Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-27 03:49 UTC

quantakrypto / pqc-tools

Open-source post-quantum readiness tooling by quantakrypto

TypeScriptApache-2.0★ 9 Sterne⑂ 0 Forksseit Juni 2026Auf GitHub ansehen ↗

quantakrypto/pqc-tools erreicht einen Gesundheitsindex von 67 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Engineering Quality (90/100) ab, am schwächsten bei Sustainability & Governance (43/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

67
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

67
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

@QuantaKryptoOrganisation
1 Follower4 öffentliche Reposseit Juni 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
npm@quantakrypto/mcp0.5.22.08713vor 4 Tagen
npm@quantakrypto/core0.5.02.04111vor 6 Tagen
npm@quantakrypto/agent0.5.07256vor 6 Tagen
npm@quantakrypto/qscan0.5.01.59711vor 6 Tagen
npm@quantakrypto/sieve0.5.01.71411vor 6 Tagen
npm@quantakrypto/qprobe0.5.03122vor 6 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

75Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
4.2/36Commit-Rhythmus — 6/52 Wochen mit Commits
18/18Commit-Volumen — 254 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year254
human_commit_share0,98
days_since_last_push0
active_weeks_last_year6

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 4 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 3 Tagen
27/27Release-Rhythmus — ein Release etwa alle 2,5 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count4
latest_release_tagv1
releases_from_tagsnein
days_since_latest_release3
mean_days_between_releases2,5
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

55Mittel · 18 % des Gesamtindex
Wie die Bewertung erfolgt
14.6/60Stars — 9 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars9
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (Apache-2.0)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templateja
Wie die Bewertung erfolgt
52.4/80Downloads pro Monat — 8.476 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packages@quantakrypto/mcp, @quantakrypto/core, @quantakrypto/agent, @quantakrypto/qscan, @quantakrypto/sieve, @quantakrypto/qprobe
dependents
ecosystemsnpm
total_downloads
monthly_downloads8.476
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

43Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
21/38.3PR-Annahme — 17/31 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/25 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs17
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs14
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
2.2/25Reichweite des Inhabers — 1 Follower von quantakrypto
5.3/25Kontohistorie — 4 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers1
owner_typeOrganization
is_verified
owner_loginquantakrypto
public_repos4
account_age_days34

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 6 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 4 Tagen
20/20Versionshistorie — 13 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packages@quantakrypto/mcp, @quantakrypto/core, @quantakrypto/agent, @quantakrypto/qscan, @quantakrypto/sieve, @quantakrypto/qprobe
ecosystemsnpm
any_deprecatednein
min_days_since_publish4

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

90Exzellent · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 7 Workflow(s)
24/24Tests vorhanden
16/16Linter-Konfiguration — eslint.config.js
0/9.6Pre-Commit-Hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfigja
has_linter_configja
has_precommit_confignein

Dokumentation

90Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://quantakrypto.com/tools
10/10Repository-Beschreibung
10/10Topics — 20 Topics
0/10Wiki
Verwendete Eingangsdaten
topicscrypto-agility, cryptography, harvest-now-decrypt-later, infosec, post-quantum, pqc, pqc-migration, pqc-readiness, pqcrypto, q-day, quantum, quantum-readiness, security-training, encryption-strategy, pqc-certification, cbom, mcp, post-quantum-cryptography, sbom, nist
has_wikinein
homepagehttps://quantakrypto.com/tools
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

77Gut · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — keine Daten
2.5/2.5CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
1.2/2.5CII-Best-Practices — badge detected: Passing
0/7.5Code-Review — Found 0/25 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
4.5/5SAST — SAST tool detected but not run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 52 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate7,1
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection, signed_releases. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages2
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:@quantakrypto/mcp@0.5.2 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 2 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

70Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 90 von 98 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,918
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
12.6/18Bootstrap mit einem Befehl — packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (Toolchain-Konvention, kein Task-Runner)
22/22Automatisierte Tests
11/11Lint-/Format-Konfiguration — eslint.config.js
11/11Statische Typprüfung — packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
8/8Automatisierte Wartung — 2 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfileja
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_configja
typecheck_configspackages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifestspackages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml, packages/core/test/benchmark/recall/rust/Cargo.toml
dependency_bot_commit_share0,02
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/454 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes59.062
source_files_sampled454
oversized_source_files0
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
20/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalja
api_schema_files

Eckdaten

9GitHub-Sterne
1Mitwirkende
254Commits, letzte 12 Monate
0Tage seit letztem Push
4Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Weitere Details

OpenSSF Scorecard 7.1 / 10
7.1Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-27 03:49 UTC

10Binary-Artifactsno binaries found in the repo
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests13 out of 13 merged PRs checked by a CI test -- score normalized to 10
5CII-Best-Practicesbadge detected: Passing
0Code-ReviewFound 0/25 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
9SASTSAST tool detected but not run on all commits
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities52 existing vulnerabilities detected
Direkte Abhängigkeiten 9
RegistryPaketVersionsvorgabeManifest
npm@quantakrypto/core0.5.0packages/action/package.json
npm@quantakrypto/qscan0.5.0packages/action/package.json
npm@quantakrypto/core0.5.0packages/agent/package.json
npm@quantakrypto/core0.5.0packages/mcp/package.json
npm@quantakrypto/qprobe0.5.0packages/mcp/package.json
npm@quantakrypto/core0.5.0packages/qprobe/package.json
npm@quantakrypto/agent0.5.0packages/qscan/package.json
npm@quantakrypto/core0.5.0packages/qscan/package.json
npm@noble/post-quantum^0.4.0validation/sieve-real-sut/package.json
Alle Abhängigkeiten 214

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 6 direkte und 208 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
npm@noble/post-quantum0.4.1direkt
npm@noble/post-quantum0.6.1direkt
npm@quantakrypto/agent0.5.0direkt
npm@quantakrypto/core0.5.0direkt
npm@quantakrypto/qprobe0.5.0direkt
npm@quantakrypto/qscan0.5.0direkt
crates.ioanyhowindirekt
crates.ioed25519-dalekindirekt
crates.iohexindirekt
crates.ioopensslindirekt
crates.iorsaindirekt
crates.ioserdeindirekt
crates.ioserde_jsonindirekt
crates.iotokioindirekt
crates.iotracingindirekt
crates.iox25519-dalekindirekt
Gogithub.com/cloudflare/circlv1.3.9indirekt
Gogithub.com/decred/dcrd/dcrec/secp256k1/v4v4.3.0indirekt
Gogithub.com/golang-jwt/jwt/v5v5.2.1indirekt
Gogolang.org/x/cryptov0.24.0indirekt
Gogolang.org/x/sysv0.21.0indirekt
Gogolang.org/x/termv0.21.0indirekt
Mavencom.fasterxml.jackson.core:jackson-databind2.17.1indirekt
Mavenio.jsonwebtoken:jjwt-api0.11.5indirekt
Mavenorg.bouncycastle:bcpkix-jdk18on1.78.1indirekt
Mavenorg.bouncycastle:bcprov-jdk18on1.78.1indirekt
npm@esbuild/aix-ppc640.28.1indirekt
npm@esbuild/android-arm0.28.1indirekt
npm@esbuild/android-arm640.28.1indirekt
npm@esbuild/android-x640.28.1indirekt
npm@esbuild/darwin-arm640.28.1indirekt
npm@esbuild/darwin-x640.28.1indirekt
npm@esbuild/freebsd-arm640.28.1indirekt
npm@esbuild/freebsd-x640.28.1indirekt
npm@esbuild/linux-arm0.28.1indirekt
npm@esbuild/linux-arm640.28.1indirekt
npm@esbuild/linux-ia320.28.1indirekt
npm@esbuild/linux-loong640.28.1indirekt
npm@esbuild/linux-mips64el0.28.1indirekt
npm@esbuild/linux-ppc640.28.1indirekt
npm@esbuild/linux-riscv640.28.1indirekt
npm@esbuild/linux-s390x0.28.1indirekt
npm@esbuild/linux-x640.28.1indirekt
npm@esbuild/netbsd-arm640.28.1indirekt
npm@esbuild/netbsd-x640.28.1indirekt
npm@esbuild/openbsd-arm640.28.1indirekt
npm@esbuild/openbsd-x640.28.1indirekt
npm@esbuild/openharmony-arm640.28.1indirekt
npm@esbuild/sunos-x640.28.1indirekt
npm@esbuild/win32-arm640.28.1indirekt
npm@esbuild/win32-ia320.28.1indirekt
npm@esbuild/win32-x640.28.1indirekt
npm@eslint-community/eslint-utils4.9.1indirekt
npm@eslint-community/regexpp4.12.2indirekt
npm@eslint/config-array0.21.2indirekt
npm@eslint/config-helpers0.4.2indirekt
npm@eslint/core0.17.0indirekt
npm@eslint/eslintrc3.3.5indirekt
npm@eslint/js9.39.4indirekt
npm@eslint/object-schema2.1.7indirekt
npm@eslint/plugin-kit0.4.1indirekt
npm@humanfs/core0.19.2indirekt
npm@humanfs/node0.16.8indirekt
npm@humanfs/types0.15.0indirekt
npm@humanwhocodes/module-importer1.0.1indirekt
npm@humanwhocodes/retry0.4.3indirekt
npm@noble/ciphers2.2.0indirekt
npm@noble/curves2.2.0indirekt
npm@noble/hashes1.8.0indirekt
npm@noble/hashes2.2.0indirekt
npm@quantakrypto/action0.5.0indirekt
npm@quantakrypto/mcp0.5.2indirekt
npm@quantakrypto/observatory0.0.0indirekt
npm@quantakrypto/sieve0.5.0indirekt
npm@types/estree1.0.9indirekt
npm@types/json-schema7.0.15indirekt
npm@types/node26.1.1indirekt
npm@types/node^20.12.0indirekt
npm@typescript-eslint/eslint-plugin8.61.0indirekt
npm@typescript-eslint/parser8.61.0indirekt
npm@typescript-eslint/project-service8.61.0indirekt
npm@typescript-eslint/scope-manager8.61.0indirekt
npm@typescript-eslint/tsconfig-utils8.61.0indirekt
npm@typescript-eslint/type-utils8.61.0indirekt
npm@typescript-eslint/types8.61.0indirekt
npm@typescript-eslint/typescript-estree8.61.0indirekt
npm@typescript-eslint/utils8.61.0indirekt
npm@typescript-eslint/visitor-keys8.61.0indirekt
npmacorn8.16.0indirekt
npmacorn-jsx5.3.2indirekt
npmajv6.15.0indirekt
npmansi-styles4.3.0indirekt
npmargparse2.0.1indirekt
npmbalanced-match1.0.2indirekt
npmbalanced-match4.0.4indirekt
npmbrace-expansion1.1.16indirekt
npmbrace-expansion5.0.7indirekt
npmcallsites3.1.0indirekt
npmchalk4.1.2indirekt
npmcolor-convert2.0.1indirekt
npmcolor-name1.1.4indirekt
npmconcat-map0.0.1indirekt
npmcross-spawn7.0.6indirekt
npmdebug4.4.3indirekt
npmdeep-is0.1.4indirekt
npmelliptic^6.5.4indirekt
npmelliptic^6.5.5indirekt
npmesbuild0.28.1indirekt
npmescape-string-regexp4.0.0indirekt
npmeslint9.39.4indirekt
npmeslint-scope8.4.0indirekt
npmeslint-visitor-keys3.4.3indirekt
npmeslint-visitor-keys4.2.1indirekt
npmeslint-visitor-keys5.0.1indirekt
npmespree10.4.0indirekt
npmesquery1.7.0indirekt
npmesrecurse4.3.0indirekt
npmestraverse5.3.0indirekt
npmesutils2.0.3indirekt
npmexpress^4.18.0indirekt
npmexpress^4.19.2indirekt
npmfast-check4.9.0indirekt
npmfast-deep-equal3.1.3indirekt
npmfast-json-stable-stringify2.1.0indirekt
npmfast-levenshtein2.0.6indirekt
npmfdir6.5.0indirekt
npmfile-entry-cache8.0.0indirekt
npmfind-up5.0.0indirekt
npmflat-cache4.0.1indirekt
npmflatted3.4.2indirekt
npmfsevents2.3.3indirekt
npmglob-parent6.0.2indirekt
npmglobals14.0.0indirekt
npmhas-flag4.0.0indirekt
npmignore5.3.2indirekt
npmignore7.0.5indirekt
npmimport-fresh3.3.1indirekt
npmimurmurhash0.1.4indirekt
npmis-extglob2.1.1indirekt
npmis-glob4.0.3indirekt
npmisexe2.0.0indirekt
npmjs-yaml4.3.0indirekt
npmjson-buffer3.0.1indirekt
npmjson-schema-traverse0.4.1indirekt
npmjson-stable-stringify-without-jsonify1.0.1indirekt
npmjsonwebtoken^9.0.0indirekt
npmjsonwebtoken^9.0.2indirekt
npmkeyv4.5.4indirekt
npmlevn0.4.1indirekt
npmlocate-path6.0.0indirekt
npmlodash^4.17.21indirekt
npmlodash.merge4.6.2indirekt
npmminimatch10.2.5indirekt
npmminimatch3.1.5indirekt
npmms2.1.3indirekt
npmnatural-compare1.4.0indirekt
npmnode-forge^1.3.1indirekt
npmoptionator0.9.4indirekt
npmp-limit3.1.0indirekt
npmp-locate5.0.0indirekt
npmparent-module1.0.1indirekt
npmpath-exists4.0.0indirekt
npmpath-key3.1.1indirekt
npmpicomatch4.0.4indirekt
npmpino^9.2.0indirekt
npmprelude-ls1.2.1indirekt
npmprettier3.8.3indirekt
npmpunycode2.3.1indirekt
npmpure-rand8.4.2indirekt
npmresolve-from4.0.0indirekt
npmsemver7.8.3indirekt
npmshebang-command2.0.0indirekt
npmshebang-regex3.0.0indirekt
npmstrip-json-comments3.1.1indirekt
npmsupports-color7.2.0indirekt
npmtinyglobby0.2.17indirekt
npmts-api-utils2.5.0indirekt
npmtsx4.23.1indirekt
npmtype-check0.4.0indirekt
npmtypescript5.9.3indirekt
npmtypescript^5.4.5indirekt
npmtypescript-eslint8.61.0indirekt
npmundici-types8.3.0indirekt
npmuri-js4.4.1indirekt
npmwhich2.0.2indirekt
npmword-wrap1.2.5indirekt
npmyocto-queue0.1.0indirekt
NuGetBouncyCastle.Cryptography2.4.0indirekt
NuGetNewtonsoft.Json13.0.3indirekt
NuGetSystem.IdentityModel.Tokens.Jwt7.5.1indirekt
PyPIcryptographyindirekt
PyPIcryptography49.0.0indirekt
PyPIfastapi0.110.1indirekt
PyPIparamikoindirekt
PyPIprometheus-client0.20.0indirekt
PyPIpycryptodome3.20.0indirekt
PyPIpycryptodome3.23.0indirekt
PyPIpydantic-settings2.2.1indirekt
PyPIpyjwtindirekt
PyPIpyopensslindirekt
PyPIpython-dotenv1.0.1indirekt
PyPIrequestsindirekt
PyPIrequests2.34.2indirekt
PyPIstructlog24.1.0indirekt
PyPIuvicorn0.29.0indirekt
RubyGemsed25519indirekt
RubyGemsjwtindirekt
RubyGemsnet-sshindirekt
RubyGemspgindirekt
RubyGemspumaindirekt
RubyGemsrailsindirekt
RubyGemsrbnaclindirekt
RubyGemsrspec-railsindirekt
RubyGemsrubocopindirekt
Abhängigkeits-Advisories 0

Die Installation von npm:@quantakrypto/mcp@0.5.2 zieht 2 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "crypto-agility",
        "cryptography",
        "harvest-now-decrypt-later",
        "infosec",
        "post-quantum",
        "pqc",
        "pqc-migration",
        "pqc-readiness",
        "pqcrypto",
        "q-day",
        "quantum",
        "quantum-readiness",
        "security-training",
        "encryption-strategy",
        "pqc-certification",
        "cbom",
        "mcp",
        "post-quantum-cryptography",
        "sbom",
        "nist"
      ],
      "is_fork": false,
      "size_kb": 2378,
      "has_wiki": false,
      "homepage": "https://quantakrypto.com/tools",
      "languages": {
        "C": 11808,
        "C#": 13339,
        "Go": 13560,
        "HCL": 448,
        "PHP": 259,
        "Java": 9201,
        "Ruby": 9206,
        "Rust": 11638,
        "Bicep": 214,
        "Shell": 1100,
        "Swift": 110,
        "Kotlin": 2093,
        "Python": 18432,
        "Dockerfile": 1319,
        "JavaScript": 146066,
        "TypeScript": 1911224
      },
      "pushed_at": "2026-07-26T17:47:28Z",
      "created_at": "2026-06-09T04:17:00Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T17:47:47Z",
      "description": "Open-source post-quantum readiness tooling by quantakrypto",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://quantakrypto.com",
      "name": "@QuantaKrypto",
      "type": "Organization",
      "login": "quantakrypto",
      "company": null,
      "location": "Switzerland",
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/295786989?v=4",
      "created_at": "2026-06-22T08:34:25Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 34
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1",
          "kind": "other",
          "published_at": "2026-07-23T05:57:13Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-20T15:46:31Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-07-19T08:10:54Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-07-15T18:46:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "409726240647384572233737a78f2a66bd9854d1",
          "body": "…lockfile depth, parallel double-stat) (#38)\n\nFour post-1.0-roadmap detection items on the benchmark-guarded surface.\nThe F1 = 1.000 precision/recall benchmark is unchanged (zero FP, zero FN).\n\n- PHP composer.json / composer.lock dependency scanning: add `composer` to\n  DependencyEcosystem, a curate\n[…]\nrf; file set and detection output are byte-identical.\n\nRebuilds the action bundle. Full gate green (test, typecheck, lint, api:check,\nformat:check).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "feat(core): detection quick-wins (PHP composer, JS recall edges, npm …",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:47:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a8b0e6f5f620a4aebcc1a18e1766355189b0802",
          "body": "…(#37)\n\nQuantify harvest-now-decrypt-later exposure so the migration backlog ranks by\nreal risk instead of finding counts. Exposure per finding =\ncrypto-vulnerability x data-sensitivity x Mosca-factor (retention + secrecy\nlifetime vs the quantum-threat horizon; Mosca's inequality made concrete).\n\nco\n[…]\nrprintFinding().\n\nSemVer: minor (additive API + CLI). Tests: parser, glob, binding, Mosca math,\nsummary, scaffold, CLI wiring. api:docs regenerated.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "feat(hndl): data-risk quantifier (hndl.yml, qscan --hndl, hndl init) …",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:27:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dcaf36631a8664ef3ad03fd1b6e542a46b9d6bdf",
          "body": "Every finding in the qScan --format json output now carries a top-level\nfingerprint field, and each SARIF result mirrors it in properties.fingerprint\nalongside the existing partialFingerprints. The value reuses the baseline\nidentity fingerprintFinding: sha256(ruleId | normalized POSIX repo-relative\n\n[…]\ntinctness across rule/path/\ncontext, the rule+path fallback, cross-format equality (JSON = SARIF =\nbaseline), and stability under snippet redaction.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "core: stable finding fingerprints in JSON and SARIF output (#36)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:22:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e73eb43a2fafd1922746309b664a5d0afdd5277",
          "body": "…m the scan\n\nmanifests were exempt from the file-size cap entirely; a hostile or broken\nlockfile could be read unbounded. give them a generous 16 MiB ceiling instead\n(real monorepo lockfiles are well under it). pure size logic, no detection change.",
          "is_bot": false,
          "headline": "fix(core): cap manifest read size so a pathological lockfile can't oo…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c4dc93b0637a2f9d252c6e318863bcd976ed230",
          "body": "everything the backlogs tracked as P0/P1 has shipped (0.5.x: 52 detectors,\n14 languages, qprobe, openvex, standards profiles, frozen api). what's left is\naccuracy nice-to-haves, the declarative detector factory, perf, and a golden-file\ncorpus. reconciled against the code 2026-07-26.",
          "is_bot": false,
          "headline": "docs: reconciled post-1.0 roadmap (supersedes the old audit backlogs)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c68538aad98554ccd772906da533063ed2e14162",
          "body": null,
          "is_bot": false,
          "headline": "docs: version-support policy for the 0.5.x packages + the v1 action tag",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4b5f48fa7eabd291dfac2cdeb054188184eb7ad",
          "body": "…ity vs cryptodeps\n\nadds tink across com.google.crypto.tink (maven), tink-crypto/tink-go +\ngoogle/tink/go (go), and pypi tink. flagged as rsa/ecdsa/eddsa signatures\nplus ecies hybrid, so hndl-exposed. catalog now 81 entries.\n\ncrypto-js stays out on purpose: it is symmetric/hash/hmac/pbkdf2 only, no\nasymmetric public-key surface, same scope boundary as the password kdfs.\ncomparison doc updated to reflect full parity on the pubkey packages\ncryptodeps documents. re-bundled the action dist.",
          "is_bot": false,
          "headline": "feat(core): catalog google tink (maven/go/pypi); note full pubkey par…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bd18cb4d42fb129aa3dd8f3f37a0dbf7da9712d",
          "body": "two head-to-head comparisons with verified coverage: algorithm matrix,\necosystem/package parity, extras and honest gaps vs cryptodeps, plus the\nfips 203/204/205, sp 800-208, cnsa 2.0 and ir 8547 mapping vs nist.\ncounts verified against the built registry and dep catalog, not prose.",
          "is_bot": false,
          "headline": "docs: add comparison vs qramm/cryptodeps and vs nist",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a0aac3fc77fcf9520a27e4f7c51f5f9f0640655",
          "body": "* docs: fix dead links, stale versioning note, and API-reference doc extraction\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numb\n[…]\nlve re-exported symbols' kind/summary from\n  their source module. Regenerated API.md (276/331 summaries now correct; surface\n  snapshot unchanged).\n\n* docs: fix unfinished 'See and' phrase in ADR 0005",
          "is_bot": false,
          "headline": "docs: fix unfinished 'See and' phrase in ADR 0005 (#35)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:42:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27ad3e3f10f339545be148d4244a7a8e84d9cf44",
          "body": "…traction (#34)\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numbers (pre-1.0, 0.x range)\n- gen-api-reference.mjs: anchor doc sum\n[…]\nolve re-exported symbols' kind/summary from\n  their source module. Regenerated API.md (276/331 summaries now correct; surface\n  snapshot unchanged).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "docs: fix dead links, stale versioning note, and API-reference doc ex…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:37:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a921a52c6e6a8d6cb9382a711b6573156ef33068",
          "body": "chore: move the observatory worker to its own repository",
          "is_bot": false,
          "headline": "Merge pull request #33 from quantakrypto/chore/remove-observatory",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T03:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74cec18da463e58ed805258009103b469c8f57fd",
          "body": "The PQC observatory worker now lives at github.com/quantakrypto/pqc-observatory,\na self-contained repo that probes public hosts via openssl (it must not depend on\nqProbe, which is ownership-gated for endpoints you control). Removed from here:\npackages/observatory, ADR 0007, the root observatory script, and the pg devDep.",
          "is_bot": false,
          "headline": "chore: move the observatory worker to its own repository",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T03:15:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7d35f4f5b15252f45e217a05eb15fbd6da50a0e",
          "body": "Observatory: internal PQC-readiness probe worker (ADR 0007)",
          "is_bot": false,
          "headline": "Merge pull request #32 from quantakrypto/feat/observatory-worker",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba8063706e85acc49fdb268b81af3d18fe21976d",
          "body": null,
          "is_bot": false,
          "headline": "docs: OpenSSF Best Practices pre-filled answers",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:37:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0f88aeeae962a56770bc0420d02cc1eccb7224c",
          "body": "Adds packages/observatory (private, unpublished): a monthly worker that probes a\nfixed panel of public hosts for PQC-hybrid key exchange (X25519MLKEM768) and\ncertificate posture, writing idempotent per-month results and a rollup to\nPostgres for the site's public /observatory page.\n\nReuses qProbe's u\n[…]\n. See docs/adr/0007.\n\nThe published packages are untouched: qprobe unchanged, zero-runtime-dependency\nand offline-boundary invariants still hold. pg is a devDependency of the\nobservatory package only.",
          "is_bot": false,
          "headline": "feat(observatory): internal PQC-readiness probe worker + ADR 0007",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:37:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "008333afb319a993c8b0f9d16c2277ae1b8da3dd",
          "body": null,
          "is_bot": false,
          "headline": "docs: add OpenSSF Best Practices passing badge (#31)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-24T02:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e68ab13934111dfc9c7fa5ee8ee5669979103093",
          "body": "- qprobe/mlkem768: replace biased modulo sampling with unbiased rejection\n  sampling for the throwaway probe key (js/biased-cryptographic-random)\n- sieve/protocol fromB64: replace the /=+$/ trailing-trim (O(n^2) on the\n  untrusted SUT response) with a linear scan (js/polynomial-redos)\n- mcp/http: di\n[…]\nests pass, including the property-based fuzz tests on the patched\nparsers. Trailing-slash trims on trusted config input (walk globs, agent\nbaseURL) are dismissed separately as not attacker-controlled.",
          "is_bot": false,
          "headline": "fix(security): resolve CodeQL findings in untrusted-input paths (#30)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T10:44:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e2991cc568d1225ae134a323a5dd68b8f731841",
          "body": "Add fast-check (dev-only) property tests that fuzz the parsers that consume\nattacker-controlled bytes: qProbe's TLS ServerHello / record / SSH KEXINIT /\nX.509 OID decoders, and Sieve's SUT response decoder. Each runs thousands of\nrandom inputs asserting the robustness contract (safe wrappers never t\n[…]\nhrow only their typed error, never a raw crash). All green,\nso the parsers hold; the tests stand as a regression guard and satisfy the\nOpenSSF Scorecard fuzzing criterion. No runtime dependency added.",
          "is_bot": false,
          "headline": "test: property-based fuzzing of the untrusted-input parsers (#29)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T10:17:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e769591f56bef2b4bb30401d7c29836b9b7cd7a5",
          "body": "* ci: add CodeQL SAST workflow (pinned)\n\n* ci: move packages:write to job scope (least-privilege top level)",
          "is_bot": false,
          "headline": "ci: add CodeQL SAST workflow (#28)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T08:51:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b346991abc40eef0fa3d13f84e5ba1b7d714bec4",
          "body": "Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.15 to 1.1.16.\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.16)\n\n---\nupdated-dependencies:\n- dependency-n\n[…]\non\n  dependency-version: 1.1.16\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump brace-expansion from 1.1.15 to 1.1.16 (#26)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T08:27:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6822434ebae7fcb5f96a416d96b3b5ae93e89f0",
          "body": "Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.0.\n- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: js-yaml\n  dependency-version: 4.3.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump js-yaml from 4.2.0 to 4.3.0 (#20)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T08:27:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7918654d8e3073d5c90fbd44a22e06f2533ffe67",
          "body": "…thub.com)",
          "is_bot": false,
          "headline": "mirror container + npm packages to github packages (ghcr + npm.pkg.gi…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f18694debd4960bfb23da4bc2d37aebed4c52ff",
          "body": null,
          "is_bot": false,
          "headline": "bump docker image to @quantakrypto/mcp 0.5.2",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:12:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e67f89ca3f6145968b281c9e5c0b61ec4b97bf6",
          "body": null,
          "is_bot": false,
          "headline": "make mcp-registry publish idempotent (skip already-published version)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:01:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c6acc5d7ad2adc95434585c352818ec915af533",
          "body": "… em dash",
          "is_bot": false,
          "headline": "shorten root action description under 125 chars for marketplace, drop…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:31:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ac2632582f46ef0bd7e7bd118d7dbdc3632c178",
          "body": null,
          "is_bot": false,
          "headline": "add root action.yml so the action can list on the github marketplace",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:18:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc6f17d4e5de400c2534d595886273c850eedcf8",
          "body": null,
          "is_bot": false,
          "headline": "add 400x400 logo for marketplace/directory listings",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:15:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "192dd4c4153d21e79929d234b246198b855e62ce",
          "body": "…rver",
          "is_bot": false,
          "headline": "add root .mcp.json so cursor / open-plugins clients can import the se…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:58:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6264359813afcda7eb217ceca17e10130cba0414",
          "body": null,
          "is_bot": false,
          "headline": "shorten server.json description to fit the registry 100-char limit",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:38:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f134a0efdc802e5d96cce9717c9e86b2fc4bde1a",
          "body": "runs mcp-publisher with github-oidc auth, so the io.github.quantakrypto namespace\nis authorized by the org's own actions token. no keys, no interactive login.",
          "is_bot": false,
          "headline": "add workflow to publish server.json to the mcp registry via oidc",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:36:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6147d56bb6432648d494e1243ccad09bbe765c56",
          "body": "the mcp registry verifies npm ownership by reading an mcpName field from the\nPUBLISHED package.json, so we ship a tiny 0.5.2 that adds it plus a server.json\n(namespace io.github.quantakrypto/pqc-tools, npm stdio package + the hosted\nstreamable-http remote). metadata only, no code change. after this publishes,\nlisting on the registry is just: mcp-publisher login github && mcp-publisher publish.",
          "is_bot": false,
          "headline": "mcp 0.5.2: add mcpName + server.json for the official mcp registry",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dbf1446a1f4afaf6f8183cffebb8a9736899a5d",
          "body": "- tool input schemas: every array field (findings/verdicts, score_delta\n  before/after) now has an 'items' object schema instead of a bare type:array.\n  mcp inspectors flag the bare form ('missing items definition') and it drags\n  the tool-definition-quality score.\n- bump @quantakrypto/mcp to 0.5.1 + changelog. pairs with the already-landed\n  resources/templates/list fix (ed6ecfd). package-only patch — core/qscan/etc\n  stay 0.5.0 (unreleased work still parked under [Unreleased]).",
          "is_bot": false,
          "headline": "mcp 0.5.1: describe tool array items, cut patch release",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T02:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6ecfdf3452c0563624a260f2dd42ad784f851a",
          "body": "the server advertises the 'resources' capability, so spec-compliant clients\n(and mcp directory health checks like glama's inspector) call\nresources/templates/list during discovery. we only expose fixed-uri resources,\nno uri templates — but we were falling through to -32601 method-not-found, which\ntrips those clients. return an empty { resourceTemplates: [] } instead.\n\nadded a test asserting it succeeds empty rather than erroring.",
          "is_bot": false,
          "headline": "handle resources/templates/list instead of 404ing discovery",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T01:31:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c58bc376dd6bd3ac7bf54d9f04018b428b3863c",
          "body": "the recall/corpus benchmark ships fake dependency manifests (pom.xml, go.mod,\ncargo.toml, requirements.txt, csproj, gemfile, package.json...) with pinned deps\non purpose — thats the test data for crypto-dependency detection. when one of\nthose pinned versions gets a security advisory (jackson-databin\n[…]\ncore).\n\nscope each fixture ecosystem under packages/core/test/benchmark/** with\nlimit 0 + ignore '*' so dependabot leaves the test corpus alone. real dev deps\n(npm at /) and action SHAs are untouched.",
          "is_bot": false,
          "headline": "stop dependabot from failing on scanner test fixtures",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T00:47:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33b823beb2e8dbdce12efe3eef7f17de3f9ce252",
          "body": "glama (and other mcp hosts) sandbox the server: they run initialize +\ntools/list over stdio and expect a valid reply. this image installs the\npublished @quantakrypto/mcp and starts the stdio transport, so that check\npasses. base image + package are both pinned; glama.json claims the listing.\nbump both pins on release.",
          "is_bot": false,
          "headline": "add dockerfile + glama.json for mcp directory listing",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-22T17:16:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6cca652a7e4f929c7d81b31501bcf3a72690295",
          "body": "the hosted MCP gateway described as future work in HOSTING.md now exists and runs in\nproduction (quantakrypto/mcp-gateway, live at mcp.quantakrypto.com). add:\n- HOSTING.md: a reference-implementation callout up top + note on §3 that oauth 2.1 is\n  what the gateway implements (better-auth, 30-day tok\n[…]\nant to use it?\" callout with the `claude mcp add --transport http` command,\n  the content-only tool surface (fs/network tools withheld), and the gateway repo link.\ndocs only; no code/behaviour change.",
          "is_bot": false,
          "headline": "docs(mcp): point HOSTING + README at the now-live hosted gateway",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-22T04:12:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a895f0a8b4e125f8df672a3d9e5e22b58d8ca612",
          "body": "…e dir as a module\n\n`node --test scripts/test/` (a directory arg) runs the tests on node 20, but on node\n21+ the runner resolves the path as a module and fails with \"Cannot find module\n.../scripts/test\", reddening build+test on the node 22 matrix leg. use\n`scripts/test/*.test.mjs` — shell-expanded to the literal file, exactly like the\nper-workspace `test/*.test.ts` scripts already do — which both node versions run.",
          "is_bot": false,
          "headline": "fix(test): explicit glob for test:scripts so node 22 doesn't treat th…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-21T03:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb3eecc23f4e8bba6916fbe8f29e843e28acb2ac",
          "body": "… EPIPE\n\nthe evidence signer (--sign/--timestamp) shells out via spawnSync with the payload on\nstdin. a command that exits before draining stdin (e.g. `false`) makes spawnSync\nsurface an EPIPE in res.error on linux — not macos — even though the child ran and\nreturned an exit status. the old code che\n[…]\nt a non-zero exit status (or terminating signal) FIRST; only fall back to\nres.error for a genuine spawn failure (e.g. ENOENT). deterministic across platforms.\naction dist re-bundled (it embeds qscan).",
          "is_bot": false,
          "headline": "fix(sign): report a signer's non-zero exit before an incidental stdin…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-21T03:38:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e397c9e6f06f7c6e190bcbd5857fea0e18907880",
          "body": null,
          "is_bot": false,
          "headline": "chore(action): re-bundle dist for the 0.5.0 release",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T15:46:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7917f17c20ee7287a9427f03eaf3a30e449e11b",
          "body": null,
          "is_bot": false,
          "headline": "docs: design for hosted OAuth-gated multi-tenant MCP gateway",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T14:27:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ede29ffa0abc3c385a2ff18b246875433e7a9775",
          "body": "Per the cleanup request: remove point-in-time audit process artifacts and\nplanning docs, keep the enduring standards/reference/decision documentation, and\nadd a clear statement of what each library is for and what we're building toward.\n\nRemoved (in the previous commit): docs/audits/, docs/AUDIT.md,\n[…]\nMODEL (§8 controls table + the agent-line note refreshed to\nthe completed/fixed status), COMPLIANCE, CONFIG, SECURITY, CONTRIBUTING, and the\nGitHub templates — no broken links to removed files remain.",
          "is_bot": false,
          "headline": "docs: prune audit logs & plans; add OBJECTIVES; fix cross-references",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:54:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2d28b1b7a8290bf8271ff5e7074949e5f75bd0d",
          "body": "…leanup\n\nDetector fixes (each with a regression test; suite 1118 -> 1123):\n- proxy (H1/H2/L1/L2): the global marker gate was too narrow, silently dropping\n  canonical HAProxy (bind ssl crt, no crt-store) and Traefik (certFile/keyFile,\n  no certResolver) configs. Replaced with per-rule self-gating; E\n[…]\n, plans, and 0.4 runbook (docs/audits/,\nAUDIT.md, ROADMAP.md, how-to-test-0.4.md, superpowers/) — the enduring 'why' is\nin the ADRs; the new OBJECTIVES.md + index rewrite land in the follow-up commit.",
          "is_bot": false,
          "headline": "fix: adversarial-audit findings in the 5 new detectors + begin docs c…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:48:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a36bd28b8537e7f6a5970afb5ef52124d4e5faf3",
          "body": "…/gRPC TLS, code-signing, weak-hash\n\nFresh coverage-gap research (3 Fable agents: assess + 2 web-research passes)\nidentified high-value PQC surfaces the scanner missed. Adds 5 detectors\n(47->52 detectors, 277->297 rules), scope kept to PQC + quantum-adjacent:\n\n- solidity: 14th source language pack (\n[…]\nassword hashing.\n\nEach with self-contained tests; benchmark F1=1.000, zero FP held. Wired into\nregistry + coverage constants + comment table; docs/README/ROADMAP/CHANGELOG\nupdated. Suite 1065 -> 1118.",
          "is_bot": false,
          "headline": "feat: 5 new detection surfaces — Solidity/blockchain, WebAuthn, proxy…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:33:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a17925014e030608025c7c20cabd453b0f736f65",
          "body": "…ant test\n\nAssessment (Fable) found two of my new packs under-reported HNDL, re-introducing\naudit bug P0-4: objc-seckey-ec and Dart ECKeyGenerator classified ambiguous EC\nkeygen as signature/ECDSA/hndl:false, while the whole fleet (java/python/c/swift/\ncloud-kms/ruby EC keygen) uses the HNDL-safe ke\n[…]\ns JWT coverage (added to JWT_HOST_EXTENSIONS); cloud-kms\nmasks comments so a commented-out YAML/JSON KeySpec can't fire; fixed the stale\n'JS/TS, Python, Go, Java' analyzable-languages doc in types.ts.",
          "is_bot": false,
          "headline": "fix: restore fleet HNDL convention for EC keygen + add catalog invari…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:22:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a1912474845689e60b42fe989db0b697d630c08",
          "body": "…n barrel\n\nstandardsReviewStatus is exported by standards.ts but NOT re-exported by the\npublic index.js barrel, so standards-check.mjs crashed on import ('does not\nprovide an export'). Because the standards-currency step is advisory\n(continue-on-error), the crash went unnoticed in CI. Import both symbols from\nthe standards.js subpath. Add a build-aware smoke test to the guard suite so an\nimport regression can't silently break this advisory gate again.",
          "is_bot": false,
          "headline": "fix(standards-check): import from standards.js subpath, not the froze…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:28:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f029ee1b20c3aa7ceb39ed62417f634b5d4076d",
          "body": "… + counts\n\n- ADR-0005 + THREAT-MODEL: F1 (blast-radius gate), F2 (system-role instruction/\n  data separation), F3 (--max-findings spend cap) are fixed in code — mark them\n  resolved instead of open, consistent with ROADMAP §1 (verified in loop.ts,\n  remediate-pipeline.ts, triage-run.ts).\n- COMPLIAN\n[…]\nd; 0.4.4 published) across COMPLIANCE,\n  VERSIONING, AUDIT, SUPPLY-CHAIN; test-count and 'supported vs benchmark-corpus\n  languages' wording refreshed; CHANGELOG Fixed section for the audit hardening.",
          "is_bot": false,
          "headline": "docs: reconcile ADR-0005/THREAT-MODEL (F1-F3 fixed), refresh versions…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:26:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adaaa20f803d3dbc7544f867636a133723cc2cf4",
          "body": "Detectors:\n- ssh-ca: add ssh-ca-config rule for TrustedUserCAKeys/HostCertificate/ssh-keygen\n  -s — the canonical CA deployment previously yielded ZERO findings (H6); stop\n  firing on program SOURCE files, so a vendored SSH lib's cert-type constant is\n  not flagged as live config (M4).\n- spire: matc\n[…]\n (file:src/a.ts#L3) (M7); the @id digest\n  includes triage status_notes so triaged/untriaged exports get distinct ids (L1).\n\nAll with regression tests. Suite 1052 -> 1063; benchmark F1=1.000, zero FP.",
          "is_bot": false,
          "headline": "fix: adversarial-audit findings in detectors, CBOM, and VEX",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:21:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dc164c054073ff4e842c9c0b662a87cb8afd244",
          "body": "…3, M6)\n\nThe line-by-line + sequential-regex guard was bypassable by ORDINARY code, so\nADR-0005's 'enforced by CI' claim was false. Rewrite with a single-pass lexer\n(code/string/comment classification, recursing into template ${…} as code) and\nwhole-file scanning with index->line mapping:\n- C1: Pret\n[…]\n: auto-merge runs on comment-stripped text, so a // gh pr merge note no\n  longer false-positives; real exec('gh pr merge') strings still fire.\nRegression tests pin every bypass. Real repo stays clean.",
          "is_bot": false,
          "headline": "fix(guard): make offline-boundary bypass-resistant (audit C1-C3, H1-H…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f550df96e8091c3cfc0e60aad84039f8991ad156",
          "body": "ADR-0005's no-auto-merge rule covers workflows, not just package source. Extend\nthe guard to scan .github/workflows/*.yml for gh-pr-merge/--admin, with a\nknown-bad-fixture test. Workflows are currently clean.",
          "is_bot": false,
          "headline": "test: offline-boundary guard also scans workflows for auto-merge",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:57:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f206c81f351977ad552485b798cc645c743a7c7",
          "body": "Closes the post-1.0 coverage gaps:\n- objc-crypto (.m/.mm): Apple Security-framework SecKey* RSA/EC keygen, RSA/ECDSA\n  signing, RSA encryption, ECDH — gated off .h to avoid C/C++ overlap.\n- dart-crypto (.dart): pointycastle + package:cryptography RSA/ECDSA/ECDH/Ed25519/X25519.\n- dkim-crypto: classic\n[…]\n1.000, zero FP). Repointed the coverage-honesty tests\noff .m/.dart (now supported) to genuinely-unsupported Lua/Perl. Docs updated\n(core README language table, ROADMAP, CHANGELOG). Suite 1002 -> 1052.",
          "is_bot": false,
          "headline": "feat: coverage packs — Objective-C, Dart, DKIM, SSH-CA, SPIFFE/SPIRE",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:54:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a660c018f4ca964b0479c7b57cc04abedfece4",
          "body": "Adds scripts/check-offline-boundary.mjs — the gate ADR-0005 called for but that\n'did not exist yet'. It enforces the two-plane split by masked source scan:\ncore/mcp/sieve import no @quantakrypto/agent, make no outbound fetch/WebSocket/XHR\ncall, and read no LLM API key; qscan reaches the agent ONLY v\n[…]\n\n(e.g. core's redaction patterns). Wired into ci.yml + supply-chain-audit.yml;\nreject logic covered by known-bad fixtures in guards.test.mjs. ADR-0005 +\nROADMAP updated to reflect the gate now exists.",
          "is_bot": false,
          "headline": "feat: CI-enforce the ADR-0005 offline/agent boundary",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:38:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6511bcba849a3680b5720293ed71ecd9e612c59c",
          "body": "The CycloneDX CBOM labelled every asset 'algorithm'. Now each finding is\nclassified into its proper CycloneDX 1.6 assetType: X.509 findings ->\ncertificate; private/public key material -> related-crypto-material (typed\nprivate-key/public-key); TLS -> protocol (protocolProperties.type tls);\neverything\n[…]\nhanged algorithmProperties. Every asset\nstill carries quantumVulnerable/harvestNowDecryptLater. Completes the refinement\nthe CBOM audit deferred. Grouping is now (assetType, algorithm, discriminator).",
          "is_bot": false,
          "headline": "feat: refine CBOM assetType (certificate / key-material / protocol)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:32:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "691d02c5e8123ca734cf582d1b679e26dbcb50c2",
          "body": "Emit the quantum-readiness posture as an OpenVEX 0.2.0 document so it flows into\nthe same supply-chain pipeline that already ingests CVE-based VEX. One statement\nper rule (synthetic QK-<ruleId> vulnerability, since PQC findings have no CVE),\nevery affected file:line product, status 'affected', the r\n[…]\nnly an operator can attest a mitigation). Deterministic output.\n\nNew core API toOpenVex + OpenVex* types; qScan --format vex / renderVex; help,\nqscan README, and CHANGELOG updated. Surface 326 -> 331.",
          "is_bot": false,
          "headline": "feat: OpenVEX 0.2.0 export (--format vex)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:28:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c03731db39cbb43d8a91dc0b7ec1fcade55f747",
          "body": "Records the toolkit-export decision the audit flagged: the frozen external\nplugin point is the public Detector interface + scan({detectors}) / RuleMeta /\nFinding types; the lexical helpers (findingFromRule, eachMatch, comment maskers)\nstay INTERNAL so their signatures aren't frozen at 1.0 (exporting later is\nadditive). Clarifies the 'Adding a detector' guide is for in-repo contributors,\nresolving the read that external authors should import findingFromRule.",
          "is_bot": false,
          "headline": "docs: settle the detector plugin surface for the 1.0 freeze",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:13:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dc5241fdc20fdbb701c7939dce7b90e5f9dde79",
          "body": "… A.8.24\n\nROADMAP current-status count ~930 -> ~985 (historical audit figures left as-is).\nAdds a note to the A.8.24 evidence doc that verifyReadinessReport recomputes the\nintegrity hash to detect body tampering independently of the external signature.",
          "is_bot": false,
          "headline": "docs: refresh current test count + document verifyReadinessReport for…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:12:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0143fc1c1d9aa17d93a1eb66fa146aa91320db67",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): note verifyReadinessReport API + test-hardening pass",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:05:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4b541845dbed7653698d6405588f6744e1ad32e",
          "body": "The anthropic/openai adapters had happy-path + one HTTP-error test but nothing\nfor the transport failure modes a BYOK integration actually hits. Add, to both:\na timeout that aborts a hung request via the AbortSignal, a propagated network\n(fetch-rejection) error, and — the load-bearing BYOK security \n[…]\n that\nthe API key travels ONLY in its auth header (x-api-key / Bearer) and never\nleaks into the request URL or body. Also gives the openai adapter the HTTP-error\ntest it was missing. Suite 979 -> 986.",
          "is_bot": false,
          "headline": "test: agent BYOK adapter error paths + API-key-only-in-header invariant",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:05:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60d7d6a188b1244701529bc2d1d8b6c5b2d5020d",
          "body": "The supply-chain / output guards (check-zero-deps, check-action-pins,\nvalidate-sarif) run as standalone CI steps, so nothing proved their FAILURE\npath still works — a guard whose reject logic silently broke would leave CI\ngreen while the invariant eroded. Add scripts/test/guards.test.mjs with\nknown-\n[…]\nd it\nto match check-action-pins.mjs; the CLI behaviour is unchanged.\n\nWired via a new root `test:scripts` (node --test), chained into `npm test` so\nCI's existing test step covers it. Suite 951 -> 979.",
          "is_bot": false,
          "headline": "test: cover the CI guard scripts + fix validate-sarif import side effect",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:01:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d1e160d62558fc9b7f83a8e510e9c36c7eabb37",
          "body": "stateful-hbs was the only built-in detector with no dedicated unit test. Add\none covering each distinctive token (LMS/HSS/pyhsslms/XMSS/XMSSMT/xmss_keypair),\nthe SP 800-208 SHAKE256 + 192-bit parameter variants, the XMSS-vs-XMSSMT\nno-double-count boundary, the bare-word negative cases, and the load-bearing\ninvariant that these approved-but-stateful schemes are signature/medium and\nNEVER hndl:true (they are a state-management hazard, not broken crypto).",
          "is_bot": false,
          "headline": "test: unit-test the stateful-HBS detector (SP 800-208)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:56:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efc2dbdcef08ad212358bec2fc05ff285cda93fe",
          "body": "…eport\n\nSieve runner: add tests for the failure paths that had none — a SUT that never\nanswers rejects with TimeoutError (carrying request + timeoutMs); a SUT that\nexits mid-request, or fails to spawn, rejects the in-flight send with a\nSutCrashError that attaches the exit reason and captured stderr;\n[…]\nlicy verdicts, subject/tool metadata)\nwhile ignoring the excluded scan time / CBOM envelope / attestation block. Tests\ncover the classic 'edit the evidence' downgrade. Additive API surface (324->326).",
          "is_bot": false,
          "headline": "test: sieve runner crash/timeout coverage + evidence verifyReadinessR…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c69941bd3474c5d6a8ae4051fbbf2328128bbd5",
          "body": "The qscan CLI and MCP tool tests were written when core.scan was a stub and\ntolerated every exit code (`[OK, FINDINGS, ERROR].includes(code)`) or both\nbranches of an if/else. core is fully implemented and main()/scan_path drive\nthe genuine detector pipeline, so these now assert deterministic outcome\n[…]\nl temp fixtures: clean dir -> 0, RSA keygen -> 1/real finding,\nbaseline written, explain_finding returns real PQC remediation.\n\nAlso drops a stray U+200B from the maskBlockComments doc comment (lint).",
          "is_bot": false,
          "headline": "test: de-stub tautological CLI/MCP tests against the real scanner",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:51:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0850f29d8420de99e0162e38d235792aad984ea",
          "body": "…/Azure KMS\n\nFrom the pre-1.0 audit's detection-gap list:\n\n- New xmldsig detector: classical XML-DSig / XML-Enc algorithm URIs (SAML SSO,\n  WS-Security) — rsa-sha*/dsa-sha*/ecdsa-sha* signatures and rsa-oaep key transport.\n- New pkcs11 detector: classical keys behind a PKCS#11 HSM/token — pkcs11-too\n[…]\ns. Messages/ids made cloud-generic.\n\nTwo new detectors registered (35 total). Regression tests (positives, negatives,\ndoc-suppression) throughout. Suite: 951 passing; all gates clean; benchmark 1.000.",
          "is_bot": false,
          "headline": "detectors: close coverage gaps — SAML/XML-DSig, PKCS#11, TDE, CDK/GCP…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:18:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f08bd446459fec5fadc1b66a23326be4f116bd5",
          "body": "The detector matched only the quoted-value SDK/JSON form (`KeySpec: \"RSA_2048\"`), so\nAWS CDK's enum-member form (`kms.KeySpec.RSA_2048`, `acm.KeyAlgorithm.EC_prime256v1`)\nand Pulumi's camelCase props (`customerMasterKeySpec: \"RSA_2048\"`) produced ZERO\nfindings — the dominant IaC idioms at AWS-heavy \n[…]\nth cases; also cover ACM `KeyAlgorithm`. The fast-reject\ngate is now case-insensitive. Terraform's snake_case spec still never double-counts\n(the regex has no underscore form). Regression tests added.",
          "is_bot": false,
          "headline": "cloud-kms: cover AWS CDK enum forms + Pulumi/camelCase key specs",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:08:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "204e89b43d5601bcb36688e258b5c7a4527ea816",
          "body": "…NCSC\n\nCloses the audit's #1 gap: the tool was hardcoded to a NIST/CNSA worldview, and its\n\"hybrids optional\" guidance was regime-WRONG for ANSSI/BSI (where hybridization is\nrequired), with no way to choose otherwise.\n\n- New core `StandardsProfile` layer (standards-profiles.ts): five cited, dated\n  \n[…]\ntionForProfile, formatProfileGuidance (frozen in the surface). A drift test\n  keeps profile params aligned with PQC_STANDARDS.\n\nDocs: CHANGELOG, ROADMAP, CLI help. Suite: 936 passing; all gates clean.",
          "is_bot": false,
          "headline": "feat: selectable standards regimes (--profile) — NIST/CNSA/BSI/ANSSI/…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:01:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cd17e3e04536d9daac70069d441a52e5826da8b",
          "body": "…E, ROADMAP)\n\n- CONFIG.md §5 was materially wrong: it implied the Action and MCP honor a\n  discovered config. Neither does (verified) — and that's deliberate: both run over\n  operator-uncontrolled trees, so a discovered config there would be a scan-integrity\n  bypass. Documented the trusted-local-op\n[…]\n/ 593 tests / 9 langs / 5\n  packages). Updated to v0.5.0 / ~930 tests / 11 langs / 7 packages, added qprobe,\n  and led with both benchmark numbers (curated 1.000 + real-world recall 0.84).\n\nDocs only.",
          "is_bot": false,
          "headline": "docs: correct drift the audit flagged (CONFIG security posture, READM…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T06:43:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe7869d5f84ab86a16113d399c66fa7520203d36",
          "body": "Nine symbols with zero cross-package consumers were being SemVer-frozen by accident\n— un-export them from @quantakrypto/core's index (they stay exported from their own\nmodules, so core's own tests still import them via ../src/): the parallel-scan\nchunk/merge helpers (mergeChunkResults, chunkByBytes)\n[…]\niewStatus, and isGeneratedPath. Public surface 324 → 315 symbols\n(core 139 → 130). Also refreshed the stale builtinDetectors doc comment (it\ndescribed ~10 detectors; there are 33). No behavior change.",
          "is_bot": false,
          "headline": "freeze-safety: trim internal plumbing from the public API surface",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T06:42:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26f4c7d57ff97958659fca364cf04db12e51c3c3",
          "body": "Two better-before-the-1.0-API-freeze items from the audit.\n\n- Block comments now mask correctly. `maskCommentLines` is line-only, so an\n  HCL/Bicep resource wrapped in `/* … */` had its inner lines left live (verified\n  FP: bicep-keyvault-rsa / tf-rsa-key fired inside a block comment). New\n  offset-\n[…]\nderReport` into async `runQscan`; the sync `commandSigner` still satisfies the\n  wider type. Added an async-signer test.\n\nRegression tests added. Suite: 928 passing; all gates clean (incl. api-check).",
          "is_bot": false,
          "headline": "freeze-safety: block-comment masking + async-capable EvidenceSigner",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:55:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f10745a5ceb62aa36fd94b73fc39a4a12cf0ca84",
          "body": "…rity drift\n\nConfirmed, low-risk findings from the pre-1.0 four-lens audit.\n\nSecurity:\n- An AUTO-DISCOVERED quantakrypto.config.json can come from the scanned tree, so a\n  hostile repo could silently WEAKEN its own scan (disable rules, raise the\n  severity-threshold, exclude files → flip exit 1→0). \n[…]\n9/X448 low→medium (aligns with node/rust/go) — the same\n  primitive must not flip CI exit codes based on which surface uses it.\n\nRegression tests added throughout. Suite: 925 passing; all gates clean.",
          "is_bot": false,
          "headline": "audit fixes: config-trust warning, verified FPs, Swift coverage, seve…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:32:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc942ea12abfb232859dc81d3a782d2bde8e1a59",
          "body": "… were missing\n\nThe generator's declaration regexes didn't allow an `async` modifier, so\n`export async function` was skipped: runQscan, runSieve, runProbe (the main public\nentry points of qscan/sieve/qprobe) were absent from the frozen surface\n(docs/api-surface.json + API.md), and since `--check` sh\n[…]\nmplete freeze. Widen the modifier prefix to\n`(?:(?:declare|async|abstract)\\s+)*` in both collectExports regexes and docFor, and\nregenerate: 318 → 324 symbols.\n\nFound by the pre-1.0 test-quality audit.",
          "is_bot": false,
          "headline": "fix(api-gen): capture `export async function` — flagship entry points…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:20:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ac14568839a1dd17270a7472371ed2729127cde",
          "body": "Completes the A.8.24 evidence chain per ADR-0004: the tool orchestrates a signer,\nit implements no cryptography.\n\n- `qscan --format evidence --sign <cmd>` / `--timestamp <cmd>` pipe the report's\n  deterministic contentHash to an operator-provided external signer (openssl /\n  cosign / an RFC-3161 TSA\n[…]\ney.\n\nDocs: A.8.24 evidence doc §3.1 (interface + examples + verify recipe), ROADMAP,\nCHANGELOG. New public exports frozen in the API surface. Suite: 922 passing;\nlint/format/zero-deps/api-check clean.",
          "is_bot": false,
          "headline": "qscan: orchestrate external evidence signing (--sign / --timestamp)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:58:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b26eeed47f8420b8197ed0dfd91f4757f0a39d7",
          "body": "Promote the roadmap's i18n YAGNI note to a load-bearing Architecture Decision\nRecord: the human-facing report ships no message catalogs or locale machinery, and\nthe structured JSON/SARIF/CBOM output is the locale-neutral integration surface for\nany consumer that needs localized presentation. Framed as a YAGNI deferral, not a\npermanent refusal — reopening requires a new ADR with a concrete localized-consumer\nneed. Indexed in docs/adr/README.md and cross-linked from ROADMAP.md.",
          "is_bot": false,
          "headline": "docs: record report-is-English-only (no i18n) as ADR-0006",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:48:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2241e0ce3c675f512409caa3beb4563f916b8de8",
          "body": "…gate)\n\nCloses the VERSIONING.md 1.0 requirement of \"a documented, frozen public API\nsurface + a generated API reference\".\n\n- scripts/gen-api-reference.mjs (zero-dep) reads each package's public entry point\n  (following a single `export * from` hop) and emits docs/API.md (human reference)\n  and docs\n[…]\ngate bites: exit 1 on a dropped/added symbol, 0 when clean.\n- Documented the closed gate in VERSIONING.md, ROADMAP.md §1, and CHANGELOG.\n\nSuite: 916 passing; lint/format/zero-deps/api-check all clean.",
          "is_bot": false,
          "headline": "docs: freeze the public API surface + generate an API reference (1.0 …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:42:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32f90adc35068db7f330c1dbc27f061ad4aa962a",
          "body": "Bump every @quantakrypto/* package 0.4.4 → 0.5.0 (and the cross-package core/\nqprobe/qscan/agent pins + the two version.ts constants), and date the CHANGELOG\n[Unreleased] → [0.5.0].\n\nMinor bump under 0.x: this line adds new backward-compatible detector surfaces\n(Azure Bicep, Swift/CryptoKit, Pulumi)\n[…]\ntop of the round 3/4/5 detection-accuracy\nand engine-correctness fixes and the dead-code/API-surface cleanup. Suite at 916\npassing; precision/recall gates and the zero-FP negative set held throughout.",
          "is_bot": false,
          "headline": "release: v0.5.0",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:35:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a84af29921dea8a22a4d2a9ea292d6e861e3cab",
          "body": "Document the detector-precision hardening (comment/prose masking, cross-detector\ndouble-count deferrals, per-language FP/FN fixes), the engine correctness fixes\n(triage cap, CBOM merge/serial, readiness ordering, CLI ENOENT/--merge, sieve KAT\nskips), the dead-code removal and API-surface narrowing, the three new detector\nsurfaces (Azure Bicep, Swift/CryptoKit, Pulumi), and the real-repo validation +\ncorpus expansion. No previously-documented entries changed.",
          "is_bot": false,
          "headline": "docs: bring CHANGELOG [Unreleased] current through rounds 3–5",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89dc0598aa850fc1abdc0faade4e74c7d1d997c1",
          "body": "Three new detector surfaces (#5), each registered, unit-tested, and pinned by the\nbenchmark corpus:\n\n- bicep: Azure-native IaC (.bicep) — Microsoft.KeyVault `kty: 'RSA'/'EC'` keys\n  (gated to the Key Vault marker) and legacy `minimumTlsVersion: 'TLS1_0'/'TLS1_1'`.\n  Complements the existing ARM/Clou\n[…]\nhe `algorithm` value (RSA/ECDSA/ED25519).\n\nValidated against real OSS repos (gin, mux, flask, terraform-aws-eks, express,\nhelm/charts): zero false positives from the new detectors. Suite: 916 passing.",
          "is_bot": false,
          "headline": "detectors: add Azure Bicep, Swift/CryptoKit, and Pulumi coverage",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:27:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "877319c024ada9a572206b21d631e7e735e5a6db",
          "body": "Add 7 labeled corpus cases so the new coverage is pinned by the precision/recall\ngates (was invisible to the benchmark before):\n\nPositives:\n- GCP service-account JSON with a single-line \\n-escaped PKCS#8 key\n  (pem-pkcs8-private-key)\n- Terraform tls_private_key ED25519 (tf-ed25519-key)\n- Ansible com\n[…]\nide a Terraform description string\n- a PEM parser's paired header/footer string constants\n- commented-out PHP openssl crypto\n\nBenchmark: recall perfect, negative set strict (0 FP). Suite: 899 passing.",
          "is_bot": false,
          "headline": "benchmark: expand corpus for the round 3/4/5 detector surfaces",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:18:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "173d388feb0909804020bd84b4cfc5e14fa16bf5",
          "body": "Empirical validation (scanning real OSS repos — gin, flask, terraform-aws-eks,\nhelm/charts, express, gorilla/mux) surfaced one false-positive class: the\nssh-kex-classical / tls-classical-kex token rules fired on classical algorithm\nnames LISTED inside a Terraform/Packer `description = \"…\"` string (\"\n[…]\n is unaffected.\n\nThe rest of the sweep (~82 findings across 6 repos) was legitimate: real embedded\ntest certs/keys, real InsecureSkipVerify, and intentional classical-crypto deps.\n\nSuite: 899 passing.",
          "is_bot": false,
          "headline": "source: don't fire transport-KEX rules on algorithm names in a doc field",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:15:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5560caa06ce10bd7549191f63e322e85da7b595c",
          "body": null,
          "is_bot": false,
          "headline": "test: cover cosign sign-blob subcommand",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:44:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd2d584af6bebd42d5c95c1dfd1aba61db40b80a",
          "body": "Un-export 71 symbols across the workspace that are referenced only within their\nown declaring file — helpers, config/option interfaces, and protocol member types\nthat are not part of any package's public API (none re-exported by an index, none\nimported by another module or test). The build (declarat\n[…]\nrms nothing outside each file used them. Also delete mcp's JsonValue type,\nwhich turned out to be unused in-file once un-exported.\n\nNo behavior change. Suite: 894 passing; lint/format/zero-deps clean.",
          "is_bot": false,
          "headline": "narrow visibility of internal-only symbols; drop dead JsonValue type",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:43:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee573f43af9d63f682362c952fb06c4ce6c008df",
          "body": "- Delete three symbols with zero references anywhere: mcp `ToolInputSchema` (and\n  the now-unused JsonSchema import it existed to reference), sieve `SuccessResponse`,\n  and mcp `writeLine` (a redundant helper — runStdioServer writes inline).\n- cicd: reorder the cosign subcommand alternation so `sign\n[…]\nhortening its matchLength).\n- cloud-kms: drop the redundant `CustomerMasterKeySpec` fast-reject conjunct — the\n  string contains `KeySpec`, so the earlier check already covers it.\n\nSuite: 894 passing.",
          "is_bot": false,
          "headline": "remove dead code: unused exports, redundant helper, unreachable branches",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88e41c5b8c2bcf3b1229272ac8638c5592b610b8",
          "body": "- ansible: an openssl_privatekey `type: X448` now reports algorithm X448 instead\n  of the shared XDH rule's default X25519 label.\n- database: the sslmode prefilter now also admits the `ssl_mode` (underscore) form\n  the RE_WEAK_SSLMODE regex already matches — previously the gate silently blocked\n  every underscore-only file, making that regex branch dead.\n\nSuite: 894 passing.",
          "is_bot": false,
          "headline": "ansible/database: correct X448 label and align the sslmode prefilter",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:27:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e97bc430284bbee36af0972ac10e55788f7a3487",
          "body": "An adversarial verification pass over the round 3 diff surfaced six regressions —\ninputs the test suite didn't cover. All fixed and pinned with tests.\n\n- pem: a long single-line, `\\n`-escaped key body (GCP service-account JSON,\n  `PRIVATE_KEY=\"…\\n…\"`) pushed the -----END marker past the 800-char win\n[…]\ny checked the immediate preceding\n  char, so a hardened full-suite exclusion (`HIGH:!ECDHE-RSA-RC4-SHA`) false-\n  positived. The lookbehind now walks back to the element boundary.\n\nSuite: 893 passing.",
          "is_bot": false,
          "headline": "fix regressions from the round 3 detector changes (verification pass)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:18:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ea64d43ce303938ecc04944562b4cbb461c0bb0",
          "body": "…m ids\n\n- c: the TLS-version rule now also matches TLSv1_1_method, the _client/_server\n  method variants, and SSLv2_method (previously only TLSv1_method/SSLv3_method).\n- openpgp: map the RFC 9580 (crypto-refresh) v6 public-key algorithm ids —\n  25 X25519, 26 X448 (key agreement, HNDL), 27 Ed25519, 28 Ed448 (signatures) —\n  so v6 keys classify precisely instead of falling back to a generic finding.\n\nSuite: 887 passing.",
          "is_bot": false,
          "headline": "c/openpgp: widen legacy TLS method forms and map RFC 9580 v6 algorith…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:59:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd436ab7aa4747d339a1378f1a837b8d78d3a3c6",
          "body": "…AT skips\n\nRound 3 audit follow-up on the non-detector engine (crashes, misleading output,\nsilent data loss).\n\n- triage: when capping to --max-findings, select the TOP by SEVERITY, not by\n  file-path order — a critical in a late-sorting file was dropped from triage and\n  sunk to the bottom of the re\n[…]\nT: an unverifiable vector (no seed/coins) is a SKIP, not a match — it no\n  longer inflates the \"N/N matched\" count into a false conformance pass.\n\nAdds regression tests throughout. Suite: 887 passing.",
          "is_bot": false,
          "headline": "engine: fix triage cap, CBOM merge crashes/serial, readiness order, K…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:57:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1384375b74d6a4cf3b88bccc48f95be282a877b9",
          "body": "Round 3 audit follow-up on the language packs.\n\nDouble-counts (deferrals added to jwtDetector, mirroring jose.ts):\n- A JWK object inlined in JS/TS/Py source no longer fires BOTH jwk-* and\n  jwt-classical-alg: jwtDetector skips alg tokens whose enclosing object has a\n  `\"kty\"` (jwk owns it).\n- A quot\n[…]\nx448::Secret`.\n- elixir: `:crypto.compute_key` (the (EC)DH agreement op); JOSE OKP X25519/X448 is\n  key agreement (HNDL), not an EdDSA signature.\n\nAdds regression tests throughout. Suite: 881 passing.",
          "is_bot": false,
          "headline": "source/language detectors: dedup double-counts and close FP/FN gaps",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:48:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a06ef9988a41ad4fd1d160e61d0270dbc3490bb",
          "body": "Round 3 audit follow-up on the infrastructure/config detectors. Root cause of the\nfalse positives: commentStyleForFile covers no config extension, so any config\ndetector that skipped maskCommentLines had zero comment protection.\n\nFalse positives (comment masking added; offsets preserved):\n- mesh, dn\n[…]\nno `\"` between the markers. This closes a self-regression where a PEM\nparser's paired header/footer string constants were accepted as a real key.\n\nAdds regression tests throughout. Suite: 870 passing.",
          "is_bot": false,
          "headline": "config detectors: comment masking for config formats, plus FN/FP fixes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:35:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99bdda97910f2a88d165573caf6d42cafc3cc709",
          "body": "… scoping\n\nRound 3 correctness pass. Fixes three P0 false-positive classes plus two\nregressions from the Round 2 JWK/JOSE work, and makes the shared object-scoping\nhelper string-aware.\n\n- comments: add PHP/.phtml/Scala (`.scala`/`.sc`) to the C-style comment table\n  and Ruby/Elixir (`.rb`/`.ex`/`.ex\n[…]\nlt marker.\n- keystore: accept BER indefinite-length PKCS#12 (0x80), emitted by NSS/Firefox\n  .p12 exports, alongside the long-form DER lengths.\n\nAdds regression tests for each fix. Suite: 862 passing.",
          "is_bot": false,
          "headline": "core: eliminate P0 false-positive classes and harden per-key JWK/JOSE…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:19:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4894d5ec21b5754b9fef379e7d2a6f167ec4d0d5",
          "body": "Binary pipeline (from the binary-audit): detect PKCS#12-format keystores named\n.jks/.keystore (keytool default since Java 9) and the 30 81 / 30 83 DER length\nforms; count latin1 keystore bytes at on-disk size (serial/parallel budget parity);\nisKeystorePath uses endsWith so bare dotfiles agree with t\n[…]\nssaging keeps only static-RSA\n(ECDHE owned by source); secrets defers PGP MESSAGE to pem; cfn ARM kty requires a\nMicrosoft.KeyVault marker. qprobe upgrade drops stale net listeners. Regression-tested.",
          "is_bot": false,
          "headline": "audit round 1 fixes: binary keystore/openpgp + detector precision",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:43:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "787b69f4e235f2268d6f2372e4915cd7d9781a51",
          "body": "…y_share\n\nThe TLS probe now sends a valid X25519MLKEM768 key_share (real X25519 public from\nnode:crypto + a valid-range ML-KEM-768 encapsulation key, ek||x25519 per\ndraft-ietf-tls-ecdhe-mlkem), so a supporting server selects 0x11EC directly in its\nServerHello — catching support-but-don't-prefer serv\n[…]\ntes the handshake): a ByteEncode12\nof in-range coefficients passes the encaps modulus check; the throwaway secret is\nnever computed. New mlkem768.ts, pure + unit-tested; fallback to x25519/HRR intact.",
          "is_bot": false,
          "headline": "qprobe: definitive hybrid negotiation via a well-formed ML-KEM-768 ke…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:19:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b0489d303f601b19ae20e3ca43b656825d09cc",
          "body": "Extend qprobe beyond TLS/SSH/SMTP to the other 'communication between things'\nendpoints, auto-selected by well-known port:\n- imap (:143) / pop3 (:110): line-based STARTTLS/STLS upgrade (generic\n  probeLineStartTls helper), then the same negotiated-parameter inspection.\n- postgres (:5432): send the 8\n[…]\n853) and IMAPS (:993) already work as direct-TLS probes.\nAll reuse the clean-close hang guard and cert/KEX classification. Pure builders +\nmock-server dance tested; postgres upgrade path e2e-verified.",
          "is_bot": false,
          "headline": "qprobe: add IMAP/POP3 STARTTLS and PostgreSQL SSLRequest probes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:12:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eab2897929c9c017cac4fc0bcad02bab6e79eabd",
          "body": "Single-source ownership for overlapping surfaces (audit precision findings):\n- source.ts owns SSH KexAlgorithms + ECDHE cipher tokens; removed the redundant\n  vpn net-sshd-classical-kex and mesh mesh-istio-classical-cipher rules.\n- cloudformation.ts owns crypto inside CFN/ARM templates: jwk + cloud-\n[…]\ntensions; usage-aware — a signing RSA/EC JWK is a signature\n  (hndl:false), encryption keys stay hndl:true.\n- jose: defer to jwk when the alg is inside a JWK object.\nRegression-tested; 837 tests pass.",
          "is_bot": false,
          "headline": "detectors: fix cross-detector double-counts + jwk sig/enc classification",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:05:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "caddec1ebc12b0afb5d24e180b86eb9fdf9912c2",
          "body": "Building on the byte-preserving binary read (keystore pipeline), extend it to\nOpenPGP keyrings (.gpg/.pgp/.kbx) and add an openpgp detector that parses packet\ntags: committed SECRET keys (sensitive; the sharp finding — a private key in a\nrepo), public keys, binary PGP-encrypted messages (PKESK → HND\n[…]\nPG\nkeyboxes. The public-key algorithm (RSA/DSA/ElGamal/ECDSA/EdDSA/ECDH) is read from\nthe packet body. Bounds-checked, fuzz-tested, pipeline-tested. Armored blocks stay\nwith the PEM/secrets detectors.",
          "is_bot": false,
          "headline": "detect binary OpenPGP key material and GnuPG keyboxes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:46:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d78c7dc8da074ebbed1e048fa318dc293b7a19c",
          "body": "Previously the networked probe_endpoint tool was refused unconditionally on the\nHTTP transport. Mirror the allowFs pattern instead: it is OFF by default on HTTP\nbut a trusted operator can enable it via QUANTAKRYPTO_MCP_ALLOW_NETWORK=1 (or the\nallowNetwork option). Threaded through HttpServerOptions/\n[…]\nlowFs, allowNetwork); startup banner shows probe:on/off.\nThe per-call ownership attestation and range refusal still apply on every transport.\nstdio (local, trusted) is unchanged. Docs + tests updated.",
          "is_bot": false,
          "headline": "mcp: make HTTP exposure of probe_endpoint an opt-in parameter",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:19:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3f4017158dde01b2ba766b8f4d68809fc8b2be3",
          "body": "The scan pipeline hard-skipped binary files, so keystores (private key material)\nwere invisible. Add a keystore extension set (walk.ts isKeystorePath); the serial\nand parallel scan paths now read those extensions byte-preserving (latin1) and\nexempt them from the minified skip, so a new keystore dete\n[…]\nppet dropped). Other binaries stay skipped.\nPipeline-tested end to end. Also records this session's platform work (qscan\n--cbom --merge, MCP probe_endpoint, infra Action recipe, detector-audit fixes).",
          "is_bot": false,
          "headline": "detect committed cryptographic keystores (JKS/JCEKS/PKCS12/BKS)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:13:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a8f882d02dcd2c65f7d7d2672fb603411d5b78b0",
          "body": "Exposes qProbe's live-endpoint probing to AI agents. The qprobe plane is loaded via\ndynamic import so the server stays offline until the tool is invoked, and the\nownership attestation is enforced: probe_endpoint refuses unless i_own_this=true and\nrefuses CIDR/ranges (helpful message). Errored/unreac\n[…]\nRefused UNCONDITIONALLY on the HTTP\ntransport (new NETWORK_TOOL_NAMES) — a hosted MCP must not be an arbitrary-host\nprobing oracle. mcp now depends on @quantakrypto/qprobe (internal, zero-dep intact).",
          "is_bot": false,
          "headline": "mcp: add gated probe_endpoint tool (the only networked MCP tool)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:06:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "033ef7175b340a5f9d04ffdc0eb7dcfc7d8e2321",
          "body": "…+ combined CBOM)\n\nNew example workflow showing the infra line end to end: qScan gates code + IaC on\nevery change, a weekly scheduled job probes owned TLS/SSH endpoints with qProbe\n(behind a committed ownership manifest), and 'qscan --cbom --merge' fuses the scan\nand endpoint CBOMs into one combined code + infrastructure + wire bill of materials.\nAdds an owned-hosts.example.txt manifest template.",
          "is_bot": false,
          "headline": "action: infrastructure readiness recipe (IaC scan + scheduled qprobe …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:22:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7547aaa27f7d9b0bf665a3ae9e4028c9267a379",
          "body": "… CBOM\n\nThe mergeCboms engine (core/cbom-merge.ts) existed but was unwired. Add a\nrepeatable --merge <cbom.json> flag: with --cbom it reads external CBOMs (e.g. a\nqprobe endpoint CBOM) and merges them with the scan CBOM via CycloneDX, producing\none combined code + infrastructure bill of materials. Errors (missing file, non-\nJSON, non-CycloneDX) exit 2 with a clear message. Unit + e2e tested.",
          "is_bot": false,
          "headline": "qscan: wire mergeCboms — qscan --cbom --merge for combined code+infra…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b54926228119bb179b99de832497e133fb68e28",
          "body": "…(audit)\n\nAddresses infra config-detector audit findings (my detectors):\n- ReDoS: bound the unbounded [^\\n]* / [^\\n&|;]*? spans in messaging (ssl.protocol,\n  ssl.cipher.suites) and cicd (gpg, codesign) — they blew the repo's 2s budget on\n  adversarial input. Add config-detector inputs to redos.test.\n[…]\n(the cipher rule reports the KEX harvest).\n\n(vpn sshd double-count and the cross-detector / other-agent-owned findings are left\nfor coordination — the other agent is actively remediating those files.)",
          "is_bot": false,
          "headline": "detectors: fix ReDoS, comment-masking FPs, and cipher classification …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "febabf20e71da5450bee9ea810081ee43a7c23da",
          "body": "Two new config-scope detectors closing audited gaps:\n- supply-chain: Docker Content Trust (Notary v1), CNCF Notation, in-toto signing\n  (signature-side, gated to CI/Dockerfile/shell, comment-masked)\n- vault: native HashiCorp Vault HCL transit key types (rsa-*/ecdsa-p*/ed25519) and\n  pki role key_type; gated to .hcl + a transit/pki marker so it never overlaps the\n  terraform detector (.tf)\n\nAlso records the ansible/age detectors and the qprobe hang fix in CHANGELOG.",
          "is_bot": false,
          "headline": "detect supply-chain signing and native vault hcl crypto",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T14:03:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9b4012b750a45f42998065c8852ac112d00198",
          "body": "Two new config-scope detectors closing audited gaps:\n- ansible: community.crypto openssl_privatekey/csr type RSA/ECC (comment-masked, gated)\n- age: committed AGE-SECRET-KEY-1 identity (X25519 private key) — worse than a\n  recipient; sensitive so the snippet is dropped. Closes the secrets-detector FN.",
          "is_bot": false,
          "headline": "detect ansible community.crypto keys and committed age identity keys",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T13:58:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 4,
      "commits_last_year": 254,
      "latest_release_at": "2026-07-23T05:57:13Z",
      "latest_release_tag": "v1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 2.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@quantakrypto/mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/mcp",
          "is_deprecated": false,
          "latest_version": "0.5.2",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 13,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2087,
          "first_published_at": "2026-06-22T13:45:51.286000Z",
          "latest_published_at": "2026-07-23T03:34:07.172000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@quantakrypto/core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/core",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2041,
          "first_published_at": "2026-06-22T13:45:42.443000Z",
          "latest_published_at": "2026-07-20T15:48:15.033000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/agent",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/agent",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 725,
          "first_published_at": "2026-07-03T12:32:08.324000Z",
          "latest_published_at": "2026-07-20T15:48:11.055000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/qscan",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/qscan",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1597,
          "first_published_at": "2026-06-22T13:45:48.337000Z",
          "latest_published_at": "2026-07-20T15:48:26.187000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/sieve",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/sieve",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1714,
          "first_published_at": "2026-06-22T13:45:45.289000Z",
          "latest_published_at": "2026-07-20T15:48:29.507000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/qprobe",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/qprobe",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 312,
          "first_published_at": "2026-07-19T08:12:24.768000Z",
          "latest_published_at": "2026-07-20T15:48:22.571000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 9,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/action/tsconfig.json",
        "packages/agent/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/mcp/tsconfig.json",
        "packages/qprobe/tsconfig.json",
        "packages/qscan/tsconfig.json",
        "packages/sieve/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
        "packages/core/test/benchmark/recall/go/go.mod",
        "packages/core/test/benchmark/recall/java/pom.xml",
        "packages/core/test/benchmark/recall/rust/Cargo.toml"
      ],
      "largest_source_bytes": 59062,
      "source_files_sampled": 454,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 2,
        "malicious_count": 0,
        "assessed_package": "npm:@quantakrypto/mcp@0.5.2",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/action/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/qscan",
          "manifest": "packages/action/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/qprobe",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/qprobe/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/agent",
          "manifest": "packages/qscan/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/qscan/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@noble/post-quantum",
          "manifest": "validation/sieve-real-sut/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@noble/post-quantum",
            "direct": true,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/post-quantum",
            "direct": true,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/agent",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/core",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/qprobe",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/qscan",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "anyhow",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ed25519-dalek",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "openssl",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rsa",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "x25519-dalek",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.3.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": false,
            "version": "v5.2.1",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": false,
            "version": "2.17.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.jsonwebtoken:jjwt-api",
            "direct": false,
            "version": "0.11.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcpkix-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcprov-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "ecosystem": "maven"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.21.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/eslintrc",
            "direct": false,
            "version": "3.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "2.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/ciphers",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/curves",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/action",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/mcp",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/observatory",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/sieve",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^20.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.16",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "^6.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "^6.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "8.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash",
            "direct": false,
            "version": "^4.17.21",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.merge",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-forge",
            "direct": false,
            "version": "^1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": false,
            "version": "^9.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "BouncyCastle.Cryptography",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "nuget"
          },
          {
            "name": "Newtonsoft.Json",
            "direct": false,
            "version": "13.0.3",
            "ecosystem": "nuget"
          },
          {
            "name": "System.IdentityModel.Tokens.Jwt",
            "direct": false,
            "version": "7.5.1",
            "ecosystem": "nuget"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "49.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "fastapi",
            "direct": false,
            "version": "0.110.1",
            "ecosystem": "pypi"
          },
          {
            "name": "paramiko",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "prometheus-client",
            "direct": false,
            "version": "0.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-settings",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyjwt",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyopenssl",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.2",
            "ecosystem": "pypi"
          },
          {
            "name": "structlog",
            "direct": false,
            "version": "24.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uvicorn",
            "direct": false,
            "version": "0.29.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ed25519",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "jwt",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "net-ssh",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "pg",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "puma",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rbnacl",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rspec-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rubocop",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 214,
        "direct_count": 6,
        "indirect_count": 208
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 7,
        "merged_prs": 17,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "leonacostaok",
          "commits": 248,
          "avatar_url": "https://avatars.githubusercontent.com/u/7293791?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "github-packages.yml",
        "mcp-registry.yml",
        "release.yml",
        "scorecard.yml",
        "supply-chain-audit.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 5,
            "reason": "badge detected: Passing",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool detected but not run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "52 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "409726240647384572233737a78f2a66bd9854d1",
        "ran_at": "2026-07-27T03:49:10Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T17:49:06Z",
      "oldest_open_prs": [
        {
          "number": 6,
          "created_at": "2026-07-15T07:31:01Z",
          "last_comment_at": "2026-07-23T10:16:56Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 7,
          "created_at": "2026-07-15T07:31:03Z",
          "last_comment_at": "2026-07-23T10:16:58Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 22,
          "created_at": "2026-07-21T13:54:49Z",
          "last_comment_at": "2026-07-23T10:17:00Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 23,
          "created_at": "2026-07-21T13:54:51Z",
          "last_comment_at": "2026-07-23T10:17:01Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 24,
          "created_at": "2026-07-21T13:54:52Z",
          "last_comment_at": "2026-07-23T10:17:03Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 25,
          "created_at": "2026-07-21T13:55:04Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 27,
          "created_at": "2026-07-23T00:48:07Z",
          "last_comment_at": "2026-07-23T10:17:05Z",
          "last_comment_author": "leonacostaok"
        }
      ],
      "last_merged_pr_at": "2026-07-26T17:47:26Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/quantakrypto/pqc-tools",
    "host": "github.com",
    "name": "pqc-tools",
    "owner": "quantakrypto"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 77,
        "vitality": 75,
        "community": 55,
        "governance": 43,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 254,
              "human_commit_share": 0.98,
              "days_since_last_push": 0,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "254 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 254
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 4,
              "latest_release_tag": "v1",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 2.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "4 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "forks": 0,
              "stars": 9,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "9 stars",
                "points": 14.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "@quantakrypto/mcp",
                "@quantakrypto/core",
                "@quantakrypto/agent",
                "@quantakrypto/qscan",
                "@quantakrypto/sieve",
                "@quantakrypto/qprobe"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 8476
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "8,476 downloads/month across npm",
                "points": 52.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 8476,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 39,
            "inputs": {
              "merged_prs": 17,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 14
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "17/31 decided PRs merged",
                "points": 21,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 17,
                      "decided": 31
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "quantakrypto",
              "public_repos": 4,
              "account_age_days": 34
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of quantakrypto",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "quantakrypto"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~0 yr old",
                "points": 5.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@quantakrypto/mcp",
                "@quantakrypto/core",
                "@quantakrypto/agent",
                "@quantakrypto/qscan",
                "@quantakrypto/sieve",
                "@quantakrypto/qprobe"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "13 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "crypto-agility",
                "cryptography",
                "harvest-now-decrypt-later",
                "infosec",
                "post-quantum",
                "pqc",
                "pqc-migration",
                "pqc-readiness",
                "pqcrypto",
                "q-day",
                "quantum",
                "quantum-readiness",
                "security-training",
                "encryption-strategy",
                "pqc-certification",
                "cbom",
                "mcp",
                "post-quantum-cryptography",
                "sbom",
                "nist"
              ],
              "has_wiki": false,
              "homepage": "https://quantakrypto.com/tools",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://quantakrypto.com/tools",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "badge detected: Passing",
                "points": 1.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected but not run on all commits",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "52 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@quantakrypto/mcp@0.5.2 runtime dependency closure — what installing the published package pulls in — 2 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@quantakrypto/mcp@0.5.2",
                  "assessed": 2
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 2,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 2,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.918,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/action/tsconfig.json",
                "packages/agent/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/mcp/tsconfig.json",
                "packages/qprobe/tsconfig.json",
                "packages/qscan/tsconfig.json",
                "packages/sieve/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
                "packages/core/test/benchmark/recall/go/go.mod",
                "packages/core/test/benchmark/recall/java/pom.xml",
                "packages/core/test/benchmark/recall/rust/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 59062,
              "source_files_sampled": 454,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/454 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 454,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T03:49:20.509862Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/q/quantakrypto/pqc-tools.svg",
  "full_name": "quantakrypto/pqc-tools",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.