example https://github.com/cloudflare/workers-oauth-provider/pull/99#issuecomment-3454786218)",
          "is_bot": false,
          "headline": "setup some release stuff (#100)",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-04T19:34:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6404359e08c432ad6253ae0d886a013106c449f1",
          "body": null,
          "is_bot": false,
          "headline": "Update package-lock.json",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-03T15:31:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0547ce1b85a55ccd5f2223ff8566139217510bfd",
          "body": "…es/worker-react/web/vite-7.1.11\n\nBump vite from 7.1.6 to 7.1.11 in /examples/worker-react/web",
          "is_bot": false,
          "headline": "Merge pull request #95 from cloudflare/dependabot/npm_and_yarn/exampl…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T19:39:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b5027580ca53d1c84bcca70e57793d7f02e6e2b",
          "body": "…ight-1.56.1\n\nBump playwright from 1.55.0 to 1.56.1",
          "is_bot": false,
          "headline": "Merge pull request #88 from cloudflare/dependabot/npm_and_yarn/playwr…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T19:39:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ead4f337e4dd614d7f5835f60aad28d42b7811e2",
          "body": "Bumps [playwright](https://github.com/microsoft/playwright) from 1.55.0 to 1.56.1.\n- [Release notes](https://github.com/microsoft/playwright/releases)\n- [Commits](https://github.com/microsoft/playwright/compare/v1.55.0...v1.56.1)\n\n---\nupdated-dependencies:\n- dependency-name: playwright\n  dependency-version: 1.56.1\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump playwright from 1.55.0 to 1.56.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-30T19:19:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bba0cfe732cdff294ec32170c3ea8581a5a1e3c",
          "body": "Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.1.6 to 7.1.11.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v7.1.11/packages/vite)\n\n---\nupdated-dependencies:\n- dependency-name: vite\n  dependency-version: 7.1.11\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump vite from 7.1.6 to 7.1.11 in /examples/worker-react/web",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-30T19:17:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9680ba09da0b627138872df294ece69b970c2761",
          "body": "….1.11\n\nBump vite from 7.1.5 to 7.1.11",
          "is_bot": false,
          "headline": "Merge pull request #89 from cloudflare/dependabot/npm_and_yarn/vite-7…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T19:16:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcc4e8c8e56b0f493474ed1eaad46e27c988946d",
          "body": "Spelling",
          "is_bot": false,
          "headline": "Merge pull request #75 from jsoref/spelling",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T15:31:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e8cd97ae76100173716e470234148c23b2b8ad2",
          "body": "Fixes for protocol definition",
          "is_bot": false,
          "headline": "Merge pull request #74 from Dr-Emann/push-pwsnvsymkmzx",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T15:25:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b1018a5ffa885117d854b078e9b67b9ef1d3a24",
          "body": "Fix types in React example",
          "is_bot": false,
          "headline": "Merge pull request #22 from third774/fix-types-in-react-example",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T15:16:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c499a1e5c9c577ab49fe2f1b57e118441c73caf",
          "body": "Try a different approach to importing \"cloudflare:workers\".",
          "is_bot": false,
          "headline": "Merge pull request #82 from cloudflare/kenton/fix-bundlers",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T14:22:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bb855ecb098a3d422d13ae899a2894104e00d2f",
          "body": "Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.1.5 to 7.1.11.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v7.1.11/packages/vite)\n\n---\nupdated-dependencies:\n- dependency-name: vite\n  dependency-version: 7.1.11\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump vite from 7.1.5 to 7.1.11",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-20T23:55:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f540551c3405654087176bbb5f20575002052f2",
          "body": "Fixes #23\n\nPer #23, many bundlers do not like our dynamic import of \"cloudflare:workers\". This PR takes a different approach, using the \"exports\" feature of \"package.json\" to point workerd at a different version of the code. That version imports \"cloudflare:workers\" and sticks it in the global scope before importing the rest of the library, thus allowing it to conditionally probe.",
          "is_bot": false,
          "headline": "Try a different approach to importing \"cloudflare:workers\".",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-11T20:57:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3409357b1c84dd515b4e739786addbdd135c244",
          "body": "This fixes two syntactical errors in code examples in the main README.md",
          "is_bot": false,
          "headline": "docs: Fix syntax errors (#79)",
          "author_name": "Timo Stamm",
          "author_login": "timostamm",
          "committed_at": "2025-10-10T19:26:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57143f5f2dccd765b776fa3609083558c3a16a55",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: the",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T03:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b1877fdf121a9baa9c5872d23728828b33fce1b",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: service",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T03:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adee13ab1b823391923eea825c717c648852c8f5",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: nonexistent",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T03:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "655484e27d948f59bcd83cdd9b5edca2bd151d96",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: brokenness",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T02:06:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6993e69e316acaef56d30916234e6ea82abc842c",
          "body": "callArguments is an array of expressions, not an expression that evaluates to an array",
          "is_bot": false,
          "headline": "docs: fix protocol docs type of callArguments",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2025-10-07T22:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ad1b15947af320c3ae6d61b009a78da05a486c5",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix protocol docs description of array escaping",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2025-10-07T22:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c4207a4830c5cb50d1c1590cfd4fa22cf50b129",
          "body": null,
          "is_bot": false,
          "headline": "docs: add deno server example to the README (#57)",
          "author_name": "Bedis Nbiba",
          "author_login": "sigmaSd",
          "committed_at": "2025-09-27T01:11:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5397427cd046994b62b15be0978a363cadca2dfe",
          "body": "docs: fix typo",
          "is_bot": false,
          "headline": "Merge pull request #49 from fukouda/main",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-25T23:30:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0dc4cbff7c9de85284fdce38b6d64161eef00bd3",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix typo",
          "author_name": "nas",
          "author_login": "fukouda",
          "committed_at": "2025-09-24T23:56:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "051358482556d577651ec8e893f4d4f007196851",
          "body": "chore: fix typos",
          "is_bot": false,
          "headline": "Merge pull request #25 from dynamic-calm/fix-typos",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-24T13:53:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1459279278226bae4eb021af7cd68c4ae78a1d0",
          "body": "spelling: typo in the README.md's example code",
          "is_bot": false,
          "headline": "Merge pull request #46 from sifatulrabbi/patch-1",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-24T12:55:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96495fd809814967a820974eaa98749acf8d72de",
          "body": "The example code of the `### HTTP server on Node.js` section has a typo in the import statement of capnweb.\r\n\r\n- Current: `capnpweb`\r\n- Correct spelling `capnweb`",
          "is_bot": false,
          "headline": "The example code has a typo in the imports",
          "author_name": "Sifatul Rabbi",
          "author_login": "sifatulrabbi",
          "committed_at": "2025-09-24T12:43:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49c3543e185231a98fef7782977006bcece46dbd",
          "body": "Add missing await in node.js example code",
          "is_bot": false,
          "headline": "Merge pull request #37 from cloudflare/kenton/missing-await",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-23T15:53:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 175,
      "latest_release_at": "2026-06-10T19:56:22Z",
      "latest_release_tag": "v0.8.0-websocket.1",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 33,
      "days_since_latest_release": 41,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@iterate-com/capnweb",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@iterate-com/capnweb",
          "is_deprecated": false,
          "latest_version": "0.10.0",
          "repository_url": "https://github.com/iterate/capnweb",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 69259,
          "first_published_at": "2026-07-17T12:44:46.116000Z",
          "latest_published_at": "2026-07-17T13:33:35.282000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "__tests__/tsconfig.json",
        "__type-tests__/tsconfig.json",
        "examples/worker-react/client/tsconfig.json",
        "examples/worker-react/server/tsconfig.json",
        "packages/capnweb-validate/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 130907,
      "source_files_sampled": 97,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 4,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "kentonv",
          "commits": 113,
          "avatar_url": "https://avatars.githubusercontent.com/u/4001805?v=4"
        },
        {
          "type": "User",
          "login": "teamchong",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/25894545?v=4"
        },
        {
          "type": "User",
          "login": "jonastemplestein",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/242550?v=4"
        },
        {
          "type": "User",
          "login": "jsoref",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/2119212?v=4"
        },
        {
          "type": "User",
          "login": "ndisidore",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/1103087?v=4"
        },
        {
          "type": "User",
          "login": "threepointone",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/18808?v=4"
        },
        {
          "type": "User",
          "login": "Dr-Emann",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/1153779?v=4"
        },
        {
          "type": "User",
          "login": "dynamic-calm",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/96750403?v=4"
        },
        {
          "type": "User",
          "login": "VastBlast",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/48421698?v=4"
        },
        {
          "type": "User",
          "login": "dimitropoulos",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/15232461?v=4"
        }
      ],
      "contributors_sampled": 28,
      "top_contributor_share": 0.638
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "pkg-pr-new.yml",
        "release.yml",
        "semgrep.yml",
        "test.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "15 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "6cd9dc89f53ee8420be0c69fe6c5d1be563954f4",
        "ran_at": "2026-07-22T15:32:27Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T00:39:26Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-17T13:31:26Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/iterate/capnweb",
    "host": "github.com",
    "name": "capnweb",
    "owner": "iterate"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 48,
      "inputs": {
        "security": 35,
        "vitality": 77,
        "community": 29,
        "governance": 60,
        "engineering": 29
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 77,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "commits_last_year": 175,
              "human_commit_share": 0.83,
              "days_since_last_push": 5,
              "active_weeks_last_year": 33
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "33/52 weeks with commits",
                "points": 22.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 33
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "175 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 175
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.8.0-websocket.1",
              "releases_from_tags": false,
              "days_since_latest_release": 41,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 41 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 41
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 29,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 81,
            "inputs": {
              "packages": [
                "@iterate-com/capnweb"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 69259
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "69,259 downloads/month across npm",
                "points": 64.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 69259,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 28,
              "top_contributor_share": 0.638
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 64% of commits",
                "points": 8.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 64
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "28 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 28
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "merged_prs": 4,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "4/5 decided PRs merged",
                "points": 30.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 4,
                      "decided": 5
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "followers": 27,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "iterate",
              "public_repos": 20,
              "account_age_days": 5820
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "27 followers of iterate",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 27,
                      "login": "iterate"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "20 public repos, account ~15 yr old",
                "points": 21.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 20
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "@iterate-com/capnweb"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "2 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "critical",
        "name": "Engineering Quality",
        "value": 29,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 35,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "15 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 11
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.964,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "80 of 83 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 80,
                      "sampled": 83
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "__tests__/tsconfig.json",
                "__type-tests__/tsconfig.json",
                "examples/worker-react/client/tsconfig.json",
                "examples/worker-react/server/tsconfig.json",
                "packages/capnweb-validate/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.04,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.03
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "__tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "__tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "4 of the last 100 commits agent-authored or agent-credited",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 4,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 130907,
              "source_files_sampled": 97,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/97 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 97,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@iterate-com/capnweb@0.10.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T15:32:50.393415Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/iterate/capnweb.svg",
  "full_name": "iterate/capnweb",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.26.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.