Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-28 08:19 UTC

liu1700 / orlop

Multi-tenant, zero-trust durable POSIX disk for untrusted agents: per-agent mTLS, content-addressed chunk store, FUSE/NFS mount client.

Go · RustApache-2.0★ 1 Stern⑂ 0 Forksseit Juni 2026Auf GitHub ansehen ↗

liu1700/orlop erreicht einen Gesundheitsindex von 54 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei AI Readiness (75/100) ab, am schwächsten bei Security (30/100). Zuletzt vor 2 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

54
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

54
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

LiuPersönliches Konto
50 Follower52 öffentliche Reposseit Nov. 2013

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/liu1700/orlopv0.4.5-14vor 2 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

70Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 2 Tagen
2.8/36Commit-Rhythmus — 4/52 Wochen mit Commits
16.7/18Commit-Volumen — 71 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year71
human_commit_share1
days_since_last_push2
active_weeks_last_year4
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 11 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 2 Tagen
27/27Release-Rhythmus — ein Release etwa alle 3,1 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count11
latest_release_tagv0.4.5
releases_from_tagsnein
days_since_latest_release2
mean_days_between_releases3,1

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

33Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 1 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

59Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.6/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 97 % der Commits
2.7/13.5Breite der Beitragenden — 2 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled2
top_contributor_share0,972
Wie die Bewertung erfolgt
46.8/46.8Issue-Lösungsquote — 100 % der Issues geschlossen
37.7/38.3PR-Annahme — 64/65 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/29 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs64
open_issues0
closed_issues24
issue_closed_ratio1
closed_unmerged_prs1
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
12.3/25Reichweite des Inhabers — 50 Follower von liu1700
24.6/25Kontohistorie — 52 öffentliche Repos, Kontoalter ca. 12 Jahre
Verwendete Eingangsdaten
followers50
owner_typeUser
is_verified
owner_loginliu1700
public_repos52
account_age_days4.624
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 2 Tagen
20/20Versionshistorie — 14 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/liu1700/orlop
ecosystemsgo
any_deprecatednein
min_days_since_publish2

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

71Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 6 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
0/15Dokumentations-/Homepage-Site
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepage
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

30Gefährdet · 16 % des Gesamtindex

Sicherheitslage

30Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — keine Daten
2.5/2.5CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 25 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

75Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 71 von 71 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes2.821
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile, third_party/fuser/Makefile
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — Go (statisch typisiert)
10/10Reproduzierbare Umgebung — devcontainer, lockfile
10/10Belegte Agentenpraxis — 65 der letzten 71 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesCargo.lock, go.sum
has_dockerfilenein
typed_languageja
bootstrap_filesMakefile, third_party/fuser/Makefile
has_devcontainerja
has_linter_confignein
typecheck_configs
agent_commit_share0,915
toolchain_manifestsCargo.toml, bench/Cargo.toml, go.mod, third_party/fuser/Cargo.toml
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Go (statisch typisiert)
54.4/55Handhabbare Dateigrößen — 3/291 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageGo
largest_source_bytes102.445
source_files_sampled291
oversized_source_files3
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalnein
api_schema_files

Eckdaten

1GitHub-Sterne
2Mitwirkende
71Commits, letzte 12 Monate
2Tage seit letztem Push
11Releases
1Bus-Faktor
0offene Issues
crates.io, GoPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'orlop' from its registry
  • Could not fetch crates package 'orlop-bench' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 3.0 / 10
3.0Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-28 08:19 UTC

10Binary-Artifactsno binaries found in the repo
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities25 existing vulnerabilities detected
Direkte Abhängigkeiten 46
RegistryPaketVersionsvorgabeManifest
crates.ioanyhow1Cargo.toml
crates.ioblake31Cargo.toml
crates.iochrono0.4Cargo.toml
crates.ioclap4Cargo.toml
crates.ioglobset0.4Cargo.toml
crates.iolibc0.2Cargo.toml
crates.iolru0.12Cargo.toml
crates.ioparking_lot0.12Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.iormp-serde1Cargo.toml
crates.ioquinn0.11Cargo.toml
crates.iorustls0.23Cargo.toml
crates.iorustls-pemfile2Cargo.toml
crates.iotokio1Cargo.toml
crates.iotokio-rustls0.26Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.ioserde_yaml0.9Cargo.toml
crates.iorusqlite0.31Cargo.toml
crates.iox509-parser0.16Cargo.toml
crates.iotempfile3Cargo.toml
crates.ioserde_bytes0.11.19Cargo.toml
crates.iofastcdc3Cargo.toml
crates.ionfsserve0.11Cargo.toml
crates.ioasync-trait0.1Cargo.toml
crates.iodaemonize0.5Cargo.toml
crates.ioos_pipe1.2Cargo.toml
crates.ioanyhow1bench/Cargo.toml
crates.iochrono0.4bench/Cargo.toml
crates.ioclap4bench/Cargo.toml
crates.iorand0.8bench/Cargo.toml
crates.ioserde1bench/Cargo.toml
crates.ioserde_json1bench/Cargo.toml
Gogithub.com/bmatcuk/doublestar/v4v4.10.0go.mod
Gogithub.com/go-chi/chi/v5v5.2.5go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogithub.com/jackc/pgx/v5v5.9.2go.mod
Gogithub.com/pressly/goose/v3v3.27.1go.mod
Gogithub.com/prometheus/client_golangv1.23.2go.mod
Gogithub.com/quic-go/quic-gov0.60.0go.mod
Gogithub.com/vmihailenco/msgpack/v5v5.4.1go.mod
Gogolang.org/x/timev0.14.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Golukechampine.com/blake3v1.4.1go.mod
Gomodernc.org/sqlitev1.49.1go.mod
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 5615,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1492330,
        "Rust": 710110,
        "Shell": 37497,
        "Makefile": 2984,
        "Dockerfile": 8567,
        "Go Template": 2270
      },
      "pushed_at": "2026-07-26T05:58:20Z",
      "created_at": "2026-06-26T05:23:59Z",
      "owner_type": "User",
      "updated_at": "2026-07-26T05:57:49Z",
      "description": "Multi-tenant, zero-trust durable POSIX disk for untrusted agents: per-agent mTLS, content-addressed chunk store, FUSE/NFS mount client.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Liu",
      "type": "User",
      "login": "liu1700",
      "company": null,
      "location": null,
      "followers": 50,
      "avatar_url": "https://avatars.githubusercontent.com/u/6064238?v=4",
      "created_at": "2013-11-29T06:10:07Z",
      "is_verified": null,
      "public_repos": 52,
      "account_age_days": 4624
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-07-26T06:01:48Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-07-16T15:53:09Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-07-05T18:18:49Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-07-05T08:32:50Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-05T06:28:25Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-07-03T20:16:20Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-07-02T15:18:02Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-06-28T05:25:31Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-06-28T03:07:14Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-06-27T23:40:47Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-06-27T21:16:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ed03ccff5c60cb5db1c1143116316f07ad171a46",
          "body": "* fix: make live handoff portable to musl\n\n* fix: explain libc-specific length conversions",
          "is_bot": false,
          "headline": "Fix live handoff on musl release targets (#89)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T05:57:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "414a3d4180686647f6575d2b23d2c22de39869c0",
          "body": null,
          "is_bot": false,
          "headline": "fix: stamp releases and configure mount paths (#88)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T05:37:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49741d22ae372a268f80ddb7af2f2f8daf0b9ecc",
          "body": null,
          "is_bot": false,
          "headline": "fix: add live FUSE mount handoff (#87)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T04:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bece032857ade7b4699489587d0c17d5e28b3dbb",
          "body": "* fix: harden infra lifecycle and POSIX semantics\n\n* ci: disable VCS stamping in FUSE rig",
          "is_bot": false,
          "headline": "Harden mount lifecycle, POSIX semantics, and infra observability (#86)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T03:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9dd90b6f529952db0f0e2a7f763bc2d6461937d",
          "body": "Refactor: shed datagateway-era residue, split worst-complexity paths",
          "is_bot": false,
          "headline": "Merge pull request #76 from liu1700/task/deep-refactor",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-16T15:46:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88e373c9653970f86789fc412c8640280502445b",
          "body": "- ORLOP_DATAGW_* env family renamed to ORLOP_* (old names remain accepted\n  fallbacks via envKeyWithLegacy); helm chart + docs on the new names.\n- manifests.go: renameOpt (cognitive 86) split into five phase helpers;\n  deleteSymlink/deleteSpecialNode clone collapsed. Rename/CAS/NOREPLACE\n  behavior \n[…]\neck code.\n- Shared startTestServer helper collapses the 3-way control test-setup clone.\n\ngo build/vet/test, cargo build/test, clippy: all clean.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: shed datagateway-era residue, split worst-complexity paths",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-07-16T06:35:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d44dd151cf2205251829b9a773b87ad2553609df",
          "body": "Rename overwrites a compatible destination, so a caller that needs a collision-\nsafe atomic move (e.g. a restore into an occupied path) had to fall back to a\nstat-then-rename TOCTOU. Add a real create-only mode.\n\n- Wire: ManifestRenameRequest gains an optional no_replace flag (Go\n  `,omitempty`; Rus\n[…]\ndataclient RenameNoReplace returns ErrExists over an existing dest;\nRust asserts no_replace=false is omitted and true round-trips.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dataplane): create-only rename (RENAME_NOREPLACE) (#75)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T17:31:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d97c3e1241d546724e61b2c00babd26ec0c87453",
          "body": "…(#74)\n\nhandleManifestPut attaches a recovery hint (with the server's current version)\non an ESTALE conflict, so the client's StaleError.CurrentVersion is populated.\nhandleManifestDelete/handleManifestRename went through manifestErrToWire, which\nmapped ErrVersionConflict to a bare ESTALE with no hin\n[…]\n\nhint (used by manifest_put); older clients ignore it. Tests assert Delete and\nRename-source conflicts return the current version.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dataplane): carry current version on Rename/Delete CAS conflicts …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T17:18:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65365caf04ec7c7c643eed8de4227fb9a576595f",
          "body": "WriteFile uploads all content chunks (chunk_put) and only then commits the\nmanifest (manifest_put). chunk_put wrote the blob to disk but inserted no row\ninto the `chunks` refcount table — that row was created solely by\napplyChunkRefDelta inside manifest Put/Delete/Rename. So whenever manifest_put\nfa\n[…]\nC candidate with its real size; once referenced, re-noting leaves refcount and\nadded_at untouched and it is no longer a candidate.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gc): reclaim chunks orphaned by an uncommitted WriteFile (#73)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T17:13:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4f85566a6f0e3631dc94e1a554322745744bafd",
          "body": "Two doc-accuracy fixes and one test-coverage gap from an adversarial review of\nthe whole-file object-ops surface. No behavior change.\n\n- ManifestRenameRequest.ExpectedVersionTo was documented \"0 = must-not-exist;\n  otherwise CAS replace\", and ErrAlreadyExists was documented as returned by\n  Rename o\n[…]\n tenant-only→\"\", and garbage/nil→\"\" fail-closed paths,\n  so SAN-parsing drift is caught in unit CI instead of as a scoping outage.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dataplane): correct Rename CAS docs; cover agentIDFromCertDER (#72)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T15:52:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8039c96429881d7fea565e02179262092b17d3be",
          "body": "…e (#71)\n\nDial presented only the leaf certificate. orlop-server's client-CA pool is\nthe org ROOT ALONE (cert_tenant_binding.go), so a leaf signed by a tenant\nintermediate can't be verified from the leaf alone: in TLS 1.3 the client's\nhandshake \"succeeds\" but the server closes the connection right a\n[…]\ned a single self-signed CA, so this class of bug only shows\nagainst a real intermediate chain — which the live test now exercises.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dataclient): present the tenant intermediate on Dial; add live e2…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T08:29:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2dd460641d13e25477f6764c9164959f17f73b35",
          "body": "…ount (#70)\n\nAdds github.com/liu1700/orlop/dataclient: a Go client that speaks\norlop-server's binary mTLS frame protocol directly to list/read/write/\ndelete/rename an agent's files with no FUSE mount and no mount lease.\nReads are lease-free; writes are guarded by manifest CAS (ErrStale).\n\n- Enroll()\n[…]\ntays\nstdlib-only). No server changes. Tested with an in-process frame server\nand a real mTLS Dial round-trip; go test -race clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dataclient): Go data-plane client for whole-file ops without a m…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T06:23:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3862d13e84e830958e50245261d30195e76ffd4d",
          "body": "…ecreate an orphan dir (#69)\n\nA data-plane connection resolves its *tenantState once at accept and reuses that\npointer for every frame (serveFrames -> identifyV2Peer -> goRequest). When\norlop-control purges a tenant (unregisterTenant: delete from map, db.Close,\nos.RemoveAll(tenantDir)), a chunk_put \n[…]\nstChunkPutOnClosedTenantReturnsESTALE — wire-level errno\n\n\nClaude-Session: https://claude.ai/code/session_01PHcvKCSt7VtJ9yJDADnXe1\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "server: gate tenant store writes on unregister so a dying pod can't r…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-03T20:06:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6192d82db97652f2c3f5e7b7da2c7093ceb3f289",
          "body": "…(#68)\n\nLinter-guided (deadcode, staticcheck, golangci-lint, clippy) plus a manual\nsweep of all three trees. Net -1,700 lines with no behavior change except\nthe listed fixes. All tests pass; clippy is warning-clean.\n\nControl plane (net -875):\n- Delete 17 dead sqlc queries (the whole anonymous-sessio\n[…]\nre and\n  .dockerignore; list advanced-usage.md in the README docs table.\n- Add CLAUDE.md (component map, build/test, invariants, docs pipeline).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: repo-wide dead-code purge, dedup, and doc/config alignment …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-02T16:02:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6561135bac1bacc6536524914e4e44d64e0bf9b5",
          "body": "…se (#67)\n\n* docs: fact-check and optimize all reference docs against the implementation\n\nSubstantive-editor pass over the README and every docs/ reference page,\nverifying each claim against the Go/Rust source and cutting or correcting\nanything unsupported.\n\nKey fact corrections:\n- container-images:\n[…]\nored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01PHcvKCSt7VtJ9yJDADnXe1\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "server: stale mount connection can no longer kill its successor's lea…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-02T15:00:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ef4295caee0731951bbddc8c0726a5ea3fbb877f",
          "body": "…tation (#66)\n\nSubstantive-editor pass over the README and every docs/ reference page,\nverifying each claim against the Go/Rust source and cutting or correcting\nanything unsupported.\n\nKey fact corrections:\n- container-images: document the real `orlop mount --from-env` env contract;\n  drop the non-ex\n[…]\nS (it's NFS there).\n\nAlso normalize doc link style and point repo-file links at absolute GitHub URLs\nso they resolve on orlop.dev.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: fact-check and optimize all reference docs against the implemen…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T20:17:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8ec8b1e1c0a6025b54bdc34c1200175bda89812",
          "body": "…panion (#65)\n\nCut the standalone quickstart to the first-integration essentials (install →\nup → see the disk → stop → verify persistence) for a shell-fluent ops/backend\nreader. Everything past that minimal path — the agent paste block, install\noverrides, build-from-source, what `dev up` does, prefl\n[…]\nta lives, and\n`doctor` troubleshooting — moves to a new advanced-usage.md companion, linked\nfrom the quickstart's \"Going further\".\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: slim the quickstart to its minimal path; add advanced-usage com…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T18:24:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "925e83db30f04bed146c5fc3db2e9feae88ad18d",
          "body": "Rewrite the agent-memory reference from a feature overview into a\npractical how-to: a local round-trip, then five abstracted steps for\ngiving an agent its own durable, isolated disk (allocate -> enroll ->\nmount -> read/write -> reattach), each with real commands and a verify.\n\nAdd a \"Where orlop sto\n[…]\nm) for positioning\nand SEO. The lead sentence is tuned so the auto-generated meta\ndescription leads with the keywords and JuiceFS.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reframe agent-memory as a how-to (per-agent disk, SEO peers) (#64)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T15:43:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4fb39ab4c03dd309b36cb4965897d1c1c9ea5867",
          "body": "Patch release consolidating the standalone dev-stack fixes (closes #51–#56):\nnon-interactive lifecycle (`dev up --detach` + `dev down`, #51), graceful\nshutdown exits 0 (#52), `status` liveness-probes UP/DEGRADED/DEAD (#53),\n`doctor --dev` + dev-up-aware warnings (#54), stable non-epoch directory mti\n[…]\n-compat — API major stays 1, no new migrations.\n\nBump version strings + the helm appVersion + the install/image examples to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.3.1 (#63)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T05:21:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e989d5d7319d498ae8e182f0f5451c9a89199e29",
          "body": "… commands (#56) (#62)\n\nThe standalone quickstart was effectively 4 mental steps (verify ports/mount →\ninstall → doctor → dev up). Fold the host checks into `dev up` itself so the\nhappy path is just install + run.\n\n- `dev up` preflight now runs the same checks as `orlop doctor --dev` (mount\n  suppor\n[…]\n busy port → fail-fast preflight with fix,\nexit 1; clean host → comes up; full install→up→write→down→up→file-survived\nwalkthrough.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dev): fold host preflight into `dev up`; shorten quickstart to 2…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:36:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8151a169f385bda6bc9b90a16b38346464bc763b",
          "body": "Directories carry no manifest (only files do), so the macOS NFSv3 server passed\nmtime_ns = 0 for every directory — surfacing as `Dec 31 1969` in `ls -l` and\nconfusing tools that sort/filter by mtime.\n\nSynthesise a sane, stable timestamp for directories: capture the mount time\nonce (`started_ns`) and\n[…]\nserts dir getattr/readdir/root mtimes are non-zero and\nstable; e2e `ls -laR` on a live mount shows real timestamps with no `1969`.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(nfs): give directories a stable non-epoch mtime over NFS (#55) (#61)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:31:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f1c7d590eb1b73238e304e3fbea2e74e6aedaf1",
          "body": "On a clean host, `orlop doctor` warned about a missing config + credentials —\nirrelevant to `orlop dev up`, which supplies them out of band — so a first-time\nuser read the standalone quickstart as \"your setup is incomplete.\"\n\nAddress both options from the issue:\n- `orlop doctor --dev`: checks exactl\n[…]\n, exit 0; with a\nstack holding the ports → port checks FAIL, exit 1 with actionable fixes;\nplain `doctor` warnings mention dev up.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(doctor): make doctor aware of the `dev up` flow (#54) (#60)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:22:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a4d7992ad98d72f0b4773f16a19c376a5ca50d6",
          "body": "…#53) (#59)\n\n`orlop status` printed a hardcoded `dev stack: UP` header straight from the\ncached `dev.json`, so a stack that died uncleanly (kill -9, OOM, crash) still\nread as a healthy UP — even though the per-component lines already probed\nliveness.\n\nDerive the overall state by probing the supervis\n[…]\n to component health.\n\nTested e2e (macOS): healthy → UP; `kill -9` supervisor → DEAD (not UP) with\nhint; `dev down` → not running.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(status): report DEAD/DEGRADED from live probes, not a cached UP (…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:16:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "baea0110aef5efeed7aa1de1bfc22e096643d187",
          "body": "A signal-initiated shutdown of `orlop dev up` is the documented, intended way\nto stop the stack, so it must be a success — a process supervisor or CI step\nshouldn't see a non-zero exit and mistake a normal stop for a crash.\n\nMake the exit status explicit and deterministic instead of always returning\n[…]\ntrol-plane child → tears the rest down and exits 1 naming the\ncrashed component. Unit tests cover the three shutdown_result cases.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dev): make `dev up` exit status reflect why it stopped (#52) (#58)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:11:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7db06aeee4e2249908ae72048a50110dfe2fbc2",
          "body": "…ecycle (#51) (#57)\n\n`orlop dev up` only ran in the foreground, stoppable solely by Ctrl-C, so CI,\nbackgrounded jobs, IDEs, and agents had to PID-hunt the supervisor to stop it\n(and the naive pgrep selects the wrapper shell, whose SIGINT is dropped).\n\n- `dev up --detach`/`-d`: re-exec the supervisor\n[…]\n up --detach → status → I/O → down; crash (kill -9) →\ndown reconcile frees ports; foreground up stopped via down; idempotent down.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dev): add `dev down` + `dev up --detach` for non-interactive lif…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T03:57:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f970c5e397a4f298a6813ec6a74a57c8b594f965",
          "body": "Feature release consolidating the consumer-feedback work: multi-arch GHCR\nimages (#47), a reference Helm chart (#48), control-plane API versioning +\nOpenAPI (#49), and upgrade-safety guards — CI in-place-upgrade test + boot\nschema self-check + migration policy (#46). All additive and back-compat\n(API major stays 1; no new migrations). Bump version strings + the helm\nappVersion + the install/image examples to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.3.0 (#50)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T03:02:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "04c96758e771a9b0023d51e940c97d58392d8d61",
          "body": "… detection (#42) (#49)\n\nThe Go SDK and orlop-control agreed on REST paths and bodies only implicitly: it\nhappened to be byte-identical across v0.1.0 and v0.2.0, but there was no\ndocumented contract and no way to detect version skew — a mismatched pair would\nsurface as an opaque 4xx, and other-langu\n[…]\nd\n  SDK/server (v0.1.0–v0.2.x) speaks major 1. Other-language clients implement\n  from the spec and check the header the same way.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "api: version the control-plane API — OpenAPI spec + SDK<->server skew…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T01:22:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "992b59577ef12d776e6a8f448f531ffd1698b0a8",
          "body": "… (#48)\n\nConsumers had to reverse-engineer the whole deployment from the binaries — the\nmigrate step, the CA/secrets topology, the mTLS self-provisioning, and a set of\ncross-component env constraints that are easy to get subtly wrong. This adds a\nreference chart (deploy/helm/orlop) that stands up a \n[…]\nallowed) and served mTLS on ops+data, both\nreached Ready, and `orlop-control server register` (the NOTES.txt next step)\nsucceeded.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "deploy: reference Helm chart for control + server on Kubernetes (#41)…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T01:11:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e374f8d733c698a3b45208ea4782f436f18d1b2",
          "body": "Consumers running orlop on Kubernetes had to rebuild from source every release —\nthe Go binaries are cheap, but the Rust mount client (libfuse3 + a multi-minute\ncargo build) is the painful one. Publish prebuilt multi-arch images instead.\n\nThe release workflow gains an `images` job (tag-only, sibling\n[…]\n and a multi-arch\n(amd64+arm64) buildx of the TARGETARCH-staged Dockerfile succeeds. The GHCR\npublish itself runs on the next tag.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "images: publish multi-arch GHCR images per release (#40) (#47)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:59:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26974e8ba722703ceab8becb686c6cf0157a39c0",
          "body": "…(#39) (#46)\n\nIn-place upgrades had no guarantee: squashing already-released migrations\n(#23) reset goose numbering, so a deployed v0.1.0 database skipped the\nsquashed baseline and silently lacked access_tokens.consumed_at and the\ncert_revocations table. goose reported success; the gap only surfaced\n[…]\nnd a v0.1.0 database without the bridge fails boot with the exact\nincident (missing cert_revocations + access_tokens.consumed_at).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "upgrade safety: CI guard + boot schema self-check + migration policy …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:46:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f761e97f1410ef26a18903e9c7bbe12a86f9ceaa",
          "body": "These two are required status checks on main. With their `pull_request`\npath filters, a PR touching no Go/Rust files (docs, config) never triggered\nthem, leaving the required `go`/`build` checks stuck \"Expected\" and the PR\nunmergeable. Drop the pull_request path filters so both always run and\nreport on every PR; this is the prerequisite for enforce_admins=true gating.\nPush-to-main path filters are left as-is.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: run go and build checks on every PR (not path-filtered) (#44)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:21:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f65cc0aaba21cb9eb2dff53ce353a2383d0c1e0e",
          "body": "…l-bring-up (#43)\n\nThe quickstart still walked the six manual steps and ended with the fragile\n`kill %1 %2 %3` teardown, predating `orlop dev up`. Rewrite it around the\none-command path: install -> `orlop dev up` (+ `orlop status`) -> write a file,\nCtrl-C, bring it back up, watch it survive. Move th\n[…]\nthe\nrestart cycle preserves the file. Update README quickstart + docs table and the\ndatabase-backends cross-reference accordingly.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: make the quickstart `orlop dev up`-first; move by-hand to manua…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:15:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31f723fa57b7129aacf2e20df7ef5dc094a61049",
          "body": "Patch release: bridge migration (#38) so v0.2.0+ upgrades a database\nprovisioned by the pre-squash v0.1.x line. Update the install-version examples\nin the quickstart and the release workflow comment to match.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.2.1",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T23:37:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a6f99c9a658579bfc89d7130f5a7bef103290c62",
          "body": "…base (#38)\n\nThe squashed baseline (0001_init, #23) reset goose numbering to version 1, but a\ndatabase migrated by v0.1.0 is already at goose version 9 (from its original\n0001-0009 files). goose only applies versions greater than the current max, so on\nthose databases it skips the squashed baseline \n[…]\n010 and adds both objects; idempotent on re-run; a fresh DB applies\n0001+0010 to the same final schema. sqlc codegen is unchanged.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(db): bridge migration so v0.2.0 upgrades a pre-squash v0.1.x data…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T23:36:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a2131424eadf9acdd0a9914fb5f796c872538e84",
          "body": "… dev up + status (#37)\n\n* cli: stop orlop-control booting a server on unknown args; add --version\n\n`orlop-control <anything>` fell through a bare os.Args[1] switch to run(),\nso a typo or `--version` silently started a control plane on :8080 with no\ndatabase configured. Classify the arguments instea\n[…]\npatch) read, removing\n  the duplicated verb list.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CLI UX: kill the orlop-control footgun, fix macOS unmount zombie, add…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T23:18:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d795efd448ba33bc8feb54d4182442473cb896c4",
          "body": "Commit the standalone quickstart to a single SQLite happy path. Drop the\nPostgres/Docker branch (now a one-line pointer to database-backends.md),\nremove the optional `migrate up` step (SQLite applies its embedded schema\non open), and cut the duplicated gotchas and thrice-stated durability\nthesis. St\n[…]\nle blocks, the durability proof as the\npayoff. Net 126 lines removed.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: make the quickstart SQLite-only and tighter (#36)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T21:28:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b33819fc874e51177a4b13516791cd1f4fd34ccb",
          "body": "1.0.0-rc.17 overstated maturity for a project still at v0.1.0. Move to\n0.2.0 and update the install-version examples in the quickstart and the\nrelease workflow comment to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.2.0 (#35)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T21:12:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f0227bbc27a01e0a3273f3b63578ba51bb2cc819",
          "body": "GitHub's Intel macos-13 runners sat unassigned for hours and blocked the\nrelease. Build x86_64-apple-darwin on macos-14 instead (Go via GOARCH,\nRust via the x86_64-apple-darwin target), same runner as darwin/arm64.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: cross-compile darwin/amd64 on the Apple-Silicon runner (#34)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T21:04:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "eba5384c300065fa8071153e2f3a09fee6eb141d",
          "body": "…l-first quickstart (#33)\n\n* release: cross-platform binary builds and install.sh\n\nAdd .github/workflows/release.yml: on a v* tag, build orlop, orlop-control,\nand orlop-server for linux/darwin x amd64/arm64 and publish tarballs +\nsha256 to the GitHub Release. Go binaries are pure-Go (modernc sqlite \n[…]\n the agent\nfast-path prompt are updated to match.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: prebuilt binaries (release workflow + install.sh) and instal…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T18:28:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f376213bc59742cf0930cb5b144dae516c099bc8",
          "body": "…s (#32)\n\nRemoving the dead device-flow code (#31) left the two now-empty tables in the\nschema. Drop them from the Postgres squashed baseline and the SQLite schema, and\nregenerate sqlc so the dead DeviceAuthorization / RefreshToken models go away.\n\nNothing references these tables. go build/vet/test \n[…]\n(which applies schema.sql on open) and the sqlc-validated db package.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: drop the unused device_authorizations and refresh_tokens table…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T17:43:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "89ae5c0bd91a253470d347ca6cc3ff3c2545821d",
          "body": "The orlop binary has no `orlop login` command and nothing drives the\ncontrol-plane device-code flow, so remove it end to end and make the docs match.\n\nControl plane (Go):\n- Remove the device routes (/auth/device/code|token, /auth/token/refresh,\n  /device, /device/lookup, /device/approve) and their h\n[…]\nsurface.\n\nVerified: go build/vet/test and cargo build/test all green.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: remove the dead device-flow login subsystem (#31)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T17:34:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b5bbb9d7ef6e2ec00fd0565cec2bf0864d11fe56",
          "body": "… (#30)\n\nRewrite the README and every docs/ page against the actual implementation,\nfixing factual drift and turning the internal design RFCs into reader-facing\nreferences.\n\n- Fact-checked every command, flag, env var, route, field, and behavior against\n  the code. Corrected the major errors: design\n[…]\nark, light/dark wordmarks); the README now leads\n  with the wordmark.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: fact-check and reframe all viewer-facing docs; add brand assets…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T16:31:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25d7b705097358e97f5d053ebf783b2a93217c80",
          "body": "Our SQLite/Postgres choice was buried inside the standalone quickstart as\n\"Option A/B\" with no single home, no comparison, and the caveats (single-node,\nCA-secrets backend constraint) scattered across the quickstart and code.\n\nRestructure it the way established multi-backend projects do — a dedicate\n[…]\n and the runbook's\nDATABASE_URL example point at it too.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add a canonical \"Database backends\" reference page (#29)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:58:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b88757661de7a50cd0ca50197a3242dea79b0ef3",
          "body": "…(#28)\n\nWires the embedded SQLite backend in so the control plane actually runs on it.\nA storage.Store union interface (every role interface) lets runtimeDeps.store\nhold either backend; a DATABASE_URL \"sqlite:\" scheme selects SQLite (schema\napplied on open), anything else is Postgres. openStore() is\n[…]\nes not\neven Postgres is required for a single-node try).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: backend selection + quick-start on SQLite (stage 6d) …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:49:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "472a9a412f38bbdb74e95dda5dd5412494d3ea77",
          "body": "Completes the SQLite adapter: the allocations subdomain (disk lifecycle, mount\nleases, purge CAS, placement + capacity reservations), the provisioning writes\n(idempotent tenant/user ensure + per-agent allocation upsert + reassign), and\ntransactions. *sqlite.Store now implements every storage role in\n[…]\nime). Still additive — wiring +\nquick-start docs are 6d.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: AllocationStore + Tx + provisioning (stage 6c) (#27)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:40:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bceaeec2ac8f5131e2631e8e03cc7455d1bb244",
          "body": "Implements the sessions subdomain (SessionOps) on the SQLite backend: device\nauthorizations, access tokens (incl. the single-use agent-enroll consume),\nrefresh tokens, and the user reads. The conditional updates preserve the\nPostgres semantics exactly — Approve/Deny match only a still-pending row\n(R\n[…]\n tests cover the flow\nagainst a real temp-file database.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: SessionStore — device flow + tokens (stage 6b) (#26)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:28:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b6e8d2ae9068f419e8ca7f380213c947d8e62564",
          "body": "…) (#25)\n\nFirst slice of an embedded, zero-external-dependency SQLite backend (issue #4's\n\"SQLite implementation\"), so the control plane can run for local quick-start\nwithout Postgres. Pure-Go driver (modernc.org/sqlite), hand-written database/sql\nadapter mirroring package postgres.\n\nThis slice land\n[…]\nemp-file\ndatabase (no external dependency — runs in CI).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: embedded backend foundation + simple stores (stage 6a…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:24:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa1b6cfb614724957ce62ffc084859aeded627df",
          "body": "…s (stage 5c) (#24)\n\nMove internal/db (the goose migration runner, sqlc query sources, generated\nsqlcdb, and squashed schema) under internal/storage/postgres/db, so everything\nPostgres-specific lives beneath the postgres adapter. The domain layer\n(internal/storage) and a future internal/storage/sqli\n[…]\nthe relocated goose embed applies\nthe baseline cleanly).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: relocate the Postgres backend under internal/storage/postgre…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:43:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "759fcf5f9acf7eeb88948c811d18080e76003ed1",
          "body": "The 12 incremental migrations (0001-0012) accreted real cruft — most visibly\nthe email-OTP self-service login added in 0009 and dropped in 0010 when #9\nremoved self-service signup. Pre-release, with no production schema history to\npreserve, collapse them into one 0001_init.sql baseline that reflects\n[…]\ne\nrecreated; there is no released deployment to migrate.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "db: squash migrations into a single clean baseline (stage 5b) (#23)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:36:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dfdb50a8fb8a30cb90f8db6397b65d3d5e17d7f2",
          "body": "With every consumer migrated onto the storage domain layer, the\nsqlc-generated db.Store alias (and db.ErrNotFound) has no users left — delete\ninternal/db/store.go. The runtimeDeps.queries field and its sqlcdb.New wiring go\nwith it; the DB-configured guards now key on deps.store. The internal/db pack\n[…]\nunner + sqlc query layer the Postgres adapter\nbuilds on.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: remove the db.Store god interface (stage 5a) (#22)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:25:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "548818ce2373a866578fed26ec22ee6d932f2b4c",
          "body": "Move the operator CLI commands (user seed/suspend, server register, token\nissue) and the serverapiMountLeaseFencer off direct sqlcdb.New(pool) usage onto\nthe storage domain layer, so sqlcdb is no longer touched outside the adapter\npackage.\n\nAdds storage.AdminStore — the privileged out-of-band operat\n[…]\n the runtimeDeps.queries field and its wiring (stage 5).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate operator CLI + fencer off sqlcdb (stage 4e) (#21)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:18:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "077f758bc60de79254da348f2ee28763ba562e45",
          "body": "The journal HTTP handler carried a db.Store field that nothing read — drop it\n(and the constructor param). The serverapiJournalAdapter's inline placement\nquerier moves onto the storage domain layer: its queries field is now a\ntenantPlacementQuerier, and opsAddrFor delegates to the shared\nresolveTena\n[…]\nstill yields an empty\njournal page rather than an error.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate journal off db.Store (stage 4d) (#20)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:06:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ea1768eba0ba38d16d0ee603128837327609e63e",
          "body": "Move the entity provisioning handler — the control-plane→control-plane\n/v1/entities + /v1/agents/{id}/enroll-token surface — off the sqlc db.Store\ngod interface and onto the storage domain layer.\n\nAdds storage.ProvisioningStore (EnsureTenant, EnsureUserWithID,\nUpsertAgentAllocation, GetAllocationByA\n[…]\n; callers are the control-plane passing canonical UUIDs.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate /v1/entities provisioning off db.Store (stage 4c) (#19)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:01:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c361ba6fa3e8d0773dcc9aeaa4d6c25b9eaa5f3b",
          "body": "Move the five read-path handlers — agent enroll, mount-lease, dashboard,\ncontrol tenant-usage, and purge-sweep — off the sqlc-generated db.Store god\ninterface and onto the backend-agnostic storage layer.\n\nEach handler now depends on a narrow domain interface listing exactly the\nmethods it calls (age\n[…]\nreshes the stale WithTx note in the storage package doc.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate read handlers off db.Store (stage 4b) (#18)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T07:43:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac739bf5309b5b95664f64f2d73f640b500d910b",
          "body": "First slice of the handler migration. The api-token routes and the bearer\nmiddleware no longer use db.Store.\n\n- storage.APITokenStore: domain types (APIToken, NewAPIToken, APITokenAuth) and\n  the role interface; postgres adapter.\n- api_token_handlers + the requireBearer middleware (RequireBearer /\n \n[…]\nship 404,\nidempotent revoke) and the bearer-middleware suite (revoked/expired/suspended)\npass, plus the whole control-plane suite.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate API tokens off db.Store (stage 4a) (#17)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T07:19:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "08cd011dfe7d0a62ec729a7fa809fecce25b8fde",
          "body": "Stage 3. allocations.Service no longer holds *sqlcdb.Queries / *pgxpool.Pool;\nit depends on storage.AllocationStore.\n\n- storage.AllocationStore / AllocationOps: domain types (Allocation, AgentEnrollment,\n  ServerVM, Server, ChosenServer) and the ~22-method role interface for disks,\n  leases, placeme\n[…]\nns suite (lease takeover, quota, capacity race,\nplacement, resize compensation, purge CAS) and the whole control-plane suite pass.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate the allocations subdomain to the domain layer (#16)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T07:07:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "15cc9c6cfea2c6034316bc3cbe09f2c5640be527",
          "body": "… (#15)\n\nStage 2 of the data-layer redesign. The devauth service no longer holds\n*sqlcdb.Queries / *pgxpool.Pool; it depends on storage.SessionStore.\n\n- storage.SessionStore / SessionOps / SessionTx: domain types and a role\n  interface for the device-flow / token subdomain, with explicit\n  Begin/Com\n[…]\nily revocation, suspended user/tenant\nrejection) passes, plus the whole control-plane suite. uuid promoted to a\ndirect dependency.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate the sessions subdomain (devauth) to the domain layer…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T06:46:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4f4c35e425483f6bc91e98a6d17ee12398ae2bcc",
          "body": "…#14)\n\nBegin redesigning the data layer from the sqlc-shaped db.Store (84\nmethods, returns pgtype) into small domain role interfaces with no\ndriver types crossing the boundary.\n\n- internal/storage: domain types + role interfaces + ErrNotFound. The\n  package doc states the conventions (intent-named m\n[…]\ned db.Store +\n  override 2\" to a clean 3-method implementation.\n\nOther subdomains still use db.Store; they migrate slice by slice.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: introduce backend-agnostic domain layer (foundation slice) (…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T06:25:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "179044db8c95e22ed3752ff82f64c031a8f70893",
          "body": "…#13)\n\nSweep the docs against the code after the #4–#8 / email-OTP-removal work.\n\nRemoved-feature cleanup (#9 deleted self-service email-OTP; docs lagged):\n- SECURITY.md: drop the RESEND_API_KEY / ORLOP_DEV_LOG_OTP mailer bullet,\n  the \"Email OTPs lock out\" hardening clause, and \"OTP\" from the\n  rat\n[…]\numn is `data_addr`); also\n  corrected the testing note's client_ca_file (org root, not intermediate).\n\nDocs only; no code changes.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: match current architecture; drop removed-feature descriptions (…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T06:25:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9a464453b8a03f7efa460f3c1c22c24b60b5f18a",
          "body": "Post-merge quality pass over the #5-#8 / #4 changes.\n\nsimplify (efficiency): the cert-revocation deny-list pruned expired\nentries on every Add, so merging a full reconcile snapshot was O(n²).\nPrune once per push batch instead (Add is O(1) again).\n\nsecurity-review (medium): parseBoolEnv (was envBoolD\n[…]\niable.\n\nTested: go vet ./... clean; full suite green against a live Postgres\n(-p 1); the previously-flaky test now passes 100/100.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cleanup + security follow-ups from /simplify and /security-review (#12)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T05:14:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "57a9e602669a0358ea4f7b77082fbaae2fc4cf7f",
          "body": "The HTTP/business handlers held the concrete pgx-backed *sqlcdb.Queries and\nimported the pgx driver directly to interpret \"no rows\", coupling the\nconsumer layer to Postgres.\n\nIntroduce a storage seam in internal/db:\n  - db.Store: the sqlc-generated query interface under a domain name, so\n    handler\n[…]\n fake\ndb.Store to demonstrate the decoupling payoff.\n\nTested: go vet ./... clean; full suite green against a live Postgres (-p 1).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Hide Postgres behind a storage interface in the control plane (#4) (#11)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T04:41:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "97e8fb7dfbf67f60a8fbc302de30b152beb790a7",
          "body": "Addresses the four open security issues surfaced while reviewing the\nidentity design (docs/design-identity.md §6).\n\n#6 — Single-use agent enroll tokens. A per-pod agent_enroll token is now\nspent on a successful /agent/enroll (atomic UPDATE ... consumed_at), and\nauthenticateRaw rejects an already-con\n[…]\n.\n\nTested: go vet ./... clean; full suite green with a live Postgres\n(-p 1) including new unit + integration tests for each issue.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden agent identity and data plane (#5, #6, #7, #8) (#10)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T04:30:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ca6c8ad3cdd6086537dae0bfbeea36e7c473ed75",
          "body": "…fier (#9)\n\n* docs(identity): add identity & data-isolation design\n\nCapture the researched design basis for issue #4: separate the load-bearing\nauthorization subject (tenant/allocation/enrollment + mTLS SPIFFE) from the\nhuman account lifecycle; correct the \"passing an id is auth\" framing with the\ntw\n[…]\nroll seam,\nand re-sourcing /agent/enroll authorization from the verifier (issue #8).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove self-service email-OTP login; add pluggable host-identity veri…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T03:10:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6894e17f86335b21e7d388d29dfeb909e02cca14",
          "body": "Lead with a tight tagline, badges, and a quick-links nav row, then\nprogressively disclose detail: scannable Highlights, an early Quickstart,\nand deep prose (Why Go and Rust) folded into a <details> block. Convert\nthe doc list into an at-a-glance table and add Contributing/Security\nsections, mirroring the structure of well-organized project READMEs.\n\n\nClaude-Session: https://claude.ai/code/session_01WKCS21TsKzt66mEo2rra77\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reorganize README homepage for scannability (#3)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T14:52:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1aeff37acaf0e34aadd47900b84fb288ed89103e",
          "body": "…is-wymls5\n\ndocs: explain the Go/Rust split and add one-command onboarding",
          "is_bot": false,
          "headline": "Merge pull request #2 from liu1700/claude/language-unification-analys…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T14:40:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cfe376fbeb13e38bc70b588d3fb618ad3865273",
          "body": "Provide one-command onboarding for the two-language layout:\n\n- Makefile `setup`/`setup-go`/`setup-rust` targets verify each toolchain,\n  install the Linux libfuse3 dev headers, and pre-fetch deps. The split\n  targets honor the \"you usually need only one side\" guidance — apt-get\n  update failures fro\n[…]\n Point CONTRIBUTING.md setup at the dev container and the make targets.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RpWseSPQhdBDmdoYk23RbH",
          "is_bot": false,
          "headline": "build: add `make setup` targets and a dev container",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-06-26T14:37:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e9dc55778295c58fb9299512920d8a7104ab66e6",
          "body": "Add docs/agent-memory.md describing what orlop's durable, isolated,\ncontent-addressed disk gives an agent-memory stack (persistence,\nfidelity-first raw storage, cheap incremental updates, overwritable\nversioned state, per-agent isolation, audit, portability) and the\nboundary where the cognitive memo\n[…]\nREADME with a new 'Why this matters for\nagent memory' section and a docs link.\n\n\nClaude-Session: https://claude.ai/code/session_01PFHaYAFUghmzjqfwt2rWQ2\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: explain orlop as the storage substrate for agent memory (#1)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T14:32:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "105347e1ae68ef91464852a5e6469bf6549b7684",
          "body": "Add a CONTRIBUTING.md that lowers the onboarding bar for the two-language\nlayout: a per-module table showing contributors they almost always need\nonly one toolchain, exact Go/Rust build+test commands (including the\nLinux libfuse3 dependency and the macOS NFS path), and the cross-language\ncontract (w\n[…]\n (no cgo/FFI), with each\nside using the language strongest for its job.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RpWseSPQhdBDmdoYk23RbH",
          "is_bot": false,
          "headline": "docs: add CONTRIBUTING guide and explain the Go/Rust split in README",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-06-26T14:32:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f1fa2c8213ea18eac31ad1f103ea2a4c24ba8ac6",
          "body": "A small, standard-library-only Go SDK for the orlop-control REST API: allocate\nand manage an agent's disk, set account budgets, reassign owners, mint the\nshort-lived per-agent enroll token, and read usage. Lifted from the proven\ncontrol-plane client; this is the canonical contract a host imports to \n[…]\nkflow (build + vet + test) — the Go control/data plane and\nthis SDK previously had no CI; only the Rust client and shellcheck did.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(client): add orlop/client Go SDK + Go CI",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T05:52:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac3a57b20fe4217e2de0af759179f3d5a8a8cd40",
          "body": "Three test initializers in the fh_tests module predated the uid/gid/atime_ns/\nrdev fields on Node and omitted them. A plain `cargo build`/`check` skips\n`#[cfg(test)]` modules so this stayed latent; CI compiling the lib tests on\nLinux surfaced E0063 (missing fields). Fill the four with their documented\nzero defaults, matching the canonical initializer.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(fs): complete Node initializers in fh_tests (uid/gid/atime_ns/rdev)",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T05:43:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "61f874fd001f1ab12abf3d524c9057d988742f35",
          "body": "Initial import. A multi-tenant file plane that gives each untrusted agent its\nown durable, auto-expanding POSIX disk over FUSE/NFS, without ever handing the\nagent a storage credential: per-agent short-lived mTLS identity (SPIFFE SAN),\ncontent-addressed chunk store with per-disk SQLite manifests, cap\n[…]\ncontrol plane that is the CA and allocator.\n\nComponents: orlop (Rust mount client), orlop-control + orlop-server (Go).\nApache-2.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "orlop: zero-trust durable POSIX disk for untrusted agents",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T05:23:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 11,
      "commits_last_year": 71,
      "latest_release_at": "2026-07-26T06:01:48Z",
      "latest_release_tag": "v0.4.5",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 2,
      "mean_days_between_releases": 3.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/liu1700/orlop",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/liu1700/orlop",
          "is_deprecated": false,
          "latest_version": "v0.4.5",
          "repository_url": "https://github.com/liu1700/orlop",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-26T05:57:44Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 2
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "third_party/fuser/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "bench/Cargo.toml",
        "go.mod",
        "third_party/fuser/Cargo.toml"
      ],
      "largest_source_bytes": 102445,
      "source_files_sampled": 291,
      "oversized_source_files": 3,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 2821
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "bench/Cargo.toml",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "go"
      ],
      "dependencies": [
        {
          "name": "anyhow",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "blake3",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "chrono",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "clap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "globset",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "libc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "lru",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "parking_lot",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "rmp-serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "quinn",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "rustls-pemfile",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "tokio",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tokio-rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_yaml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "rusqlite",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.31"
        },
        {
          "name": "x509-parser",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.16"
        },
        {
          "name": "tempfile",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "serde_bytes",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11.19"
        },
        {
          "name": "fastcdc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "nfsserve",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "async-trait",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "daemonize",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.5"
        },
        {
          "name": "os_pipe",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.2"
        },
        {
          "name": "anyhow",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "chrono",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "clap",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "rand",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "serde",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "github.com/bmatcuk/doublestar/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.10.0"
        },
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.5"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.9.2"
        },
        {
          "name": "github.com/pressly/goose/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.27.1"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.23.2"
        },
        {
          "name": "github.com/quic-go/quic-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.60.0"
        },
        {
          "name": "github.com/vmihailenco/msgpack/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.4.1"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.14.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "lukechampine.com/blake3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.49.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 64,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 24,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "liu1700",
          "commits": 69,
          "avatar_url": "https://avatars.githubusercontent.com/u/6064238?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.972
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "go.yml",
        "orlop-cli.yml",
        "posix.yml",
        "release.yml",
        "shellcheck.yml",
        "upgrade.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "25 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ed03ccff5c60cb5db1c1143116316f07ad171a46",
        "ran_at": "2026-07-28T08:19:06Z",
        "aggregate_score": 3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T06:03:44Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T05:57:45Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/liu1700/orlop",
    "host": "github.com",
    "name": "orlop",
    "owner": "liu1700"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 54,
      "inputs": {
        "security": 30,
        "vitality": 70,
        "community": 33,
        "governance": 59,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 71,
              "human_commit_share": 1,
              "days_since_last_push": 2,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "71 commits in the last year",
                "points": 16.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 71
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 11,
              "latest_release_tag": "v0.4.5",
              "releases_from_tags": false,
              "days_since_latest_release": 2,
              "mean_days_between_releases": 3.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "11 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.972
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 97% of commits",
                "points": 0.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 64,
              "open_issues": 0,
              "closed_issues": 24,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "64/65 decided PRs merged",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 64,
                      "decided": 65
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "followers": 50,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "liu1700",
              "public_repos": 52,
              "account_age_days": 4624
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "50 followers of liu1700",
                "points": 12.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 50,
                      "login": "liu1700"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "52 public repos, account ~12 yr old",
                "points": 24.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 52
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 12
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/liu1700/orlop"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 2
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 2 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "14 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 30,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "25 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 75,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 2821
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "71 of 71 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 71,
                      "sampled": 71
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "third_party/fuser/Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.915,
              "toolchain_manifests": [
                "Cargo.toml",
                "bench/Cargo.toml",
                "go.mod",
                "third_party/fuser/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, third_party/fuser/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, third_party/fuser/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "65 of the last 71 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 65,
                      "sampled": 71
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 102445,
              "source_files_sampled": 291,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/291 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 291,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'orlop' from its registry",
    "Could not fetch crates package 'orlop-bench' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T08:19:22.659347Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/liu1700/orlop.svg",
  "full_name": "liu1700/orlop",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo.