Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-26 09:53 UTC

kaspernj / rollbridge

JavaScriptMIT★ 0 Sterne⑂ 0 Forksseit Mai 2026Auf GitHub ansehen ↗

kaspernj/rollbridge erreicht einen Gesundheitsindex von 43 von 100 und liegt damit im Bereich Gefährdet. Am stärksten schneidet es bei AI Readiness (59/100) ab, am schwächsten bei Community & Adoption (32/100). Zuletzt vor 6 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

43
gesamt / 100
Gefährdet

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

43
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Kasper StöckelPersönliches Konto
54 Follower307 öffentliche Reposseit März 2010

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
npmrollbridge0.1.123.13410vor 6 Tagendeployzero-downtimeprocess-supervisorreverse-proxywebsocketrollbridgevelocious

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

35Gefährdet · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 6 Tagen
2.8/36Commit-Rhythmus — 4/52 Wochen mit Commits
18/18Commit-Volumen — 176 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year176
human_commit_share1
days_since_last_push6
active_weeks_last_year4
Wie die Bewertung erfolgt
0/27Liefert Releases aus — keine Releases veröffentlicht
0/36Release-Aktualität — keine Releases
0/27Release-Rhythmus — keine Releases
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

32Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
46.6/80Downloads pro Monat — 3.134 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesrollbridge
dependents
ecosystemsnpm
total_downloads
monthly_downloads3.134
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

56Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
38.2/38.3PR-Annahme — 60/60 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/16 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs60
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
12.5/25Reichweite des Inhabers — 54 Follower von kaspernj
25/25Kontohistorie — 307 öffentliche Repos, Kontoalter ca. 16 Jahre
Verwendete Eingangsdaten
followers54
owner_typeUser
is_verified
owner_loginkaspernj
public_repos307
account_age_days5.960
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 6 Tagen
20/20Versionshistorie — 10 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesrollbridge
ecosystemsnpm
any_deprecatednein
min_days_since_publish6

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

50Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
16/16Linter-Konfiguration — eslint.config.js
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 9 merged PRs checked by a CI test -- score normalized to 0
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
0/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmeja
has_docs_dirja
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

38Gefährdet · 16 % des Gesamtindex

Sicherheitslage

23Kritisch
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 9 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/16 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
0/10Dangerous-Workflow — keine Daten
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — keine Daten
0/5Pinned-Dependencies — keine Daten
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate2,3
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages5
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:rollbridge@0.1.12 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 5 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

59Mittel · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 86 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,86
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — eslint.config.js
11/11Statische Typprüfung — tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 44 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_configja
typecheck_configstsconfig.json
agent_commit_share0,44
toolchain_manifests
dependency_bot_commit_share0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Pinned-Dependencies. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
27/45Typprüfbarer Code — JavaScript mit Typprüfungs-Konfiguration (tsconfig.json)
55/55Handhabbare Dateigrößen — 0/47 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageJavaScript
largest_source_bytes54.069
source_files_sampled47
oversized_source_files0
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

0GitHub-Sterne
1Mitwirkende
176Commits, letzte 12 Monate
6Tage seit letztem Push
0Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 2.3 / 10
2.3Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-26 09:53 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 9 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/16 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
k. A.Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
k. A.Packagingpackaging workflow not detected
k. A.Pinned-Dependenciesno dependencies found
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
8Vulnerabilities2 existing vulnerabilities detected
Direkte Abhängigkeiten 2
RegistryPaketVersionsvorgabeManifest
npmcommander^12.1.0package.json
npmhttp-proxy^1.18.1package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 0

Die Installation von npm:rollbridge@0.1.12 zieht 5 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 515,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 357999
      },
      "pushed_at": "2026-07-20T08:21:10Z",
      "created_at": "2026-05-21T08:34:42Z",
      "owner_type": "User",
      "updated_at": "2026-07-20T08:21:28Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Kasper Stöckel",
      "type": "User",
      "login": "kaspernj",
      "company": null,
      "location": "Germany",
      "followers": 54,
      "avatar_url": "https://avatars.githubusercontent.com/u/234531?v=4",
      "created_at": "2010-03-31T23:08:52Z",
      "is_verified": null,
      "public_repos": 307,
      "account_age_days": 5960
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "1824e6a586a03cd6a62ab15f2e88ebbb1894b27e",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-07-20T08:21:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3da47042e9f8554bc5f7fcd09718c1617e765e26",
          "body": "Reload process config on deploy",
          "is_bot": false,
          "headline": "Merge pull request #60 from kaspernj/task-10426-live-config-reload",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-07-20T08:20:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38dc4adb89e3ef2abe1125339c27b56e3c1c8ead",
          "body": null,
          "is_bot": false,
          "headline": "Reload CommonJS configuration changes",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-07-20T08:17:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1590659f1f360f6ead12406c987f5ee80056ed72",
          "body": null,
          "is_bot": false,
          "headline": "Reload Rollbridge config on deploy",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-07-20T08:04:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "930727cf954e1345c9af72f59af88b367f53c35c",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-11T15:35:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46a6f0ac18e62df7a5950162da60fa089c5c8be0",
          "body": "Log cleanup status for failed release startup",
          "is_bot": false,
          "headline": "Merge pull request #59 from kaspernj/log-startup-cleanup-status",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-06-11T15:35:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7247d87ff5180f2607aa501450185b9c3132a6a7",
          "body": null,
          "is_bot": false,
          "headline": "Log failed startup before and after cleanup",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-11T15:31:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e279bbc41c55b95e38ef7a9c26671552df2b781",
          "body": null,
          "is_bot": false,
          "headline": "Log cleanup status for failed release startup",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-11T15:26:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6baaec28752ef259438a6e07a04368af598dab6d",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-08T15:56:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b8e64a01ca84de275c4561702eeaf0949a73809",
          "body": "Add handoff services",
          "is_bot": false,
          "headline": "Merge pull request #58 from kaspernj/handoff-services",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-06-08T15:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "918a11abcbf89b2f9d0118eaecd5fc37246e9a73",
          "body": null,
          "is_bot": false,
          "headline": "Stop handoff services after dependents",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-08T15:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb3a3b4b09cd1b84ebb10fdef1fa7af16b4ab72f",
          "body": null,
          "is_bot": false,
          "headline": "Add handoff services",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-08T15:43:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7202949095ab4d8addc491f3fcf6a66d262eb8b9",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-08T15:38:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78bbd0b1e3d08d3e478d2c1e6bf2437276aeab5f",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-07T10:34:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a608bf361825c9835b39fb390b61bd7095a23bc",
          "body": "Treat running daemon as healthy in doctor",
          "is_bot": false,
          "headline": "Merge pull request #57 from kaspernj/fix-doctor-running-daemon",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-06-07T10:34:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab4cc62661fed49927ca20ee8a05e40eace04617",
          "body": null,
          "is_bot": false,
          "headline": "Verify daemon proxy ownership in doctor",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-07T10:28:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b2a96e157b8d126ef24290db9a712035a2b815a",
          "body": null,
          "is_bot": false,
          "headline": "Treat running daemon as healthy in doctor",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-06-07T08:50:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8489fc24135acb1e06921b82311d84dabb833672",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T13:13:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbd13348134afe86f9854cd2d6ce289ea472f182",
          "body": "Add predeploy legacy takeover cleanup",
          "is_bot": false,
          "headline": "Merge pull request #56 from kaspernj/rollbridge-legacy-takeover",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T13:13:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad16514719bb62e3e97d800d02e3c8a6e13a08aa",
          "body": null,
          "is_bot": false,
          "headline": "Protect cleanup process by pid",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T13:02:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56407f1f6050e05da199661359b5154941109fb8",
          "body": null,
          "is_bot": false,
          "headline": "Restart daemon when pending release changes runtime",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T12:52:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93d262744df089a7fe33ce5b888f8023238b6821",
          "body": null,
          "is_bot": false,
          "headline": "Add predeploy legacy takeover cleanup",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T12:48:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8033f17373e4a3a8709dd5357001d7e453c2837",
          "body": "TODO: tick the three completed parent items",
          "is_bot": false,
          "headline": "Merge pull request #55 from kaspernj/tick-completed-parent-todos",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T06:52:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f37f510e4ef811a06835e1457a337d31b965c09a",
          "body": "The \"Worker auto-restart and restart policy controls\", \"Observability and\ndiagnostics\", and \"Config validation and doctoring\" parents had every sub-item\nchecked and shipped, but their parent boxes were still unticked. Tick them so the\nroadmap reflects reality — every item in TODO.md is now complete.\n\nDocs-only; no code or behavior change.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "TODO: tick the three completed parent items",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:52:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d942f21cee06973769bf0f65db2e65778ce5b296",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:42:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5739bd1fb8dcb2ba013fe39ae7a755dc9b740630",
          "body": "status: surface still-alive orphaned processes from a previous daemon",
          "is_bot": false,
          "headline": "Merge pull request #54 from kaspernj/status-surface-orphans",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:42:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17f7ecb958ce51fd21758b2e3ec15d323abd6259",
          "body": "…d one\n\nCodex review (P2): status() filtered this.orphans by liveness but never removed\ndead entries, so if the OS later recycled a cleared orphan's pid for an unrelated\nprocess, that orphan could reappear — a non-monotonic, misleading view.\n\nstatus() now prunes the underlying list to only-alive ent\n[…]\nforgotten permanently. Test asserts the underlying list (daemon.orphans) is empty\nafter the orphan dies, not just the status view.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "status: prune dead orphans so a recycled pid can't resurrect a cleare…",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:36:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a64f5f6a4ce2c215b8ab80c22607766769dcc7f7",
          "body": "Implements the feasible subset of TODO \"Reconnect status to still-running child\nprocesses after daemon restart where possible.\" Full re-management is infeasible\n(a new daemon can't re-attach exit/stdout to processes it didn't spawn), but the\nliteral ask — making `status` reflect still-running childr\n[…]\nmputed on restart.\n\nDocs: status and statePath sections. Test: status reports a live orphan and drops\nit once the process is gone.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Surface still-alive orphaned processes from a previous daemon in status",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:26:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ba018e822c3bd961df66b633e0af25cc94fe883",
          "body": "Add a maintainer release checklist",
          "is_bot": false,
          "headline": "Merge pull request #45 from kaspernj/add-release-checklist",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:20:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "897c464931eeceaee9341049f2ca89d06436fc72",
          "body": "Fix CI hang: unref the auto-restart timer",
          "is_bot": false,
          "headline": "Merge pull request #53 from kaspernj/fix-restart-timer-unref-hang",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T05:20:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee1c722d4a8ae045f330e20fdb21afebed2fbe7c",
          "body": "…block exit\n\nThe test runner (and a real daemon) could hang indefinitely because the\ncrash-restart timer was the one supervision timer left ref'd. memoryTimer and\npersistTimer are unref'd; queueRestart's setTimeout was not.\n\nUnder the default restart policy (maxRestarts: undefined, backoffFactor: 1)\n[…]\nn (or an awaiting test) is alive.\n\nAdds a managed-process test asserting the queued restart timer is unref'd\n(hasRef() === false).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix CI hang: unref the auto-restart timer so a crashed process can't …",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T04:40:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "227415c4ee9a0574250604a0a2d882af39bc8690",
          "body": "…n the remote\n\nAddresses Codex review (two P2s) on the release checklist:\n\n- Stop hardcoding `master`/`origin/master`. Derive the default branch once\n  (`default_branch=$(git rev-parse --abbrev-ref origin/HEAD | …)`) and use it in\n  the checks, so they stay correct in repos whose default branch diff\n[…]\nsh would still pass it. Now it\n  fetches and inspects `origin/$default_branch` explicitly.\n\nDocs-only; no code or behavior change.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs/releasing: branch-agnostic checks and verify the pushed commit o…",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T04:29:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ab0d941282059eaf32589935792f1f33a1eebf76",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/master' into add-release-checklist",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T04:21:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6daed7e329f08675de78a11c285d6b1f946a2b3d",
          "body": "doctor: pre-flight a release with --release-path",
          "is_bot": false,
          "headline": "Merge pull request #52 from kaspernj/doctor-release-path-checks",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T04:17:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8b9e135554e7eec67bbe60ef19666bc907ebe89",
          "body": "Completes TODO \"Extend doctor with process-command and release-path checks once\nthose are resolvable.\" Those checks need per-release rendered templates, which\nonly exist at deploy time — so the operator now supplies the release via\n`rollbridge doctor --release-path <path>` (with optional --release-i\n[…]\nnd, a missing working\ndirectory, a missing release path, and the doctor CLI --release-path flow. Docs:\ndocs/cli.md doctor section.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "doctor: add release pre-flight checks behind --release-path",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T04:12:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63e0a7892e0fd2c620fb2d535238cc6387e335c3",
          "body": "Validate stopCommand + custom stopSignal combination",
          "is_bot": false,
          "headline": "Merge pull request #51 from kaspernj/validate-stopcommand-stopsignal",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-24T04:04:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e3df6398132e0b719c15358ea9248ebdb183089",
          "body": "Completes TODO \"Validate unsupported lifecycle-hook combinations once worker\nlifecycle hooks land.\" The two earlier lifecycle validations (drainCommand\nrequires a positive drainTimeoutMs; nonBlockingDrain is companion-only) shipped\nwith the feature; this adds the remaining combination.\n\nA lifecycle.\n[…]\ncs/config.md (lifecycle section + validation-rules\nlist) and added config-validation tests for the accepted and rejected pairings.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "config: reject a custom stopSignal combined with a lifecycle.stopCommand",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T20:04:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e146e308c15623406c462c4df5957a8f2ecaf09b",
          "body": "Add recover command for crash recovery",
          "is_bot": false,
          "headline": "Merge pull request #50 from kaspernj/add-recover-command",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:59:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8419f731d99c2ddda4ed11874e6f12a8f89a90c",
          "body": "Codex review (P1): `recover --force` swallowed every `process.kill` error and\nalways cleared the state file, so it could report success while an orphan was\nstill running (for example EPERM when the process is owned by another user) —\ndeleting the only record the operator needs to find and retry the \n[…]\ne `liveProcesses(state, alive)` pattern) plus a test\ncovering the un-stoppable-orphan path, and documented the behavior in cli.md.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "recover: keep state and fail when an orphan cannot be stopped",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:57:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8bcb3085dc9a9b6eec922320a21088377442046",
          "body": "Adds `rollbridge recover` for crash recovery (TODO line 47, building on the\npersisted state + orphan reporting). It reads `statePath`, finds managed\nprocesses whose pids are still alive, and:\n\n- without `--force`, lists them (a dry run) so the operator can verify;\n- with `--force`, stops each one's \n[…]\ncs: `docs/cli.md` recover section, README and `docs/config.md` statePath\nnotes, and the TensorBuzz runbook crash-recovery section.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add recover command to clean up orphaned processes after a daemon crash",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:43:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d90810c674d58cb49851d259096a8bba30b7bd43",
          "body": "Add a TensorBuzz production runbook",
          "is_bot": false,
          "headline": "Merge pull request #49 from kaspernj/add-tensorbuzz-runbook",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:34:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6bb470c4fe32fb8170d45b8f6a4d8091035d68d",
          "body": "Add docs/tensorbuzz-runbook.md, grounded in examples/tensorbuzz.com.js (the\nproduction config): the production ports (4500 public proxy; 7330 beacon; 7331\nbackground-jobs-main; 14500-14599 web releases) and control socket, the process\ntopology and wait-for-it startup ordering, the deploy command + o\n[…]\nes are operated outside\nRollbridge and configured via the app's environment. Link the runbook from the\nREADME. Documentation only.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a TensorBuzz production runbook",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:28:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df67031d55634560093763b963e4c0f538c12ba7",
          "body": "Extend doctor with state-path checks",
          "is_bot": false,
          "headline": "Merge pull request #48 from kaspernj/extend-doctor-state-checks",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:25:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab16d8cd7960394f5fbd3bb55ca553b6fc03de44",
          "body": "A running daemon persists its own (live) process pids into statePath, so the\norphan check would misclassify the active daemon's managed processes as orphans\nand fail — a false positive in exactly the case where the state file is freshest.\nUse the control-socket inspection runEnvironmentChecks alread\n[…]\n\nruns when no daemon is live (the genuine crash-leftover case).\n\nAdd a test that the orphan check is ok while a daemon is running.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Skip doctor's orphan check while a daemon is running",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T19:05:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "10142dc5bbb44695b09ec1272f4e98bdd3333ca6",
          "body": "When statePath is configured, doctor now also checks that the state file's\ndirectory is writable (so persistence will work) and reports orphaned managed\nprocesses — processes still alive in a prior state file, left by a daemon that\ndidn't shut down cleanly (advisory; a recycled pid can be a false po\n[…]\n), and orphan reporting for a live leftover pid. README\nalready links docs/config.md; docs/cli.md documents the new doctor checks.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Extend doctor with state-path checks",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T17:39:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bb91081a0a8e52d45cdebdd0b627580c9dc5957",
          "body": "Persist daemon state and report orphaned processes on startup",
          "is_bot": false,
          "headline": "Merge pull request #47 from kaspernj/add-state-persistence",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T17:32:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a936aec971cadacb571c7c97fdb1bc31fab0aa1f",
          "body": "P1: persistState() launched writeState() fire-and-forget, so a write started\njust before shutdown could finish after clearState() and recreate the state file\nwith stale pids (false orphans next startup). Serialize persist writes via a\ntracked this.pendingWrite chain and await it in shutdown before c\n[…]\n persist write in flight\n(deploy then immediate shutdown), and concurrent writeState calls leave a\ncomplete, uncorrupted snapshot.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Await in-flight state writes on shutdown and use per-write temp paths",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T17:20:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "007c8abd677ebf1d03ffa1907c5f93d5053be9ef",
          "body": "Add an opt-in statePath: when set, the daemon persists a state snapshot (active\nand draining releases, each managed process's metadata incl. pid, restart\ncounters, and recent events) to that file atomically (on deploy/stop/drain plus\nevery few seconds). A clean shutdown removes the file.\n\nOn the nex\n[…]\nis reported as an orphan while a dead pid is not). README and\ndocs/config.md document statePath and the advisory orphan detection.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Persist daemon state and report orphaned processes on startup",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T17:13:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1ac7362b11e7173b6495383c915ca8a0a6b9b289",
          "body": "Add a non-blocking drain mode for worker companions",
          "is_bot": false,
          "headline": "Merge pull request #46 from kaspernj/add-non-blocking-drain",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T17:00:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61672004f8781e5b3152f539f8e02621ce40bf47",
          "body": "Add a per-process nonBlockingDrain flag (companion-only). When a release is\nretired, its nonBlockingDrain processes start their graceful stop immediately —\nin parallel with the proxied connection drain — instead of waiting until after\nit. So the new release's workers (started before traffic switches\n[…]\ns.md document it; the roadmap notes\nin workers.md/velocious.md are refreshed. Completes the graceful job-worker\nlifecycle section.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a non-blocking drain mode for worker companions",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T16:56:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5aba47049e97ed9d7d30f73bbd7101856208357",
          "body": "Add docs/releasing.md: the pre-flight checks before `npm run release:patch` (on\nthe default branch, clean tree, CI/all-checks green, README/docs/TODO updated,\nnpm publish rights), what the script does, and what to verify after (the version\nis on the registry, the bump commit is on origin). Link it f\n[…]\ntion.\n\nDocumentation only — describes the maintainer steps around the existing\nrelease-patch script; no tooling or runtime change.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a maintainer release checklist",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T16:42:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da911dbebb0fd301bb9e33f34861fd66aa96e8d4",
          "body": "Add a Velocious background-jobs-worker recipe",
          "is_bot": false,
          "headline": "Merge pull request #44 from kaspernj/add-velocious-worker-recipe",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T16:39:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bffc0ebad84d9126a8a669cb7fe3b357b7f265dd",
          "body": "Now that the worker lifecycle contract is implemented (companion + replicas +\nstopSignal/lifecycle hooks + gracefulStopMs), add a complete, copy-pasteable\nbackground-jobs-worker recipe to docs/velocious.md: a companion worker pool with\na graceful drain window, what happens to old/new workers across \n[…]\nempotent), and a lifecycle\nquietCommand variant for workers that quiesce via a command or non-default signal.\n\nDocumentation only.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a Velocious background-jobs-worker recipe",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T16:03:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a08989e3baa3fc2d7fc0dba6a9f9e2cf59e4b9ce",
          "body": "Add command-based worker lifecycle hooks",
          "is_bot": false,
          "headline": "Merge pull request #43 from kaspernj/add-lifecycle-hooks",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T16:00:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e2e6ae52ed4e84bc075735a0df3c72052fa4e79",
          "body": "- drainTimeoutMs: 0 now skips the drain step entirely, even when drainCommand is\n  set (previously `drainTimeoutMs || stopTimeoutMs` fell back to the full stop\n  timeout, contradicting the documented \"0 skips\" semantics and adding shutdown\n  delay). drainCommand is bounded by the actual drainTimeout\n[…]\nand-without-drainTimeoutMs validation, and a failing quietCommand\n(exit 3) is logged while the stop still completes. Docs updated.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Honor zero drainTimeoutMs and surface failing lifecycle hooks",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:58:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d5d69a714fe1674759c68ebd8980c50f430324a7",
          "body": "Add a per-process `lifecycle` object with quietCommand, drainCommand,\ndrainTimeoutMs, and stopCommand hooks that run when Rollbridge gracefully stops\na process (deploy drain, restart command, memory restart, or shutdown). The stop\nsequence becomes: quietCommand -> drain (drainCommand, or wait drainT\n[…]\nence on shell signal forwarding. README, docs/config.md, and\ndocs/workers.md document the hooks; docs/velocious.md note refreshed.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add command-based worker lifecycle hooks",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:40:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "019d171632167176a8488fee7cbf0db13b577e56",
          "body": "Document safe background-job worker deployment",
          "is_bot": false,
          "headline": "Merge pull request #42 from kaspernj/add-worker-deployment-docs",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:29:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60cc38c92d68c65c422a7285262e7f1a10a49168",
          "body": "Add docs/workers.md: how to deploy background-job workers safely with the\nfeatures that exist today — run them as a release-scoped companion, scale the\npool with replicas (worker#0, worker#1, … with ROLLBRIDGE_REPLICA_INDEX/COUNT),\nand finish in-flight jobs on a deploy/restart with stopSignal + grac\n[…]\nly. Splits the worker-lifecycle-docs TODO: safe deployment\npatterns are documented now; the command-hooks docs await that feature.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document safe background-job worker deployment",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:24:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bdd0e7938cee43c506a25b88a4dc04e0c6d92e65",
          "body": "Add companion replicas with stable worker indexes",
          "is_bot": false,
          "headline": "Merge pull request #41 from kaspernj/add-replicas",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:19:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "308c49ee0ed7a2ad193c301e097bfe245f585c67",
          "body": "Add a per-process `replicas` count that starts a pool of identical instances.\nEach replica runs as its own managed process with id `<id>#<index>` and gets\nROLLBRIDGE_REPLICA_INDEX / ROLLBRIDGE_REPLICA_COUNT in its environment plus\n{{replicaIndex}} / {{replicaCount}} template variables, so an instanc\n[…]\nrker#0..#2 and restarts one replica vs all. README and docs/config.md document\nreplicas, the env vars, and the template variables.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add companion replicas with stable worker indexes",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:16:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a66acb998c5dbbeb951f4288ffcf2326e8fcec63",
          "body": "Document file logging and rotation guidance",
          "is_bot": false,
          "headline": "Merge pull request #40 from kaspernj/add-logging-docs",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T15:05:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "919ccd4281f0488f2f7b8ac4d7b61d6b62a05a40",
          "body": "Add docs/logging.md: where the daemon's structured JSON logs go (foreground\nstdout, systemd journald, or the --daemon-log-path file for an ensured daemon),\nhow that differs from the in-memory `logs`/`events` views, and how to rotate the\ndaemon log file. The key guidance: the detached daemon holds th\n[…]\nonly — file logging already exists via --daemon-log-path; this\ndocuments it and adds the rotation guidance the roadmap called for.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document file logging and rotation guidance",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T14:55:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30f7f586d5ab65c5ee88b8f77fe154a7b2608538",
          "body": "Add a configurable graceful-stop signal (stopSignal)",
          "is_bot": false,
          "headline": "Merge pull request #39 from kaspernj/add-stop-signal",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T14:52:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a3dff16828dafe4b2c8c5949c9d07c1c3841ad8",
          "body": "The deterministic stopSignal test (spying killProcessGroup to verify the\nconfigured graceful signal) belongs with the fixture removal; commit the test\nfile that the previous commit missed.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Replace the fragile stopSignal test with a deterministic spy",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T14:47:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8fe526d75583da05a2790698e91c3f7b6a1e8826",
          "body": "The previous test relied on a SIGINT-trapping fixture exiting promptly, which\ndepends on the shell wrapper forwarding the signal to the child — that differs\nbetween shells and failed in CI (it fell through to the SIGKILL fallback at\nstopTimeoutMs). Assert the behavior stopSignal actually controls in\n[…]\nhe graceful stop sends the configured signal, with\nno dependency on signal delivery or exit timing. Remove the now-unused fixture.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make the stopSignal test deterministic across shells",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T14:47:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b9f718de52b2fec85c57a7f976c1c859f8d28b47",
          "body": "Add a per-process stopSignal (default \"SIGTERM\") sent to gracefully stop the\nprocess before the existing SIGKILL-after-gracefulStopMs fallback, so a worker\nthat quiets and finishes in-flight work on a specific signal (e.g. SIGINT) can\ndrain within its gracefulStopMs window. The signal name is valida\n[…]\nptly rather than falling through to\nSIGKILL. README and docs/config.md document stopSignal and its relationship to\ngracefulStopMs.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a configurable graceful-stop signal (stopSignal)",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T14:34:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26c7af96a539e4220e94f2c32d43229788c66d38",
          "body": "Report the child process tree in status for memory-supervised processes",
          "is_bot": false,
          "headline": "Merge pull request #38 from kaspernj/add-process-tree-status",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T14:26:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10694f641005cc162340f8a102555c9b6262186a",
          "body": "Add a `processGroupMembers` helper to process-memory (each group member's pid,\ncommand, and RSS) and reimplement the RSS total on top of it. The memory monitor\nnow caches the sampled tree on the process, and status reports it as `children`\nalongside the existing rssBytes/memoryRestarts/lastMemoryRes\n[…]\ns a populated children tree. README, docs/cli.md, and docs/config.md\ndocument the status field. The /proc tests skip on non-Linux.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Report the child process tree in status for memory-supervised processes",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T13:49:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41d697bfc4556e1a9fd6f64e1ce3ed7b77640528",
          "body": "Add control-socket owner/group options",
          "is_bot": false,
          "headline": "Merge pull request #37 from kaspernj/add-control-socket-owner-group",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T13:43:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4668d76cbd75ee949a170c5d2ab833776e486c14",
          "body": "Add control.owner and control.group config, applied to the control socket via\nchown right after the existing control.mode chmod, so a shared deploy group can\ntalk to the daemon. Each accepts a numeric id or a name; names are resolved to\nids via /etc/passwd / /etc/group (local users/groups) in a smal\n[…]\nThe /proc-style and chown tests skip on non-Linux. README and\ndocs/config.md document the options and the local-resolution caveat.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add control-socket owner/group options",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T13:27:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "665fc455a0a1c119da702bab595edd6af48086f3",
          "body": "Add memory supervision",
          "is_bot": false,
          "headline": "Merge pull request #36 from kaspernj/add-memory-supervision",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T13:20:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c48a7aa35c9e57163a931fdfcb8e934d19d71ee1",
          "body": "…ss stopped\n\nrestartForMemory always respawned after stop(), so a memory restart racing a\ndaemon shutdown or a draining release could start a child after shutdown had\nalready collected its stop promises, leaving it running. Only restart when\nshouldRestart() is still true (false during shutdown, or f\n[…]\nProcess tests for both paths: respawns and counts when shouldRestart\nis true, and stays stopped without counting when it is false.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Skip the memory-triggered restart when the supervisor wants the proce…",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T13:18:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "33afe58bb97ba0cd859653c7212b4a86d2bf6e1f",
          "body": "Add per-process memory supervision: a `memory` config ({limitBytes, warnBytes,\ncheckIntervalMs}) makes the daemon sample the process's RSS on an interval and\ngracefully restart it (SIGTERM, then SIGKILL after gracefulStopMs) when it\nexceeds the limit, logging a one-shot warning at warnBytes.\n\n- RSS \n[…]\neason \"memory\". README and docs/config.md\ndocument the config, status fields, and events. The /proc-based tests skip on\nnon-Linux.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add memory supervision",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T13:13:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0f22e0e39046d838cdff83d3ddc28e478a05eb91",
          "body": "Add a rollback command",
          "is_bot": false,
          "headline": "Merge pull request #35 from kaspernj/add-rollback-command",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:59:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8883e8c5b04951c7f86e718377f55afa50f79ba",
          "body": "Rollback re-deploys the target's id, which overwrites its entry in this.releases.\nIf the target was still draining a prior deploy, the old still-running instance\nwas dropped from status/pruning/shutdown and could be orphaned (a shutdown in\nthat window would exit without stopping it). Stop the target\n[…]\nWebSocket holding the previous release in draining\nstate, rolling back to it leaves no orphaned process (the old web pid is gone).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Stop a still-draining target before reusing its id on rollback",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:55:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1f30354b74f1c2d520cc0720544cdbf63f83d2a7",
          "body": "Add a `rollback` command (and `rollback` control command) that switches traffic\nback to a previously-active release by re-running the deploy flow on its\nretained metadata: it re-starts the target, health-checks the proxied process,\nswitches traffic, replaces singletons, and drains the current releas\n[…]\ns (rollback manages processes, not database state). The\ncompletion command's expected command list is updated for the new command.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a rollback command",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:44:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ab9580c25b99e300b6b7c2270ce8e33c5b08676",
          "body": "Distinguish restart reasons in status and events",
          "is_bot": false,
          "headline": "Merge pull request #34 from kaspernj/distinguish-restart-reasons",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:38:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52ff8e63188e9087142a2fe72d9c491d2dd26e37",
          "body": "Move the lastStartReason assignment into the \"spawn\" success handler so a failed\nstart attempt (e.g. an invalid cwd that triggers the error path) no longer\noverwrites status with a reason for a process that never ran. Add a regression\ntest that a failed spawn leaves lastStartReason unset.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Record lastStartReason only after a successful spawn",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:37:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2fb123c3214f53898c71c68e9b4b24254c16ae61",
          "body": "Thread a start reason through ManagedProcess.start(reason): \"deploy\" for\ndeploy-driven starts (release processes, services, singleton replacements),\n\"crash\" for auto-restarts after a non-intentional exit, \"manual\" for the restart\ncommand, and a reserved \"memory\" for memory supervision. The reason is\n[…]\nvs-manual distinction through status and the events command. README and\ndocs/cli.md document lastStartReason and the event reason.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Distinguish restart reasons in status and events",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:32:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dfd82fede2098f0fce68f8853527acb4807f499d",
          "body": "Add shell completion generation for bash and zsh",
          "is_bot": false,
          "headline": "Merge pull request #33 from kaspernj/add-shell-completion",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:26:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4a7cb52d0a0b91833825c9a24a13312752e1595",
          "body": "Add a `rollbridge completion <bash|zsh>` command that prints a sourceable\ncompletion script. The script is generated by introspecting the configured\ncommander program (command names and each command's long option flags), so it\nnever drifts from the real command surface. Bash completion offers comman\n[…]\n, the zsh script (#compdef and per-command options), and the\nunsupported-shell error. README and docs/cli.md document enabling it.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add shell completion generation for bash and zsh",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:20:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "474e17061ebe93619d76add06a20292c932af8ec",
          "body": "Add a structured event history and an events CLI command",
          "is_bot": false,
          "headline": "Merge pull request #32 from kaspernj/add-structured-event-history",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T12:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bd3c7fa5afe5d58c179f485333c4461c4e05396",
          "body": "Add an in-memory EventLog (bounded to the most recent 1000 events) that the\ndaemon records into by tapping its logger: every operational milestone already\nflows through this.logger, so deploys, traffic switches, release stops, process\ncrashes/restarts, restart-limit-reached, and failed control comma\n[…]\nd daemon\nintegration (deploy events recorded and served, --limit, failed-command\nrecording). Docs added to README and docs/cli.md.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a structured event history and an events CLI command",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T11:10:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d4da798bd0d17a0e223e092bca850bd08077ac5",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump patch version",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T08:27:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3eb09920f1dd57b2e66b09aec97bb56e88503069",
          "body": "Add a restart CLI command for non-proxied processes",
          "is_bot": false,
          "headline": "Merge pull request #31 from kaspernj/add-restart-cli-command",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T08:27:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25f52b93cb2052a981961bceaeb19b7170716933",
          "body": "Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Use release-patch package for release:patch script",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T08:01:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0e4ac12b4aad6c220a3527f4b71d585fd142879d",
          "body": "collectRestartTargets acts on tracked process instances regardless of state,\nbut the docs and the \"No running process\" error claimed running-only. Align\nthem to the conventional restart meaning (like systemctl restart): a running\nprocess is bounced and a crashed or stopped one is revived — which is \n[…]\n no instance is\ntracked for the id) and update docs/cli.md. Add a test that restart revives a\nstopped process instead of erroring.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make restart revive crashed/stopped processes, consistent with the docs",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T07:58:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "49fe3a45ef253602b4e96f80f7be07671bb62fef",
          "body": "Add a `restart` command (and `restart` control command) that bounces running\nnon-proxied processes in place: all of them by default, one with `--process\n<id>`, or a policy group with `--policy <companion|singleton|service>`. The\ndaemon collects matching running instances from the active release, sin\n[…]\nunknown-id errors, and\nthe control-command path over the socket. README and docs/cli.md document the\ncommand and its safety rules.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a restart CLI command for non-proxied processes",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T03:19:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f81668355974b12d899b856f468e032e3d207340",
          "body": "Add a per-process restart policy (max restarts, window, backoff, disable)",
          "is_bot": false,
          "headline": "Merge pull request #30 from kaspernj/add-restart-policy-config",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T03:11:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aca4bfaac8bf99f6d626f30411add1f3a455e0a",
          "body": "The unlimited-restarts, constant-delay fast path queued restartDelayMs directly,\nbypassing maxDelayMs. Queue restartDelayFor(0) instead so a configured\nmaxDelayMs caps the delay even when backoffFactor is 1 (the value is constant\nacross attempts in this branch, so attempt 0 is exact). Add a regression test\nthat the fast path applies maxDelayMs.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Apply maxDelayMs in the default-policy restart fast path",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T03:05:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c2ba9e242eecbb0952438fe205c3721299bee7d5",
          "body": "…ble)\n\nAdd a `restart` config object to each process that controls automatic restarts\nafter a crash, while keeping today's behavior as the default:\n\n- maxRestarts: cap on automatic restarts within windowMs before Rollbridge gives\n  up and leaves the process failed; 0 disables automatic restarts enti\n[…]\nisabled restarts, the windowed cap, the backoff/cap math, and\nconfig validation/defaults. Docs added to README and docs/config.md.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a per-process restart policy (max restarts, window, backoff, disa…",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:56:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "894a1e2924ba7abe45c9c08605f58caf9858ae62",
          "body": "Add a test for singleton replacement failure behavior",
          "is_bot": false,
          "headline": "Merge pull request #29 from kaspernj/test-singleton-replacement-failure",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:47:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd285a9cfd8ed61ff84a3103d194683749e1a67d",
          "body": "Cover the failure path of singleton replacement during a deploy: when the new\nrelease's singleton cannot start, the deploy surfaces the error, the previous\nsingleton has already been stopped (two copies never overlap even on a failed\nreplacement), and the singleton is left in a failed state with no \n[…]\ndateConfig collects it; normalizeConfig throws on it), completing the\n\"duplicate IDs and singleton replacement failure\" TODO item.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a test for singleton replacement failure behavior",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:43:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5700f900a4c185ce8654c9818e00b911452291e",
          "body": "Document Rollbridge release script versioning",
          "is_bot": false,
          "headline": "Merge pull request #26 from kaspernj/document-release-script-versioning",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:38:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c555356a59f5b56d564099d3a74ccb947906bcfb",
          "body": "Add a Velocious deployment guide",
          "is_bot": false,
          "headline": "Merge pull request #28 from kaspernj/add-velocious-guide",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:37:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69f93f2cb10b794e49a30d238d55ced7178ec859",
          "body": "Define $release_path and read the revision from the prepared release checkout\n($release_path/backend) instead of an undefined $repo, so the snippet is\nself-consistent and copy-pasteable.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix undefined $repo in the Velocious deploy example",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:35:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fbceb9a0b52e1fce92a147433fd7acf7cb5987ef",
          "body": "Add docs/velocious.md: how a Velocious backend's Beacon, background-jobs-main,\nbackground-jobs-worker, and web processes map to Rollbridge policies, with a\ncomplete rollbridge.js, port wiring via {{ports.<id>}}, wait-for-it startup\nordering, deploy behavior, and the service-vs-singleton trade-off fo\n[…]\n the roadmap, so background-jobs-worker uses gracefulStopMs\nfor in-flight jobs today. Link it from the README. Documentation only.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a Velocious deployment guide",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:27:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "94089a31e2d4faf563e343279e4cd02924e8719b",
          "body": "Add an Nginx guide",
          "is_bot": false,
          "headline": "Merge pull request #27 from kaspernj/add-nginx-guide",
          "author_name": "Kasper Stöckel",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:21:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b55dc1e00145e33f136964268fd662521f0146b",
          "body": "Add docs/nginx.md: a production Nginx guide for fronting Rollbridge's stable\nproxy port — a full server block, the WebSocket upgrade headers (with the\nmap-based connection-upgrade pattern), timeouts for long-lived connections\n(and their relation to proxy.drainTimeoutMs), forwarded headers and buffer\n[…]\nand a common-failure-modes table (502/503, dropped WebSockets,\n504, mid-deploy cuts). Link it from the README. Documentation only.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add an Nginx guide",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T02:07:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73d1b158e42c5257cd7baabe959bc5496f526b84",
          "body": null,
          "is_bot": false,
          "headline": "Document release script versioning",
          "author_name": "kaspernj",
          "author_login": "kaspernj",
          "committed_at": "2026-05-23T01:58:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 176,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 6,
      "active_weeks_last_year": 4,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "rollbridge",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "deploy",
            "zero-downtime",
            "process-supervisor",
            "reverse-proxy",
            "websocket",
            "rollbridge",
            "velocious"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/rollbridge",
          "is_deprecated": false,
          "latest_version": "0.1.12",
          "repository_url": "https://github.com/kaspernj/rollbridge",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3134,
          "first_published_at": "2026-05-22T08:12:48.201000Z",
          "latest_published_at": "2026-07-20T08:21:11.760000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 54069,
      "source_files_sampled": 47,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 5,
        "malicious_count": 0,
        "assessed_package": "npm:rollbridge@0.1.12",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "http-proxy",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.18.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 60,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "kaspernj",
          "commits": 176,
          "avatar_url": "https://avatars.githubusercontent.com/u/234531?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 9 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/16 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "1824e6a586a03cd6a62ab15f2e88ebbb1894b27e",
        "ran_at": "2026-07-26T09:53:19Z",
        "aggregate_score": 2.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T08:21:11Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-20T08:20:53Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kaspernj/rollbridge",
    "host": "github.com",
    "name": "rollbridge",
    "owner": "kaspernj"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 43,
      "inputs": {
        "security": 38,
        "vitality": 35,
        "community": 32,
        "governance": 56,
        "engineering": 50
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 35,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "commits_last_year": 176,
              "human_commit_share": 1,
              "days_since_last_push": 6,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "176 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 176
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 32,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "rollbridge"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3134
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,134 downloads/month across npm",
                "points": 46.6,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3134,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 60,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "60/60 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 60,
                      "decided": 60
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/16 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "followers": 54,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "kaspernj",
              "public_repos": 307,
              "account_age_days": 5960
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "54 followers of kaspernj",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 54,
                      "login": "kaspernj"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "307 public repos, account ~16 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 307
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 16
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "rollbridge"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "10 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 50,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 9 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 38,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 23,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 2.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 9 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/16 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:rollbridge@0.1.12 runtime dependency closure — what installing the published package pulls in — 5 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:rollbridge@0.1.12",
                  "assessed": 5
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 5,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 5,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 59,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.86,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "86 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 86,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.44,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "44 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 44,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 54069,
              "source_files_sampled": 47,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/47 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 47,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T09:53:30.777910Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kaspernj/rollbridge.svg",
  "full_name": "kaspernj/rollbridge",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.