Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-25 00:05 UTC

nehmeroumani / microsandbox

🧱 easy, fast, local-first microVM runtime

RustApache-2.0★ 0 Sterne⑂ 0 Forksseit Juni 2026ForkAuf GitHub ansehen ↗

nehmeroumani/microsandbox erreicht einen Gesundheitsindex von 52 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei AI Readiness (85/100) ab, am schwächsten bei Community & Adoption (12/100). Zuletzt vor 6 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

52
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

52
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Nehme RoumaniPersönliches Konto
13 Follower31 öffentliche Reposseit Jan. 2015

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Gogithub.com/nehmeroumani/microsandbox/sdk/gov0.6.6-2vor 6 Tagen
crates.iomicrosandbox-dbverweist auf ein anderes Repo — nicht bewertet0.6.64.78938vor 17 Tagen
crates.iomicrosandbox-cliverweist auf ein anderes Repo — nicht bewertet0.6.617143vor 17 Tagen
crates.iomicrosandbox-imageverweist auf ein anderes Repo — nicht bewertet0.6.64.73238vor 17 Tagen
crates.iomicrosandbox-utilsverweist auf ein anderes Repo — nicht bewertet0.6.64.96045vor 17 Tagen
crates.iomicrosandbox-agentdverweist auf ein anderes Repo — nicht bewertet0.6.69817vor 17 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

79Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 6 Tagen
16.6/36Commit-Rhythmus — 24/52 Wochen mit Commits
18/18Commit-Volumen — 433 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year433
human_commit_share0,89
days_since_last_push6
active_weeks_last_year24
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 2 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 6 Tagen
27/27Release-Rhythmus — ein Release etwa alle 11,6 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count2
latest_release_tagv0.6.6
releases_from_tagsnein
days_since_latest_release6
mean_days_between_releases11,6

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

12Kritisch · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 0 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
0/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmenein
has_licensenein
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

44Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
8.3/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 63 % der Commits
13.5/13.5Breite der Beitragenden — 37 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled37
top_contributor_share0,632
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
0/38.3PR-Annahme — keine entschiedenen Pull Requests oder keine Daten
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote, PR-Annahme. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
8.2/25Reichweite des Inhabers — 13 Follower von nehmeroumani
23/25Kontohistorie — 31 öffentliche Repos, Kontoalter ca. 11 Jahre
Verwendete Eingangsdaten
followers13
owner_typeUser
is_verified
owner_loginnehmeroumani
public_repos31
account_age_days4.219
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

92Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf go
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 6 Tagen
12/20Versionshistorie — 2 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesgithub.com/nehmeroumani/microsandbox/sdk/go
ecosystemsgo
any_deprecatednein
min_days_since_publish6

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

71Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 6 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration
9.6/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_configja
has_precommit_configja
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.

Dokumentation

40Gefährdet
Wie die Bewertung erfolgt
0/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://docs.microsandbox.dev
0/10Repository-Beschreibung
0/10Topics
0/10Wiki
Verwendete Eingangsdaten
topics
has_wikinein
homepagehttps://docs.microsandbox.dev
has_readmenein
has_docs_dirja
has_descriptionnein

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

48Gefährdet · 16 % des Gesamtindex

Sicherheitslage

48Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 16 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4,8
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

85Exzellent · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 87 von 89 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,978
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes14.305
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — justfile
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — packages/agent-client/typescript/tsconfig.json, packages/microsandbox-types/typescript/tsconfig.json, sdk/node-ts/tsconfig.json, sdk/python/microsandbox/py.typed
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 15 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 2 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesCargo.lock, package-lock.json, uv.lock
has_dockerfileja
typed_languageja
bootstrap_filesjustfile
has_devcontainernein
has_linter_configja
typecheck_configspackages/agent-client/typescript/tsconfig.json, packages/microsandbox-types/typescript/tsconfig.json, sdk/node-ts/tsconfig.json, sdk/python/microsandbox/py.typed
agent_commit_share0,15
toolchain_manifestsCargo.toml, crates/agentd/Cargo.toml, crates/cli/Cargo.toml, crates/db/Cargo.toml, crates/filesystem/Cargo.toml, crates/image/Cargo.toml, crates/metrics-collector/Cargo.toml, crates/metrics/Cargo.toml, crates/migration/Cargo.toml, crates/network/Cargo.toml, crates/protocol/Cargo.toml, crates/runtime/Cargo.toml, crates/test-init/Cargo.toml, crates/test-macros/Cargo.toml, crates/test-utils/Cargo.toml, crates/utils/Cargo.toml, examples/rust/cloud-backend/Cargo.toml, examples/rust/fs-read-stream/Cargo.toml, examples/rust/init-handoff/Cargo.toml, examples/rust/logs-read/Cargo.toml, examples/rust/metrics-stream/Cargo.toml, examples/rust/net-basic/Cargo.toml, examples/rust/net-dns/Cargo.toml, examples/rust/net-policy/Cargo.toml, examples/rust/net-ports/Cargo.toml, examples/rust/net-secrets-body/Cargo.toml, examples/rust/net-secrets/Cargo.toml, examples/rust/net-tls/Cargo.toml, examples/rust/root-bind/Cargo.toml, examples/rust/root-block/Cargo.toml, examples/rust/root-oci/Cargo.toml, examples/rust/rootfs-patch/Cargo.toml, examples/rust/shell-attach/Cargo.toml, examples/rust/snapshot-fork/Cargo.toml, examples/rust/volume-disk/Cargo.toml, examples/rust/volume-named/Cargo.toml, packages/agent-client/rust/Cargo.toml, packages/microsandbox-types/rust/Cargo.toml, sdk/go/go.mod, sdk/go/native/Cargo.toml, sdk/node-ts/Cargo.toml, sdk/python/Cargo.toml, sdk/rust/Cargo.toml, sdk/rust/fuzz/Cargo.toml
dependency_bot_commit_share0,02
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Rust (statisch typisiert)
53.3/55Handhabbare Dateigrößen — 24/768 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageRust
largest_source_bytes229.189
source_files_sampled768
oversized_source_files24
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
0/20MCP-Server
40/40Lauffähige Beispiele — examples, recipes
Verwendete Eingangsdaten
example_dirsexamples, recipes
has_mcp_signalnein
api_schema_files

Eckdaten

0GitHub-Sterne
37Mitwirkende
433Commits, letzte 12 Monate
6Tage seit letztem Push
2Releases
1Bus-Faktor
0offene Issues
crates.ioPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Community profile unavailable
  • crates package 'microsandbox-db' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring
  • crates package 'microsandbox-cli' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring
  • Could not fetch crates package 'microsandbox-py' from its registry
  • Could not fetch crates package 'microsandbox-node' from its registry
  • crates package 'microsandbox-image' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring
  • crates package 'microsandbox-utils' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring
  • crates package 'microsandbox-agentd' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 4.8 / 10
4.8Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-25 00:04 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities16 existing vulnerabilities detected
Direkte Abhängigkeiten 197
RegistryPaketVersionsvorgabeManifest
crates.iobase64crates/agentd/Cargo.toml
crates.iochronocrates/agentd/Cargo.toml
crates.iociboriumcrates/agentd/Cargo.toml
crates.iolibccrates/agentd/Cargo.toml
crates.iomicrosandbox-protocolcrates/agentd/Cargo.toml
crates.ionixcrates/agentd/Cargo.toml
crates.ioserdecrates/agentd/Cargo.toml
crates.ioserde_jsoncrates/agentd/Cargo.toml
crates.iothiserrorcrates/agentd/Cargo.toml
crates.iotokiocrates/agentd/Cargo.toml
crates.ioanyhowcrates/cli/Cargo.toml
crates.iobase64crates/cli/Cargo.toml
crates.iobytescrates/cli/Cargo.toml
crates.iochronocrates/cli/Cargo.toml
crates.ioclapcrates/cli/Cargo.toml
crates.ioconsolecrates/cli/Cargo.toml
crates.iodirscrates/cli/Cargo.toml
crates.iofuturescrates/cli/Cargo.toml
crates.ioindicatifcrates/cli/Cargo.toml
crates.ioipnetworkcrates/cli/Cargo.toml
crates.iolibccrates/cli/Cargo.toml
crates.iomicrosandboxcrates/cli/Cargo.toml
crates.iomicrosandbox-dbcrates/cli/Cargo.toml
crates.iomicrosandbox-imagecrates/cli/Cargo.toml
crates.iomicrosandbox-migrationcrates/cli/Cargo.toml
crates.iomicrosandbox-networkcrates/cli/Cargo.toml
crates.iomicrosandbox-protocolcrates/cli/Cargo.toml
crates.iomicrosandbox-runtimecrates/cli/Cargo.toml
crates.iomicrosandbox-utilscrates/cli/Cargo.toml
crates.iorandcrates/cli/Cargo.toml
crates.ioregex1crates/cli/Cargo.toml
crates.ioreqwestcrates/cli/Cargo.toml
crates.iorpasswordcrates/cli/Cargo.toml
crates.iorusshcrates/cli/Cargo.toml
crates.iosea-ormcrates/cli/Cargo.toml
crates.ioserdecrates/cli/Cargo.toml
crates.ioserde_jsoncrates/cli/Cargo.toml
crates.iotempfilecrates/cli/Cargo.toml
crates.iothiserrorcrates/cli/Cargo.toml
crates.iotokiocrates/cli/Cargo.toml
crates.iotracingcrates/cli/Cargo.toml
crates.iotracing-subscribercrates/cli/Cargo.toml
crates.ioasync-trait0.1crates/db/Cargo.toml
crates.iosea-ormcrates/db/Cargo.toml
crates.iosqlxcrates/db/Cargo.toml
crates.iotokiocrates/db/Cargo.toml
crates.iotracingcrates/db/Cargo.toml
crates.iociboriumcrates/filesystem/Cargo.toml
crates.iolibccrates/filesystem/Cargo.toml
crates.iomicrosandbox-utilscrates/filesystem/Cargo.toml
crates.iomsb_kruncrates/filesystem/Cargo.toml
crates.ioscopeguardcrates/filesystem/Cargo.toml
crates.ioserdecrates/filesystem/Cargo.toml
crates.ioserde_bytescrates/filesystem/Cargo.toml
crates.iotempfilecrates/filesystem/Cargo.toml
crates.iotracingcrates/filesystem/Cargo.toml
crates.ioastral-tokio-tarcrates/image/Cargo.toml
crates.ioasync-compressioncrates/image/Cargo.toml
crates.iofuturescrates/image/Cargo.toml
crates.iohexcrates/image/Cargo.toml
crates.iolibccrates/image/Cargo.toml
crates.iomicrosandbox-utilscrates/image/Cargo.toml
crates.iooci-clientcrates/image/Cargo.toml
crates.iorustls-pemfilecrates/image/Cargo.toml
crates.iooci-speccrates/image/Cargo.toml
crates.ioscopeguardcrates/image/Cargo.toml
crates.ioserdecrates/image/Cargo.toml
crates.ioserde_jsoncrates/image/Cargo.toml
crates.iosha2crates/image/Cargo.toml
crates.iotarcrates/image/Cargo.toml
crates.iothiserrorcrates/image/Cargo.toml
crates.iotokiocrates/image/Cargo.toml
crates.iotokio-utilcrates/image/Cargo.toml
crates.iotracingcrates/image/Cargo.toml
crates.iomicrosandbox-metricscrates/metrics-collector/Cargo.toml
crates.iolibccrates/metrics-collector/Cargo.toml
crates.iotokiocrates/metrics-collector/Cargo.toml
crates.iofuturescrates/metrics-collector/Cargo.toml
crates.ioasync-trait0.1crates/metrics-collector/Cargo.toml
crates.iochronocrates/metrics-collector/Cargo.toml
crates.ioclapcrates/metrics-collector/Cargo.toml
crates.ioanyhowcrates/metrics-collector/Cargo.toml
crates.iothiserrorcrates/metrics-collector/Cargo.toml
crates.iotracingcrates/metrics-collector/Cargo.toml
crates.iotracing-subscribercrates/metrics-collector/Cargo.toml
crates.iomicrosandbox-dbcrates/metrics-collector/Cargo.toml
crates.iosea-ormcrates/metrics-collector/Cargo.toml
crates.iomicrosandbox-utilscrates/metrics-collector/Cargo.toml
crates.iohumantime2crates/metrics-collector/Cargo.toml
crates.ioopentelemetry0.32crates/metrics-collector/Cargo.toml
crates.ioopentelemetry-otlp0.32crates/metrics-collector/Cargo.toml
crates.ioopentelemetry_sdk0.32crates/metrics-collector/Cargo.toml
crates.iotonic0.14crates/metrics-collector/Cargo.toml
crates.iochronocrates/metrics/Cargo.toml
crates.iolibccrates/metrics/Cargo.toml
crates.iothiserrorcrates/metrics/Cargo.toml
crates.iotracingcrates/metrics/Cargo.toml
crates.iosea-orm-migrationcrates/migration/Cargo.toml
crates.ioserde_jsoncrates/migration/Cargo.toml
crates.iobase640.22crates/network/Cargo.toml
crates.iobytescrates/network/Cargo.toml
crates.iocrossbeam-queuecrates/network/Cargo.toml
crates.iodirscrates/network/Cargo.toml
crates.iofuturescrates/network/Cargo.toml
crates.iohickory-clientcrates/network/Cargo.toml
crates.iohickory-protocrates/network/Cargo.toml
crates.iohttlib-hpackcrates/network/Cargo.toml
crates.iohttparse1crates/network/Cargo.toml
crates.ioipnetworkcrates/network/Cargo.toml
crates.iolibccrates/network/Cargo.toml
crates.iolrucrates/network/Cargo.toml
crates.iomicrosandbox-protocolcrates/network/Cargo.toml
crates.iomicrosandbox-typescrates/network/Cargo.toml
crates.iomicrosandbox-utilscrates/network/Cargo.toml
crates.iomsb_kruncrates/network/Cargo.toml
crates.iomsb_krun_utilscrates/network/Cargo.toml
crates.ioparking_lotcrates/network/Cargo.toml
crates.iopem3crates/network/Cargo.toml
crates.iopercent-encoding2crates/network/Cargo.toml
crates.iorcgencrates/network/Cargo.toml
crates.ioresolv-confcrates/network/Cargo.toml
crates.iorustlscrates/network/Cargo.toml
crates.iorustls-native-certscrates/network/Cargo.toml
crates.iorustls-pemfile2crates/network/Cargo.toml
crates.ioserdecrates/network/Cargo.toml
crates.iosocket2crates/network/Cargo.toml
crates.iosmoltcpcrates/network/Cargo.toml
crates.iothiserrorcrates/network/Cargo.toml
crates.iotimecrates/network/Cargo.toml
crates.iotokiocrates/network/Cargo.toml
crates.iotokio-rustlscrates/network/Cargo.toml
crates.iotracingcrates/network/Cargo.toml
crates.iozeroizecrates/network/Cargo.toml
crates.iochronocrates/protocol/Cargo.toml
crates.iociboriumcrates/protocol/Cargo.toml
crates.iomicrosandbox-typescrates/protocol/Cargo.toml
crates.ioserdecrates/protocol/Cargo.toml
crates.ioserde_bytescrates/protocol/Cargo.toml
crates.iostrumcrates/protocol/Cargo.toml
crates.iothiserrorcrates/protocol/Cargo.toml
crates.iotokio1.52crates/protocol/Cargo.toml
crates.iobytescrates/runtime/Cargo.toml
crates.iochronocrates/runtime/Cargo.toml
crates.ioclapcrates/runtime/Cargo.toml
crates.iocrossbeam-queuecrates/runtime/Cargo.toml
crates.iolibccrates/runtime/Cargo.toml
crates.iomicrosandbox-agent-clientcrates/runtime/Cargo.toml
crates.iomicrosandbox-dbcrates/runtime/Cargo.toml
crates.iomicrosandbox-filesystemcrates/runtime/Cargo.toml
crates.iomicrosandbox-metricscrates/runtime/Cargo.toml
crates.iomicrosandbox-networkcrates/runtime/Cargo.toml
crates.iomicrosandbox-protocolcrates/runtime/Cargo.toml
crates.iomicrosandbox-typescrates/runtime/Cargo.toml
crates.iomicrosandbox-utilscrates/runtime/Cargo.toml
crates.iomsb_kruncrates/runtime/Cargo.toml
crates.ionixcrates/runtime/Cargo.toml
crates.iorustlscrates/runtime/Cargo.toml
crates.iosea-ormcrates/runtime/Cargo.toml
crates.ioserdecrates/runtime/Cargo.toml
crates.ioserde_jsoncrates/runtime/Cargo.toml
crates.iotempfilecrates/runtime/Cargo.toml
crates.iothiserrorcrates/runtime/Cargo.toml
crates.iotokiocrates/runtime/Cargo.toml
crates.iotracingcrates/runtime/Cargo.toml
crates.iozeroizecrates/runtime/Cargo.toml
crates.iolibccrates/test-init/Cargo.toml
crates.ioproc-macro21crates/test-macros/Cargo.toml
crates.ioquote1crates/test-macros/Cargo.toml
crates.iosyn2crates/test-macros/Cargo.toml
crates.iotest-macroscrates/test-utils/Cargo.toml
crates.iotempfilecrates/test-utils/Cargo.toml
crates.iodirscrates/utils/Cargo.toml
crates.iolibccrates/utils/Cargo.toml
crates.ioreflink-copycrates/utils/Cargo.toml
crates.ioscopeguardcrates/utils/Cargo.toml
crates.ioureqcrates/utils/Cargo.toml
crates.iomicrosandboxsdk/node-ts/Cargo.toml
crates.iomicrosandbox-networksdk/node-ts/Cargo.toml
crates.ioipnetworksdk/node-ts/Cargo.toml
crates.ionapi3sdk/node-ts/Cargo.toml
crates.ionapi-derive3sdk/node-ts/Cargo.toml
crates.iotokiosdk/node-ts/Cargo.toml
crates.iofuturessdk/node-ts/Cargo.toml
crates.iochronosdk/node-ts/Cargo.toml
crates.iobytessdk/node-ts/Cargo.toml
crates.ioserde_jsonsdk/node-ts/Cargo.toml
crates.iomicrosandboxsdk/python/Cargo.toml
crates.iomicrosandbox-networksdk/python/Cargo.toml
crates.iochronosdk/python/Cargo.toml
crates.ioipnetwork0.21.0sdk/python/Cargo.toml
crates.iopyo30.24sdk/python/Cargo.toml
crates.iopyo3-async-runtimes0.24sdk/python/Cargo.toml
crates.ioserde_jsonsdk/python/Cargo.toml
crates.iotempfilesdk/python/Cargo.toml
crates.iotokiosdk/python/Cargo.toml
crates.iofuturessdk/python/Cargo.toml
crates.iotyped-pathsdk/python/Cargo.toml
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 39370,
      "has_wiki": false,
      "homepage": "https://docs.microsandbox.dev",
      "languages": {
        "C": 33262,
        "Go": 701117,
        "Just": 13397,
        "Rust": 7619295,
        "Shell": 26940,
        "Python": 126979,
        "Dockerfile": 538,
        "JavaScript": 40118,
        "PowerShell": 53711,
        "TypeScript": 279265
      },
      "pushed_at": "2026-07-18T19:39:36Z",
      "created_at": "2026-06-23T15:42:15Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T17:21:29Z",
      "description": "🧱 easy, fast, local-first microVM runtime",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Nehme Roumani",
      "type": "User",
      "login": "nehmeroumani",
      "company": null,
      "location": "Lebanon",
      "followers": 13,
      "avatar_url": "https://avatars.githubusercontent.com/u/10393081?v=4",
      "created_at": "2015-01-04T21:36:25Z",
      "is_verified": null,
      "public_repos": 31,
      "account_age_days": 4219
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.6.6",
          "kind": "patch",
          "published_at": "2026-07-18T20:20:27Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-07-07T07:05:11Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "18003c3cd7ec25560bb27c26cd82057acb2b7f78",
          "body": "…s builds\n\nserve_snapshot_entries_for_each and snapshot_entries_after are only called\nfrom the unix backends (passthroughfs/unix, memfs, dualfs); the windows\npassthrough and the cross-platform vfs backend use serve_snapshot_entries.\nThe fork's windows CI compiles this crate under -D warnings — cover\n[…]\nD warnings clean on the full\nmicrosandbox-cli (net,ssh) tree, filesystem lib+tests, runtime lib+tests;\nhost workspace check and fmt still clean.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(filesystem): gate unix-only snapshot streaming helpers for window…",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-18T17:21:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f64004add86a0d358b86b08cd8781a5b1e4d8e07",
          "body": "…te refactor\n\nThe v0.6.5 sync deleted apply_create_opts when upstream inlined option\napplication into msb_sandbox_create, leaving build_sandbox_builder (the\npull-progress entry) calling a function that no longer existed — caught by\nthe release build. Extract upstream's full option chain into\nbuild_s\n[…]\ntual mounts.\n\nVerified: CI=1 cargo check on sdk/go/native (0 warnings) and\n--workspace --all-targets, native crate tests (10 passed), cargo fmt.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sdk/go): rebuild create-options plumbing severed by upstream crea…",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-18T16:35:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d062ccae70116d504e78f8b48b88cbd4cfdb70c4",
          "body": "Conflicting hunks resolved in favor of upstream, then fork features\nre-grafted where upstream's hunks displaced them:\n\n- Cargo.toml: restore uds_windows workspace dep (crates/filesystem needs it)\n- microsandbox-types: re-add VirtualMount + SandboxSpec.virtual_mounts on\n  upstream's restructured doma\n[…]\neck --workspace --all-targets, microsandbox-types tests\n(TS binding sync), go build/vet/test on sdk/go, cargo check on\nsdk/go/native, cargo fmt.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Merge upstream superradcompany/microsandbox main (v0.6.6) into main",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-18T15:31:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e2c8ceeadaf7f1d0fec8d70ad203024862cfb465",
          "body": "## TL;DR\nUpdate the vendored libkrunfw to 5.6.0 and keep every build, installer,\nworkflow, and SDK filename reference in sync.\n\n## Description\n- Advance `vendor/libkrunfw` to the merged `krunfw` head, which includes\nLinux 6.12.95, the Windows live-resize configuration, and kernel update\nsafeguards.\n\n[…]\nll, Node, workflow YAML, actionlint, formatting, submodule\nancestry, and version-consistency checks pass\n- [x] Microsandbox CI builds and packages libkrunfw 5.6.0 on its\nsupported runners (runs in CI)",
          "is_bot": false,
          "headline": "build(libkrunfw): update vendor to 5.6.0 (#1182)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-18T01:24:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5427608672656ae20251a9ced98008740bbcda46",
          "body": "…1179)\n\n## TL;DR\nThe npm package's exports map only declares `types` and `import`, so any\nCommonJS consumer fails with ERR_PACKAGE_PATH_NOT_EXPORTED before module\nloading even starts. Adding a `default` condition makes\n`require('microsandbox')` resolve, and the ESM dist loads fine under\nrequire() on\n[…]\nx')\"` still loads (no ESM regression)\n- [x] `bun -e \"require('microsandbox')\"` loads\n- [ ] republish check: `npm pack` artifact resolves the same way from\nthe registry tarball (verify on next release)",
          "is_bot": false,
          "headline": "fix(sdk/node): add default export condition for CommonJS consumers (#…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-17T16:47:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b46979aaa132c22aa69d689f95e6b572ef4d1bee",
          "body": "Fixes #1170.\n\nRepeated `--secret ENV@HOST` rules share the same placeholder. If one\nrule matched and another did not, the non-matching rule could block the\nrequest before substitution.\n\nThis filters duplicate ineligible placeholders when the same placeholder\nis allowed for the current host. It also supports `--secret\n'ENV@host1,host2'` so one CLI secret can carry multiple allowed hosts.",
          "is_bot": false,
          "headline": "fix(network): allow duplicate secret placeholders (#1178)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-17T11:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f091acac06ffe77a35172424bd165228b54f0c9",
          "body": "## TL;DR\nLocks in the snapshot contract across the CLI and all four SDKs:\nsnapshot.json is the only descriptor, save/load/reindex are the only\nverbs, and creation is name-first with an optional dest_dir for placing\nartifacts on another volume. We are pre-1.0, so all legacy shapes are\nremoved outrigh\n[…]\nre-snapshot\nmarker file\n- [ ] full non-snapshot Go and Node integration suites (runs in CI;\nlocal `core.ping` smoke check is blocked by released runtime artifacts\nstill speaking protocol generation 5)",
          "is_bot": false,
          "headline": "feat(snapshot): finalize descriptor and api contract (#1118)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-14T23:18:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66199361882d5f47d89e07bc34b7ef9c9eb2b142",
          "body": "## TL;DR\nBrings the image archive import/export from #1151 to the Node and Go\nSDKs, and folds in the review follow-ups from #1151 and #1161 (helper\ndedup, blocking I/O fix, multi-reference Python save, quota_mib\nvalidation, docs).\n\n## Description\n- Node SDK: new `imageLoad`/`imageSave` napi bindings\n[…]\ninst a real cached image\n- [ ] Go smoke test for load/save against a locally built cdylib\n(deferred, no smoke coverage for image archive ops yet; same core\nexercised by the CLI and Python round-trips)",
          "is_bot": false,
          "headline": "feat(sdk): extend image load/save to Node and Go SDKs (#1174)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-14T19:55:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9fd9ecec753128ce84a109b5b00bce4f2f2812c",
          "body": "## TL;DR\n\nThe Go SDK drops `quota_mib` for bind mounts in the FFI layer, so Go\ncallers cannot override the protective 4 GiB default from #1020 the way\nCLI and Rust SDK callers can. Forward it like the CLI does.\n\n## Description\n\n- `sdk/go/native/src/lib.rs`: the `apply_volume` bind branch now\nforward\n[…]\nENOSPC at\n`2047+0 records out` (unpatched baseline: 4.1G and `4095+0 records\nout`).\n- Same with `QuotaMiB: 6144`: guest `df` reports ~6.1G.\n- With `QuotaMiB` unset: unchanged 4 GiB protective default.",
          "is_bot": false,
          "headline": "fix(sdk/go): forward guest-write quota to bind mounts (#1161)",
          "author_name": "zhuanyongxigua",
          "author_login": "zhuanyongxigua",
          "committed_at": "2026-07-14T16:47:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c996ca47642251df8c3ff73e92200e4e52462c9",
          "body": "…(#1151)\n\n## TL;DR\n\nExpose `Image.load()` and `Image.save()` in the Python SDK so local\nimage archives (`docker save` tarballs, OCI Image Layout) can be\nimported and exported without shelling out to the CLI. Closes #973.\n\n## Description\n\n- Add `Image::load` / `Image::load_local` and `Image::save` /\n\n[…]\nfor the stdin spool file.\n\nGenerated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Stephen Akinyemi <appcypher@outlook.com>",
          "is_bot": false,
          "headline": "feat(sdk): expose Image.load and Image.save for local image archives …",
          "author_name": "luotao",
          "author_login": "ya-luotao",
          "committed_at": "2026-07-13T08:01:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "960e3cb5dd9e328a2290d8e93850320855668450",
          "body": "…e root disks (#1169)\n\n## TL;DR\n\nSnapshotting a tmpfs-root-disk sandbox failed with the raw `\"has no\nupper.ext4 at <path>\"` error: tmpfs sandboxes are OCI-rooted, so they\npassed the only-OCI check and fell through to the file-existence check\n(tmpfs uppers live in guest RAM and have no host file). Ch\n[…]\nw unit tests: managed/default pass, tmpfs and disk-image\nrejected with kind-specific messages\n- [x] `cargo test -p microsandbox --lib snapshot::create` green;\nworkspace fmt/clippy via pre-commit hooks",
          "is_bot": false,
          "headline": "fix(snapshot): purposeful errors when snapshotting tmpfs or disk-imag…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-13T03:24:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67c81ffcbc35dd1f11108ef6e5a581b07fc54de1",
          "body": "## TL;DR\n\nImplements `design/storage/sparse-snapshot-archive.md` on top of #1150's\nold-GNU sparse export writer: a shared `ExtentMap::scan`\n(SEEK_DATA/SEEK_HOLE on unix, FSCTL_QUERY_ALLOCATED_RANGES on Windows)\nfeeds the writer on every platform, and import replaces\n`tokio_tar::Archive` with an owne\n[…]\nport → remove → import → boot-from-snapshot, guest data byte-exact\n(see Measurements)\n\n---------\n\nCo-authored-by: nuri-yoo <nuri-yoo@users.noreply.github.com>\nCo-authored-by: nuri <yoonuri1@gmail.com>",
          "is_bot": false,
          "headline": "feat(snapshot): own the sparse archive codec end to end (#1166)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-13T03:24:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d46ce7bf013c55187411556cad65a2deee33ec7",
          "body": "…(#1164)\n\n## TL;DR\n\nIntegration Tests can kill rust-lld with SIGBUS when the shared runner\ndisk fills during parallel test linking (#1162, hit on #1150). This\napplies the three workflow-reachable mitigations from that issue:\nline-tables-only debuginfo for the integration-test job, a wider /tmp\nclean\n[…]\nyaml`)\n- [ ] shellcheck/actionlint — not installed locally; covered by CI lint\nif configured\n- [ ] Integration Tests green on this PR with visibly smaller `target/`\n(watch the job's disk-usage groups)",
          "is_bot": false,
          "headline": "ci: shrink integration-test debuginfo and harden runner disk cleanup …",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-11T16:49:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5dce0cbfdae3ffe8367a01de52ca275fdf0699b1",
          "body": "… (#1165)\n\n## TL;DR\nThe writable layer of an OCI sandbox is now a \"root disk\" you can back\nthree ways: the managed ext4 upper (default, unchanged), a RAM-backed\ntmpfs that gives you a pristine rootfs on every boot, or your own disk\nimage attached writable. The old `oci-upper-size` spellings keep wor\n[…]\n behave\n- [ ] Full CI matrix incl. Linux hosts and agentd unit test execution\n(runs in CI)\n- [ ] Go SDK boot through the native dylib (not exercised locally;\ncovered by wire-shape tests on both sides)",
          "is_bot": false,
          "headline": "feat(sandbox)!: replace oci-upper-size with structured root-disk spec…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-11T15:54:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8474fa9eb5a869d0d07f5b12959b98c5148f6c71",
          "body": "…xport (#1150)\n\n## TL;DR\n\n`snapshot export` streams the entire logical size of the sparse\n`upper.ext4` through tar and zstd, even when almost none of it is\nallocated: a default 4 GiB upper with ~2.9 MB of data takes ~6.5 s to\nexport into a ~2 MB `.tar.zst`. This PR teaches export to write files\nthat\n[…]\ned\n- `cargo clippy -p microsandbox --lib` and `cargo fmt`: clean, no new\nwarnings\n\nCo-authored-by: nuri-yoo <nuri-yoo@users.noreply.github.com>\nCo-authored-by: Stephen Akinyemi <appcypher@outlook.com>",
          "is_bot": false,
          "headline": "perf(snapshot): store files with holes as GNU sparse tar entries on e…",
          "author_name": "nuri",
          "author_login": "nuri-yoo",
          "committed_at": "2026-07-10T17:58:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8b1769c02ce424846bdb83ca3ba8c0fee199808d",
          "body": "## TL;DR\nWorkloads that hold many files open on a virtiofs share (Gradle, JVMs,\n`rm -r node_modules`) exhaust the host sandbox process's fd limit, which\nmade files silently vanish from guest listings and blocked recovery.\nThis raises the host fd limit at startup and makes the passthrough\nbackend fai\n[…]\nsoft shell; guest\nholds 1500 open files cleanly at default limits; under a hard 512 cap\nerrors are EMFILE (not FileNotFoundError), listings stay complete, and\nclose/recovery works (0/376 close errors)",
          "is_bot": false,
          "headline": "fix(filesystem): survive host fd exhaustion on virtiofs shares (#1157)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-10T07:02:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16b6649b0c0a65ae3abe23e5bbd1e8149b07f624",
          "body": "…ut (#1149)\n\n## TL;DR\nThe passthrough filesystem followed symlinks when opening a mount root,\nso a symlink planted at or under the root could redirect the mount out\nof its intended target (a cross-tenant escape in a multi-tenant setup).\nThis makes symlink-free root resolution the default for every m\n[…]\noot on Linux: symlink mount root refused with ELOOP, real\nand single-file mounts boot, opt-out restores following (ran on the\ngcloud Linux runner this session; not re-runnable in local CI without\nKVM)",
          "is_bot": false,
          "headline": "feat(filesystem): default-on mount-root symlink protection with opt-o…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-10T01:30:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "286afbf520caefc9d82786037783a811d920a971",
          "body": "## TL;DR\nStable clippy moved to 1.97 on 2026-07-07 and the CI `-D warnings` gate\nnow rejects two pre-existing patterns, so every PR fails the Linux Check\njobs until these land. Two one-line fixes, no behavior change.\n\n## Description\n- Remove a redundant `&` on `args.name` in an `anyhow!` format argu\n[…]\nTest Plan\n- [x] `cargo +1.97.0 clippy --workspace --exclude microsandbox-agentd --\n-D warnings` is clean\n- [x] `cargo fmt --all -- --check` is clean\n- [x] Linux Check jobs pass on this PR (runs in CI)",
          "is_bot": false,
          "headline": "chore(lint): fix clippy 1.97 lints in cli and python sdk (#1160)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-09T22:11:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae8197435ec3c52f21c88d5b12384386e8eb0336",
          "body": "…(#1148)\n\n## TL;DR\nGuest paths are always Linux paths, but `HandoffInit.cmd` was typed as\n`PathBuf` and a handful of spots handled paths with host OS semantics\nthat break on Windows. This types the last guest path as a string and\nfixes every place a path crossed the host/guest fence with the wrong\ns\n[…]\nes (3 tests)\n- [x] Windows build compiles the `#[cfg(windows)]` classifier code\n(Check Windows passed in CI on both architectures)\n- [x] `cargo deny check licenses` accepts `typed-path` (passed in CI)",
          "is_bot": false,
          "headline": "fix(sdk)!: type guest paths as strings and fix Windows path handling …",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-09T18:45:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a8347433c5dc51a11853e325c29ca2c7b9a54de",
          "body": "…ut (#1155)\n\n## TL;DR\n\nDEVELOPMENT.md and AGENTS.md have drifted from the current repo layout\nand release process (dead Benchmarking section, incomplete crate tables,\noutdated release steps, wrong agentd workspace claim). This brings both\nfiles back in line with `main`. Fixes #1154.\n\n## Description\n\n[…]\n` for the npm package names; `ls\ndocs examples` for the directory lists\n\nGenerated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(docs:) sync DEVELOPMENT.md and AGENTS.md with current repo layo…",
          "author_name": "luotao",
          "author_login": "ya-luotao",
          "committed_at": "2026-07-09T12:39:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5681bd6ca2bf398b33f185b64607a0f5d1a0461b",
          "body": "tidies the doc comments on the cloud wire types (`CloudSandboxSpec`,\n`CloudNetworkSpec`, `CloudSandboxRuntimeOptions`) to describe each\ntype's shape and drop incidental prose. the checked-in typescript\nbindings (`cloud.ts`) are regenerated so the jsdoc stays in sync.",
          "is_bot": false,
          "headline": "docs(types): simplify cloud wire type doc comments (#1158)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-09T12:16:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c05673c46d84919b257beda635f38409ae282e7e",
          "body": "## TL;DR\nAdds `msb update`, `msb upgrade`, and `msb downgrade` as top-level\ncommands so you don't have to type the full `msb self ...` form.\n\n## Description\n- Add `Update` (with visible alias `upgrade`) and `Downgrade` variants\nto the top-level `Commands` enum, reusing the existing\n`SelfUpdateArgs`/\n[…]\nthe `upgrade` alias\nunder Installation\n- [x] `msb update --help` and `msb downgrade --help` show the same\noptions as their `self` counterparts\n- [x] `msb upgrade --help` resolves to the update command",
          "is_bot": false,
          "headline": "feat(cli): add top-level update, upgrade, and downgrade aliases (#1147)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-09T00:58:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7713d604934ce85881bf822b3a0a44555eb3ac4",
          "body": "Adds typed request/response types for the cloud sandbox API, and makes\nthe shared network/secrets spec fully typed (concrete types instead of\nopaque JSON `Value`).\n\n- New cloud API types in `cloud.rs` that convert to/from the domain spec\n- `NetworkSpec` `policy` / `secrets` / `interface` / `dns` / `\n[…]\n to\n`main`, so the local on-disk format and the Go/Node/Python SDKs and CLI\nare unchanged (the only SDK edit is `retract v0.6.5` in `go.mod`).\nTypeScript bindings change only for the new/typed pieces.",
          "is_bot": false,
          "headline": "feat(types): more explicit sandbox spec types (#1144)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-08T18:43:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "40a57d1c89122142d63516a519d18427330b7655",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.6, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.6 (#1146)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T20:50:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2367d506103f87fe733d7252c3202b278eadef88",
          "body": "## TL;DR\nRebase the release bump on the independently published 0.6.5 line and\nmove microsandbox to 0.6.6. This keeps the workspace, SDK packages,\nexamples, MCP pointer, and skills pointer aligned for the next patch\nrelease.\n\n## Description\n- Bump the Cargo workspace version and internal microsandbo\n[…]\nin\ndevelop --release`, `uv run pytest`, and `uv run ruff check .`; Go ran\n`go test -count=1 .`\n- [x] Submodule checks: MCP local SDK install, `npm run build`, and `npm\ntest`; skills `git diff --check`",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.6.6 (#1134)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-07T19:03:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a192db5e2cc4e850705b2108256e27b8d31e08d",
          "body": "Reverts superradcompany/microsandbox#1014",
          "is_bot": false,
          "headline": "chore(revert): \"feat(types): compose types from SandboxSpec\" (#1143)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-07T18:18:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8a5f49d285089ad09a3b84cccd09de571016b9f",
          "body": "Re-dispatching for the dist-tag step failed: unpublish errors on\nalready-removed versions and the re-point step lacked if: always(). Skip\nmissing versions; run the re-point regardless of loop outcome.",
          "is_bot": false,
          "headline": "ci(yank): make re-runs idempotent; always run latest re-point (#1142)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-07T15:48:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "922078cbf7a979304ae03b2e83501ca002bbe89e",
          "body": "The main microsandbox package has registry dependents, so npm refuses\nversion unpublish permanently; deprecation only warns and `latest` keeps\nserving the yanked version. Adds an optional latest_fallback input that\nre-points the dist-tag.",
          "is_bot": false,
          "headline": "ci(yank): re-point npm latest when unpublish is refused (#1141)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-07T15:43:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34e13c2515f5068cc4e4b75cd14fc2ca0ad64f07",
          "body": "Adds a workflow_dispatch that yanks a version across registries:\ncargo-yank all 15 workspace crates, npm unpublish the 8 packages\n(deprecate fallback outside the 72h window), delete GHCR container\nversions with the tag. PyPI has no yank API (OIDC trusted publishing) —\nstays a manual web-UI step. First use: yanking 0.6.5 (breaking changes\nshipped as a patch).",
          "is_bot": false,
          "headline": "ci: add yank workflow for pulling back a published release (#1140)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-07T15:40:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "336ac027bc227933633dbe80f528e482350084f6",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.5, so `npm ci` keeps working on main.\n\nCo-authored-by: toksdotdev <11903253+toksdotdev@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.5 (#1138)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T15:31:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac2b79b63eff390afdcb5e76bb7dedad90103912",
          "body": "## TL;DR\nStream directory entries through libkrun's dynamic filesystem callbacks\nso repeated readdir calls stop retaining leaked name buffers. This fixes\nthe host RSS growth reproduced in issue #1115 and now uses the published\n`msb_krun` 0.1.25 crates.\n\nCloses #1115.\n\n## Description\n- Uses the publi\n[…]\nx] `cargo check -p microsandbox-filesystem --no-default-features\n--locked`\n- [x] Linux KVM repro on `ci-runner-ubuntu-2404-x64`: warmed patched run\nstayed at `132608 kB -> 133132 kB`, fds `130 -> 130`",
          "is_bot": false,
          "headline": "fix(filesystem): stream readdir snapshot entries (#1133)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-07T15:28:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "107d12e105f13ad593082dcc0168dd63737da5e1",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'superradcompany:main' into main",
          "author_name": "Nehme Roumani",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-07T12:52:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "057816ab187e19722eed73bd514a336b0ecec7a0",
          "body": "release preparation for `v0.6.5`.\n\nbumped by `scripts/bump-version.sh`:\n- `Cargo.toml` workspace + path-dep versions\n- `packages/agent-client/typescript/package.json`\n- `packages/microsandbox-types/typescript/package.json`\n- `sdk/node-ts/package.json` and per-platform sub-packages\n- `sdk/go/setup.go\n[…]\nge-commit>`\n2. `git push --tags`\n3. `release.yml` runs and publishes to crates.io, npm, pypi, ghcr, and\ntags `sdk/go/v0.6.5`.\n\nCo-authored-by: toksdotdev <11903253+toksdotdev@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: release v0.6.5 (#1136)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T11:08:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a1d184c472169709e3049e0845d1d7fc0bb5485",
          "body": "## The bug\n\nWhen a sandbox is created **restoring from a snapshot**, `create_local`\n(in `sdk/rust/lib/sandbox/mod.rs`) re-pulled the base image by its\n**mutable reference** (a tag like `python:3.12`) and then compared the\nfreshly-resolved manifest digest against the digest the snapshot\n**pinned** at\n[…]\n\n`cargo build -p microsandbox`, `cargo fmt --check`, and the new unit\ntests all pass.\n\nAddresses the regression introduced by #998.\n\n---------\n\nCo-authored-by: Stephen Akinyemi <appcypher@outlook.com>",
          "is_bot": false,
          "headline": "fix(snapshot): restore by pinned digest, not the mutable tag (#1130)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-07T10:59:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a8bb38f2b88838455fbe6eb97e4632e187c2cea",
          "body": "# Conflicts:\n#\t.github/workflows/check.yml\n#\tpackages/microsandbox-types/rust/lib/lib.rs\n#\tsdk/go/internal/ffi/ffi.go\n#\tsdk/go/native/microsandbox_go_ffi.h\n#\tsdk/go/native/src/lib.rs",
          "is_bot": false,
          "headline": "Merge branch 'main' of github.com:superradcompany/microsandbox",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-07T09:55:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9fcee4bb72d179896b5d5b963d4f4b532f824fd",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(types): regenerate TS bindings for virtual_mounts spec field",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-07T09:31:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "34141b2b68ab8bf32530b8a365b360076d723bab",
          "body": "Node/Python SDK, TS packages, and MCP server are published only from\nsuperradcompany, so forks skip building and testing them — mirroring\nthe release.yml upstream-only gates. go-sdk-test now tolerates the\nskipped python-sdk-test while keeping self-hosted jobs serialized.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(fork): skip upstream-only library checks outside superradcompany",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-07T09:31:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3d3b8555fe414fe5441d9dea2f17e745c6751c61",
          "body": "## What\n\nMake the cloud wire types compose `SandboxSpec` instead of restating its\nfields, so they can never drift from `domain.rs`.\n\n- **`CloudCreateSandboxRequest`** is now a thin envelope over the spec —\na single `#[serde(flatten)] pub spec: SandboxSpec` field. Consumers that\nneed extra fields wra\n[…]\nndbox-types --features ts` / `--features\nutoipa` / `--features typeshare`\n- `cargo check -p microsandbox`\n- `typeshare … --lang go` generates valid Go for the annotated sub-types\n(builds + vets clean)",
          "is_bot": false,
          "headline": "feat(types): compose types from SandboxSpec (#1014)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-07T09:25:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14cdbbc3a49558324649912b709c241a7be58612",
          "body": "Rename the sdk/go module path from superradcompany to nehmeroumani so\n`go get` resolves against the fork, and enable the go-sdk-tag release\njob here: retarget its repository guard and the module-proxy warm URLs.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(fork): point Go SDK module at nehmeroumani/microsandbox",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-07T07:44:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a8bf923fbcab6957537223726420da867eb58e48",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'superradcompany:main' into main",
          "author_name": "Nehme Roumani",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-07T06:05:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6913046233075ec91f7b739afbbc66659687e823",
          "body": "## TL;DR\nCloses two of the design doc's remaining-work items and two\ntesting-discovered runtime bugs in one change: the Python, TypeScript,\nand Go SDKs can now author secret modifications (previously Rust-only);\n`msb modify --oci-upper-size` grows the OCI overlay upper with a\npure-Rust offline ext4 \n[…]\n] microsandbox SDK 430 lib tests (incl. reap identity logic), CLI\n222, bindings suites (go/py/ts), fmt + CI-style clippy clean; reap.rs\nWin32 surface compiled + clippy'd against x86_64-pc-windows-msvc",
          "is_bot": false,
          "headline": "feat(sandbox): secret modify parity and offline oci upper growth (#1128)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-07T02:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "96eb59be6311715e1e8a44de11dedfe0492f1452",
          "body": "Repoint every prebuilt-artifact download at this fork's GitHub releases:\nGITHUB_ORG in microsandbox-utils (agentd/libkrunfw/msb downloads and\nmsb self update), githubOrg in the Go SDK's setup, and the repo slug in\nthe install scripts.\n\nGuard the upstream-only publish jobs (npm, crates.io, PyPI, Home\n[…]\nuilt-in token.\n\nThe Go module path intentionally keeps the upstream slug: rewriting it\nwould touch every import and break drop-in compatibility.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(fork): self-host releases on nehmeroumani/microsandbox",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:55:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b861fe958549f336c671a13c501bbc89d79c76e2",
          "body": "## TL;DR\nThe runtime control channel (memory/CPU targets, live secret updates)\nwas unix-socket-only, so every Windows modify classified as\nrestart-backed. Serve the same one-line JSON protocol over a named pipe\nand teach the SDK client to dial it. Together with msb_krun 0.1.24\n(libkrun #85/#86: WHP \n[…]\nured convergence: memory grow <= 0.3 s, CPU changes and memory\nshrink ~1 s (same class as KVM/HVF)\n- [x] full re-verification sweep on macOS HVF and Linux KVM with the\nsame flows (no unix regressions)",
          "is_bot": false,
          "headline": "feat(runtime): serve live control over a named pipe on Windows (#1119)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-06T22:25:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea1fef81cba31bcec72e37e2757f3b1e6ebd9e35",
          "body": "Add a Virtual Mounts concept page (how a provider in your process serves a\nguest path over the VFS RPC socket, lifetime and validation rules, platform\nsupport) and a Go SDK reference for WithVirtualMount and the vfs provider\npackage. Document WithPullProgress and the pull event phases in the Go\nsandbox reference, the virtual_mount builder in the Rust sandbox reference,\nand cross-link from Volumes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: document virtual mounts and pull progress",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:23:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "67c98cb0a65d7bdc544436f5596f1e297c7a0697",
          "body": "…ipes\n\nRun the filesystem crate's test suite in the windows-check job (the VirtualFs\nscaffold + RPC tests cover framing, dispatch, and real AF_UNIX socketpairs via\nuds_windows) and keep the pure-Go vfs package Windows-clean with a\nGOOS=windows build/vet step.\n\nThe justfile gains go-ffi (build the Go SDK FFI cdylib locally) and go-run\n(run a Go SDK example against it via the microsandbox_ffi_path build tag).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ci): exercise the vfs backend on windows and add go-ffi dev rec…",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:23:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "73a0e38d366cf16175b84c9e969d23c9e4deb38d",
          "body": "WithVirtualMount(guestPath, provider) mounts a filesystem implemented in Go\ninside the sandbox. The new dependency-free vfs package supplies the provider\nsurface — a path-addressed PathFs interface with []byte paths and Linux Errno\nerrors, an embeddable ReadOnly base, and a Serve loop speaking the r\n[…]\nath now shares a single builder-construction routine with the streaming one.\n\nRunnable examples: examples/virtual-mount, examples/pull-progress.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sdk/go): virtual mounts and image pull progress",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:22:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f6ce61a8a24375625d68c04b0ee877fb43712d4f",
          "body": "Add the VirtualMount spec type (guest_path + host socket_path; additive and\nserde-defaulted so persisted specs round-trip) and the\nSandboxBuilder::virtual_mount method. Spawn translates each virtual mount into\nthe launch config's vfs_mounts alongside the guest-side dir-mount entry.\n\nVirtual mounts a\n[…]\n\nnon-empty. The caller hosts the provider socket, so the builder documents the\ndetached-lifetime contract instead of rejecting detached creates.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sdk): add virtual_mount builder API with guest-path validation",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:21:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8fcb34520ce7254efa1be47bbf93c1b8a5199eb",
          "body": "Carry programmable virtual-filesystem mounts through the launch config as\ntag:socket_path pairs (the tag is hex and never contains a colon). At boot the\nruntime connects to each provider socket via vfs::rpc::MountStream — AF_UNIX\non every host platform, including Windows — and registers the RPC-back\n[…]\nunder the tag. The guest mounts it at\nits guest path through the same MSB_DIR_MOUNTS plumbing as a bind mount, so\nonly the host backend differs.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(runtime): serve virtual-mount sockets as virtio-fs shares",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:20:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f22dc4905ee77634181c6e773cbaebf4339aedad",
          "body": "…r protocol\n\nVirtualFs<P: PathFs> is a DynFileSystem scaffold that owns every FUSE-shaped\nconcern (inode interning, lookup refcounts, tombstones, per-handle directory\nsnapshots with kernel-buffer-bounded paging, zero-copy staging I/O) and\ndelegates semantics to a path-addressed PathFs provider. An R\n[…]\nror with the Windows passthrough delegating to\nit, and rpc::MountStream aliases std's UnixStream on unix and\nuds_windows::UnixStream on Windows.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(filesystem): add programmable VirtualFs backend with RPC provide…",
          "author_name": "Nehme",
          "author_login": "nehmeroumani",
          "committed_at": "2026-07-06T22:20:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a82406e610bbd4b3be43406fc35c0aa163f4449e",
          "body": "the release workflow pushed a merge commit straight to mintlify when the\nsync merged cleanly, and on conflict opened a pr that could only be\nsquash-merged. every squash erased the recorded common ancestor, so each\nfollowing sync conflicted on every file main had touched since (95 files\nby v0.6.4, se\n[…]\nands unattended, a conflicted\none is left for the releaser with instructions to merge mintlify into\nthe branch and enqueue. the sync is skipped entirely when the release\ncommit is already on mintlify.",
          "is_bot": false,
          "headline": "chore(ci): land mintlify sync prs through the merge queue (#1122)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-06T13:46:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fa51234963411d7f6dcede419e93f24c834e4dc",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.4, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.4 (#1117)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-05T20:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91e4d369bfc9431b4f8e01d869113f1df9e728f6",
          "body": "## TL;DR\nBump the microsandbox release train from 0.6.3 to 0.6.4 across the Rust\nworkspace, shared packages, SDKs, TypeScript examples, and release\nsubmodules.\n\n## Description\n- Updates the workspace version, exact internal Rust crate pins, and\nCargo.lock entries for all microsandbox release crates \n[…]\n `(cd sdk/node-ts && npm ci --ignore-scripts && npm run build:ts &&\nnpm run typecheck) && (cd sdk/go && go test -count=1 .)`\n- [x] `(cd mcp && npm run build && npm test) && git -C skills diff\n--check`",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.6.4 (#1102)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-05T19:24:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "56fb92463e1fa352b4a5b0b34aaad092c79df79a",
          "body": "## TL;DR\nPin msb_krun and msb_krun_utils to 0.1.22 so the next release carries\nthe WHP fixes from libkrun #79 and #80. Needs to land before the 0.6.4\nrelease in #1102 is cut, otherwise Windows users stay on the broken\n0.1.21 bits.\n\n## Description\n- Bumps the `=0.1.21` pins to `=0.1.22` and refreshes\n[…]\ns 0\n- [x] pre-commit suite (fmt, clippy, doc, msb build) passed on commit\n- [ ] full Windows box run against a release build of this pin (covered\nby the libkrun-side verification of identical sources)",
          "is_bot": false,
          "headline": "build(deps): bump msb_krun crates to 0.1.22 (#1114)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-05T13:04:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b2f046073513eecb009a925f3a93eef0b0da42",
          "body": "follow-up cleanup on the scoped upstream tls verification feature from\n#1073. behavior-preserving, plus layout and doc fixes.\n\n## code\n- replaced the manual accumulator in `upstream_connector_for` with a\nfilter/max_by_key chain and split out `scoped_upstream_connector_for`\n- swapped the vec+hashmap \n[…]\nr before the types section in the rust and\ntypescript networking pages\n- moved the orphaned python scoped-type code block into proper type\nsections\n\nnetwork lib tests pass (394), fmt and clippy clean.",
          "is_bot": false,
          "headline": "refactor(network): tidy scoped upstream tls internals and docs (#1108)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-05T08:25:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "353bef10b6b075121e4efe406f175fa3e6c64946",
          "body": "## TL;DR\n`msb ps` now shows each sandbox's CPU and memory allocation as\n`effective / max`, so you can see at a glance what a sandbox has and how\nmuch live-resize headroom is left.\n\n## Description\n- Adds `CPUS` and `MEM` columns to the `msb ps` / `msb status` table,\nrendered as `effective / max` wher\n[…]\nb ps`, live-resized\nwith `msb modify --cpus 2 --memory 1G`, confirmed columns flipped to `2\n/ 4` and `1 GiB / 2 GiB`\n- [x] Manual: `msb ps pstest --format json` includes the four new\nallocation fields",
          "is_bot": false,
          "headline": "feat(cli): show resource allocations in msb ps (#1107)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-05T08:24:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1251ca7606306f433ea5ffec23b275285f64f26f",
          "body": "…es (#1106)\n\n## TL;DR\n`msb metrics` no longer reports crashed sandboxes as running, shows each\nrow's state (`running` / `stalled` / `exited`), and gains `--watch` /\n`--follow` live modes with per-second I/O rates and resize-aware CPU/MEM\ndenominators.\n\n## Description\n- Registry readers now check the\n[…]\nmicrosandbox-cli` is clean\n- [x] `msb metrics --watch` against a live sandbox, kill -9 the runtime,\nsandbox drops out of the live view and shows `exited` under `--all`\n- [ ] full CI suite (runs in CI)",
          "is_bot": false,
          "headline": "feat(cli): show sandbox state in msb metrics and add watch/follow mod…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-05T08:24:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "793f89a3b992d82fd30f9aa83f6e5f1eebf40382",
          "body": "…#1104)\n\n## TL;DR\nKilling an exec only signalled the direct child pid, so any background\njobs the command had spawned survived as orphans inside the guest.\nEnough of them and the guest CPU is silently saturated, which is why\nlater execs crawled while pings stayed fast. Exec children are now\nsession \n[…]\n exec, and signal forwarding still work (exec\nsuite via pre-commit build; manual exec checks on the fixed sandbox)\n- [x] `cargo clippy` workspace clean; full pre-commit hooks green\n- [ ] CI on this PR",
          "is_bot": false,
          "headline": "fix(agentd): kill the exec process group, not just the direct child (…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-05T08:20:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47be1e9eb44ee832ed057f2e0398c8f512272c9c",
          "body": "## TL;DR\nAdd one modify concept for stopped and running sandboxes, including live\nCPU and memory resize, live secret rotation, and the restart, touch, and\nping lifecycle commands. No gating: the surface ships as a regular\nfeature.\n\nCloses #729.\n\n## Description\n- Add msb modify (and Sandbox::modify()\n[…]\nges\nare merged, and msb_krun 0.1.21 is published to crates.io. This branch\npins =0.1.21 and the vendor/libkrunfw submodule points at the merged\nkernel with the virtio-msb-cpu driver. Ready for review.",
          "is_bot": false,
          "headline": "feat(sandbox): live modify and resize for running sandboxes (#1099)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-04T23:29:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a05c83925a4ceec3088d48e975756b2fd091132",
          "body": "## TL;DR\nAllow operators to override the VM shutdown flush timeout with an\nenvironment variable. This lets Windows WHP tests and short-lived\nsandboxes skip the default wait when they do not need the extra flush\nwindow.\n\n## Description\n- Add `MSB_SHUTDOWN_FLUSH_TIMEOUT_MS` as an optional millisecond\n\n[…]\n--check`\n- [x] `cargo test -p microsandbox-runtime\ntest_guest_shutdown_flush_timeout --lib`\n- [x] `MSB_SHUTDOWN_FLUSH_TIMEOUT_MS=0` reduces Windows WHP short-lived\nsandbox shutdown time on the test VM",
          "is_bot": false,
          "headline": "fix(runtime): allow overriding shutdown flush timeout (#1088)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-04T18:59:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "28ec71e031bc49197c6865b762baef79319c251e",
          "body": "## TL;DR\nTreat runtime cleanup of local ephemeral sandboxes as a successful\nstopped observation, so `msb stop` no longer reports `sandbox not found`\nafter the stop request wins but cleanup deletes the row first.\n\n## Description\n- Treat a missing local ephemeral sandbox row as a stopped result when\n`\n[…]\nsandbox-cli stop`\n- [x] `cargo check -p microsandbox-cli`\n- [x] `just build-msb` plus a temp-`MSB_HOME` `./build/msb run ubuntu\n--cpus 2 --memory 1G -d -- sleep 30` followed by `./build/msb stop <id>`",
          "is_bot": false,
          "headline": "fix(sdk): accept ephemeral cleanup during stop waits (#1087)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-04T18:58:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f9765396fdff0747a05a32b88b60534cf6ff9b3",
          "body": "## TL;DR\nFix UDP relay handling for oversized and fragmented datagrams so they\nround-trip instead of blackholing, while keeping fragmented traffic\nbehind the normal egress policy checks.\n\n## Description\n- Reassemble outbound IPv4 and IPv6 UDP fragments with bounded state,\noverlap rejection, and time\n[…]\nbuild && cp target/debug/msb build/msb &&\ncodesign --entitlements msb-entitlements.plist --force -s - build/msb`\n- [x] Local `msb` UDP E2E repro returns `ALLOW_PASS`, `DENY_TIMEOUT_OK`,\nand `E2E_PASS`",
          "is_bot": false,
          "headline": "fix(network): handle fragmented UDP and PMTU relay traffic (#1086)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-04T15:11:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74d7c13a8d3d376aa0835a16641f7c5a02b9070f",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.3, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.3 (#1098)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-04T13:40:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fbe9b632eb6eb53717bea0f996673fdc74dad9c",
          "body": "…1 directory (#1096)\n\nBumps the cargo group with 1 update in the / directory:\n[cmov](https://github.com/RustCrypto/utils).\n\nUpdates `cmov` from 0.5.3 to 0.5.4\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/RustCrypto/utils/commit/5c7e4f9bb31af81bf766360e836b6d633b84dbff\"><\n[…]\nb.com/superradcompany/microsandbox/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump cmov from 0.5.3 to 0.5.4 in the cargo group across …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-04T13:38:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7121a8c3385252d9a9ec83677fea5a49a475cdb2",
          "body": "## TL;DR\nBump microsandbox from 0.6.2 to 0.6.3 across the parent release train,\nSDK/package metadata, TypeScript examples, and the mcp/skills submodule\npointers.\n\n## Description\n- Bump the Rust workspace version, exact internal crate pins, and\nCargo.lock entries for microsandbox packages to `0.6.3`.\n[…]\nexecutes the full VM-backed test suite\n(deferred to CI with real runtime artifacts; local validation compiled\nthe test targets with `--no-run` because `v0.6.3` release artifacts are\nnot published yet)",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.6.3 (#1094)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-04T09:40:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5fe3ef45e6d74b962ef7f8e1bb01cdab28bb62f",
          "body": "## TL;DR\nCloses #1076.\n\nRestore local SDK features and compatibility surfaces that regressed\nduring the backend-routing refactor. This brings SSH forwarding, image\nprune, Rust API helpers, and guest filesystem handle APIs back in line\nwith the pre-PR behavior.\n\n## Description\n- Restore SSH `direct-t\n[…]\nt-path sdk/go/native/Cargo.toml`\n- [ ] `cargo test -p microsandbox --lib\nruntime::spawn::tests::test_sigchld_handler_uses_alt_stack_after_prepare`\n(deferred: Linux-only test filtered out on this host)",
          "is_bot": false,
          "headline": "fix(sdk): restore pr 754 local feature parity (#1091)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-03T17:35:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d60b07f3beea96a5226d5d891d3ed8f0c85f2674",
          "body": "## tl;dr\n\nadds host-scoped upstream tls trust controls so self-signed/private\nupstreams can stay intercepted for secret substitution.\n\n## description\n\nthis covers both cases from #1069:\n\n- if you have a CA PEM, trust it only for matching upstream hosts\n- if the endpoint is ephemeral and you need curl `-k`-style behavior,\ndisable upstream verification only for matching hosts\n\nthis is wired through Rust, the CLI, Python, Node, Go, docs, and the TLS\nproxy itself.\n\nfixes #1069.",
          "is_bot": false,
          "headline": "feat(network): scope upstream tls verification (#1073)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-02T03:20:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b15c8fd6b7545e7d59062076e0647b5cfbfb02e3",
          "body": "## Summary\n- suppress unusable DNS answers for inactive address families\n- make generated network config files readable\n- normalize IPv4-mapped IPv6 addresses\n\n## Test Plan\n- cargo fmt --all -- --check\n- cargo fmt --manifest-path crates/agentd/Cargo.toml -- --check\n- cargo test -p microsandbox-network dns::forwarder\n- cargo test -p microsandbox-network ipv4_mapped\n- cargo test --manifest-path crates/agentd/Cargo.toml network",
          "is_bot": false,
          "headline": "fix(network): handle IPv6 DNS edge cases (#1083)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-02T03:18:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f11e152b54e34a9e3bbe45618512cb85eb12888",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.2, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.2 (#1082)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-01T23:38:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9043c89d3432a548908bb145581be4fa1e2e3d9",
          "body": "## TL;DR\nBump microsandbox from 0.6.1 to 0.6.2 across the release train and\nadvance the MCP and skills submodule pointers to their matching release\nPR commits.\n\n## Description\n- Updates the Rust workspace version, exact internal dependency pins,\nand lockfile entries for microsandbox crates to 0.6.2.\n[…]\nde-ts`\n- [ ] `cargo publish --dry-run -p microsandbox-protocol` and `cargo\npublish --dry-run -p microsandbox-agent-client` (blocked until\nexact-pinned internal 0.6.2 crates are published to crates.io)",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.6.2 (#1079)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-01T21:45:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f634d1960d8268d41e1b7c6c2456b28aa6cb7ac",
          "body": "## TL;DR\nRefresh the SDK READMEs so they match the current install and runtime\nstory, with links to the docs site for full references. Also align the\nGo docs with the explicit EnsureInstalled flow and fix the TypeScript\nDNS example.\n\n## Description\n- Rewrite the Rust, Python, TypeScript, and Go SDK \n[…]\nSub-100ms\"\n$files; then exit 1; fi'` exits 0\n- [x] `cd sdk/node-ts && npm run typecheck` exits 0\n- [x] `cd sdk/node-ts && npm run test:unit` exits 0\n- [x] `cd sdk/go && go test -count=1 ./...` exits 0",
          "is_bot": false,
          "headline": "docs(sdk): refresh sdk readmes (#1080)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-01T19:14:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf38033a5e03954b58f80132bb7ef625d2fb4579",
          "body": "…de (#1075)\n\n## What\n\n`msb load` re-materialized an image from scratch on every run —\nextracting and SHA-256-hashing every layer blob (~16 s for a 1.3 GB\nimage) — even when that exact image was already fully materialized in\nthe cache. This adds an **early cache gate** to both archive load paths:\nwhe\n[…]\nnc-compression; `sdk/rust` in `setup/download.rs`), and gzip decode\nis byte-identical across backends — no behavior change, only speed. `msb\npull` shares the same materialize path, so it benefits too.",
          "is_bot": false,
          "headline": "perf(image): faster msb load & pull — early cache gate + zlib-rs deco…",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-01T15:05:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8eddf50dcf46e33c29c87d8eea9a31b7e61c2eff",
          "body": "…builder\" (#1078)\n\nReverts superradcompany/microsandbox#983 in favour of the old format.\nthere's a new direction on this, and will be restored in a new pr.",
          "is_bot": false,
          "headline": "revert \"feat(sdk): rename overlay sizing to disk_size on the sandbox …",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-07-01T15:05:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e63ff2bb402c74e756d8dc23cc9ca913e1389d2",
          "body": "## TL;DR\nTwo changes on this branch:\n1. **`msb load` progress UI** — load now renders the same progress bars\nas `pull` (it was a silent ~11 s blackbox), including a spinner while a\npiped `docker save | msb load` streams in.\n2. **Bump `msb-imago` 0.1.0 → 0.1.1** — pulls the published VMDK FLAT\nsector\n[…]\n\n- [x] **#1071 end-to-end** (matched 0.6.1 build, no patch, published\n0.1.1): a 2.3 GiB-layer OCI image's post-2 GiB file reads\n`AFTER_BOUNDARY_222222` (sha `5b44123b…`) — correct, vs garbage on 0.1.0",
          "is_bot": false,
          "headline": "feat(cli): msb load progress + msb-imago 0.1.1 (#1071 fix) (#1074)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-07-01T02:08:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "744d7f79d81568ddb3bdc2990b635e1445210ebd",
          "body": "…(#983)\n\n## Summary\n\nRenames the writable-overlay sizing API to a clearer, user-facing\n`disk_size` across all SDKs, and **relocates it from the image builder\nto the sandbox builder** (a peer of `cpus`/`memory`) — the writable\noverlay (`upper.ext4`) is a sandbox runtime concern, not an image\nattribut\n[…]\npace` clean; the core `disk_size` builder tests, the\nCLI test, and the Go native wire-compat tests pass locally. The\nGo/Python/TS SDK test suites + native module rebuilds (maturin/napi/cgo)\nrun in CI.",
          "is_bot": false,
          "headline": "feat(sdk): rename overlay sizing to disk_size on the sandbox builder …",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-06-30T05:01:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "517d139ba1f6970b662a167b8f7b66a30a578537",
          "body": "## TL;DR\nRemove the winget install command from the README while the package is\nstill in review, so users only see install paths that are available now.\n\n## Description\n- Remove the stale winget command from the README package manager list.\n- Keep the PowerShell installer as the Windows install path\n[…]\n[x] `git diff origin/main..HEAD --name-only` prints only `README.md`\n- [x] `git diff --check origin/main..HEAD` exits 0\n- [x] `! rg -n \"winget install|SuperRadCompany.Microsandbox\" README.md`\nsucceeds",
          "is_bot": false,
          "headline": "docs(readme): remove winget install command (#1070)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-29T14:34:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4821df371967457ebcf5071360291eb584c0e90",
          "body": "## TL;DR\nMake `msb doctor` use the same runtime resolution behavior as sandbox\nlaunches, so package-manager and side-by-side installs do not get\nreported as broken. This also removes planning-era wording from\ndowngrade output and docs.\n\n## Description\n- Resolve `msb` and `libkrunfw` in doctor throug\n[…]\nff --check`\n- [x] `rg -n \"\\\\bV1\\\\b|V1 only|forward-looking downgrades\" .` exits with\nno matches\n- [x] `ruby -e \"require 'yaml';\nYAML.load_file('.github/workflows/check.yml'); puts 'workflow yaml ok'\"`",
          "is_bot": false,
          "headline": "fix(cli): align doctor runtime diagnostics (#1068)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-29T13:56:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ecb4e77b65bb5e7f792decbc4e327e625f7a736b",
          "body": "## TL;DR\nRoute the custom top-level help through the same terminal-aware color\nhandling as the command tree view. This keeps colors in supported\nterminals and avoids raw ANSI escape text in older Windows console\nhosts.\n\n## Description\n- Replace hand-written ANSI escape strings in grouped top-level h\n[…]\n fmt --all -- --check`\n- [x] `cargo check -p microsandbox-cli --no-default-features --features\nnet,ssh`\n- [x] `cargo clippy -p microsandbox-cli --no-default-features --features\nnet,ssh -- -D warnings`",
          "is_bot": false,
          "headline": "fix(cli): use terminal-aware help colors (#1066)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T21:21:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "42a2d3a01a7952c48ad674df7114d582510e3055",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.1, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.1 (#1063)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-28T19:28:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "868ac5a8f04fadca357b377537e7a5740a856509",
          "body": "## TL;DR\nBump the microsandbox release train from 0.6.0 to 0.6.1 across the Rust\nworkspace, SDK packages, shared packages, examples, and submodule\npointers.\n\n## Description\n- Bump the Rust workspace version, exact internal crate pins, and\nCargo.lock package entries to 0.6.1.\n- Update the Node SDK, G\n[…]\ngent-client`, `@microsandbox/types`, and `microsandbox`\n- [ ] Go FFI smoke test deferred because `EnsureInstalled` creates a\nfresh `MSB_HOME` and tries to download the unpublished 0.6.1 runtime\nbundle",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.6.1 (#1061)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T15:27:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0473a89f0024575fc1bfb4f94dbd4078e31410d4",
          "body": "## TL;DR\nAdd `msb self downgrade <version>` so users can move to a supported\nolder release while keeping local database state safe.\n\n## Description\n- Add `msb self downgrade <version>` with support for `--yes`,\n`--force`, `--keep-cache`, and `--no-backup`.\n- Refuse downgrade targets below 0.6.0 and \n[…]\ngs`\n- [x] `cargo test --workspace`\n- [x] `cargo build -p microsandbox-cli`\n- [x] `target/debug/msb __schema-baseline --json`\n- [x] `target/debug/msb self downgrade 0.5.10` refuses with the 0.6.0\nfloor",
          "is_bot": false,
          "headline": "feat(cli): add self downgrade (#1058)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T13:14:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82616b3adb4c602e927d6fdcba1860164bf281c7",
          "body": "## TL;DR\nAdd `--no-tty` to `msb run` and `msb exec` so scripts can force\nnon-interactive, captured execution even when launched from a terminal.\n\n## Description\n- Add `--no-tty` to `msb run` and `msb exec`, with parser conflicts so\nit cannot be combined with `--tty`.\n- Route interactive mode through\n[…]\n&1 & done; wait; grep -L ok\n/tmp/vm_*.log`\n- [x] `for i in $(seq 1 10); do msb run -q python:3-alpine --no-tty --\npython3 -c 'print(\"ok\")' > /tmp/vm_$i.log 2>&1 & done; wait; grep -L ok\n/tmp/vm_*.log`",
          "is_bot": false,
          "headline": "feat(cli): add --no-tty execution mode (#1059)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T11:50:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c60beb7edb98d37963ab9a90b316e2cb7b68ca3",
          "body": "## Why\nwinget-pkgs validation of\n[microsoft/winget-pkgs#394540](https://github.com/microsoft/winget-pkgs/pull/394540)\nflagged `Validation-Executable-Error`: on a clean VM, `msb.exe` fails to\nlaunch with `STATUS_DLL_NOT_FOUND` (0xC0000135). `msb.exe` imports\n`VCRUNTIME140.dll`, which ships with the V\n[…]\nto-submissions inherit it)\n\nThe same fix is already pushed to the live winget-pkgs PR #394540 to\nre-trigger its validation.\n\n## Validation\n- `winget validate` passes on the updated 0.6.0 manifest set.",
          "is_bot": false,
          "headline": "packaging(winget): declare VCRedist 2015+ dependency (#1057)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T11:48:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5afadbeca7ce45fae940f35dcb354b8d365c118",
          "body": "## TL;DR\nEnable Windows host bind roots and bind mounts through the existing\npassthrough filesystem path, and add Windows build/check CI for both\nsupported host architectures.\n\n## Description\n- Use the passthrough backend for `ImageSource::bind` roots on Windows\ninstead of rejecting host-directory r\n[…]\nt,ssh -p microsandbox --lib windows_drive`\n- [x] Azure Windows x86_64: `cargo check --no-default-features\n--features net,ssh -p microsandbox-cli`\n- [x] Windows arm64 CI matrix (runs in GitHub Actions)",
          "is_bot": false,
          "headline": "feat(windows): support bind mounts (#1055)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T11:47:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de234b7f2ddb7ad89fd3b45ec20e62e15de3fa52",
          "body": "## TL;DR\nMake `msb doctor` work across Linux, macOS, and Windows instead of only\nhandling the Windows hypervisor case, and turn `--fix` into something\nthat actually applies safe fixes instead of just printing advice.\n\n## Description\n- Add a presentation-agnostic diagnosis model in the SDK (`Diagnosi\n[…]\nission path runs `usermod`/`setfacl` and\nre-checks green (needs a real Linux host; verified by compile +\nhost-typecheck only)\n- [ ] Windows `--fix` enables WHP (needs native Windows build; runs in\nCI)",
          "is_bot": false,
          "headline": "feat(doctor): cross-platform host checks with safe auto-fixes (#1054)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T11:45:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13c987cd4dd3089c5bb020b4f51e9364f79e9887",
          "body": "## TL;DR\nFixes two stop-path edge cases that could leave callers stuck, and\nstages the v0.6.0 Winget manifests needed for a package submission.\n\n## Description\n- Treat `Draining` sandboxes with no active run as stopped during SDK\nand runtime reconciliation, so stop callers do not keep polling after\n\n[…]\nnget-installer-1.12.0.json -d\n/tmp/SuperRadCompany.Microsandbox.installer.yaml.json`\n- [ ] `winget validate\npackaging/winget/manifests/s/SuperRadCompany/Microsandbox/0.6.0` (needs\nWindows with winget)",
          "is_bot": false,
          "headline": "fix: stop stale sandboxes and stage winget package (#1050)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-28T02:10:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccd9dee63aa77a98902fe3d9982fc220da5edc63",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.6.0, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.6.0 (#1047)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-27T14:31:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efaab0ec14e57b93e385244cbbd831950618a028",
          "body": "## TL;DR\nBump the microsandbox release train from 0.5.10 to 0.6.0 across the\nparent repo, SDK/package metadata, examples, and agent integration\nsubmodules.\n\n## Description\n- Bump the Rust workspace version and exact internal workspace\ndependency pins to 0.6.0, then refresh Cargo.lock.\n- Update `@mic\n[…]\nsandbox-types --features ts --bin microsandbox-types-generate --\n--check`\n- [x] Dry-run publish checks for `microsandbox-utils`,\n`@microsandbox/agent-client`, `@microsandbox/types`, and `microsandbox`",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.6.0 (#1042)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-27T12:08:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07281f9753a646d06ef2ad6efb4e08de45ab0d36",
          "body": "## TL;DR\nAdd Windows package support for the Node and Python SDKs so release\nbuilds can publish usable Windows artifacts with `msb.exe` and\n`libkrunfw.dll`.\n\n## Description\n- Add `win32-arm64-msvc` and `win32-x64-msvc` Node platform package\nmanifests.\n- Teach the Node SDK package metadata, CLI shim,\n[…]\nlver returns `bin/msb.exe`\n- [ ] ARM64 Python builds and installs\n`microsandbox-0.5.10-cp310-abi3-win_arm64.whl`, and\n`_runtime.msb_path()` plus the `msb.exe` console script resolve the\nbundled binary",
          "is_bot": false,
          "headline": "build(sdk): add Windows SDK packages (#1044)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-27T11:07:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "98b299aeb9da09ebe3c0fc064d00f2fe56454085",
          "body": "Fixes\nhttps://github.com/superradcompany/microsandbox/issues/752#issuecomment-4767847704\n\n## Summary\n\nSecret substitution silently fails when the guest uses an HTTP CONNECT\nproxy (`HTTPS_PROXY=http://proxy:port`). The `SecretsHandler` DNS-cache\npin check verifies that the guest previously resolved t\n[…]\n| n/a | always runs\n|](https://github.com/superradcompany/microsandbox/issues/752#issuecomment-4767847704)\n\n---------\n\nCo-authored-by: Tochukwu Nkemdilim <11903253+toksdotdev@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(network): substitute secrets through CONNECT proxies (#1022)",
          "author_name": "Sibasish Behera",
          "author_login": "TheRealSibasishBehera",
          "committed_at": "2026-06-27T01:52:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8106ef7e898f9b00955a809f40dff3d20a3541b",
          "body": "## What\n\nExpose a **bind rootfs** (`RootfsSource::Bind`) as a first-class SDK\noption — boot a sandbox with a host directory used directly as the root\nfilesystem (no OCI pull, no overlay), mirroring the existing disk-image\nrootfs path. Python already exposed it (`ImageSource.bind`); this brings\nRust,\n[…]\nBind`.\n- `cargo check -p microsandbox-go` / `-p microsandbox-node` — the\nFFI/napi crates compile with the new option.\n- `go test ./sdk/go` — `image_bind` wire shape (present when set;\n`image` absent).",
          "is_bot": false,
          "headline": "feat(sdk): support a host-directory bind rootfs (#1021)",
          "author_name": "toks",
          "author_login": "toksdotdev",
          "committed_at": "2026-06-26T22:45:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "404da35d5b536e1c98eb66f90281d60b12a0cf20",
          "body": "## TL;DR\nFix the Windows libkrunfw DLL build path and switch microsandbox from\nthe temporary libkrun git branch to the published `msb_krun*` 0.1.18\ncrates.\n\n## Description\n- Remove the forced `/ALIGN:65536` flag from the Windows libkrunfw\nfallback link path so the DLL can be loaded normally by Windo\n[…]\nx-runtime --target aarch64-pc-windows-msvc --features net\"`\nexits 0\n- [x] `powershell.exe -NoProfile -ExecutionPolicy Bypass -File\nscripts/dev-windows.ps1 build-libkrunfw` builds `build\\libkrunfw.dll`",
          "is_bot": false,
          "headline": "build(windows): use published libkrun inputs (#1043)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-26T22:33:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfbe9473fd39e6fda95f9076650e55a1bf5c747a",
          "body": "## TL;DR\nThis is the first real Windows support branch for microsandbox. It adds\nthe local Windows runtime path around the libkrun/libkrunfw Windows\nports, plus the CLI, SDK, filesystem, networking, image, installer,\ndocs, and packaging work needed to build, install, diagnose, and run\nlocal sandboxe\n[…]\nlds were used during local smoke\ntesting on this Windows ARM64 machine.\n- [ ] Run full workspace CI on Linux/macOS/Windows.\n- [ ] Run x86_64 Windows WHP smoke on a native Windows x64 host.\n\nCloses #47",
          "is_bot": false,
          "headline": "feat(windows): add Windows support (#1019)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-26T19:18:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "221ad9c20656b4b4fc30e687079188638c73dc87",
          "body": "## TL;DR\nFix local sandbox stop and attach behavior when the runtime process has\nalready exited as a zombie. This prevents `msb stop` from waiting\nforever on a dead runtime and makes dead attach sessions close instead\nof swallowing input.\n\n## Description\n- Treat zombie PIDs as dead in shared host-si\n[…]\nest -p microsandbox --lib sandbox::tests`\n- [x] `cargo test -p microsandbox-runtime maintenance`\n- [x] `cargo test -p microsandbox --lib sandbox::attach::tests`\n- [x] `cargo build -p microsandbox-cli`",
          "is_bot": false,
          "headline": "fix(sdk): stop waiting on zombie sandbox runtimes (#1036)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-26T06:43:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a63d7740d0b3b3e8f4670f4faa11a0d5d1016ed",
          "body": "…iple ecosystems (#1035)\n\nBumps the dependencies group with 7 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [bytes](https://github.com/tokio-rs/bytes) | `1.11.1` | `1.12.0` |\n| [reflink-copy](https://github.com/cargo-bins/reflink-copy) | `0.1.29`\n| `0.1.30` |\n| [time](https://github.com/ti\n[…]\n of the specified dependency and ignore\nconditions\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump the \"dependencies\" group with 2 updates across mult…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-25T05:56:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a92f50bf5971b76149ebefa247ac96006ac54ccd",
          "body": "Regenerates `sdk/node-ts/package-lock.json` against the platform\npackages published for v0.5.10, so `npm ci` keeps working on main.\n\nCo-authored-by: appcypher <20358651+appcypher@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: refresh npm lockfile after v0.5.10 (#1034)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-24T23:14:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a62c4e45da7320e89aafc44b8a44fc74ec49fb53",
          "body": "## TL;DR\nBump microsandbox from 0.5.9 to 0.5.10 across the workspace, SDK/package\nmetadata, examples, and release reference docs.\n\n## Description\n- Bump the Rust workspace version and exact internal crate pins to\n0.5.10.\n- Refresh Cargo.lock plus npm lock metadata for the Node SDK and shared\nTypeScr\n[…]\ny`\n- [ ] Full Cargo publish verification: deferred because package\nverification downloads the not-yet-published `v0.5.10/agentd-aarch64`\nrelease artifact and currently 404s before this release exists.",
          "is_bot": false,
          "headline": "chore(release): bump microsandbox to 0.5.10 (#1031)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-24T22:02:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef53aef215dc8360c1283642fe0aa9d97762859c",
          "body": "## TL;DR\nUpdate the repository agent instructions so contributors pause and warn\nmaintainers before risky or breaking changes.\n\n## Description\n- Replace broad compatibility-shim guidance with a change-safety rule\nfor work that may introduce regressions or breaking changes.\n- Ask agents to call out b\n[…]\n, and feature work.\n- Keep the change limited to AGENTS.md contributor guidance.\n\n## Test Plan\n- [x] `git diff --check origin/main..HEAD` exits 0\n- [x] `git show --check --pretty=format: HEAD` exits 0",
          "is_bot": false,
          "headline": "docs(agents): update change safety guidance (#1032)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-24T21:55:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b278f93de2a47e0fa5bd121df530276422069840",
          "body": "## TL;DR\nRestore the named-volume behavior that regressed in the backend split,\nincluding disk-backed named volumes for Docker-in-Docker. This also\nrestores the lifecycle cleanup, locking, backend routing, and SDK\nbindings that depended on that old behavior.\n\n## Description\n- Restore named-volume re\n[…]\ne:debug && npm run build:ts\n&& npm run typecheck && npm run test:unit`\n- [x] `just build-msb` plus a `docker:dind` smoke using `--mount-named\n...:kind=disk,size=10G` runs `docker run --rm hello-world`",
          "is_bot": false,
          "headline": "fix(sdk): restore named volume mount semantics (#1030)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-24T18:27:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df613230065b658c046cc13f58b75ac3796477d0",
          "body": "## TL;DR\n\nNamed volumes created with `kind=disk` were mounted over virtiofs\ninstead of as a virtio-blk block device, so overlayfs (e.g. docker's\ndefault storage driver) on top of them failed with `EINVAL`. This routes\nthem to virtio-blk, and also recovers the disk kind from the volume\nstore so the f\n[…]\n+ directory named volumes in one config) and\na focused unit test for the store lookup would broaden coverage; the\ncurrent tests cover the three core states (first-run disk / restart disk\n/ directory).",
          "is_bot": false,
          "headline": "fix(runtime): mount named kind=disk volume as virtio-blk (#1028)",
          "author_name": "zhuanyongxigua",
          "author_login": "zhuanyongxigua",
          "committed_at": "2026-06-24T15:46:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2332df46dc012a73faa06bede3096747205b1378",
          "body": "## TL;DR\nRestore the live sandbox lifecycle methods across SDK bindings so\ncallers can stop, kill, drain, and wait on the object they already have.\nThis also fixes Node list APIs to return usable sandbox handles again\nand frees disk in the Linux test job before workspace tests.\n\n## Description\n- Res\n[…]\nasses\n- [x] `cargo check -p microsandbox-py` passes\n- [x] `cd sdk/go && go test -count=1 .` passes\n- [x] `ruby -e 'require \"yaml\";\nYAML.load_file(\".github/workflows/test.yml\"); puts \"yaml ok\"'` passes",
          "is_bot": false,
          "headline": "fix(sdk): restore live sandbox lifecycle APIs (#1024)",
          "author_name": "Stephen Akinyemi",
          "author_login": "appcypher",
          "committed_at": "2026-06-24T06:45:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 433,
      "latest_release_at": "2026-07-18T20:20:27Z",
      "latest_release_tag": "v0.6.6",
      "releases_from_tags": false,
      "days_since_last_push": 6,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 11.6
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/nehmeroumani/microsandbox/sdk/go",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/nehmeroumani/microsandbox/sdk/go",
          "is_deprecated": false,
          "latest_version": "v0.6.6",
          "repository_url": "https://github.com/nehmeroumani/microsandbox",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T17:21:23Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "microsandbox-db",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/microsandbox-db",
          "is_deprecated": false,
          "latest_version": "0.6.6",
          "repository_url": "https://github.com/superradcompany/microsandbox",
          "versions_count": 38,
          "total_downloads": 16908,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 4789,
          "first_published_at": "2026-03-20T01:35:19.022871Z",
          "latest_published_at": "2026-07-07T19:46:02.990495Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 17
        },
        {
          "name": "microsandbox-cli",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/microsandbox-cli",
          "is_deprecated": false,
          "latest_version": "0.6.6",
          "repository_url": "https://github.com/superradcompany/microsandbox",
          "versions_count": 43,
          "total_downloads": 4101,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 171,
          "first_published_at": "2025-05-20T15:18:28.150023Z",
          "latest_published_at": "2026-07-07T19:55:31.122396Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 17
        },
        {
          "name": "microsandbox-image",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/microsandbox-image",
          "is_deprecated": false,
          "latest_version": "0.6.6",
          "repository_url": "https://github.com/superradcompany/microsandbox",
          "versions_count": 38,
          "total_downloads": 16720,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 4732,
          "first_published_at": "2026-03-20T01:36:56.730490Z",
          "latest_published_at": "2026-07-07T19:48:08.101062Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 17
        },
        {
          "name": "microsandbox-utils",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/microsandbox-utils",
          "is_deprecated": false,
          "latest_version": "0.6.6",
          "repository_url": "https://github.com/superradcompany/microsandbox",
          "versions_count": 45,
          "total_downloads": 21459,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 4960,
          "first_published_at": "2025-05-20T13:13:47.211739Z",
          "latest_published_at": "2026-07-07T19:40:51.413719Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 17
        },
        {
          "name": "microsandbox-agentd",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/microsandbox-agentd",
          "is_deprecated": false,
          "latest_version": "0.6.6",
          "repository_url": "https://github.com/superradcompany/microsandbox",
          "versions_count": 17,
          "total_downloads": 309,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 98,
          "first_published_at": "2026-03-20T01:58:14.110892Z",
          "latest_published_at": "2026-07-07T19:45:00.648550Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 17
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "recipes"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/agent-client/typescript/tsconfig.json",
        "packages/microsandbox-types/typescript/tsconfig.json",
        "sdk/node-ts/tsconfig.json",
        "sdk/python/microsandbox/py.typed"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/agentd/Cargo.toml",
        "crates/cli/Cargo.toml",
        "crates/db/Cargo.toml",
        "crates/filesystem/Cargo.toml",
        "crates/image/Cargo.toml",
        "crates/metrics-collector/Cargo.toml",
        "crates/metrics/Cargo.toml",
        "crates/migration/Cargo.toml",
        "crates/network/Cargo.toml",
        "crates/protocol/Cargo.toml",
        "crates/runtime/Cargo.toml",
        "crates/test-init/Cargo.toml",
        "crates/test-macros/Cargo.toml",
        "crates/test-utils/Cargo.toml",
        "crates/utils/Cargo.toml",
        "examples/rust/cloud-backend/Cargo.toml",
        "examples/rust/fs-read-stream/Cargo.toml",
        "examples/rust/init-handoff/Cargo.toml",
        "examples/rust/logs-read/Cargo.toml",
        "examples/rust/metrics-stream/Cargo.toml",
        "examples/rust/net-basic/Cargo.toml",
        "examples/rust/net-dns/Cargo.toml",
        "examples/rust/net-policy/Cargo.toml",
        "examples/rust/net-ports/Cargo.toml",
        "examples/rust/net-secrets-body/Cargo.toml",
        "examples/rust/net-secrets/Cargo.toml",
        "examples/rust/net-tls/Cargo.toml",
        "examples/rust/root-bind/Cargo.toml",
        "examples/rust/root-block/Cargo.toml",
        "examples/rust/root-oci/Cargo.toml",
        "examples/rust/rootfs-patch/Cargo.toml",
        "examples/rust/shell-attach/Cargo.toml",
        "examples/rust/snapshot-fork/Cargo.toml",
        "examples/rust/volume-disk/Cargo.toml",
        "examples/rust/volume-named/Cargo.toml",
        "packages/agent-client/rust/Cargo.toml",
        "packages/microsandbox-types/rust/Cargo.toml",
        "sdk/go/go.mod",
        "sdk/go/native/Cargo.toml",
        "sdk/node-ts/Cargo.toml",
        "sdk/python/Cargo.toml",
        "sdk/rust/Cargo.toml",
        "sdk/rust/fuzz/Cargo.toml"
      ],
      "largest_source_bytes": 229189,
      "source_files_sampled": 768,
      "oversized_source_files": 24,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 14305
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "base64",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ciborium",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-protocol",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "nix",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/agentd/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "base64",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bytes",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "console",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "indicatif",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ipnetwork",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-db",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-image",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-migration",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-network",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-protocol",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-runtime",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-utils",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rand",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "reqwest",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rpassword",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "russh",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sea-orm",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing-subscriber",
          "manifest": "crates/cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/db/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "sea-orm",
          "manifest": "crates/db/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sqlx",
          "manifest": "crates/db/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/db/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/db/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ciborium",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-utils",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "msb_krun",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "scopeguard",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_bytes",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/filesystem/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "astral-tokio-tar",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-compression",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hex",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-utils",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "oci-client",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rustls-pemfile",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "oci-spec",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "scopeguard",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tar",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio-util",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/image/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-metrics",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "chrono",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing-subscriber",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-db",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sea-orm",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-utils",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "humantime",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "opentelemetry",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.32"
        },
        {
          "name": "opentelemetry-otlp",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.32"
        },
        {
          "name": "opentelemetry_sdk",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.32"
        },
        {
          "name": "tonic",
          "manifest": "crates/metrics-collector/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14"
        },
        {
          "name": "chrono",
          "manifest": "crates/metrics/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/metrics/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/metrics/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/metrics/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sea-orm-migration",
          "manifest": "crates/migration/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/migration/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "base64",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "bytes",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "crossbeam-queue",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hickory-client",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hickory-proto",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "httlib-hpack",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "httparse",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "ipnetwork",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "lru",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-protocol",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-types",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-utils",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "msb_krun",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "msb_krun_utils",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "parking_lot",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "pem",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "percent-encoding",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "rcgen",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "resolv-conf",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rustls",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rustls-native-certs",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rustls-pemfile",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "serde",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "socket2",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "smoltcp",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "time",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio-rustls",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "zeroize",
          "manifest": "crates/network/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ciborium",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-types",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_bytes",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "strum",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.52"
        },
        {
          "name": "bytes",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "crossbeam-queue",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-agent-client",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-db",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-filesystem",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-metrics",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-network",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-protocol",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-types",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-utils",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "msb_krun",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "nix",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rustls",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sea-orm",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "zeroize",
          "manifest": "crates/runtime/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/test-init/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proc-macro2",
          "manifest": "crates/test-macros/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "quote",
          "manifest": "crates/test-macros/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "syn",
          "manifest": "crates/test-macros/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "test-macros",
          "manifest": "crates/test-utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/test-utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "libc",
          "manifest": "crates/utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reflink-copy",
          "manifest": "crates/utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "scopeguard",
          "manifest": "crates/utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ureq",
          "manifest": "crates/utils/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-network",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ipnetwork",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "napi",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "napi-derive",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "tokio",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bytes",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "sdk/node-ts/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "microsandbox-network",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ipnetwork",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.21.0"
        },
        {
          "name": "pyo3",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.24"
        },
        {
          "name": "pyo3-async-runtimes",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.24"
        },
        {
          "name": "serde_json",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "typed-path",
          "manifest": "sdk/python/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "appcypher",
          "commits": 380,
          "avatar_url": "https://avatars.githubusercontent.com/u/20358651?v=4"
        },
        {
          "type": "User",
          "login": "toksdotdev",
          "commits": 136,
          "avatar_url": "https://avatars.githubusercontent.com/u/11903253?v=4"
        },
        {
          "type": "User",
          "login": "nehmeroumani",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/10393081?v=4"
        },
        {
          "type": "User",
          "login": "dijdzv",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/103440382?v=4"
        },
        {
          "type": "User",
          "login": "cedws",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/38229097?v=4"
        },
        {
          "type": "User",
          "login": "wellsbunk5",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/71154493?v=4"
        },
        {
          "type": "User",
          "login": "enricoschaaf",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/54645197?v=4"
        },
        {
          "type": "User",
          "login": "TheRealSibasishBehera",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/95071627?v=4"
        },
        {
          "type": "User",
          "login": "nuri-yoo",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/24609760?v=4"
        },
        {
          "type": "User",
          "login": "Eronmmer",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/37238033?v=4"
        }
      ],
      "contributors_sampled": 37,
      "top_contributor_share": 0.632
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "check.yml",
        "fuzz.yml",
        "release-bump.yml",
        "release.yml",
        "test.yml",
        "yank.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "package-lock.json",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "16 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "18003c3cd7ec25560bb27c26cd82057acb2b7f78",
        "ran_at": "2026-07-25T00:04:45Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T06:06:32Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/nehmeroumani/microsandbox",
    "host": "github.com",
    "name": "microsandbox",
    "owner": "nehmeroumani"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 52,
      "inputs": {
        "security": 48,
        "vitality": 79,
        "community": 12,
        "governance": 44,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 79,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "commits_last_year": 433,
              "human_commit_share": 0.89,
              "days_since_last_push": 6,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "433 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 433
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.6.6",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 11.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~11.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 11.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 12,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 44,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 37,
              "top_contributor_share": 0.632
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 63% of commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 63
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "37 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "followers": 13,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "nehmeroumani",
              "public_repos": 31,
              "account_age_days": 4219
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "13 followers of nehmeroumani",
                "points": 8.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 13,
                      "login": "nehmeroumani"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "31 public repos, account ~11 yr old",
                "points": 23,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 31
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/nehmeroumani/microsandbox/sdk/go"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "2 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 92,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://docs.microsandbox.dev",
              "has_readme": false,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://docs.microsandbox.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "16 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 8
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 85,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.978,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 14305
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "87 of 89 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 87,
                      "sampled": 89
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "package-lock.json",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/agent-client/typescript/tsconfig.json",
                "packages/microsandbox-types/typescript/tsconfig.json",
                "sdk/node-ts/tsconfig.json",
                "sdk/python/microsandbox/py.typed"
              ],
              "agent_commit_share": 0.15,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/agentd/Cargo.toml",
                "crates/cli/Cargo.toml",
                "crates/db/Cargo.toml",
                "crates/filesystem/Cargo.toml",
                "crates/image/Cargo.toml",
                "crates/metrics-collector/Cargo.toml",
                "crates/metrics/Cargo.toml",
                "crates/migration/Cargo.toml",
                "crates/network/Cargo.toml",
                "crates/protocol/Cargo.toml",
                "crates/runtime/Cargo.toml",
                "crates/test-init/Cargo.toml",
                "crates/test-macros/Cargo.toml",
                "crates/test-utils/Cargo.toml",
                "crates/utils/Cargo.toml",
                "examples/rust/cloud-backend/Cargo.toml",
                "examples/rust/fs-read-stream/Cargo.toml",
                "examples/rust/init-handoff/Cargo.toml",
                "examples/rust/logs-read/Cargo.toml",
                "examples/rust/metrics-stream/Cargo.toml",
                "examples/rust/net-basic/Cargo.toml",
                "examples/rust/net-dns/Cargo.toml",
                "examples/rust/net-policy/Cargo.toml",
                "examples/rust/net-ports/Cargo.toml",
                "examples/rust/net-secrets-body/Cargo.toml",
                "examples/rust/net-secrets/Cargo.toml",
                "examples/rust/net-tls/Cargo.toml",
                "examples/rust/root-bind/Cargo.toml",
                "examples/rust/root-block/Cargo.toml",
                "examples/rust/root-oci/Cargo.toml",
                "examples/rust/rootfs-patch/Cargo.toml",
                "examples/rust/shell-attach/Cargo.toml",
                "examples/rust/snapshot-fork/Cargo.toml",
                "examples/rust/volume-disk/Cargo.toml",
                "examples/rust/volume-named/Cargo.toml",
                "packages/agent-client/rust/Cargo.toml",
                "packages/microsandbox-types/rust/Cargo.toml",
                "sdk/go/go.mod",
                "sdk/go/native/Cargo.toml",
                "sdk/node-ts/Cargo.toml",
                "sdk/python/Cargo.toml",
                "sdk/rust/Cargo.toml",
                "sdk/rust/fuzz/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/agent-client/typescript/tsconfig.json, packages/microsandbox-types/typescript/tsconfig.json, sdk/node-ts/tsconfig.json, sdk/python/microsandbox/py.typed",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/agent-client/typescript/tsconfig.json, packages/microsandbox-types/typescript/tsconfig.json, sdk/node-ts/tsconfig.json, sdk/python/microsandbox/py.typed"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "15 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 15,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 229189,
              "source_files_sampled": 768,
              "oversized_source_files": 24
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "24/768 source files over 60KB",
                "points": 53.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 768,
                      "oversized": 24
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples",
                "recipes"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, recipes",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, recipes"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable",
    "crates package 'microsandbox-db' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring",
    "crates package 'microsandbox-cli' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring",
    "Could not fetch crates package 'microsandbox-py' from its registry",
    "Could not fetch crates package 'microsandbox-node' from its registry",
    "crates package 'microsandbox-image' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring",
    "crates package 'microsandbox-utils' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring",
    "crates package 'microsandbox-agentd' points at a different repository (https://github.com/superradcompany/microsandbox); excluded from ecosystem scoring",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T00:05:02.497537Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/nehmeroumani/microsandbox.svg",
  "full_name": "nehmeroumani/microsandbox",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenGo, crates.io.