Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-24 02:33 UTC

pivoshenko / kasetto

📼 A declarative AI agent environment manager, written in Rust

Rust · MDXEigene Lizenz★ 117 Sterne⑂ 7 Forksseit März 2026Auf GitHub ansehen ↗

pivoshenko/kasetto erreicht einen Gesundheitsindex von 62 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (82/100) ab, am schwächsten bei Security (49/100). Zuletzt vor 5 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

62
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

62
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

Volodymyr PivoshenkoPersönliches Konto
49 Follower25 öffentliche Reposseit Juni 2018Bally's Interactive

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
crates.iokasetto3.6.012829vor 6 Tagencursorclaude-codecodexskillsmcps

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

82Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 5 Tagen
11.8/36Commit-Rhythmus — 17/52 Wochen mit Commits
18/18Commit-Volumen — 409 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year409
human_commit_share0,93
days_since_last_push5
active_weeks_last_year17
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 30 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 6 Tagen
27/27Release-Rhythmus — ein Release etwa alle 6,6 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count30
latest_release_tagv3.6.0
releases_from_tagsnein
days_since_latest_release6
mean_days_between_releases6,6

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

55Mittel · 18 % des Gesamtindex
Wie die Bewertung erfolgt
33.5/60Stars — 117 Stars
6.5/25Forks — 7 Forks
0/15Watcher — 2 Watcher
Verwendete Eingangsdaten
forks7
stars117
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
16.9/22.5Lizenz — Lizenzdatei vorhanden, keine anerkannte Lizenz
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templateja
Wie die Bewertung erfolgt
28.1/80Downloads pro Monat — 128 Downloads/Monat über crates
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packageskasetto
dependents
ecosystemscrates
total_downloads485
monthly_downloads128
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

55Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.6/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 97 % der Commits
2.7/13.5Breite der Beitragenden — 2 Beitragende
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Verwendete Eingangsdaten
bus_factor1
contributors_sampled2
top_contributor_share0,973
Wie die Bewertung erfolgt
38.9/46.8Issue-Lösungsquote — 83 % der Issues geschlossen
25.2/38.3PR-Annahme — 25/38 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/13 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs25
open_issues2
closed_issues10
issue_closed_ratio0,833
closed_unmerged_prs13
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
12.2/25Reichweite des Inhabers — 49 Follower von pivoshenko
22.3/25Kontohistorie — 25 öffentliche Repos, Kontoalter ca. 8 Jahre
Verwendete Eingangsdaten
followers49
owner_typeUser
is_verified
owner_loginpivoshenko
public_repos25
account_age_days2.953
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf crates
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 6 Tagen
20/20Versionshistorie — 29 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packageskasetto
ecosystemscrates
any_deprecatednein
min_days_since_publish6

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

66Mittel · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 4 Workflow(s)
0/24Tests vorhanden
16/16Linter-Konfiguration — biome.json
0/9.6Pre-Commit-Hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsnein
has_editorconfigja
has_linter_configja
has_precommit_confignein
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://www.kasetto.dev
10/10Repository-Beschreibung
10/10Topics — 20 Topics
0/10Wiki
Verwendete Eingangsdaten
topicsai, skills, claude-code, copilot, cursor, mcp, codex, openclaw, opencode, mcps, ai-agent, ai-skills-manager, antigravity, claude, claude-skills, developer-tool, gemini, kiro, pi, ai-commands
has_wikinein
homepagehttps://www.kasetto.dev
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

49Gefährdet · 16 % des Gesamtindex

Sicherheitslage

49Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/13 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate4,9

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

71Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 93 von 93 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes23.446
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — justfile
0/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — biome.json
11/11Statische Typprüfung — site/tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsnein
lockfilesCargo.lock, pnpm-lock.yaml
has_dockerfilenein
typed_languageja
bootstrap_filesjustfile
has_devcontainernein
has_linter_configja
typecheck_configssite/tsconfig.json
agent_commit_share0
toolchain_manifestsCargo.toml
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — Rust (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/85 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageRust
largest_source_bytes41.394
source_files_sampled85
oversized_source_files0

Eckdaten

117GitHub-Sterne
2Mitwirkende
409Commits, letzte 12 Monate
5Tage seit letztem Push
30Releases
1Bus-Faktor
2offene Issues
crates.io, npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 7 ⇿
0Sterne
7Forks
26Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

234567722026-032026-052026-07
Major 2Minor 18Patch 6
OpenSSF Scorecard 4.9 / 10
4.9Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-24 02:33 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/13 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
1Vulnerabilities9 existing vulnerabilities detected
Direkte Abhängigkeiten 24
RegistryPaketVersionsvorgabeManifest
crates.ioclap4Cargo.toml
crates.ioclap_complete4Cargo.toml
crates.ioflate21Cargo.toml
crates.iomimalloc0.1Cargo.toml
crates.iorayon1Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.ioserde_yaml0.9Cargo.toml
crates.iosha20.10Cargo.toml
crates.ioshlex1Cargo.toml
crates.iotar0.4Cargo.toml
crates.iotoml0.8Cargo.toml
crates.iounicode-width0.2Cargo.toml
npm@vercel/analytics^1.6.1site/package.json
npm@vercel/speed-insights^1.3.1site/package.json
npmfumadocs-core^14.7.7site/package.json
npmfumadocs-mdx^11.10.1site/package.json
npmfumadocs-ui^14.7.7site/package.json
npmmermaid^11.16.0site/package.json
npmnext^15.5.20site/package.json
npmreact^19.2.7site/package.json
npmreact-dom^19.2.7site/package.json
npmreact-icons^5.7.0site/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "ai",
        "skills",
        "claude-code",
        "copilot",
        "cursor",
        "mcp",
        "codex",
        "openclaw",
        "opencode",
        "mcps",
        "ai-agent",
        "ai-skills-manager",
        "antigravity",
        "claude",
        "claude-skills",
        "developer-tool",
        "gemini",
        "kiro",
        "pi",
        "ai-commands"
      ],
      "is_fork": false,
      "size_kb": 1473,
      "has_wiki": false,
      "homepage": "https://www.kasetto.dev",
      "languages": {
        "CSS": 36467,
        "MDX": 104208,
        "Just": 1326,
        "Ruby": 656,
        "Rust": 669391,
        "Shell": 11290,
        "JavaScript": 5611,
        "PowerShell": 4078,
        "TypeScript": 63258
      },
      "pushed_at": "2026-07-18T13:34:55Z",
      "created_at": "2026-03-17T19:27:54Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T14:14:55Z",
      "description": "📼 A declarative AI agent environment manager, written in Rust",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust",
        "MDX"
      ]
    },
    "owner": {
      "blog": "https://www.pivoshenko.dev",
      "name": "Volodymyr Pivoshenko",
      "type": "User",
      "login": "pivoshenko",
      "company": "Bally's Interactive",
      "location": "London",
      "followers": 49,
      "avatar_url": "https://avatars.githubusercontent.com/u/40499728?v=4",
      "created_at": "2018-06-22T17:16:57Z",
      "is_verified": null,
      "public_repos": 25,
      "account_age_days": 2953
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-07-17T13:03:55Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-06-28T09:47:03Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-06-21T20:56:13Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2026-06-18T20:24:57Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-06-18T20:13:38Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-06-12T17:09:12Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-06-04T10:03:47Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-06-01T08:53:44Z"
        },
        {
          "tag": "v2.12.0",
          "kind": "minor",
          "published_at": "2026-05-25T13:52:14Z"
        },
        {
          "tag": "v2.11.0",
          "kind": "minor",
          "published_at": "2026-05-19T07:03:34Z"
        },
        {
          "tag": "v2.10.0",
          "kind": "minor",
          "published_at": "2026-05-18T19:56:29Z"
        },
        {
          "tag": "v2.9.1",
          "kind": "patch",
          "published_at": "2026-05-12T20:53:28Z"
        },
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2026-05-10T20:19:08Z"
        },
        {
          "tag": "v2.8.1",
          "kind": "patch",
          "published_at": "2026-05-10T16:47:13Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2026-05-10T16:27:08Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-05-09T18:44:45Z"
        },
        {
          "tag": "v2.6.1",
          "kind": "patch",
          "published_at": "2026-05-07T20:41:37Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-05-04T11:41:25Z"
        },
        {
          "tag": "v2.5.1",
          "kind": "patch",
          "published_at": "2026-05-04T10:00:14Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-05-03T20:08:00Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-04-26T15:01:00Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-04-23T07:59:03Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-04-21T19:18:20Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-04-19T19:05:58Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-04-06T13:14:48Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-04-06T12:55:03Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-03-20T16:59:36Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-03-20T16:28:32Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-03-20T15:59:58Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-03-19T07:45:28Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "b4cc4d023685478eed1e1b89c185e672bf93658c",
          "body": null,
          "is_bot": false,
          "headline": "chore: add editorconfig",
          "author_name": "Volodymyr Pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-18T13:34:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a9e6e311465a6523344844145f44c1b5687b319",
          "body": "Biome's noSvgWithoutTitle a11y rule fails on the icon, favicon, and\nlogo because they render visible text without an accessible name.\nGive each svg a title matching its visible content so screen readers\nannounce it and just lint passes.",
          "is_bot": false,
          "headline": "fix(site): add titles to svg assets for accessibility",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T17:57:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd8d7d6747015920d75191a052c990c5dd75f2e5",
          "body": null,
          "is_bot": false,
          "headline": "build(deps): update dependencies",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T17:57:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f0c813808cce04e6906fc95e923fc146aa7af03",
          "body": "The header hardcoded \"21 PRESETS, BUILT IN\" and went stale when the\nzcode preset joined the grid. Render AGENTS.length instead so the count\ntracks the list.",
          "is_bot": false,
          "headline": "fix(site): derive agents-grid preset count from list length",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T13:14:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d4039818900f904f6b7342dc1eb4ea5bbcaf607",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.6.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T12:59:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3752c4dd65d5df97228fcc5079bef50f7937eea6",
          "body": null,
          "is_bot": false,
          "headline": "build: bump crossbeam-epoch to 0.9.20 for RUSTSEC-2026-0204",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T12:56:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53d68a718f5e0896326a7c007246422017e95ba4",
          "body": "Add ZCode (https://zcode.z.ai) as the 22nd agent preset, covering all\nfour asset kinds:\n\n- skills: ~/.zcode/skills (global), .zcode/skills (project)\n- commands: ~/.zcode/commands + .zcode/commands, Markdown + frontmatter\n- MCP servers: new McpSettingsFormat::ZCode writing the nested\n  mcp.servers ob\n[…]\nregate AGENTS.md (workspace) + ~/.zcode/AGENTS.md\n\nThe JSON merge/remove/list helpers in mcps/ are generalized from a\nsingle root key to a nested key path to support the mcp.servers shape.\n\nCloses #45",
          "is_bot": false,
          "headline": "feat: add zcode agent preset",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-07-17T12:56:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e07827d1d4505a3bfd9f90519e642a2a88ae0b4",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.5.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-28T09:43:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "146b23d806cc1595afc0bcd0fdaab0134204f4f1",
          "body": "… and CLI help",
          "is_bot": false,
          "headline": "style: normalize unicode ellipsis to ASCII ... across docs, comments,…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:37:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50737d988d59ae3051953c84df7bb9a929fda42e",
          "body": null,
          "is_bot": false,
          "headline": "style: collapse single-line use import in sync/skills",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:26:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf40cf7b7bb1838321cea8b3c0d1a811365fb08f",
          "body": "Collapse dedup_targets/dedup_command_targets/dedup_paths/dedup_instruction_targets\nonto one generic dedup_by_path(iter, key); extract json_object() for the shared\nread->parse->get-object preamble behind json_server_names/json_all_keys_present.",
          "is_bot": false,
          "headline": "refactor: dedup path-set helpers and share MCP JSON object parsing",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:24:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d04e8daa3281bee48cd2178938fd25a71e598c1",
          "body": "`doctor` now diffs every managed install path for the active scope against\nthe lock and reports untracked entries across all four asset kinds:\n\n- skills: a `SKILL.md` dir in a managed skills path but absent from the lock\n- commands / per-dir instructions: files in managed dirs not in the lock\n- inst\n[…]\nhealth flag. A config-level custom `destination` redirects the\nskill scan to that dir, matching sync. Surfaced as a Checks row plus an amber\n\"Untracked\" group, and in --json via the `unmanaged` array.",
          "is_bot": false,
          "headline": "feat(doctor): report untracked entries in managed install paths",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-28T09:22:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99ea5e2c8b4e0f74478fb67985dfaca37e3b1282",
          "body": "Present the tagged-form secret sources as a list (source -> manager +\nCLI), add a \"Secrets, never committed\" feature bullet, and reframe the\npositioning from \"skill management\" to \"AI environment management across\nprojects, machines, and agents\".",
          "is_bot": false,
          "headline": "docs(readme): list secret managers and broaden positioning",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:27:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "134a658778127b210be8cbbfd15359018f19732c",
          "body": "Clears the high-severity advisory (unbounded out-of-order stream\nreassembly) that was failing audit-rs in CI.",
          "is_bot": false,
          "headline": "fix(deps): bump quinn-proto to 0.11.15 for RUSTSEC-2026-0185",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "217947d51253f334bac8d8401a9942187d1720e0",
          "body": null,
          "is_bot": false,
          "headline": "docs(lock): note the comma-in-path limitation of the destination CSV",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0b550f55c0a64d0f1550aef1be6aa193e6feb79",
          "body": "The `kasetto lock` re-resolve path wrote only destinations[0] -- the\nlock-side twin of the multi-agent data-loss bug fixed in the previous\ncommit (#42). In a multi-agent setup `lock` / `lock --upgrade-package`\npinned a single agent dir, so later teardown orphaned the other agents'\ncopies and doctor \n[…]\ning ones.\n\nExtract fsops::join_dest_csv and route both the sync and lock write\npaths through it so the two cannot drift apart again. Adds unit tests\nfor the helper's relative and out-of-root behavior.",
          "is_bot": false,
          "headline": "fix(lock): record every skill destination in the lock rebuild",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a96600c66dd11770263b94801ed901086035e3e",
          "body": "SkillEntry recorded only the first agent dir, but skills install into all\nconfigured agent dirs. On a source retarget (URL -> local path) the skill\nkey changes, so the new entry installs into every dir and the stale-removal\npass then deletes the old entry's recorded path -- the dir just written --\nd\n[…]\noctor: verify each locked destination exists on disk; fail when missing\n- clean/list: split the multi-value destination\n\nAdds regression tests for the retarget collision and full multi-agent teardown.",
          "is_bot": false,
          "headline": "fix(sync): track every skill destination to stop multi-agent data loss",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24daafe18cdfa623ec3336279550898da5016d1e",
          "body": "Both split a payload on the first `#`. Route vault_path_field through\nsplit_field and add the mandatory-field check on top, so the delimiter\nlogic lives in one place.",
          "is_bot": false,
          "headline": "refactor(secrets): derive vault_path_field from split_field",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "734cbddf14be88f377aef1b907c941d8cdcc686a",
          "body": "Selective `kst sync --update <name>` recomputed the update flag once per\nsource and applied it to every file in that source. When a source held\nseveral secret-bearing MCP files, rotating one force-remerged (overwrite)\nthe others too, clobbering hand-edited servers from the sibling files.\n\nDerive the\n[…]\n fetch decision. Also scope the\nsecret-placeholder check to the injected `mcpServers` object so a\nplaceholder in an unrelated key no longer triggers a spurious\nworld-readable warning and rotation tip.",
          "is_bot": false,
          "headline": "fix(secrets): scope --update rotation per file, not per source",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eda21a86f7b5800c5de00fae2560e15b49e5b370",
          "body": "The tagged form documents ten providers, not four — the count was a\nleftover from before the extra managers were added. Drop the number so\nit can't go stale again.",
          "is_bot": false,
          "headline": "docs(secrets): drop stale provider count in tagged-form intro",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5e227ccc6ecbe4c4b4b60a9620687ccb33a5149",
          "body": null,
          "is_bot": false,
          "headline": "docs(site): tighten feature-tab copy",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b029b3fda06a1c00e563cc3c933bc8fa1898d8e5",
          "body": null,
          "is_bot": false,
          "headline": "docs(secrets): document #json-key for gcp and az",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8007d87b05f1e7f2114d253e7e77146ca8c03517",
          "body": "GCP Secret Manager and Azure Key Vault secrets are frequently JSON documents,\nlike AWS. Give `gcp`/`az` the same optional `#<json-key>` selector aws already\nhas, reusing split_field + extract_json_field. No `#` returns the raw secret\n(unchanged behavior).",
          "is_bot": false,
          "headline": "feat(secrets): support #json-key extraction for gcp and az",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6aa501f1748e08b508404abcd1f66fc9cae5ae5",
          "body": "The track title \"SECRET SOURCES\" already labels the section, so the inner\nheader line was redundant.",
          "is_bot": false,
          "headline": "refactor(site): drop the secret-cards header bar",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67b956e606e642d9d9617e60305c5d38a79d8c90",
          "body": "…e example\n\nThe per-card CLI label duplicated the source name (e.g. \"HashiCorp Vault\" /\n\"vault\"); remove it (and its unused style) so each card is just logo + name +\n${kst:…} example. Move the SECRET SOURCES track above EXAMPLE.",
          "is_bot": false,
          "headline": "refactor(site): drop redundant CLI label from secret cards, move abov…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77e221269b15d9eb7a294250ed03efc5b102bfae",
          "body": "New \"SECRET SOURCES\" track with a card per provider — brand logo, name, the CLI\nit uses, and a copy-ready ${kst:…} usage example. Covers all ten sources (env,\ncredentials.yaml, 1Password, Vault, KeePass, AWS, GCP, Azure, pass, Keychain)\nusing monochrome react-icons glyphs tinted to the palette (no image assets).\n\nAlso closes the landing gap where the feature copy only mentioned env/credentials\n— it now names the external managers too.",
          "is_bot": false,
          "headline": "feat(site): add secret-sources cards to the homepage",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6321e315dbc982b844509463c87eea54b0944b97",
          "body": "Add a \"Pinning a source\" subsection for each new provider, refresh the\nunknown-tag list, and update the README, security page, and module map.",
          "is_bot": false,
          "headline": "docs(secrets): document aws, gcp, az, pass, and keychain sources",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11de374b57664fa9b28bb0b6535ac5d63a0b55cb",
          "body": "Five more tagged secret sources, each a thin SecretSource that shells out to the\nprovider's own CLI (so kasetto still stores no tokens):\n\n  ${kst:aws:<secret-id>#<json-key>}   aws secretsmanager get-secret-value\n  ${kst:gcp:<name>}                   gcloud secrets versions access latest\n  ${kst:az:<\n[…]\nson_field); the `#field` split is shared with keychain via split_field.\nLike op/vault/kp these are registered unconditionally but gated by `handles`, so\nthey cost nothing until a matching tag appears.",
          "is_bot": false,
          "headline": "feat(secrets): add aws, gcp, az, pass, and keychain sources",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4825acba6ee2c78e87590f8597ae33d123e7b94b",
          "body": "The per-file classification was an immediately-invoked closure inside the\nsync_mcps loop — a smell used only to get `?`-style error handling, and the\nmain reason the function ran ~320 lines. Extract it into a named\n`classify_mcp_file` that returns an `McpFileOutcome` (Unchanged / SecretError /\nInsta\n[…]\n.\n\nPreserves the status distinction: a malformed file is `broken` (exit 0) while\nan unresolved secret is `source_error` (exit 1), and the `--update`-only\nre-merge of secret-bearing packs is unchanged.",
          "is_bot": false,
          "headline": "refactor(sync): extract classify_mcp_file from sync_mcps",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c04932aed61c5cf849306dbef0b5c418d7c5414",
          "body": "`process_single_skill` took nine positional arguments and carried an\n`#[allow(clippy::too_many_arguments)]`. Group the five cohesive per-skill\ndescriptors (source, revision, name, path, label) into a `SkillJob` struct so\nthe installer takes a single descriptor, and drop the lint allow.",
          "is_bot": false,
          "headline": "refactor(sync): bundle per-skill install args into SkillJob",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba30d3b549119132a74f18322434de1ae1c08ff1",
          "body": "Add a prominent callout that a plain sync leaves the old secret in place, and\nrecord the review hardening (memo, rotation hint, has_secrets lock flag,\ndestination perms warning) in the module map.",
          "is_bot": false,
          "headline": "docs(secrets): flag that rotation requires --update",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b59dffbcd4f2ed0920912cfd48ca26f5cc6c84c3",
          "body": "Address findings from an architectural review of the secret-injection feature:\n\n- memoize resolution per run (SecretContext.cache, keyed on the placeholder)\n  so a repeated secret spawns op/vault/keepassxc once — no duplicate biometric\n  prompts\n- fix the misleading \"kp is not supported\" error to po\n[…]\nhen a destination settings file holding a resolved secret is\n  group/world-readable (reuses warn_if_world_readable, symmetric to credentials)\n- document the write-then-read constraint in run_cli_stdin",
          "is_bot": false,
          "headline": "feat(secrets): harden injection per design review",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c1d5f10036ade4133371ca603f55a45eea2ba7a",
          "body": "Add the KeePass section and config block to the secrets docs, plus README,\nsecurity page, landing/module references and the unknown-tag list.",
          "is_bot": false,
          "headline": "docs(secrets): document the KeePass (kp) secret source",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02dacf6456c5a6692fa4e9e8569863b7cd6f52d6",
          "body": "Add KeePass as a tagged secret source. `${kst:kp:<entry>#<attr>}` (attribute\ndefaults to `Password`) runs `keepassxc-cli show -s -a <attr> <db> <entry>`.\n\nThe database location comes from a new `secrets.keepass` config block\n(`database` + optional `key_file`); unlock supports both a key-file and a\nm\n[…]\ntdin`. With no password, stdin is closed and\n`--no-password` is passed so a prompting CLI fails fast instead of hanging.\nLike op/vault, a failing CLI hard-errors regardless of --allow-missing-secrets.",
          "is_bot": false,
          "headline": "feat(secrets): resolve ${kst:kp:…} via the KeePassXC CLI",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f7d6a0493d5f0506e66cd13b1137fc3396e40b9",
          "body": "Update README, docs site (secrets/security/configuration), landing copy,\nand the module map to the lowercase sentinel and the four explicit source\ntags (env, crd, op, vault).",
          "is_bot": false,
          "headline": "docs(secrets): lowercase ${kst_…} grammar and env/crd source tags",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96ba15b8a3cbb98413e65636c269858904cd4bdf",
          "body": "Switch the placeholder sentinel to lowercase `${kst…}` (matching the\nkasetto/kst brand) and add `env`/`crd` as explicit tags alongside\n`op`/`vault`, so a ref can pin exactly one source:\n\n  ${kst_vercel_token}        chain: env (as-written, then uppercased) -> credentials.yaml\n  ${kst:env:VERCEL_TOKE\n[…]\nesolves the conventional UPPER_CASE env var. Credential\nlookups go through case-insensitive lookup_key/descend helpers. An uppercase\n`${KST…}` is treated as a foreign var and passes through untouched.",
          "is_bot": false,
          "headline": "feat(secrets): lowercase sentinel and explicit env/crd source tags",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e357d1cfd28aab78d72ab10218ab692510bd568",
          "body": "Add an External Secret Managers section to /docs/secrets, update the security\nmodel and README Secrets subsection, and drop the \"not supported yet\" language\nnow that the tagged form resolves through the op/vault CLIs.",
          "is_bot": false,
          "headline": "docs(secrets): document op and vault external secret managers",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ea3627aed9c40c40b9bd451c5a26ef5347851dd",
          "body": "…t CLIs\n\nAdd 1Password and HashiCorp Vault as secret sources behind the tagged\nplaceholder form. ${KST:op:<vault>/<item>/<field>} (or a full op:// URI) shells\nout to `op read`; ${KST:vault:<kv-path>#<field>} shells out to\n`vault kv get -field`. Both inherit the user's existing CLI session — kasetto\n\n[…]\nrs. A failing\nCLI (missing binary, auth error, item not found) hard-fails the entry with the\nCLI's stderr; an unknown tag errors as unsupported. Resolved values are captured\nvia run_cli, never echoed.",
          "is_bot": false,
          "headline": "feat(secrets): resolve ${KST:op:…} and ${KST:vault:…} via the op/vaul…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1fd29b5690afce7f01cf9c7f582778fdf4bc8960",
          "body": "Add a dedicated /docs/secrets page, wire the secrets field into the\nconfiguration reference, reconcile the security model's overwrite and\ncredentials-file claims, note injection on the enterprise feature pillar, and\nadd a README Secrets subsection.",
          "is_bot": false,
          "headline": "docs(secrets): document ${KST_…} secret injection across README and site",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8257b9d9302bb3e21ea528165e764f68f8a0021a",
          "body": "…time\n\nResolve ${KST_<NAME>} placeholders (with __ nested keys) in MCP packs from\nenvironment variables and ~/.config/kasetto/credentials.yaml, so packs can ship\ntoken/password references without committing values.\n\nInjection is in-memory only: the lock hashes the placeholder source file, so\nsecrets\n[…]\nT:op://…} form is\nreserved and errors as unsupported.\n\nmerge_mcp_config now consumes the pre-injected mcpServers map with an overwrite\nflag (the rotation path) instead of reading the pack file itself.",
          "is_bot": false,
          "headline": "feat(secrets): inject ${KST_…} placeholders into MCP configs at sync …",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-27T21:21:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9bde2c26e4ce641c9b37079a789a83c06bd7be37",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.4.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-21T20:52:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "148429297ebc3dad97417f8b8a23ddf2b171e0b4",
          "body": "Same bug class as the MCP fix: command sync used `cleanup_dir` (the archive\nroot, with no `sub-dir` applied) as the search root on the staged-remote path,\nso a remote command source pinned to a branch/default ref with a `sub-dir`\ndiscovered commands under the repo root instead of the sub-dir. Resolve against\n`materialized.source_root`, which honors `sub-dir` for every source kind.",
          "is_bot": false,
          "headline": "fix(commands): resolve commands from source_root, not cleanup_dir",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4069bd81e83a7855c733cad3436d88cd6c4ae3cf",
          "body": "`store` propagated cache scratch-setup failures (no HOME, read-only\nXDG_CACHE_HOME) as errors, breaking an otherwise-valid sync since `ref:` sources\nroute through the cache. The cache is an optimization, so setup failures now\ndegrade to a miss (`None`), letting the caller extract into its stage dir. Split\nthe promote step into `store_promote` so genuine extraction/promotion errors\nstill surface. Add a regression test.",
          "is_bot": false,
          "headline": "fix(cache): fall back to direct extract when the cache dir is unwritable",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a78ef5bce2b89d8ee664870facdd32593e52d511",
          "body": "The MCP sync path used `cleanup_dir` as the search root, falling back to the\nliteral `src.source` string when it was `None`. Now that a `ref:`-pinned remote\nsource is served from the on-disk cache (no throwaway stage, so `cleanup_dir` is\n`None`), a tag/SHA-pinned `mcps:` source searched under `Path:\n[…]\nalized.source_root` instead — correct for local, freshly\nstaged, and cache-served sources alike (this mirrors what the instructions sync\npath already does). `cleanup_dir` stays a teardown-only handle.",
          "is_bot": false,
          "headline": "fix(mcps): resolve MCP files from source_root, not cleanup_dir",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1faea84863cf4eab4ea37b146326f2df764546b",
          "body": "Audited CLAUDE.md, README, and the site docs against the code:\n\n- CLAUDE.md: materialize_source calls remote::download_extract (the removed\n  fetch_remote wrapper is gone); load_config_any lives in config.rs; rewrite the\n  stale UI System section to the real 24-bit truecolor palette (ACCENT/ATTENTIO\n[…]\n-sub-dir (remove).\n- slash-commands.mdx: drop aider, which is not a kasetto agent preset.\n- configuration.mdx: MCP entry paths resolve relative to the source root only\n  (MCP sources have no sub-dir).",
          "is_bot": false,
          "headline": "docs: correct inaccuracies found in a full docs audit",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a00526c5129d1163c6c898d1c04bf329fbf48d4",
          "body": "Update CLAUDE.md (source/ + fsops/ module notes, sync data flow) for the\nimmutable-ref source cache, streaming + sparse tarball extraction, and rayon\nparallel skill-source materialization. Document the KASETTO_NO_CACHE opt-out in\nthe site configuration reference.",
          "is_bot": false,
          "headline": "docs: document source cache, sparse extraction, parallel fetch",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9333653f228e1bb1a17bd8c2ca61401f7dd206fb",
          "body": "Stream the HTTP response straight into the gzip decoder instead of buffering the\nwhole archive in memory, and sparse-extract only entries under sub-dir, skipping\nthe create/write/chmod syscalls for the rest of a monorepo.",
          "is_bot": false,
          "headline": "perf: sparse-extract sub-dir sources and stream archive bodies",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "060eebc0392f59b36cbb453ba95c277593110278",
          "body": "Add scripts/bench-sync.sh (a hyperfine harness for cold sync) and a just recipe\nto drive it.",
          "is_bot": false,
          "headline": "bench: add hyperfine cold-sync benchmark",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2e45a35fa4c19f214476bfcd23883dac7b47940",
          "body": "Split skill sync into three phases: plan each source locally (locked\nsatisfiability, needs_fetch), materialize every fetch-bound source in parallel\nvia rayon (downloads/extractions are independent; the source cache serializes\nsame-key races), then process results sequentially in config order so outp\n[…]\n and last-writer-wins destination semantics stay deterministic.\n\nAlso fixes a latent unchanged check that only inspected destinations[0]: it now\nverifies every destination via dest_status().all_match.",
          "is_bot": false,
          "headline": "perf: download source archives in parallel during skill sync",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1a0e67a6c20d7e9eb16eccb20d330f3e8d4007f",
          "body": "Cache extracted source trees under $XDG_CACHE_HOME/kasetto/sources/<hash>/tree/\nwith a sibling .complete marker (atomic extract-to-tmp then rename). Immutable\nrefs reuse the cached tree with zero revalidation, so repeat cold syncs skip\nthe download + extract entirely. Opt out with KASETTO_NO_CACHE.",
          "is_bot": false,
          "headline": "perf: cache extracted source trees for immutable refs",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T20:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6389d41aaefe446bed3b62961773576c79b2899f",
          "body": "Add X-Content-Type-Options, X-Frame-Options, Referrer-Policy and\nPermissions-Policy to all routes via next.config.mjs headers(), matching\nthe pivoshenko brand sites. Wire @vercel/analytics + @vercel/speed-insights\nin the root layout.",
          "is_bot": false,
          "headline": "feat(site): add security headers, Analytics and Speed Insights",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-21T17:49:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea375303a811fa57aea00d751233ba8f11d8c13d",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.3.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-18T20:18:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1f85a90e12a92347186a866b0cabb29ac0a5b3b",
          "body": "…e extension names\n\nAddress three P2 review findings in the instructions sync path:\n\n- Discovery now uses materialized.source_root instead of\n  cleanup_dir.unwrap_or(source_root); for a remote source with sub-dir,\n  cleanup_dir is the archive root, so the configured sub-dir was ignored\n  and instruc\n[…]\nction_names strips an explicit .md/.mdc extension from\n  object entries, matching resolve_instruction_entry's stored name, so\n  the lock lookup no longer misses and forces refetches / --locked errors.",
          "is_bot": false,
          "headline": "fix(instructions): honor sub-dir, prune targetless reconfig, normaliz…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:18:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a46f1e68807e08d77b391e3d33a9bcd28a511cc",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.3.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-18T20:08:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2611bba2a429b91ad7bec19200d18c755e6e2b28",
          "body": "The 32-char instruction:multi-agent-dispatch slug overflowed the status\ngutter, breaking column alignment in both demos.\n\n- demo.svg: re-pad all sync rows so every status word starts at column 34\n- globals.css: hero terminal .t-row grid slug column minmax(24ch -> 34ch) so\n  status tails align across rows (no row exceeds the widest existing line)",
          "is_bot": false,
          "headline": "fix(site): align demo status column for longer instruction slugs",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4b2ab200bd7a9efe042f6f96867033483926e83",
          "body": "Instructions were under-documented after the rules->instructions rename:\nseveral surfaces still described three asset kinds (skills, commands, MCPs).\n\n- landing cards: \"SKILLS, COMMANDS & MCPS\" -> \"... & INSTRUCTIONS\", four kinds\n- commands/sync-flow/auth/configuration/cookbook docs: add/remove/list\n[…]\n README list/clean copy includes instructions\n- example config sources instructions from github.com/pivoshenko/pivoshenko.ai\n  (docs-autoupdate, multi-agent-dispatch); regenerated via just sync-config",
          "is_bot": false,
          "headline": "docs: document instructions as a first-class asset kind",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84f417b7f5cc45b64de36af70438d262f2cb084c",
          "body": "Add two instruction rows (instruction:docs-autoupdate and\ninstruction:multi-agent-dispatch) to the github.com/pivoshenko/pivoshenko.ai\nsource group in the animated README demo.svg and the site hero terminal,\nmarked \"added\" so the new instructions asset kind is visible in the sync\ndemo. Grow the SVG canvas and retime the reveal cascade for the two new\nrows; bump the demo.svg cache-buster to v6.",
          "is_bot": false,
          "headline": "docs: showcase instructions in readme demo and hero terminal",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4561e80113d54e8967775933ded10029ff9f9a7d",
          "body": "Rename the fourth asset kind from \"rules\" to \"instructions\" across the\nRust crate (types, modules, config key, lock kind), the example config,\nand all prose. Each agent's native destination is unchanged: instructions\nstill write to CLAUDE.md / .cursor/rules / AGENTS.md, etc.\n\n- src/rules -> src/inst\n[…]\n -> Instruction*\n- config key `rules:` -> `instructions:`; lock kind -> \"instructions\"\n- source discovery dir rules/ -> instructions/\n- README, docs site, example yaml, CLAUDE.md, CONTRIBUTING updated",
          "is_bot": false,
          "headline": "refactor: rename rules asset kind to instructions",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a068621ffe83e53a00bc3b4dc94656ec3556f29",
          "body": "Add a fourth asset type — rules — that syncs agent instruction files\n(CLAUDE.md, .cursor/rules/*.mdc, AGENTS.md, GEMINI.md, …) from a source's\nrules/ directory into each agent's native location.\n\n- model: RuleSourceSpec/RulesField/RuleEntry config, RuleFormat/RuleTarget,\n  per-agent rules_project_pa\n[…]\nsets with agg:/file: destination tokens\n- wire add/remove/list/doctor/clean/lock + CLI --rule flag and --type rules\n- docs: README, configuration.mdx, agents.mdx (full per-agent path table), CLAUDE.md",
          "is_bot": false,
          "headline": "feat(rules): distribute agent rules across all agents",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T20:06:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3fcb3283511deb2ee8f77d6f8b2f40ac51837a54",
          "body": null,
          "is_bot": false,
          "headline": "fix(site): override js-yaml and dompurify to patch transitive vulns",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T13:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18b93a8f1876a1611c8b15f264783dc6b84f81ae",
          "body": null,
          "is_bot": false,
          "headline": "docs: use brew tap/trust/install for Homebrew instructions",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-18T12:45:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec01ccaffad67e5fc57987f441a610682bac6290",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.2.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-12T17:04:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3d0aaf2d23588e02b77af78b579b38d68926a30",
          "body": "needs_fetch, the repair-source lookup, and the process step each\nre-walked and re-SHA256ed the same destination dirs — up to three\nfull tree hashes per skill per sync, multiplied across agent\ndestinations. A per-run HashCache memoizes per-destination hashes\nand a single dest_status pass derives both\n[…]\ny failure cannot leave a stale verdict. Sharing\none snapshot between needs_fetch and the process step also closes\nthe TOCTOU where the repair-copy guarantee could break between\nthe two hashing passes.",
          "is_bot": false,
          "headline": "perf(sync): hash each skill destination once per run",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "037b1c066166ecd6e80b54504152e7bd98a7fe6e",
          "body": "The buffered read/write loop created destination files with\ndefault permissions, so executable scripts inside skills lost\ntheir +x bit on install. fs::copy preserves permissions and uses\nkernel-level copy where available (clonefile on APFS). On Windows\nthe READONLY attribute is cleared after the copy, since a\npropagated read-only flag would make the next sync's\nremove_dir_all fail with PermissionDenied.\n\nRead-only source files now install read-only on Unix, matching\ncp/cargo/uv semantics.",
          "is_bot": false,
          "headline": "fix(fsops): preserve file permissions in copy_file",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "acd4226f0e7b2e3bb3418f7607ae7f69931607b6",
          "body": "Apply the clippy perf lint set (redundant_clone,\nneedless_pass_by_value, needless_collect) plus adjacent idiom\ncleanups: merge_yaml consumes its inputs instead of cloning both\nmaps per extends level, remove_stale borrows the tracked-asset\nlist instead of cloning it into a second map, join_lines takes a\nslice, and string keys and paths stop round-tripping through\nowned Strings. Behavior is unchanged throughout.",
          "is_bot": false,
          "headline": "perf: drop redundant clones and allocations",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04ecc289ded5057ecd7ac2c36b2afc47dabb9099",
          "body": "The `<source>::<name>` lock key was hand-built with format! in\nfive places; one helper keeps the key format from drifting\nbetween the lock writer and the lookup sites.",
          "is_bot": false,
          "headline": "refactor(sync): add skill_key helper for lock keys",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3c9bd858b3c372cec879d2886fdcefa16cbbf4a",
          "body": "The function returns unix seconds as a string; the name promised\nISO 8601 it never delivered. Output format is unchanged.",
          "is_bot": false,
          "headline": "refactor(fsops): rename now_iso to now_unix_str",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69211a91ee2cdf2e3bdbf71da0826f6ba3d5fb40",
          "body": "write_cache swallowed serde_json failures via unwrap_or_default\nand silently wrote an empty cache file. Surface the error to the\ncaller instead; the background refresh thread already treats the\nwrite as best-effort.",
          "is_bot": false,
          "headline": "fix(update-notifier): propagate cache serialization errors",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0e60643f2dd026c043321e8f29f39044d6c1cae",
          "body": "String env values are handled by the arm above, and Display\noutput for numbers, bools, and null is never quote-wrapped, so\nthe trim_matches('\"') could not fire. Render via Display alone.",
          "is_bot": false,
          "headline": "refactor(mcps): drop dead quote-trim on codex env values",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cb35d155043ec1a3d4eade9283858a6331d3337",
          "body": "Wildcard targets were pushed in HashMap iteration order, so\ninstall order, spinner labels, and --json output shuffled\nbetween runs. Sort the selection so output is reproducible,\nconsistent with the deterministic lock.",
          "is_bot": false,
          "headline": "fix(fsops): make wildcard skill selection deterministic",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1240a69d07d3f0280410a1b05a2553302c3502c4",
          "body": "resolve_path replaced every `~` in the string with the home\ndirectory, so a path like `./backup~old/skills` had home spliced\ninto its middle. Only a leading `~/` (or a bare `~`) is a home\nprefix; a tilde elsewhere is an ordinary path character.",
          "is_bot": false,
          "headline": "fix(fsops): expand only a leading tilde in resolve_path",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1774f8e9a17e9507295a55331a208b66797abb34",
          "body": "Parallel test threads can observe the same nanosecond, so the\npid+nanos nonce used by the per-module temp_dir helpers let\nconcurrent tests share a scratch dir and corrupt each other's\nhash expectations (~2 in 5 full-suite runs failed). Add a\nprocess-wide atomic counter to the nonce of the existing fsops\nhelper and drop the 11 duplicated copies in favor of it.",
          "is_bot": false,
          "headline": "test: share one race-free temp_dir helper across modules",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-12T17:04:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a4cea5db410ac4238d8f8490197d10028c4a4cc",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh CLAUDE.md for current justfile + CI shape",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T13:08:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73c389444b202ea24ae21c76517bfe0b4be72266",
          "body": null,
          "is_bot": false,
          "headline": "ci: fix action versions and test recipe failures",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T11:15:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f39dc6564b46a4fa39d55b51d6b4f631bbd526d",
          "body": null,
          "is_bot": false,
          "headline": "ci: drop hashFiles guard; move .no-tests sentinel handling into justfile",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T11:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a9104c85d471f33d18cc871b461b2fd37ced3e2",
          "body": null,
          "is_bot": false,
          "headline": "ci: flatten to one job per language",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T11:02:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6a5e55882fa98ca32584192cd6db289c29c3ad5",
          "body": null,
          "is_bot": false,
          "headline": "ci: bump action versions to latest major",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T10:59:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6366cc0cdf51ea6e7f30dc52b3bc00bf719cddb9",
          "body": "…-24.04-arm",
          "is_bot": false,
          "headline": "ci: standardize workflow to per-language parallel pipelines on ubuntu…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-07T10:56:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e02b3f9a4a4c3affbba8f844c67703fae259387e",
          "body": null,
          "is_bot": true,
          "headline": "release: v3.1.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-04T09:59:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec8b5419482d17b4400f941481877c49f714cbed",
          "body": "`kasetto add <deep-URL>` writes source + ref/branch + sub-dir, but\n`remove` was discarding the derived ref/branch/sub-dir and matching\non the bare source alone. In a config with multiple entries from the\nsame repo (different sub-dirs or refs), `remove` either errored as\nambiguous or could only targe\n[…]\nTODO;\n  proper fix is a host branches-API probe.\n\nThree new tests cover sub-dir disambiguation, the ambiguity error\nwhen sub-dir is omitted, and matching entries without a sub-dir via\nan empty filter.",
          "is_bot": false,
          "headline": "fix(commands): match remove by sub-dir from deep browse URLs",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b50ad7f744511babc60c3a79ef585b1c5ae73f7a",
          "body": "…emo screens\n\n- add: reject `--locked` without `--no-sync` up front (cargo-style \"lock\n  would need updating but --locked was passed\"). A brand-new source has\n  no lock entry yet, so the implicit sync would fail mid-flight after\n  the manifest edit; the error now points at the two valid workflows\n- \n[…]\n assets/demo.svg: fade the scene-2 add lines at 8.06s → 8.32s (just\n  before remove appears at 8.50s) and reposition remove lines back to\n  the top of the terminal; comment updated to reflect 3 scenes",
          "is_bot": false,
          "headline": "feat(commands): guard add --locked + split add/remove into separate d…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d4ce5fe672e78ba08ccbf252b533d3143d6cfe6",
          "body": "- add/remove: <source>@<ref> shorthand, --dry-run, --locked, --json,\n  -qq count plumbing, `tip:` hint after --no-sync; verb tense corrected\n  to present continuous (Adding/Removing) so the sync summary's past\n  tense (Installed N items) closes the rhythm\n- lock: --check (aliases --locked/--frozen) \n[…]\n per the cross-surface sync rule, including a new cookbook recipe for\n  cargo/uv-style editing and one for lock --check / --upgrade-package\n- justfile: drop the now-unused demo-vhs / demo-fish recipes",
          "is_bot": false,
          "headline": "feat(commands): cargo/uv-style flags on add/remove/lock + two-scene demo",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c03a1bfa2abf903905979d9be698866fc9c7cb82",
          "body": "Add three config-editing subcommands inspired by cargo/uv:\n\n- `add <source>`: append a source to the local kasetto.yaml (comments\n  preserved via line-surgical edits, never a serde round-trip) and sync\n  it in. Kind-tagged repeatable flags --skill/--mcp/--command name entries\n  and can touch several\n[…]\n CLI style\n(terse name-only-colored edit confirmations, green Locked summary verb,\ncolor gated on color_stdout_enabled).\n\nDocs updated across README, the docs site commands/index pages, and\nCLAUDE.md.",
          "is_bot": false,
          "headline": "feat(commands): add cargo/uv-style add, remove, and lock subcommands",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-04T09:56:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b1ffd2d4e142f93f0fc76dab4e2c4aa3d57b00d",
          "body": null,
          "is_bot": false,
          "headline": "docs(assets): tighten social preview centering",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T19:04:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea3a6327c72fd7adf9893837b8853f8cc8ae27c5",
          "body": null,
          "is_bot": false,
          "headline": "docs(assets): drop terminal chrome from social preview, center wordmark",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T19:00:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a692c4d11d1cd9ab0b6dd0aa417eeb902a5f374b",
          "body": "… mono",
          "is_bot": false,
          "headline": "docs(assets): restore ascii wordmark in social preview, use jetbrains…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:58:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73bb54df5261439cbc5ca190a3932f98b0d1b782",
          "body": null,
          "is_bot": false,
          "headline": "docs(assets): redesign social preview with clean wordmark",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:55:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6263e9df965f165f585d15ae7ff597d5ddc0093",
          "body": "…mo svg",
          "is_bot": false,
          "headline": "docs(readme): color inline status words (updated/added/removed) in de…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:55:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46878cf16b0a5806e1e655e1791d7ff2201c1605",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): bust camo cache for demo svg",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a420107b778a3917a7bc03df2e505729d04e9277",
          "body": null,
          "is_bot": false,
          "headline": "revert(readme): drop two-column demo layout, restore single column",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:48:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfd752e238c3e36ab8466ef00900bb2cab3bc4bf",
          "body": "… display",
          "is_bot": false,
          "headline": "docs(readme): reflow demo svg into two columns for shorter full-width…",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:32:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bf59f2f376e5e65a5d8be73a359e04e4899a4ff",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): scale demo svg to 50% width, centered",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:28:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a30974d84423bb60c34dd4ff6b8ae4dd218cb669",
          "body": null,
          "is_bot": false,
          "headline": "ci: rename Deploy Site workflow to Site",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:27:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cde41936f823481afde0edaef5b4f77bf86d8968",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): shrink demo svg further (376h, 12px font, 11px rows)",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:27:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c8e4213b7528609a4bbddfeb1f005f317960c6d",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): compress demo svg vertically, restore full width",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:24:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c665c03b59207ef38a247e722ad6b5b1f90cd2f",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): shrink demo svg to 720px and center",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T18:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "995b8bcfd57bf4419119601225be1f633c8a50f1",
          "body": "Promotes the bold \"About the name\" to a heading-style line on its own\nand updates the body to cover all three asset kinds (skills, MCPs,\ncommands) instead of just two.",
          "is_bot": false,
          "headline": "docs(readme): split about-the-name into its own paragraph",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67df306a1ff87eeb2f923b607b935b15390fc2f2",
          "body": "The five overlapping spinner frames read as a glitch under GitHub's\nrendering, so revert to the simpler prompt → Resolved transition.\n\nMove the etymology line under the mock and label it \"About the name\"\nso it reads as a footnote rather than the lead paragraph.",
          "is_bot": false,
          "headline": "docs(readme): drop resolving spinner, move name blurb below demo",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2824c83bfabcb84ee48bf4055eefa5517645f53e",
          "body": "Drop per-line spacing from 18 → 14 px and tighten the section gaps so\nthe 1:0.97 square aspect ratio becomes 1:0.78. At width=100% on\nGitHub's README column the terminal is now ~20% shorter without\nlosing readability or any rows.",
          "is_bot": false,
          "headline": "docs(readme): compress demo svg vertically",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0367314d9fb9c4cae430402c4e6514a3ec7a2266",
          "body": "- New phase between the prompt and the Resolved line: five braille\n  spinner frames (⠋⠙⠹⠸⠼) cycle for ~600 ms next to \"Resolving sources\"\n  before the ✓ Resolved line lands, matching the site's resolve state.\n- Rename sync-demo.svg → demo.svg now that it's the only README mock.\n- Drop the centering wrapper and set img width=\"100%\" so the terminal\n  spans the README column instead of sitting at 580 px.\n- viewBox tightened to 580×560 (was 580×580) to drop unused padding.",
          "is_bot": false,
          "headline": "docs(readme): add resolving spinner, rename to demo.svg, span full width",
          "author_name": "pivoshenko",
          "author_login": "pivoshenko",
          "committed_at": "2026-06-01T11:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 30,
      "commits_last_year": 409,
      "latest_release_at": "2026-07-17T13:03:55Z",
      "latest_release_tag": "v3.6.0",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 17,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 6.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "kasetto",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "cursor",
            "claude-code",
            "codex",
            "skills",
            "mcps"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/kasetto",
          "is_deprecated": false,
          "latest_version": "3.6.0",
          "repository_url": "https://github.com/pivoshenko/kasetto",
          "versions_count": 29,
          "total_downloads": 485,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 128,
          "first_published_at": "2026-03-19T07:53:56.660116Z",
          "latest_published_at": "2026-07-17T13:04:42.620240Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 7,
      "stars": 117,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-21",
            "count": 2
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 2
          }
        ],
        "complete": true,
        "collected": 7,
        "total_forks": 7
      },
      "star_history": null,
      "open_issues_and_prs": 3
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "site/tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml"
      ],
      "largest_source_bytes": 41394,
      "source_files_sampled": 85,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 23446
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "site/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "clap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "clap_complete",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "flate2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "mimalloc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "rayon",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_yaml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "shlex",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tar",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "toml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "unicode-width",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "@vercel/analytics",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "@vercel/speed-insights",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.1"
        },
        {
          "name": "fumadocs-core",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.7.7"
        },
        {
          "name": "fumadocs-mdx",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.10.1"
        },
        {
          "name": "fumadocs-ui",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^14.7.7"
        },
        {
          "name": "mermaid",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.16.0"
        },
        {
          "name": "next",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.5.20"
        },
        {
          "name": "react",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-dom",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-icons",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.7.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 25,
        "open_issues": 2,
        "closed_ratio": 0.833,
        "closed_issues": 10,
        "closed_unmerged_prs": 13
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "pivoshenko",
          "commits": 367,
          "avatar_url": "https://avatars.githubusercontent.com/u/40499728?v=4"
        },
        {
          "type": "User",
          "login": "aaronflorey",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/948073?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.973
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "ci.yaml",
        "labels.yaml",
        "release.yaml",
        "site.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/13 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "b4cc4d023685478eed1e1b89c185e672bf93658c",
        "ran_at": "2026-07-24T02:33:44Z",
        "aggregate_score": 4.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T13:36:33Z",
      "oldest_open_prs": [
        {
          "number": 51,
          "created_at": "2026-07-21T02:02:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-17T13:14:57Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 48,
          "created_at": "2026-07-19T15:24:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 49,
          "created_at": "2026-07-19T15:32:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/pivoshenko/kasetto",
    "host": "github.com",
    "name": "kasetto",
    "owner": "pivoshenko"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 49,
        "vitality": 82,
        "community": 55,
        "governance": 55,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 82,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "commits_last_year": 409,
              "human_commit_share": 0.93,
              "days_since_last_push": 5,
              "active_weeks_last_year": 17
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "17/52 weeks with commits",
                "points": 11.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 17
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "409 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 409
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 30,
              "latest_release_tag": "v3.6.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 6.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "30 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~6.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 6.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "forks": 7,
              "stars": 117,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "117 stars",
                "points": 33.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 117
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "7 forks",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "packages": [
                "kasetto"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 485,
              "monthly_downloads": 128
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "128 downloads/month across crates",
                "points": 28.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 128,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.973
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 97% of commits",
                "points": 0.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 25,
              "open_issues": 2,
              "closed_issues": 10,
              "issue_closed_ratio": 0.833,
              "closed_unmerged_prs": 13
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "83% of issues closed",
                "points": 38.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 83
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "25/38 decided PRs merged",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 25,
                      "decided": 38
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "followers": 49,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "pivoshenko",
              "public_repos": 25,
              "account_age_days": 2953
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "49 followers of pivoshenko",
                "points": 12.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 49,
                      "login": "pivoshenko"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "25 public repos, account ~8 yr old",
                "points": 22.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 25
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 8
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "kasetto"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "29 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "ai",
                "skills",
                "claude-code",
                "copilot",
                "cursor",
                "mcp",
                "codex",
                "openclaw",
                "opencode",
                "mcps",
                "ai-agent",
                "ai-skills-manager",
                "antigravity",
                "claude",
                "claude-skills",
                "developer-tool",
                "gemini",
                "kiro",
                "pi",
                "ai-commands"
              ],
              "has_wiki": false,
              "homepage": "https://www.kasetto.dev",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.kasetto.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 4.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 71,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 23446
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "93 of 93 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 93,
                      "sampled": 93
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [
                "Cargo.lock",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "site/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "site/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "site/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 41394,
              "source_files_sampled": 85,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/85 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 85,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T02:33:57.752187Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/pivoshenko/kasetto.svg",
  "full_name": "pivoshenko/kasetto",
  "license_state": "custom",
  "license_spdx": null
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikencrates.io.