JSON-Rohbericht maschinenlesbar
{
"data": {
"repo": {
"topics": [
"cli",
"code",
"convex",
"extension",
"nextjs",
"role-based-access-control",
"vs"
],
"is_fork": false,
"size_kb": 15085,
"has_wiki": true,
"homepage": "https://envpilot.dev",
"languages": {
"CSS": 21848,
"MDX": 509741,
"HTML": 348,
"Shell": 17209,
"Python": 28427,
"JavaScript": 17426,
"TypeScript": 4831287
},
"pushed_at": "2026-07-20T10:29:58Z",
"created_at": "2026-02-24T13:47:28Z",
"owner_type": "User",
"updated_at": "2026-07-20T09:14:55Z",
"description": "The Ultimate tool for managing and securing the Environment Variables. ",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://rafay99.com",
"name": "Abdul Rafay",
"type": "User",
"login": "rafay99-epic",
"company": "@Tudo-Tech-Lab ",
"location": "Islamabad",
"followers": 9,
"avatar_url": "https://avatars.githubusercontent.com/u/82662797?v=4",
"created_at": "2021-04-16T14:01:05Z",
"is_verified": null,
"public_repos": 64,
"account_age_days": 1926
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.43.0+311a623",
"kind": "minor",
"published_at": "2026-07-20T09:17:24Z"
},
{
"tag": "v1.43.0",
"kind": "minor",
"published_at": "2026-07-20T08:28:55Z"
},
{
"tag": "v1.42.0+82294d4",
"kind": "minor",
"published_at": "2026-07-20T07:40:36Z"
},
{
"tag": "v1.42.0+45632a8",
"kind": "minor",
"published_at": "2026-07-19T23:50:52Z"
},
{
"tag": "v1.42.0+1662e22",
"kind": "minor",
"published_at": "2026-07-19T23:22:35Z"
},
{
"tag": "v1.42.0+0817718",
"kind": "minor",
"published_at": "2026-07-19T19:50:52Z"
},
{
"tag": "v1.42.0",
"kind": "minor",
"published_at": "2026-07-19T15:13:14Z"
},
{
"tag": "v1.41.0+4bbb02e",
"kind": "minor",
"published_at": "2026-07-18T22:02:12Z"
},
{
"tag": "v1.41.0+f2543de",
"kind": "minor",
"published_at": "2026-07-18T16:15:37Z"
},
{
"tag": "v1.41.0",
"kind": "minor",
"published_at": "2026-07-18T15:42:37Z"
},
{
"tag": "v1.40.0",
"kind": "minor",
"published_at": "2026-07-18T15:37:04Z"
},
{
"tag": "v1.39.0+3e7098b",
"kind": "minor",
"published_at": "2026-07-18T14:23:30Z"
},
{
"tag": "v1.39.0",
"kind": "minor",
"published_at": "2026-07-18T10:35:03Z"
},
{
"tag": "v1.38.0+a356984",
"kind": "minor",
"published_at": "2026-07-17T23:38:03Z"
},
{
"tag": "v1.38.0+839e60a",
"kind": "minor",
"published_at": "2026-07-17T23:33:45Z"
},
{
"tag": "v1.38.0",
"kind": "minor",
"published_at": "2026-07-17T23:28:29Z"
},
{
"tag": "v1.37.0",
"kind": "minor",
"published_at": "2026-07-17T23:21:53Z"
},
{
"tag": "v1.35.0",
"kind": "minor",
"published_at": "2026-07-17T14:46:06Z"
},
{
"tag": "v1.34.3+c8527bc",
"kind": "patch",
"published_at": "2026-07-16T21:10:42Z"
},
{
"tag": "v1.34.3+312587d",
"kind": "patch",
"published_at": "2026-07-16T21:08:22Z"
},
{
"tag": "v1.34.3",
"kind": "patch",
"published_at": "2026-07-16T21:05:26Z"
},
{
"tag": "v1.34.2+dfde4fe",
"kind": "patch",
"published_at": "2026-07-16T18:38:58Z"
},
{
"tag": "v1.34.2+c2ab3d1",
"kind": "patch",
"published_at": "2026-07-16T18:05:50Z"
},
{
"tag": "v1.34.2",
"kind": "patch",
"published_at": "2026-07-16T16:06:00Z"
},
{
"tag": "v1.34.1",
"kind": "patch",
"published_at": "2026-07-16T15:51:38Z"
},
{
"tag": "v1.34.0",
"kind": "minor",
"published_at": "2026-07-16T15:25:34Z"
},
{
"tag": "v1.33.1+b54d303",
"kind": "patch",
"published_at": "2026-07-12T01:15:31Z"
},
{
"tag": "v1.33.1+b9e030d",
"kind": "patch",
"published_at": "2026-07-12T01:08:59Z"
},
{
"tag": "v1.33.1+053738d",
"kind": "patch",
"published_at": "2026-07-12T00:38:02Z"
},
{
"tag": "v1.33.1+7130477",
"kind": "patch",
"published_at": "2026-07-11T23:58:40Z"
},
{
"tag": "v1.33.1+7e70c5d",
"kind": "patch",
"published_at": "2026-07-11T22:32:36Z"
},
{
"tag": "v1.33.1+e9cc2d0",
"kind": "patch",
"published_at": "2026-07-11T21:18:31Z"
},
{
"tag": "v1.33.1",
"kind": "patch",
"published_at": "2026-07-11T21:12:32Z"
},
{
"tag": "v1.33.0+6426bca",
"kind": "minor",
"published_at": "2026-07-11T20:03:14Z"
},
{
"tag": "v1.33.0",
"kind": "minor",
"published_at": "2026-07-11T19:07:47Z"
},
{
"tag": "v1.32.0",
"kind": "minor",
"published_at": "2026-07-11T19:00:02Z"
},
{
"tag": "v1.31.0+435b07e",
"kind": "minor",
"published_at": "2026-07-11T11:09:12Z"
},
{
"tag": "v1.31.0+74f81b7",
"kind": "minor",
"published_at": "2026-07-11T09:00:36Z"
},
{
"tag": "v1.31.0",
"kind": "minor",
"published_at": "2026-07-11T08:14:24Z"
},
{
"tag": "v1.30.0+367989a",
"kind": "minor",
"published_at": "2026-07-11T00:46:27Z"
},
{
"tag": "v1.30.0",
"kind": "minor",
"published_at": "2026-07-11T00:33:47Z"
},
{
"tag": "v1.29.1+4857e19",
"kind": "patch",
"published_at": "2026-07-10T22:51:01Z"
},
{
"tag": "v1.29.1",
"kind": "patch",
"published_at": "2026-07-10T22:21:55Z"
},
{
"tag": "v1.29.0",
"kind": "minor",
"published_at": "2026-07-10T20:54:18Z"
},
{
"tag": "v1.28.2",
"kind": "patch",
"published_at": "2026-07-10T13:37:22Z"
},
{
"tag": "v1.28.1",
"kind": "patch",
"published_at": "2026-07-09T21:47:38Z"
},
{
"tag": "v1.28.0+1f9cf8f",
"kind": "minor",
"published_at": "2026-07-09T19:46:00Z"
},
{
"tag": "v1.28.0+2945131",
"kind": "minor",
"published_at": "2026-07-09T16:41:23Z"
},
{
"tag": "v1.28.0+5cbebf6",
"kind": "minor",
"published_at": "2026-07-09T16:24:47Z"
},
{
"tag": "v1.28.0",
"kind": "minor",
"published_at": "2026-07-09T16:14:10Z"
},
{
"tag": "v1.27.0",
"kind": "minor",
"published_at": "2026-07-06T08:04:18Z"
},
{
"tag": "v1.26.1",
"kind": "patch",
"published_at": "2026-07-06T02:02:22Z"
},
{
"tag": "v1.26.0",
"kind": "minor",
"published_at": "2026-07-06T01:23:07Z"
},
{
"tag": "v1.25.0+07d968b",
"kind": "minor",
"published_at": "2026-07-06T00:54:43Z"
},
{
"tag": "v1.25.0+5d6c044",
"kind": "minor",
"published_at": "2026-07-05T23:58:39Z"
},
{
"tag": "v1.25.0+58a6582",
"kind": "minor",
"published_at": "2026-07-05T23:00:08Z"
},
{
"tag": "v1.25.0",
"kind": "minor",
"published_at": "2026-07-05T21:35:34Z"
},
{
"tag": "v1.22.1+9b48c88",
"kind": "patch",
"published_at": "2026-07-05T03:06:23Z"
},
{
"tag": "v1.22.1",
"kind": "patch",
"published_at": "2026-07-05T02:59:42Z"
},
{
"tag": "v1.22.0",
"kind": "minor",
"published_at": "2026-07-04T14:58:50Z"
},
{
"tag": "v1.21.0",
"kind": "minor",
"published_at": "2026-07-04T13:56:53Z"
},
{
"tag": "v1.20.1",
"kind": "patch",
"published_at": "2026-07-04T13:31:34Z"
},
{
"tag": "v1.20.0",
"kind": "minor",
"published_at": "2026-07-04T12:46:11Z"
},
{
"tag": "v1.19.0",
"kind": "minor",
"published_at": "2026-07-03T18:03:39Z"
},
{
"tag": "v1.18.0+2162334",
"kind": "minor",
"published_at": "2026-07-03T17:58:12Z"
},
{
"tag": "v1.18.0+178eed0",
"kind": "minor",
"published_at": "2026-07-03T17:54:50Z"
},
{
"tag": "v1.18.0",
"kind": "minor",
"published_at": "2026-07-03T17:06:32Z"
},
{
"tag": "v1.16.0+5ae00db",
"kind": "minor",
"published_at": "2026-07-03T08:08:03Z"
},
{
"tag": "v1.16.0",
"kind": "minor",
"published_at": "2026-07-03T01:45:08Z"
},
{
"tag": "v1.15.1+fc9e4af",
"kind": "patch",
"published_at": "2026-07-02T20:06:00Z"
},
{
"tag": "v1.15.1+4354f36",
"kind": "patch",
"published_at": "2026-07-02T19:58:49Z"
},
{
"tag": "v1.15.1",
"kind": "patch",
"published_at": "2026-07-02T10:30:19Z"
},
{
"tag": "v1.12.1",
"kind": "patch",
"published_at": "2026-07-01T20:11:55Z"
},
{
"tag": "v1.12.0",
"kind": "minor",
"published_at": "2026-06-12T08:38:25Z"
},
{
"tag": "v1.11.0+803c0be",
"kind": "minor",
"published_at": "2026-06-08T09:33:47Z"
},
{
"tag": "v1.11.0",
"kind": "minor",
"published_at": "2026-04-22T22:36:49Z"
},
{
"tag": "cli-v1.6.1",
"kind": "other",
"published_at": "2026-04-17T18:46:17Z"
},
{
"tag": "cli-v1.6.0",
"kind": "other",
"published_at": "2026-04-16T22:14:21Z"
},
{
"tag": "cli-v1.5.0",
"kind": "other",
"published_at": "2026-04-15T19:40:06Z"
}
],
"recent_commits": [
{
"oid": "311a623aa78b20ef168b3f9e779cca4e961d0274",
"body": "…e MCP secrets (#156)\n\nContent backlog #1 and #2 from the GTM playbook:\n- 'dotenv-vault Is Deprecated — Here's Your Migration Path' (keyword:\n dotenv-vault alternative). Honest three-way comparison: dotenvx as the\n official successor, Doppler/Infisical per-seat, Envpilot flat — with a\n real 10-mi\n[…]\ndge). Facts sourced from docs/mcp-server.mdx: endpoint, five\n read-only tools, scoped keys, metadata_only, audit, rate limits, run\n injection. Dated Jul 23 per playbook cadence.\n\nblog 1.5.0 -> 1.6.0",
"is_bot": false,
"headline": "feat(blog): week-1 GTM articles — dotenv-vault migration + Claude Cod…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-20T09:14:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "42bc6702a432e091b7c7c679e159f76c4667ffe9",
"body": "* feat: MCP key scope guidance + unredacted API denials\n\nAn MCP key minted with the default scopes (variables only) failed every\ntool call, and prod redaction turned each denial into an opaque\n\"Server Error\"/500 — invisible in dev where plain Error survives.\n\n- create-key form: MCP panel maps each r\n[…]\n 'recommended' (requests/accounts-only\n keys are valid), canceled request status, transport-level 401 for\n missing bearer, request-tools denial variant, 5/hour request bucket\n in the rate-limit row",
"is_bot": false,
"headline": "MCP key scope guidance + unredacted public API denials (#155)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-20T08:20:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "82294d4f1d19d485d059c3d44ae467c02210d4c7",
"body": "* docs: reorder MCP client setup, add Codex CLI, sync CLI reference with code\n\nMCP server page:\n- Move 'Connect a client' above tool/rate-limit reference so setup is first\n- Add Codex CLI setup (codex mcp add / config.toml, bearer_token_env_var)\n- Expand Claude Code entry with scope flags and verify\n[…]\n stale 'lower roles create requests' claim, fix 'approval-aware' wording\n- cli logout: state --all partial-failure behavior instead of promising it\n always signs out every account\n\n* fixing-formating",
"is_bot": false,
"headline": "docs: MCP client setup (Codex + reorder) and CLI reference sync (#154)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-20T07:37:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45632a8879c1af4f245b66df9b0c804dfb8af2f0",
"body": "…CLI 1.19.0 reference) (#153)\n\n* docs(cli): document the 1.19.0 command surface\n\n- new sections: secrets set/rm (masked two-step flow, role routing,\n shared-environment semantics), variable requests review\n (approve/reject/cancel, --value-stdin, masked machine-request\n approval), diff (metadata d\n[…]\n+ full-page noise were layered behind body\ntext — decorative on marketing pages, hostile on a reading surface.\nDoc articles now render on a plain background; effects remain on\nnon-reading pages (404).",
"is_bot": false,
"headline": "Docs overhaul: categorized sidebar, deep rewrites, four new pages (+ …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-19T23:47:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1662e225f98b478c2b05e63ba7b54f361687f9a0",
"body": "…152)\n\n* fix(cli): run picks up variable changes; warns about other-env vars\n\nThe missing-variables bug: run cached decrypted secrets for 1h and made\nZERO server contact within that window, so a variable added/changed in\nthe dashboard was invisible for up to an hour. Root fix:\n\n- default --cache-ttl\n[…]\nith truncated/undecryptable as fields (warnings no longer\n corrupt stdout).\n- requests approve: --value rejected on a TTY (masked prompt is the\n interactive path); --value-stdin/--value stay for CI.",
"is_bot": false,
"headline": "CLI terminal-first: run fix + var/requests/diff commands (v1.19.0) (#…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-19T23:16:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0817718d4942e12980ea83990e3ac5e5600ab874",
"body": "* fix(authz): enforce membership on projects.getById and listByOrganization\n\nBoth were bare public Convex queries — callable by anyone with the\ndeployment URL, no identity check, leaking project metadata across org\nboundaries (same class as the getBySlug hole closed in #150).\n\n- getById / listByOrga\n[…]\n, and\nprojects.getById/getBySlug now hard-depend on it. Docs now state the\nreal contract: sync the users row first, one authed client per handler,\nand getProjectOrganization requires an authed client.",
"is_bot": false,
"headline": "Enforce membership on projects.getById and listByOrganization (#151)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-19T19:44:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "584daf465a1a7fab7d42d13375b4567a0ed2b008",
"body": "…e mermaid (#150)\n\n* perf(content): single-pass MDX parse with React cache() in blog and docs\n\ngetDocBySlug/getAllDocs/getPostBySlug/getAllPosts now memoize per request;\nllms-full.txt builds from getAllDocsFull() instead of re-reading every file\na second time (O(2N) -> O(N) file I/O).\n\n* chore(hygie\n[…]\nrom the\n pre-ResizeObserver measure\n\nRejected cubic finding: pulse-glow keyframe DOES exist\n(packages/ui/src/styles.css:55) and three shipped components use the\nidentical arbitrary-animation pattern.",
"is_bot": false,
"headline": "Next.js audit fixes, faster dashboard navigation, Next 16.2.10, inlin…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-19T15:04:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4bbb02ed375d59537802f097fcbfec45e0b5bac5",
"body": "…s, series support (#149)\n\n* content(blog): ten engineering posts from the PR history (blog v1.2.0)\n\nTen long-form posts, each reconstructed from the real PRs, diffs and\ncurrent source rather than summarised from titles:\n\n- the-auth-cutover #83 #84 #85 #87 #88 #90\n- deletion-tha\n[…]\n 18 engineering posts are \"Building Envpilot\", numbered by date.\n\n47 mermaid diagrams parse under 11.16; verified rendering against the\nproduction build. 27 static pages, typecheck and prettier green.",
"is_bot": false,
"headline": "Blog: 18-post 'Building Envpilot' engineering series, mermaid diagram…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T21:53:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f2543de18c7a8cda44806b9718c541b54bb8ffb7",
"body": "* ci: enable Vercel prod deploys for web, admin, blog, and docs\n\nThe GitHub Actions migration (#139) hard-disabled every Vercel deploy job\n(if: false &&) expecting Vercel's git integration to take over — but git\nauto-deploy was never enabled (all four vercel.json files still have\ngit.deploymentEnabl\n[…]\nnotes table shows real per-app\n deploy statuses instead of a static Vercel label.\n- Pin the Vercel CLI to 56.3.1 in deploy-vercel.yml so prod deploy\n behavior can't change via a silent @latest bump.",
"is_bot": false,
"headline": "ci: enable Vercel prod deploys for web, admin, blog, and docs (#148)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T16:05:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b4c587eed5404d4782a78030c1cfed51b0e8ecfc",
"body": "* feat(requests): machine-initiated variable requests + serviceTokens retirement\n\nAgents authenticated with an API key carrying the new 'requests' resource\n(the ONE mutating capability a key can have) file variable requests via\ntwo new MCP tools; a human reviewer approves in the dashboard and suppli\n[…]\name attribute — the one shape the pipeline preserves. Static import\n(build-resolved), console error + raw-source fallback instead of a\nsilent blank on render failure, StrictMode-safe fresh render ids.",
"is_bot": false,
"headline": "Machine-initiated variable requests + serviceTokens retirement (#147)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T15:38:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "889b3811e6e57c5f3d86f97c0b85fbe555ee9342",
"body": "…edentials (#146)\n\n* feat(api): one token model — surfaces field unifies Action/REST/MCP credentials\n\napiKeys gains an explicit surfaces array (github_action | rest_api |\nmcp_server); absent = grandfathered pre-surfaces key, valid everywhere.\n_authorizeRequest enforces surface scope (new surface_sco\n[…]\ny row's scope line wraps instead of truncating, so the surface\n and expiry portion of a credential's scope is never hidden\n\n* fix(ui): DrawerPanel keeps focus pinned when it has no focusable children",
"is_bot": false,
"headline": "One Token Model: surfaces field unifies GitHub Action / REST / MCP cr…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T15:33:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3e7098b5c2323aa856f119a402fd9ad1a5476084",
"body": "…g fixes (1.16.0) (#144)\n\n* feat(extension): clipboard lockdown — guard scope, cloaking, path identity\n\n* feat(extension): secret-name autocomplete + masked hover (ported from DopplerHQ/vscode, Apache-2.0)\n\n* fix(extension): sync correctness — self-write suppression, rebaseline drop, multi-root, ato\n[…]\nddress cubic review findings (PR #144)\n\n* docs(extension): add changelog for 1.16.0\n\n* docs(changelog): seed v1.49.1 entry — VS Code clipboard lockdown, cloaking, IntelliSense; drop stray CHANGELOG.md",
"is_bot": false,
"headline": "feat(extension): clipboard lockdown, IntelliSense, and 26 verified bu…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T14:19:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "209b7ecc5d4f0b082ef9e9e014faabaf82ea49c8",
"body": "…builds (#145)\n\n* feat(admin): auth cutover - WorkOS AuthKit replaces shared admin secret\n\n* feat(admin): terminal design system + primitives\n\n* feat(admin): page rebuilds - tiers tab split, QueryState everywhere, cleanup\n\n* chore(admin): version bumps (admin 1.8.0, root 1.39.0)\n\n* fix(admin): apply\n[…]\ne list served by the backend allowlist (frontend\n copy had drifted); login page explains the needs-an-account case\n\n* fix(admin): sign out returns to the admin origin, not the WorkOS default redirect",
"is_bot": false,
"headline": "Admin panel overhaul: WorkOS AuthKit, terminal design system, page re…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T10:32:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d15649c8d16d995deb01808e686c9c49438882f5",
"body": "* docs: rewrite README for the public repo — pitch users, fix stale proprietary notice\n\nThe README was written for the private monorepo: contributor-only content,\nand a License section still claiming 'This project is proprietary software'\ndirectly under the MIT badge. Now that the repo is public, th\n[…]\ned\ntable, CLI quickstart, security, open-source-vs-paid, contributing, license.\nContributor setup and repo layout collapse into a details block so the\ntop of the page speaks to users, not maintainers.",
"is_bot": false,
"headline": "docs: rewrite README for the public repo (#143)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-18T08:10:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "747527a514b910f9c6219bcf0a106f25c36555af",
"body": "…ng, badges, CI refresh) (#142)\n\n* docs: open-source contributor set — CONTRIBUTING, SECURITY, self-hosting, badges, CI refresh\n\n- CONTRIBUTING.md: how to contribute — setup, branch/PR flow, code style,\n testing, commit conventions.\n- SECURITY.md: private vulnerability disclosure (GitHub advisories\n[…]\ns\n now flow through GitHub issues.\n\n* chore: remove .plans/ — internal planning notes, not needed in the open-source repo\n\n* chore: remove tracked .vscode/settings.json (empty) and gitignore .vscode/",
"is_bot": false,
"headline": "docs: open-source contributor set (CONTRIBUTING, SECURITY, self-hosti…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T23:41:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a356984c826598d5412321689c01daf1eeab877d",
"body": "The platform is now MIT-licensed and public on GitHub (#138). Surface it\nwhere buyers evaluate trust: a proof-bar 'open source · MIT' badge, a Star\non GitHub CTA in the 'Built in the open' section (which finally links real\nsource), a hero mention, a footer Source link, and a dedicated FAQ entry.\nAls\n[…]\n— no longer true. Adds github to SITE_URLS as the single source\nfor the repo URL, and extends landing.spec.ts to lock the new links + schema.\n\nWeb 1.48.0 -> 1.49.0 (versions.ts manifest kept in sync).",
"is_bot": false,
"headline": "feat(web): showcase open source on the landing page (#140)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T23:33:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "839e60a901f0653914438b569c53860f25b42493",
"body": "… (#141)\n\nThe GitHub Actions convex-deploy seed loop was missing seed-role-registry\nand migrate-roles (added for the Role Registry release, and present in the\nold CircleCI loop). After the CircleCI->GitHub migration, a fresh deploy\nwould stop syncing the dynamic role system and every role would reso\n[…]\nd-tier-features, seed-role-registry,\n migrate-roles, seed-changelog\n\nSo one deploy auto-syncs feature gates, tier overrides, the role registry,\nand the website changelog — no manual admin-panel step.",
"is_bot": false,
"headline": "ci(convex): seed role registry + migrate-roles on every GitHub deploy…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T23:31:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44c65883a739bf51e23bac9a88be914a03dad2c3",
"body": "…n floors raised (#131)\n\nPhase 2 of registry hardening. The registry-native builds are the new\nminimum: minCli 1.18.0, minExtension 1.15.0 (first builds calling the\nreal features/* Convex paths and consuming capability-driven roles).\n\n- delete all 11 legacy root convex/<module>.ts compat shims — no\n\n[…]\n@envpilot/cli 1.18.0 (blocked on new NPM_TOKEN in CircleCI)\n2. Open VSX has envpilot 1.15.0 (publish fixed by #129, unverified)\nSetting a min above a published, installable version is a total lockout.",
"is_bot": false,
"headline": "feat(platform): retire legacy client fallback — shims deleted, versio…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T23:24:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c058de9e46e3d1297afa312022396569db43489",
"body": "Envpilot is open source now, so GitHub Actions minutes are free and the\nwhole pipeline moves back to it.\n\n- ci.yml: restore the real trigger (push:main + pull_request), keeping\n workflow_dispatch. Quality gate + per-surface builds + main-only\n deploys (convex, vercel web/admin, cli, extension, hom\n[…]\nI stubs,\n doc Bearer snippets) so only real credentials fail the gate. Full\n history was swept clean once at open-sourcing; no real secrets found.\n\nRepo stays private until a separate explicit flip.",
"is_bot": false,
"headline": "ci: migrate from CircleCI to GitHub Actions; add gitleaks guard (#139)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T23:16:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9240c45ed88134007c5727be941887aaa8dd440a",
"body": "Syntax Lab Technology open-sources Envpilot; Rafay is the developer.\n\n- Root LICENSE: proprietary -> MIT\n- apps/cli, apps/vscode-extension LICENSE: proprietary -> MIT\n- apps/web, apps/admin: add MIT LICENSE\n- package.json license: UNLICENSED/SEE-LICENSE -> MIT across root, web,\n admin, cli, extension; author set to Rafay (Syntax Lab Technology)\n- GitHub Action package already MIT (unchanged)\n\nCopyright (c) 2026 Syntax Lab Technology and Rafay",
"is_bot": false,
"headline": "chore: relicense the monorepo under MIT (open source) (#138)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T23:12:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "348c18b3660fbe30b97da77037dc1f8b947f5354",
"body": "…ead bytes (#137)\n\nPrints sha256 + client_ counts for dist/extension.js, its sourcemap, and\nthe unzipped VSIX bundle, then exits before publish. Temporary — reverted\nonce the real discrepancy is identified.",
"is_bot": false,
"headline": "ci(debug): forensic dump in extension package step — stop guessing, r…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T22:25:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0fb7cceb57fda563603c284f773e51da763fe3c",
"body": "…d it (#136)\n\nTHE actual root cause of every 'client id not in vsix' failure, from the\njob log: the value was provably in dist/extension.js AND the VSIX bundle\nwas checksum-identical to that dist — yet the embed grep failed. The\ngrep ran against $(unzip -p ...) captured into a shell variable; Linux\n\n[…]\nPES unzip|shasum.\n\nThe check now streams unzip -p | grep, exactly like the checksum pipe —\nbyte-exact, no variable. The build was correct all along; only the\nverification was reading a corrupted copy.",
"is_bot": false,
"headline": "fix(ci): stream the VSIX bundle into grep — variable capture truncate…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T22:13:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "173d46ba51c2eb5e886ba68222558c963d23ff38",
"body": "The standalone verify step failed 'client id not in vsix' while the\npackage step in the SAME job proved the id was in dist and the VSIX\nbundle was checksum-identical to dist — the two steps were reading\ndifferent env values for the same variable. The check now runs in the\nsame shell that bakes the v\n[…]\name bytes, one truth.\n\nOn failure it prints value lengths and sha8 prefixes (never values) and\nwhich dist files contain the value, so any recurrence names the\nmismatch instead of presenting a mystery.",
"is_bot": false,
"headline": "fix(ci): extension embed verification moves into the build shell (#135)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T22:06:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "761888717bc83759f96308add2fce7cb54534c4b",
"body": "…ist (#134)\n\nThe EXT_PREBUILT env flag traveled through the same vsce-spawned npm\nchain that scrubs env on the CI image — the very bug that produced empty\nclient ids. The hook never saw the flag, rebuilt without env, and wiped\nthe good dist, so the embed verification kept failing.\n\nThe CI step now d\n[…]\nur-back is named explicitly instead of surfacing as a\nmystery embed failure.\n\nVerified locally with env -i (fully scrubbed env): marker survives,\nchecksums match, marker self-cleans, VSIX excludes it.",
"is_bot": false,
"headline": "fix(ci): file marker replaces env flag for the extension's prebuilt d…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T21:53:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "667fac334323c5e67ef29a55cb210bc490e59287",
"body": "…son (#133)",
"is_bot": false,
"headline": "fix: prettier formatting on extension prepublish script and package.j…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T21:38:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3a185d40489947d55d34cbb81285f4baef924f91",
"body": "…'s nested npm chain (#132)\n\npublish-extension failed its embed verification (client id absent from\nthe VSIX) even though the same project env vars passed the CLI job's\nidentical check. The CLI builds directly in the step shell; the\nextension rebuilt inside vsce's spawned npm chain, where the env di\n[…]\nust-built dist instead of\nrebuilding. Local vsce usage is unchanged (no flag = full chain).\n\nVerified locally: marker env values embed and survive into the VSIX\nthrough the exact new command sequence.",
"is_bot": false,
"headline": "fix(ci): build the extension in the step shell — env never risks vsce…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T21:33:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02fb40e62b0f6ae8f2ca4d0b5212c05fea9bdece",
"body": "…dmin panel (owner locked) (#130)\n\n* feat(rbac): merge-seed + system-role capability unlock (owner stays locked)\n\nPhase 1 of registry hardening. Granting a new feature's capability to a\nsystem role no longer requires a code edit.\n\n- seed-role-registry: system-role capability matrices now MERGE — key\n[…]\n of reading as 'no changes'\n- merge filter checks catalog membership only ('key in' walked the\n prototype chain and admitted junk keys like toString)\n- capability-matrix intro copy matches the unlock",
"is_bot": false,
"headline": "feat(rbac): merge-seed — system-role capabilities editable from the a…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T21:25:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d3e4985f8933dae9ffe9fcbd144c902dddd1fe65",
"body": "…mpt hangs CI (#129)\n\nvsce package warns when no LICENSE file exists and waits on an\ninteractive y/N confirmation; CircleCI has no TTY, so publish-extension\nstalled until the 10-minute no-output timeout. Same proprietary license\ntext the CLI already publishes.",
"is_bot": false,
"headline": "fix(extension): ship LICENSE in the VSIX — vsce's missing-license pro…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T21:06:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "340b39dc5c7d09d155dc02c82c7f2bff01aaca8d",
"body": "* feat(rbac): role registry core — capability catalog, profiles, resolver, authz rewire\n\nRoles become data; capabilities stay code. The Feature-Registry pattern\napplied to RBAC:\n\n- convex/lib/capabilities.ts: the ~30-key capability catalog with\n metadata, plus ORG/PROJECT_ACTION_TO_CAPABILITY compa\n[…]\nty per distinct slug\n before the fan-out (memo no longer races inside Promise.all)\n- system slugs reserved in createRole (pre-seed shadowing blocked);\n updateRoleMeta authenticates before validating",
"is_bot": false,
"headline": "feat(rbac): Role Registry — roles as data, capabilities as code (#128)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T20:51:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "243f7e2138fc851372b71c8e7d74b8fc4bab1b62",
"body": "…ounder strip, FAQ + free-tier seed alignment (#125)\n\n* feat(web): problem-first landing hero + free-tier CLI/extension seed alignment\n\n- Hero H1 leads with the pain point (\"Stop pasting .env files into Slack.\");\n subline states surfaces + free-tier promise\n- Final CTA gets a new closer so the page\n[…]\n testimonial grid\nrenders only when TESTIMONIALS has real, permissioned entries — avatar\ninitials, name linking to the source, role, quote.\n\n* fix(web): trust section contact email -> ceo@envpilot.dev",
"is_bot": false,
"headline": "feat(web): landing conversion pass — problem-first hero, proof bar, f…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T14:37:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d908d4ff8e63dfbd7451723938d2d2d477881c4f",
"body": "…, audit; restore 7 broken extension paths (#124)\n\n* feat(convex): unsync-on-close flags, pro gate, cascade resolution, unsync audit\n\n- projects.vscodeAutoUnsyncOnClose + projectMembers override (absent = secure default ON)\n- feature registry: vscode_unsync_customization (free false / pro true)\n- pr\n[…]\ntup sync pipeline starts only in trusted windows; granting trust\n (onDidGrantWorkspaceTrust) starts it immediately without a reload\n\n* docs(changelog): v1.46.0 — VS Code unsync-on-close release entry",
"is_bot": false,
"headline": "feat: VS Code unsync-on-close — hash-guarded purge, pro-gated toggles…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-17T12:36:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c8527bccd6b75f94ad3bcff216b49264d750602c",
"body": "…omplete (#123)\n\nAdd searchInProject query that walks a project's entire active variable set\n(bounded) and matches key/description substring + tag names in memory, reusing\nlistWithAccessPaginated's exact access model (resolveProjectAccessContext +\nmapVariableRow) so a hit never surfaces a variable t\n[…]\n the paginated list unchanged.\n\nRemove the dead, access-leaking `search` query (org-wide, no access filtering,\ntake-cap dropped newest rows) and its unused useVariableSearch hook.\n\nBump web to 1.45.0.",
"is_bot": false,
"headline": "feat(web): per-project variable search — server-side, access-aware, c…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T20:58:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "312587d1d8113f80b99c454ca877e4c300e63fee",
"body": "…ge (#122)\n\n* feat(web): move Variable Requests to its own project page\n\nReplace the inline Variable Requests card at the bottom of the project\nvariables page with a dedicated /dashboard/projects/[slug]/requests\npage, reachable from a new sidebar item with a pending-count badge.\n\n- New convex query \n[…]\nsidebar badge.\n- NavItem/NavLink gain an optional badge pill, shown only when > 0.\n- apps/web bumped to 1.43.0 (feature); versions.ts APP_VERSIONS.web matches.\n\n* chore: web 1.44.0 (stacked on 1.43.0)",
"is_bot": false,
"headline": "feat(web): Variable Requests get their own project page + sidebar bad…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T20:57:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8586a745e091806f3304c40c409195ea4b773011",
"body": "…ycle + request notifications (#121)\n\nSharing:\n- Convert every user-facing throw in sharing mutations/share action to\n ConvexError so messages survive prod redaction; classify share routes via\n sanitizeConvexError instead of error.message (expired/burned/revoked/\n locked-out/invalid-OTP now map t\n[…]\nster on approve/reject\n (scheduled, best-effort, dev-safe when RESEND is absent).\n\nweb 1.42.1 -> 1.43.0 (+ versions.ts), root +patch. Extend share e2e with a\ndelete-cascade -> reveal-fails assertion.",
"is_bot": false,
"headline": "fix(sharing,requests): ConvexError-based error handling + share lifec…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T20:56:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dfde4fe2942601b0265d2174610fbb0be1b032f8",
"body": "…omain rules) (#120)\n\nCLAUDE.md rebuilt: removes the obsolete command-code subagent section and\nall GitHub-Actions-era CI prose; adds CircleCI pipeline v2 (dynamic\nconfig, quality-first, main-only deploys, force params, validate-before-\npush rule), per-environment variable-key uniqueness as a critic\n[…]\nligned (new apps, CircleCI, Vercel git-integration\nOFF); FEATURES gains the per-env uniqueness rule; ROADMAP + SECURITY-TODO\nget dated status headers; e2e README clarifies Playwright never runs in CI.",
"is_bot": false,
"headline": "docs: align every doc with current reality (pipeline v2, multi-app, d…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T18:30:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c2ab3d10788987db1d134e9edd8506cf293eac2c",
"body": "… gated deploys (#119)\n\nSetup phase (config.yml): a ~15s detect job diffs the push (main: the\nmerge; branches: vs merge-base with main), maps paths to surfaces\n(convex/web/blog/docs/admin/cli/extension/action; packages/ui fans out\nto the three Next sites; root manifests/.circleci fan out to all), OR\n[…]\nd). Deploys can never\nrun from a branch. Manual control via pipeline parameters\n(force-<surface>, run-everything) from the UI or API.\n\nValidated offline: setup config + 6 generated-workflow scenarios.",
"is_bot": false,
"headline": "ci: pipeline v2 — dynamic per-surface workflows, quality-first, fully…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T17:57:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc99647e2d6ef480158b2249d7b8d6d3a7730869",
"body": "…eness (#118)\n\nA same-key variable (re)created while the original sat in the trash made\nrestore resurrect a clashing copy — two active variables in the same\nenvironment, nondeterministic pulls. Restore now runs the same\nfindEnvironmentConflicts check as create/update and rejects with the\nclashing en\n[…]\npecific\nduplicate message into 'already exists in this project' — that wording\nis now wrong (same key IS allowed in a different environment) and hid\nwhich environment clashed. Web 1.42.1, root 1.34.2.",
"is_bot": false,
"headline": "fix(variables): restore from trash re-validates per-environment uniqu…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T16:01:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "facf21ad908ff325f6e655cf25970f5788b836f6",
"body": "…ty + vault orphan fix (#117)\n\n* fix(variables): surface real errors in prod + stop vault orphans on duplicate import\n\nBulk-importing env vars in production showed 'Server Error' per row and\nleaked an orphaned WorkOS Vault secret for every duplicate key.\n\nRoot causes:\n1. The duplicate-key rejection \n[…]\nlit + CircleCI); web 1.42.0, root 1.34.1\n\n* ci(circleci): version-tracker comment failures warn-and-skip (advisory job)\n\n* ci(circleci): drop version-tracker job (low value, kept causing PAT friction)",
"is_bot": false,
"headline": "feat(variables): per-environment key uniqueness + prod error visibili…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T15:47:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9eeb1fa94e1f1d3ff6cf637c3269000f0747d8ed",
"body": "…s.envpilot.dev) with shared @envpilot/ui (#116)\n\n* feat: static MDX blog — disk-based, Zod-validated, search + tag filtering\n\nBlog posts are stored as MDX files in apps/web/content/blog/, parsed with\ngray-matter and validated at build time via a Zod frontmatter schema.\nThe listing page at /blog fea\n[…]\nSX tokens — first merge no longer fails on the not-yet-minted\nOPEN_VSX_TOKEN.\n\n---------\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: split blog + docs into standalone apps (blog.envpilot.dev / doc…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-16T15:23:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b54d303deecc5337b94d950e256410b9a5846770",
"body": "…y jobs (#115)\n\nFree-tier Actions minutes nearly exhausted 12 days into the cycle. Per-PR cost was ~13 jobs, each billed as a rounded-up minute with its own checkout+install (~15 billed min/push). Changes: (1) 8 check jobs (format + 6 per-package + convex) merged into one consolidated job — setup pa\n[…]\n cold, ~2-3 warm. Deploy pipeline, e2e gate wiring, and the 'All checks passed' required-check name untouched. No branch protection references the removed job names (verified — branch is unprotected).",
"is_bot": false,
"headline": "perf(ci): minutes diet — consolidate checks, cache turbo, gate PR-onl…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-12T01:06:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b9e030d80ca9f719405266a5ee43c0f4aacc4040",
"body": "… on deploy (#114)\n\n12 new changelog entries covering everything shipped since v1.27.0: vault GC/trash, auth overhaul (device flow, server-verified identity, backend vault crypto), version enforcement, Homebrew, Pro plans go-live, GitHub Action + service tokens, public REST API + MCP server, securit\n[…]\nage revamp, billing UX, launch + welcome email. seed-changelog added to the deploy-convex seed loop so the website changelog updates automatically on every deploy (idempotent upsert by version+title).",
"is_bot": false,
"headline": "feat: changelog refresh — July release wave (v1.28–v1.40) + auto-seed…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-12T01:03:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "053738d2aeb867d38957a1ca0ddfbb163f634f9b",
"body": "* feat: sync users to Loops.so marketing audience (web v1.41.0)\n\nNew signups are upserted as Loops contacts (email, first/last name, userId, source app-signup) via a scheduled internal action on the users.upsert insert branch — same seam as the welcome email, fires once per user. backfillContactsToL\n[…]\nrcel.json). Caveat documented in ci.yml: git auto-deploy loses the strict backend-first ordering (web can go live before deploy-convex finishes).\n\n* revert: drop web version bump — backend-only change",
"is_bot": false,
"headline": "feat: sync users to Loops.so marketing audience (web v1.41.0) (#113)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-12T00:32:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7130477dfa3de1e6d5e94a434cbc2a91a674f253",
"body": "* chore(scripts): add one-off launch email sender (Gmail SMTP)\n\n* feat: welcome email on first signup via Resend (web v1.40.0)\n\nNew users (free tier by default) now receive a personalized welcome email on their first sign-in. sendWelcomeEmail internalAction follows the existing dark-theme template s\n[…]\nexactly once per user regardless of which API route triggers creation. Falls back to 'there' greeting when WorkOS provides no name. DISABLE_EMAILS kill-switch and FROM_EMAIL config respected for free.",
"is_bot": false,
"headline": "feat: welcome email on first signup via Resend (web v1.40.0) (#112)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T23:54:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7e70c5d128c96631ff7ba02e4937a56e86c922c3",
"body": "…links + alpha badge retired (web v1.39.0) (#111)\n\n* feat(web): billing management UX — required cancel feedback, portal links, alpha badge retired (web v1.39.0)\n\n- Cancellation reason now REQUIRED (server zod + UI: Confirm disabled until\n selected) — feedback lands on the Polar subscription\n (cus\n[…]\ns 7.2/7.3: portal availability + cancellation-reason disclosure\n- Privacy 3.5: cancellation feedback recorded with the payment processor\n\n* chore(web): bump terms/privacy last-updated to July 12, 2026",
"is_bot": false,
"headline": "feat(web): billing management UX — required cancel feedback + portal …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T22:28:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e9cc2d0cd3c52724cffa28d1a2b47c4ab1872bf9",
"body": "…errors (web v1.38.1) (#110)\n\n* fix(web): friendly duplicate-variable-key feedback, no raw Convex errors (web v1.38.1)\n\n- sanitizeConvexError strips REPEATED 'Uncaught Error:' prefixes — actions\n re-throwing a mutation's error double-wrap it, and the single strip leaked\n 'Uncaught Error: Variable \n[…]\nrms\n- e2e: duplicate-variable-error.spec.ts drives the real drawer, asserts the\n friendly message and the absence of raw 'Uncaught Error' text\n\n* chore: merge main (perf wave 1), rebump web to 1.38.2",
"is_bot": false,
"headline": "fix(web): friendly duplicate-variable-key feedback, never raw Convex …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T21:09:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab4517336736abef807b7762aaf30ed44a09d600",
"body": "* perf: cut Convex function calls and DB I/O (wave 1)\n\nBackend:\n- getOrgTiersBatch: lean tier-name-only sibling of getResolvedFeaturesBatch\n (~4 docs/org vs ~60); /api/auth/me and the dashboard layout use it\n- tierDefinitions.by_default index: getDefaultTierName point-read instead of\n whole-table \n[…]\nad of being\nreplaced by the normalized one from the route — normalize it at the\nsource for parity. All current consumers already normalize on read; this\nremoves the trap for the next one that doesn't.",
"is_bot": false,
"headline": "perf: cut Convex function calls and DB I/O — wave 1 (web v1.38.1) (#109)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T21:07:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6426bca265f37a6f930b32e687861cdeb3f7a53f",
"body": "* feat(web): revamp usage page — plan strip, alert zone, grouped quotas, plan-feature grid (web v1.38.0)\n\n* fix(web): responsive wrap on usage plan strip/alert/info bar; singular alert grammar; CLAUDE.md: developer runs full e2e suite",
"is_bot": false,
"headline": "feat(web): revamp organization usage page (web v1.38.0) (#108)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T19:59:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "064e95e7d43565cc7c9a037c5f6a21b16572716c",
"body": "…) (#107)\n\nThe trash UI was a collapsed 'Recently deleted' section buried at the\nbottom of the project page. Now a dedicated page at\n/dashboard/projects/[slug]/trash, linked from the project header next to\nCompare/Members (visible to roles that can delete variables):\n\n- Variables and shared accounts\n[…]\nomponent deleted; trash-restore e2e spec updated to\n drive the new page + a new empty-trash round-trip spec (safe: each\n worker owns its fixture project).\n\nRoot bump 1.31.0 -> 1.32.0 (web + convex).",
"is_bot": false,
"headline": "feat(web): dedicated project trash page with empty-trash (web v1.37.0…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T19:01:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "70855af6b37b090d63e8a0fd29c68449ba1b0961",
"body": "….36.0, cli v1.17.0, ext v1.13.0) (#106)\n\n* feat: security hold (suspend member access) + removal exit UX (web v1.36.0)\n\nNew pro feature 'security_hold': freeze an org member's access org-wide\nwithout removing them — for compromised-device incidents. Membership,\nrole, project assignments, and grants\n[…]\nevocation-event subscriptions are\n user-scoped so a suspended user who re-signs-in still receives the\n unlink+delete events; the suspended message doesn't false-match the\n session-expired regex.",
"is_bot": false,
"headline": "feat: security hold (suspend member access) + removal exit UX (web v1…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T18:54:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "435b07eb747e2e709e497756ac4737771e57d3b4",
"body": "* ci: manual Vercel deploys triggered after Convex (backend-first)\n\nVercel's git integration auto-deployed web + admin on every push to\nmain, racing ahead of the Convex deploy — a frontend calling functions\nthat weren't live yet. Now:\n\n- apps/web/vercel.json + apps/admin/vercel.json disable auto-dep\n[…]\nurpose: provide terse/caveman communication modes, token-saving compression tooling, review/commit helpers, and validation/safety checks (sensitive-file denylist, 500KB limit, Anthropic/CLI fallback).",
"is_bot": false,
"headline": "ci: manual Vercel deploys triggered after Convex (backend-first) (#105)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T11:04:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "74f81b7fef8e877b572c5432d258ddfbe81e234d",
"body": "…104)\n\n* fix(extension): purge synced .env files on uninstall (ext v1.12.0)\n\nSynced .env files (plaintext secrets) survived extension uninstall\nforever — nothing in VS Code purges them, and deactivate() must never\ndelete (runs on every shutdown; caused data loss once).\n\nFix: vscode:uninstall hook + \n[…]\nshared/org machines — VS Code cannot clear SecretStorage during\nuninstall (microsoft/vscode#123817), so sign-out is what removes stored\ncredentials; admins can also revoke device sessions server-side.",
"is_bot": false,
"headline": "fix(extension): purge synced .env files on uninstall (ext v1.12.0) (#…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T08:56:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "660455e191d81674b52a93c7ac606a8efc4871b7",
"body": "….35.0) (#103)\n\n* docs(api): quickstart, REST reference, MCP setup, Action guide, security model (Phase D)\n\nFive MDX pages in the existing file-based docs system (content/docs +\nnext-mdx-remote — nothing stored in Convex), registered in the docs index\nwith icons. Documents the /api/v1 endpoints, fil\n[…]\nuces an expiry badge); row locators scoped to the list container so the\ntoast's own <li> (which now contains the key name) can't cause strict-mode\nmatches. Full suite 72 passed / 4 skipped / 0 failed.",
"is_bot": false,
"headline": "feat: public REST API + MCP server + API keys platform + docs (web v1…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T08:09:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "367989a5dee890360dd4568e06a6cf79210e398b",
"body": "* ci: GitHub Action check + publish pipeline (deploy-action)\n\nThe action package had no CI linkage: nothing built/tested it on PRs, and\npublishing to the public repo was manual-only. Now:\n\n- changes job gets an `action` path filter (packages/github-action/**);\n check-action builds/lints/typechecks/\n[…]\ndating the package. Annotated in-workflow: the action is\ntag-pinned (deploy-action publishes + moves the floating v1) with no\n/api/version manifest entry — bumps are manual and each bump IS a\nrelease.",
"is_bot": false,
"headline": "ci: GitHub Action check + publish pipeline (#102)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T00:41:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0943fb0f7f6fa738d6caa45491750d2635b1a57e",
"body": "… (#101)\n\n* feat(cicd): service tokens + GitHub Action secret pulls (web v1.34.0)\n\nEnvpilot's first machine identity: long-lived, READ-ONLY service tokens\nscoped to one project + explicit environment list, consumed by the new\nGitHub Action to pull env vars into CI — one revocable secret in GitHub\nin\n[…]\nropped the tr -d '[:space:]',\nwhich would itself have corrupted secrets containing spaces (command\nsubstitution already strips the trailing newline). Same fix applied to\nscripts/convex-local-setup.sh.",
"is_bot": false,
"headline": "feat(cicd): service tokens + GitHub Action secret pulls (web v1.34.0)…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-11T00:28:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4857e19a9c9dbece0fad7d5cdcb0520f54174ac2",
"body": "…xt v1.11.0) (#100)\n\n* perf(web): stop the app-wide getExtendedUsage subscription (v1.33.3)\n\ngetExtendedUsage reads up to ~2000 variable docs plus full per-project\nscans for shares, rotation variables, and shared accounts. It was\nsubscribed by useTierStoreSync, which the global dashboard nav mounts \n[…]\nplicate subscriptions\" (Convex client dedupes\nidentical query+args).\n\nVerified: check:all green; extension build/lint/typecheck/test 45/45;\nfull e2e suite 44 passed / 3 self-skipped / 0 failed (1.6m).",
"is_bot": false,
"headline": "perf: Convex Database I/O reduction + CI e2e gate off (web v1.33.3, e…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-10T22:45:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c4eeab101d4c60a3f4deecbe615df19c7be5f2d",
"body": "…33.2) (#99)\n\n* fix(billing): production-harden the Polar gateway (v1.33.2)\n\nPre-live-transaction hardening of the entire payment path, fixing every\ncritical/high finding from the billing audit:\n\nTRUST BOUNDARY (critical)\n- processWebhookEvent now requires a bridgeSecret checked constant-time\n agai\n[…]\nas a\nduplicate, permanently dropping the payment event. The release now has its\nown try/catch (loud console.error including the webhook id for manual\ncleanup) and the original error always propagates.",
"is_bot": false,
"headline": "fix(billing): production-harden the Polar gateway before go-live (v1.…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-10T22:13:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "baac0856df26bab186468cb7b085fa401406a19f",
"body": "…ast + retrying assertions (#98)\n\n* test(e2e): filter Vercel Analytics 404 + fix ambiguous usage-meter selector\n\nThe prod-build e2e run failed the zero-client-errors specs on a\n/_vercel/insights/script.js 404 — Vercel Web Analytics' script is served\nonly by Vercel's edge in real production, so a loc\n[…]\neave\ndebris with no signal in the report. Each skip is now console.warn'd and\nattached to the setup result as a warning annotation; the sweep still never\nfails the run over them (they retry next run).",
"is_bot": false,
"headline": "fix(e2e): unblock suite from tier-cap debris — pre-run purge + fail-f…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-10T20:45:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a0b891817ff0a67fa5439a5c147a7b7ca5890f64",
"body": "…ld (#97)\n\nRoot cause of the main e2e gate failure (run 29100933255): a Convex query\nfired before the WorkOS JWT was attached to the socket, throwing the\ntransient 'Unauthenticated: no verified user identity'. Strict specs count\nthat console error as a failure. Barely visible locally, it dominated C\n[…]\natches what ships. Local runs unchanged (reuse the dev server).\n- search-projects-org: waitForURL inner timeout 3s -> 5s (it's the\n click-retry cadence inside a 20s .toPass, not the assertion bound).",
"is_bot": false,
"headline": "fix(e2e): eliminate pre-auth Convex query race + run gate on prod bui…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-10T15:44:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "647b9076844727b31d4a7e067d9f9aac7e784097",
"body": "…(#96)\n\n* feat(ci): e2e deploy gate, strict deploy ordering, Node 22\n\n- New e2e job on main pushes: deploys the new convex functions to an\n isolated e2e deployment, runs the full Playwright suite (1 worker,\n 2 retries), and BLOCKS every deploy when it fails. Fails loudly when\n the e2e secrets are\n[…]\nright.config.ts already applies both when CI is set, but the gate's\nserial-run + retry contract now lives at the callsite too, so a config\nrefactor can't silently reintroduce the parallel-load flakes.",
"is_bot": false,
"headline": "feat(ci): e2e deploy gate, strict deploy ordering, Node 22 (v1.29.0) …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-10T14:43:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1dc1d1f2011431341b00c09b84b3d4f8e37be46",
"body": "…emoval (v1.28.2) (#95)\n\n* refactor(convex): extract shared helpers into convex/lib with compat barrels\n\n- lib/identity.ts, lib/users.ts, lib/rateLimits.ts, lib/audit.ts,\n lib/authHelpers.ts, lib/authz.ts, lib/roleCompat.ts\n- registered queries getMyPermissions + resolveLegacyRoles move to\n featur\n[…]\nonolith, verified against d116ad5), surfaced by Greptile\nreview; break instead falls through to the shared record-processed step.\nFailure paths still skip recording so Polar retries can succeed later.",
"is_bot": false,
"headline": "refactor(convex): feature-based backend structure, dedup, dead-code r…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-10T13:33:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ea40452e3f9154a1ea1ef908931ac576badd406",
"body": "…(#94)\n\n* fix: resolve Sentry issue backlog across web/cli/extension (v1.33.1, cli 1.15.1, ext 1.9.1)\n\nWeb (@envpilot/web 1.33.1):\n- error-messages: isTierLimitError matched neither actual backend wording\n ('Limit reached (n/m). Upgrade your tier' / 'requires a higher tier') —\n expected tier-limit\n[…]\nirect shape gets the session-expired\n message; other non-JSON responses report their status (P2)\n- console-health spec: replace fixed 3s settles with networkidle + 1s\n grace (saves ~6s per run) (P2)",
"is_bot": false,
"headline": "fix: resolve Sentry issue backlog across web/cli/extension (v1.33.1) …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-09T21:43:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f9cf8fe617c17f53f522c0880bea66aa3f1f383",
"body": "* feat: auth error boundary with dedicated error page\n\n- AuthErrorPage component: terminal-themed full-page error with\n collapsible details, Try Again / Sign In Again links, and\n contact support section (syntaxlabtechnology@gmail.com)\n- AuthErrorBoundary: client-side ErrorBoundary that detects\n a\n[…]\n\n- handleRetry clears any pending auto-retry timer so a manual retry can't race\n a deferred setState against a freshly-caught error\n\n---------\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
"is_bot": false,
"headline": "feat: auth error boundary with dedicated error page (v1.33.0) (#93)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-09T19:42:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2945131a0a74bb45322d23266ab55dd55a2b0cbc",
"body": "The npm registry strips the scope from tarball filenames for scoped\npackages. @envpilot/cli publishes to .../cli-{version}.tgz, not\n.../envpilot-cli-{version}.tgz. The old URL caused every Homebrew\nformula fetch to 404.\n\nThis fix was on PR #92 but only the retry commit made it in — the\nURL fix commit was orphaned during merge. Cherry-picking now.\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
"is_bot": false,
"headline": "fix: correct npm tarball URL for scoped packages",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-09T16:39:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5cbebf6527a38c6b395ee72979e66c9cbf1fd5e7",
"body": "The npm registry can return 404 for up to ~45 seconds after publish\ndue to CDN propagation. The single-shot curl -fsSL was failing with\nexit code 22, causing the entire deploy-homebrew workflow to error out.\n\nNow retries 5 times with exponential backoff (3, 6, 9, 12, 15 s —\n~45 s total) before giving up. Uses a temp file for the download to\navoid piping issues with set -euo pipefail.\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
"is_bot": false,
"headline": "fix: retry npm tarball fetch on 404 (propagation delay) (#92)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-09T16:23:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "17cc02d3efc8f18d7484b407c8fa2a35ee5091c8",
"body": "* feat(cli): Homebrew distribution via existing homebrew-apps tap\n\nAdds a formula generator script and CI workflow that publishes the\nenvpilot CLI formula to the existing rafay99-epic/homebrew-apps tap\nwhenever a new version is published to npm. The monorepo stays private\n— only the npm tarball URL \n[…]\n\nof raw ${{ inputs.version }}, preventing injection from workflow_dispatch.\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>\n\n---------\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
"is_bot": false,
"headline": "feat(cli): Homebrew distribution via existing homebrew-apps tap (#91)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-09T16:09:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb1eb8088912297a2cc50c4613afb63cb0741dd5",
"body": "…is the single backend) (#86)\n\n# Stage 3 — WorkOS Vault crypto moved into Convex\n\nConvex becomes the **single backend**. Plaintext secret values now travel to Convex, which encrypts them into WorkOS Vault and stores only the opaque `vaultRef`. The web app no longer holds vault crypto — `apps/web/src\n[…]\nxes + `vaultReveal` functions.\n\n---\n_Merged `main` (through #90) — CLI/extension auth + version-enforcement fixes — and resolved version conflicts. cubic review issues addressed in follow-up commits._",
"is_bot": false,
"headline": "feat(vault): Stage 3 — WorkOS Vault crypto moved into Convex (Convex …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-06T07:59:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7a6ed461a62d48b01717f186397e7d8965a21323",
"body": "…#90)\n\n* fix(ci): build CLI/extension directly (not turbo) + guard the embed\n\nThe published 1.13.0 CLI / 1.8.0 extension STILL shipped an empty WorkOS client\nid despite the secret resolving on the build step. Root cause: `bunx turbo\nbuild` did not propagate WORKOS_CLIENT_ID / NEXT_PUBLIC_CONVEX_URL \n[…]\nterministic: derive the exact filename\nfrom package.json version instead of `ls | head` (alias-fragile and could grab a\nstale VSIX). Verified locally: both checks pass against the packaged 1.8.1 VSIX.",
"is_bot": false,
"headline": "fix(ci): build CLI/extension directly (not turbo) + guard the embed (…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-06T01:57:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a5ae155a233496e4fc5e03b19f7494cb1ddaf07a",
"body": "…ock) (#89)\n\n* feat(versioning): two-tier client version enforcement (warn + hard-block)\n\nForce CLI/extension users onto supported versions so stale clients can't call\nserver/Convex contracts that were removed (e.g. the Stage 2 auth cutover).\n\nServer (source of truth: apps/web/src/lib/versions.ts):\n\n[…]\nent always runs against the\nlast-known cached min/latest.\n\ncubic P2 (repeated 3s CLI hangs on network failure) was already addressed in\n176ebb2 — lastVersionCheck is written up front before the fetch.",
"is_bot": false,
"headline": "feat(versioning): two-tier client version enforcement (warn + hard-bl…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-06T01:17:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "07d968bed91b34f360510a8004a6a48bac862a12",
"body": "…on (#88)\n\n* fix(ci): embed WORKOS_CLIENT_ID + Convex URL in published CLI/extension builds\n\nThe device-flow auth (Stage 2) reads a build-time-baked WorkOS client id and\nConvex URL: tsup/esbuild `define` replace `__WORKOS_CLIENT_ID__` / `__CONVEX_URL__`\nfrom `process.env.WORKOS_CLIENT_ID` / `NEXT_PU\n[…]\nPUBLIC_CONVEX_URL), referenced via ${{ secrets.* }}.\nKeeps them out of the committed YAML and masked in CI logs. They remain\nembedded in the published CLI/extension artifacts at runtime (unavoidable).",
"is_bot": false,
"headline": "fix(ci): embed WorkOS client id + Convex URL in published CLI/extensi…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-06T00:49:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d6c044d8c3b8e45b76af6e89642c998fe4810c5",
"body": "…eak dev login) (#87)\n\nThe prod emergency fix hardcoded the PROD WorkOS client id in auth.config.ts.\nThat file deploys to BOTH Convex deployments, so the dev/staging deployment\nstarted trusting the PROD client — every dev CLI/extension/web JWT (issued for\nthe STAGING client) then failed with 'No aut\n[…]\nthis reaches prod: the prod Convex deployment MUST have\nWORKOS_CLIENT_ID set (the Convex CLI rejects a push referencing an unset env\nvar). It should be client_01KHWDD75944NBADKY0ANTRXR8 (the prod id).",
"is_bot": false,
"headline": "fix(auth): auth.config resolves WORKOS_CLIENT_ID per-deployment (unbr…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T23:57:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "58a6582ae83e690a7a0d9580a5eb967d3f5bf433",
"body": null,
"is_bot": false,
"headline": "auth:fix",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T22:58:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "964e95fd683a608bf1305f675ea936eeec684bd9",
"body": "…vex WebSocket (#85)\n\n## What\n\nCompletes Stage 2 by migrating the **VS Code extension** off the homegrown/deleted token auth onto the WorkOS AuthKit device flow — the mirror of the CLI cutover (#84). This closes the breakage that #84 introduced: the extension was calling backend routes/functions tha\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
"is_bot": false,
"headline": "feat(extension): Stage 2 — WorkOS device-flow auth, authenticated Con…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T21:30:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a7acf6edd96380fd3e9322366193f92cbe1df62b",
"body": "…ken bridge removed (#84)\n\n* feat(auth): Stage 2 — WorkOS device-flow auth for CLI, ForToken bridge removed\n\nBackend:\n- cliSessions + pendingExtensionAuthSessions deleted (tables + module);\n cliTokens repurposed as a display/revoke device-session record\n (optional tokens, sessionId + clientType ad\n[…]\n from identity resolution\n- deviceSessions.revoke queries the by_user_active index instead of loading\n all rows and filtering in memory\n\nVerified live: revoke lifecycle + vault happy path both green.",
"is_bot": false,
"headline": "feat(cli): Stage 2 — WorkOS device-flow auth, direct-to-Convex, ForTo…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T19:34:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ce89d94bddc02089b4652614548126b5cc236e69",
"body": "… (Stage 1) (#83)\n\n## What\n\nCloses the platform's biggest security hole: **every Convex function trusted a client-supplied `userId` arg**, so anyone who reached the public Convex deployment could impersonate any user. After this PR, every function derives its actor from a **verified identity** — a W\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
"is_bot": false,
"headline": "feat(auth): Convex auth cutover — server-verified identity everywhere…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T13:02:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9b48c886d74b44e91593571af65521ae1dc2aa8c",
"body": "The cleanup-dead-data runMigration handler shipped in #81 but had no\nentry in listMigrations, so it never rendered as a card in the admin\nmigrations page — runnable via API only, invisible in the UI. Added its\ncatalog entry under One-Time Migrations so it can be run from the panel.",
"is_bot": false,
"headline": "fix(admin): surface cleanup-dead-data in the migrations panel (#82)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T03:05:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aae6fb39aa6211fc51233371b6abcc150f6ebe80",
"body": "* perf: Convex usage optimization + dead-code purge (-3,400 lines)\n\nThree-agent audit (hot path, crons/gating, long tail + dead code) →\nranked fixes, every diff reviewed, zero behavior change for live flows.\n\nRead-cost fixes:\n- globalSearchWithAccess: capped per-project reads (was unbounded full-doc\n[…]\nlus shared-fixture pollution (leftover E2E\naccounts hitting the free 5-account limit, which correctly disables Add\nAccount — enforcement working as intended), not product regressions.\n\n* fixing format",
"is_bot": false,
"headline": "perf: Convex usage optimization + dead-code purge (−3,500 lines) (#81)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-05T02:54:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7df9b31b10bd08f711fd3868a0bc739ea8ee223a",
"body": "…urge) (#80)\n\n* feat: vault GC — deletion becomes real (7-day trash, then permanent purge)\n\nBefore this, nothing ever deleted a WorkOS Vault object: 'deleted'\nsecrets lived in the vault forever, and deletion was an indefinite\nsoft-hide with no user-facing restore either.\n\nNew model (user-confirmed):\n[…]\nbut that would range-scan every\ntenant's deleted rows and filter projectId in memory — the compound\nindex is strictly better.)\n\nVerified live: trash-restore e2e round-trips pass through the new\nindex.",
"is_bot": false,
"headline": "feat: vault GC — deletion becomes real (7-day trash, then permanent p…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-04T14:54:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5b8673b47a82bbc785ecb73e7078485784d2648b",
"body": "Users previously got zero feedback when an action failed — no toast\nsystem existed at all (the one toast component was dead code). Now:\n\n- sonner Toaster mounted globally (dark theme, bottom-right)\n- The Convex client error bridge toasts every mutation/action failure:\n expected tier-limit/permissio\n[…]\nueRestored.\n- In-app changelog entry (v1.27.0) publishing the statement about the\n legacy version limitation and the new rollback guarantees.\n\nVersions: web 1.27.0, root 1.21.0 (minor — new feature).",
"is_bot": false,
"headline": "feat(web): error toast notifications + honest rollback disclosure (#79)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-04T13:52:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f1f103dfe32db7e69bfb756d5771917505e1fefe",
"body": "…(#78)\n\n* fix(hardening): real vault version rollback + twin parity fixes for variables/accounts\n\nVault versioning (the headline fix): web PATCH value updates now mint a\nNEW vault object per change (the pattern the CLI bulk-push already used)\ninstead of overwriting in place. Every variableVersions r\n[…]\nects\n (authorization/validation) after a new vault object was minted for the\n value, best-effort deleteSecret the orphan before rethrowing — same\n compensation pattern as the accounts create route.",
"is_bot": false,
"headline": "fix: real vault version rollback + variables/accounts twin hardening …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-04T13:27:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd1f92663f140f9e86d4bbc44ff93875da22b989",
"body": "* feat(observability): complete Sentry coverage across web API, Convex client, CLI, and extension\n\nWeb API routes: add reportApiError() (report-only, skips expected tier/authz\nerrors) and insert it into ~60 previously-silent catch blocks across 55 route\nfiles (vault, billing, cli/*, extension/*, and\n[…]\ny disabled. Verified by\nrebuilding both packages through 'turbo build' and grepping the dist\noutput for the baked-in DSN (missing before, present after).\nENVPILOT_SERVER_URL added for the same reason.",
"is_bot": false,
"headline": "feat(observability): complete Sentry coverage across all surfaces (#77)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-04T12:41:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b97023dfc8b5b162847a9189f8891669f64651b",
"body": "* feat(usage): shared accounts in the usage dashboard meters\n\n- getExtendedUsage now returns sharedAccounts (countActiveAccounts, fetched in\n parallel with the other org counts)\n- usage page: shared_accounts / shared_accounts_limit added to the Security\n feature catalog, free/pro value maps (free \n[…]\ncost — the index already narrows rows)\n\nCLI/extension usage routes intentionally unchanged — shared accounts are\nweb-only.\n\n* chore(release): web 1.25.0, root 1.19.0 — usage meters for shared accounts",
"is_bot": false,
"headline": "feat(usage): Shared Accounts in the usage dashboard meters (#76)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-03T17:59:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2162334d34fca9407fe7803c75357b3ed021f1d4",
"body": "…under projects (#75)\n\n* feat(web): shared account credentials under projects — vault-encrypted storage, RBAC parity, internal & external sharing\n\n- New projectAccounts + accountPermissions tables; username & password stored\n encrypted in WorkOS Vault (JSON payload), Convex holds only vault refs\n- \n[…]\npassword when the block is hidden so a prior\n unmask doesn't persist into the next reveal\n- drop unused required organizationId from createAccountSchema (org is resolved\n server-side from projectId)",
"is_bot": false,
"headline": "feat: Shared Accounts — vault-encrypted credential storage & sharing …",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-03T17:01:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ae00dbe6ec03402c0ca6005ceb92a5602fe278f",
"body": "Introduce a shared GitHub Actions setup composite (.github/actions/setup/action.yml) and a new orchestrated CI pipeline (.github/workflows/ci.yml) that detects changed scopes, runs scoped quality checks, builds artifacts, and calls reusable deploy workflows. Add reusable deploy workflows for Convex,\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
"is_bot": false,
"headline": "Add reusable CI workflows and setup action (#74)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-03T08:03:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f3b6c98394ccfd6d4dd697c3a53b9006112a5342",
"body": "* feat(vscode): unified RBAC + brutal-review fixes + optimization\n\nUnify the VS Code extension with the web/CLI role model and fix a batch of\nreal bugs found in a full audit. Server changes are additive so old installed\nextensions keep working.\n\nServer (/api/extension/*): add unifiedRole, assigned, \n[…]\n before responding\n (the CLI route already did), maps duplicate-pending to 409 instead of a\n raw 500, and maps authorization/scope rejections to 403 via the shared\n isAuthorizationError classifier.",
"is_bot": false,
"headline": "VS Code extension: unified RBAC, brutal-review fixes, optimization (#73)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-03T01:39:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc9e4af79e7f543badd527428d8003a4156e9bdb",
"body": "## Summary\nBrings the CLI onto the unified role model, rewrites `envpilot run`, and fixes a batch of real bugs found in a three-part audit (RBAC, general quality, `run` deep-dive). **Server changes are additive**, so already-installed CLIs keep working.\n\n## Server (`/api/cli/*`, additive)\nAdds `unif\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
"is_bot": false,
"headline": "CLI: unified RBAC, envpilot run rewrite, and bug fixes (#71)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-02T20:00:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4354f3686cf1eb90d9da8f1b50b0b9b2bdbcea29",
"body": "…#72)\n\nRedesigns the shared email helpers in `convex/emails.ts` so every transactional email matches Envpilot's dark terminal brand identity — signature green accent, terminal-window chrome, and the `$ envpilot` prompt wordmark (mirroring `apps/web` `globals.css` + the landing-page `TerminalFrame`).\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
"is_bot": false,
"headline": "feat(emails): rebrand transactional emails with dark terminal theme (…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-02T19:53:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e0818f7f50001a1c3dc25da37309dee0e5dd47c1",
"body": "…ex cost fixes (#70)\n\n* feat(rbac): unified organization-wide role system\n\nReplace the three overlapping role layers (org roles, project roles,\nvariable permission levels) with ONE role per user:\n\n owner > project_manager > team_lead > developer\n\n- projectMembers is now a pure scope assignment (no \n[…]\ne selector, and validation are unchanged — only the container swapped.\nUtility dialogs (confirm, export, keyboard help, variable history) keep their\ncentered-modal pattern, which is correct for those.",
"is_bot": false,
"headline": "Unified organization-wide RBAC: env scoping, security hardening, Conv…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-02T10:24:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e7a83c3aae38721ca1c13e8f530fb68af4f7cfeb",
"body": "…dening (#69)\n\nPerformance:\n- Split @sentry/node into a lazily-loaded chunk (activation bundle 2.8MB -> ~1MB)\n- Stop blocking activation on Convex config HTTP call and commit guard git spawns\n- Remove workspaceContains:.env* activation event (onStartupFinished already covers it)\n- Drop redundant val\n[…]\n auth session token) only copied to clipboard when the\n browser fails to open\n- refreshToken only signs out on 4xx, not on transient network errors\n\nVersions: extension 1.4.1, web 1.14.1, root 1.12.1",
"is_bot": false,
"headline": "perf(extension): faster activation and variable loading, security har…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-07-01T20:07:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b6bf5ac016c6602244c124aec21bb35fc31d3319",
"body": null,
"is_bot": false,
"headline": "Update Scarlet Speedster automated PR review workflow",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-06-23T15:42:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4b38d7087b1491b48f7bded7a4e5db3adb977f6",
"body": "…s (#67)\n\n* feat(web): marketing redesign with SEO, a11y, performance, and uptime status\n\nMarketing surface overhaul (v1.14.0):\n\nFixes\n- Add /api/auth/me, /docs, /faq, /feed.xml, /llms.txt, /llms-full.txt to\n middleware unauthenticatedPaths — public pages no longer redirect to\n sign-in, and client\n[…]\nms prerender\n\nThe deleted root loading.tsx had been providing an implicit Suspense\nboundary; without it, static prerendering of /cli/auth fails the build.\n/extension/auth already had its own boundary.",
"is_bot": false,
"headline": "Marketing redesign: SEO fixes, comparison pages, guides, uptime statu…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-06-12T08:33:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "803c0be2f43c439ce147fe0dffacb42766b026cd",
"body": "The CLI deploy failed with \"missing authentication (run 'bunx npm\nlogin')\" because `bun publish` does not reliably read the ~/.npmrc the\nworkflow wrote. Pass the token through the NPM_CONFIG_TOKEN env var\ninstead, which is bun's supported CI auth path.\n\nBump CLI to 1.7.2 so the deploy-detection (which gates on apps/cli\nchanges + version delta) re-triggers the publish; 1.7.1 was never\npublished and no tag was created since the publish step failed first.",
"is_bot": false,
"headline": "fix(ci): authenticate bun publish via NPM_CONFIG_TOKEN (#66)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-06-08T09:28:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b84f7ba3cb888d2d9eda6d3958ff7d392011ac82",
"body": "The \"press any key to return\" prompt read raw process.stdin\n(setRawMode + resume + once) after the Ink picker unmounted and a\ncommand ran in a child process with inherited stdio. In that state raw\nmode failed to re-engage and the event loop emptied, surfacing a\n\"Detected unsettled top-level await\" c\n[…]\n(PressAnyKey) so the\nstdin lifecycle stays consistent across renders, and wrap the entry in\nan async main() so an empty event loop can no longer surface the\ntop-level-await warning. Bump CLI to 1.7.1.",
"is_bot": false,
"headline": "fix(cli): stop TUI crashing after each command run (#65)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-06-08T09:09:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0f051b6868ddb7371a29db865225c1d600389c0c",
"body": "* Add DashboardShell and Convex boundary provider\n\nMove dashboard UI into a new client component (DashboardShell) and simplify the dashboard layout to render that shell. Export a ConvexBoundaryProvider from ConvexClientProvider and use it inside the new shell so client-only pieces (nav, command pale\n[…]\ns sending to Sentry.\n\n* Bump web app version to 1.6.1\n\nUpdate APP_VERSIONS.web from 1.6.0 to 1.6.1 to reflect a new web release. This increments the published web surface version for release tracking.",
"is_bot": false,
"headline": "(fix)/sentry fix (#63)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-22T22:31:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "20f45e43eb2b938f00ac940094c861eed9b6b27a",
"body": "…erts (#62)\n\n* Add anomaly detection system across platform\n\n- Admin dashboard for managing anomaly events, rules, and running test suite\n- Backend detection engine with configurable rules and severity levels\n- Web dashboard pages for anomaly monitoring and rule management\n- Feature registry entries\n[…]\nding; whitelist workoscdn.com in\n remotePatterns\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "Add comprehensive anomaly detection system with admin controls and al…",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-21T15:21:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c7a4a41a9fdee6ddd8565df89b0062449d952f7c",
"body": null,
"is_bot": false,
"headline": "Read me",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-17T20:58:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f6b070faea83310161e0f10db79fec322dfbdbe1",
"body": "- Move FEATURES, ROADMAP, SECURITY-TODO to docs/\n- Update README.md links\n- Remove cleanup.sh",
"is_bot": false,
"headline": "Move documentation to docs/ directory",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-17T20:55:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4874442130a4a2ec0431849d1d3151dbf09362aa",
"body": null,
"is_bot": false,
"headline": "fixing format",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-17T20:50:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe7cedcfcc796f0f33b1397c3c856c5b998c4dd7",
"body": "- Merge ci.yml, build-extension.yml, deploy-convex.yml, deploy-extension.yml, and release-cli.yml into single ci-deploy.yml\n- Implement 5-stage pipeline: quality gate → build → detect changes → deploy → release\n- Add automatic version detection and deployment triggers for convex, extension, and CLI\n- Disable old workflow files (.disabled suffix) for reference\n- Remove legacy deployment scripts and .vscode config files\n- Update CLAUDE.md documentation with new development and deployment workflows",
"is_bot": false,
"headline": "Consolidate CI/CD workflows into unified pipeline (#61)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-17T20:46:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "169e1ac64bc02fabfb2345c9520e443a7b1b0d09",
"body": "- Implement safe redirect following that preserves Authorization header for same-site (registrable domain) redirects while stripping for cross-site ones\n- Add normalizeApiUrl() to canonicalize envpilot.dev → www.envpilot.dev in config and commands\n- Validate tokens exist when poll() returns authenti\n[…]\nssion code collision detection to reject all existing codes, not just pending ones\n- Consolidate /api/cli/auth/* endpoints to single route with action query parameter\n- Add interactive CLI test script",
"is_bot": false,
"headline": "Fix CLI auth header stripping on apex→www redirects (#60)",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-17T18:44:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c3bdc0141bbbdac1f047ec251e8a8b9f3642b4a",
"body": null,
"is_bot": false,
"headline": "org fix",
"author_name": "Abdul Rafay",
"author_login": "rafay99-epic",
"committed_at": "2026-04-16T22:52:40Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 79,
"commits_last_year": 155,
"latest_release_at": "2026-07-20T09:17:24Z",
"latest_release_tag": "v1.43.0+311a623",
"releases_from_tags": false,
"days_since_last_push": 5,
"active_weeks_last_year": 13,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.2
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 71,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@envpilot/cli",
"exists": true,
"license": "MIT",
"keywords": [
"env",
"environment",
"variables",
"cli",
"dotenv",
"secrets"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@envpilot/cli",
"is_deprecated": false,
"latest_version": "1.19.0",
"repository_url": "https://github.com/rafay99-epic/envpilot.dev",
"versions_count": 29,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2472,
"first_published_at": "2026-03-10T13:09:08.771000Z",
"latest_published_at": "2026-07-19T23:20:03.285000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
},
{
"name": "envpilot",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": null,
"registry_url": "https://www.npmjs.com/package/envpilot",
"is_deprecated": false,
"latest_version": "1.0.4",
"repository_url": null,
"versions_count": 5,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 35,
"first_published_at": "2015-11-06T19:16:52.064000Z",
"latest_published_at": "2016-02-07T02:28:22.798000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 3821
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 2
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"apps/admin/tsconfig.json",
"apps/blog/tsconfig.json",
"apps/cli/tsconfig.json",
"apps/docs/tsconfig.json",
"apps/vscode-extension/tsconfig.json",
"apps/web/tsconfig.json",
"convex/tsconfig.json",
"packages/github-action/tsconfig.json",
"packages/ui/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 76271,
"source_files_sampled": 697,
"oversized_source_files": 5,
"agent_instruction_files": [
".agents/skills/vercel-react-best-practices/AGENTS.md",
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 105774
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 186,
"malicious_count": 0,
"assessed_package": "npm:@envpilot/cli@1.19.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@convex-dev/rate-limiter",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.3.2"
},
{
"name": "@convex-dev/workflow",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.3.5"
},
{
"name": "@convex-dev/workpool",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.4.1"
},
{
"name": "resend",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^6.9.3"
},
{
"name": "@dnd-kit/core",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^6.3.1"
},
{
"name": "@dnd-kit/utilities",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^3.2.2"
},
{
"name": "@fontsource-variable/geist",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^5.2.8"
},
{
"name": "@fontsource-variable/geist-mono",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^5.2.8"
},
{
"name": "@tanstack/react-router",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.120.3"
},
{
"name": "@workos-inc/authkit-react",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^0.16.1"
},
{
"name": "class-variance-authority",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^0.7.1"
},
{
"name": "clsx",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.1"
},
{
"name": "convex",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.32.0"
},
{
"name": "date-fns",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^4.1.0"
},
{
"name": "lucide-react",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^0.577.0"
},
{
"name": "react",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^19.1.0"
},
{
"name": "react-dom",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^19.1.0"
},
{
"name": "react-markdown",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^10.1.0"
},
{
"name": "remark-gfm",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.1"
},
{
"name": "tailwind-merge",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.2"
},
{
"name": "zustand",
"manifest": "apps/admin/package.json",
"ecosystem": "npm",
"version_constraint": "^5.0.5"
},
{
"name": "@envpilot/ui",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "date-fns",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^4.1.0"
},
{
"name": "gray-matter",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.3"
},
{
"name": "lucide-react",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^0.577.0"
},
{
"name": "next",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^16.2.10"
},
{
"name": "next-mdx-remote",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
},
{
"name": "react",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.4"
},
{
"name": "react-dom",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.4"
},
{
"name": "rehype-pretty-code",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^0.14.3"
},
{
"name": "remark-gfm",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.1"
},
{
"name": "shiki",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.2"
},
{
"name": "zod",
"manifest": "apps/blog/package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.6"
},
{
"name": "@sentry/node",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^10.43.0"
},
{
"name": "chalk",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^5.3.0"
},
{
"name": "commander",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^12.1.0"
},
{
"name": "conf",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^13.0.1"
},
{
"name": "convex",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^1.32.0"
},
{
"name": "cross-spawn",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^7.0.6"
},
{
"name": "dotenv",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^16.4.7"
},
{
"name": "ink",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^5.2.1"
},
{
"name": "inquirer",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^12.3.2"
},
{
"name": "open",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^10.1.0"
},
{
"name": "ora",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^8.1.1"
},
{
"name": "react",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^18.3.1"
},
{
"name": "zod",
"manifest": "apps/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.6"
},
{
"name": "@sentry/node",
"manifest": "apps/vscode-extension/package.json",
"ecosystem": "npm",
"version_constraint": "^10.43.0"
},
{
"name": "axios",
"manifest": "apps/vscode-extension/package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.2"
},
{
"name": "convex",
"manifest": "apps/vscode-extension/package.json",
"ecosystem": "npm",
"version_constraint": "^1.32.0"
},
{
"name": "@envpilot/ui",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "@polar-sh/sdk",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^0.46.6"
},
{
"name": "@sentry/nextjs",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^10"
},
{
"name": "@tanstack/react-hotkeys",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^0.4.1"
},
{
"name": "@tanstack/react-query",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^5.90.21"
},
{
"name": "@vercel/analytics",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.1"
},
{
"name": "@workos-inc/authkit-nextjs",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^2.14.0"
},
{
"name": "@workos-inc/node",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^8.5.0"
},
{
"name": "canvas-confetti",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^1.9.4"
},
{
"name": "class-variance-authority",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^0.7.1"
},
{
"name": "clsx",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.1"
},
{
"name": "convex",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^1.32.0"
},
{
"name": "date-fns",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^4.1.0"
},
{
"name": "framer-motion",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^12.35.2"
},
{
"name": "jose",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^5.10.0"
},
{
"name": "lucide-react",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^0.577.0"
},
{
"name": "mcp-handler",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "1.1.0"
},
{
"name": "next",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^16.2.10"
},
{
"name": "react",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.4"
},
{
"name": "react-dom",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.4"
},
{
"name": "react-markdown",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^10.1.0"
},
{
"name": "recharts",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^3.8.0"
},
{
"name": "remark-gfm",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.1"
},
{
"name": "sonner",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.7"
},
{
"name": "tailwind-merge",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^3.5.0"
},
{
"name": "zod",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.6"
},
{
"name": "zustand",
"manifest": "apps/web/package.json",
"ecosystem": "npm",
"version_constraint": "^5.0.11"
},
{
"name": "typescript-eslint",
"manifest": "packages/eslint-config/package.json",
"ecosystem": "npm",
"version_constraint": "^8"
},
{
"name": "@actions/core",
"manifest": "packages/github-action/package.json",
"ecosystem": "npm",
"version_constraint": "^1.11.1"
},
{
"name": "date-fns",
"manifest": "packages/ui/package.json",
"ecosystem": "npm",
"version_constraint": "^4.1.0"
},
{
"name": "framer-motion",
"manifest": "packages/ui/package.json",
"ecosystem": "npm",
"version_constraint": "^12.35.2"
},
{
"name": "lucide-react",
"manifest": "packages/ui/package.json",
"ecosystem": "npm",
"version_constraint": "^0.577.0"
},
{
"name": "mermaid",
"manifest": "packages/ui/package.json",
"ecosystem": "npm",
"version_constraint": "^11"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@actions/core",
"direct": true,
"version": "^1.11.1",
"ecosystem": "npm"
},
{
"name": "@convex-dev/rate-limiter",
"direct": true,
"version": "^0.3.2",
"ecosystem": "npm"
},
{
"name": "@convex-dev/workflow",
"direct": true,
"version": "^0.3.5",
"ecosystem": "npm"
},
{
"name": "@convex-dev/workpool",
"direct": true,
"version": "^0.4.1",
"ecosystem": "npm"
},
{
"name": "@dnd-kit/core",
"direct": true,
"version": "^6.3.1",
"ecosystem": "npm"
},
{
"name": "@dnd-kit/utilities",
"direct": true,
"version": "^3.2.2",
"ecosystem": "npm"
},
{
"name": "@fontsource-variable/geist",
"direct": true,
"version": "^5.2.8",
"ecosystem": "npm"
},
{
"name": "@fontsource-variable/geist-mono",
"direct": true,
"version": "^5.2.8",
"ecosystem": "npm"
},
{
"name": "@modelcontextprotocol/sdk",
"direct": true,
"version": "^1.29.0",
"ecosystem": "npm"
},
{
"name": "@polar-sh/sdk",
"direct": true,
"version": "^0.46.6",
"ecosystem": "npm"
},
{
"name": "@sentry/nextjs",
"direct": true,
"version": "^10",
"ecosystem": "npm"
},
{
"name": "@sentry/node",
"direct": true,
"version": "^10.43.0",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-hotkeys",
"direct": true,
"version": "^0.4.1",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-query",
"direct": true,
"version": "^5.90.21",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-router",
"direct": true,
"version": "^1.120.3",
"ecosystem": "npm"
},
{
"name": "@vercel/analytics",
"direct": true,
"version": "^1.6.1",
"ecosystem": "npm"
},
{
"name": "@workos-inc/authkit-nextjs",
"direct": true,
"version": "^2.14.0",
"ecosystem": "npm"
},
{
"name": "@workos-inc/authkit-react",
"direct": true,
"version": "^0.16.1",
"ecosystem": "npm"
},
{
"name": "@workos-inc/node",
"direct": true,
"version": "^8.5.0",
"ecosystem": "npm"
},
{
"name": "axios",
"direct": true,
"version": "^1.6.2",
"ecosystem": "npm"
},
{
"name": "canvas-confetti",
"direct": true,
"version": "^1.9.4",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": true,
"version": "^5.3.0",
"ecosystem": "npm"
},
{
"name": "class-variance-authority",
"direct": true,
"version": "^0.7.1",
"ecosystem": "npm"
},
{
"name": "clsx",
"direct": true,
"version": "^2.1.1",
"ecosystem": "npm"
},
{
"name": "commander",
"direct": true,
"version": "^12.1.0",
"ecosystem": "npm"
},
{
"name": "conf",
"direct": true,
"version": "^13.0.1",
"ecosystem": "npm"
},
{
"name": "convex",
"direct": true,
"version": "^1.32.0",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": true,
"version": "^7.0.6",
"ecosystem": "npm"
},
{
"name": "date-fns",
"direct": true,
"version": "^4.1.0",
"ecosystem": "npm"
},
{
"name": "dotenv",
"direct": true,
"version": "^16.4.7",
"ecosystem": "npm"
},
{
"name": "framer-motion",
"direct": true,
"version": "^12.35.2",
"ecosystem": "npm"
},
{
"name": "gray-matter",
"direct": true,
"version": "^4.0.3",
"ecosystem": "npm"
},
{
"name": "ink",
"direct": true,
"version": "^5.2.1",
"ecosystem": "npm"
},
{
"name": "inquirer",
"direct": true,
"version": "^12.3.2",
"ecosystem": "npm"
},
{
"name": "jose",
"direct": true,
"version": "^5.10.0",
"ecosystem": "npm"
},
{
"name": "lucide-react",
"direct": true,
"version": "^0.577.0",
"ecosystem": "npm"
},
{
"name": "mcp-handler",
"direct": true,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "mermaid",
"direct": true,
"version": "^11",
"ecosystem": "npm"
},
{
"name": "next",
"direct": true,
"version": "^16.2.10",
"ecosystem": "npm"
},
{
"name": "next-mdx-remote",
"direct": true,
"version": "^6.0.0",
"ecosystem": "npm"
},
{
"name": "open",
"direct": true,
"version": "^10.1.0",
"ecosystem": "npm"
},
{
"name": "ora",
"direct": true,
"version": "^8.1.1",
"ecosystem": "npm"
},
{
"name": "react",
"direct": true,
"version": "^18.3.1",
"ecosystem": "npm"
},
{
"name": "react",
"direct": true,
"version": "^19.1.0",
"ecosystem": "npm"
},
{
"name": "react",
"direct": true,
"version": "^19.2.4",
"ecosystem": "npm"
},
{
"name": "react-dom",
"direct": true,
"version": "^19.1.0",
"ecosystem": "npm"
},
{
"name": "react-dom",
"direct": true,
"version": "^19.2.4",
"ecosystem": "npm"
},
{
"name": "react-markdown",
"direct": true,
"version": "^10.1.0",
"ecosystem": "npm"
},
{
"name": "recharts",
"direct": true,
"version": "^3.8.0",
"ecosystem": "npm"
},
{
"name": "rehype-pretty-code",
"direct": true,
"version": "^0.14.3",
"ecosystem": "npm"
},
{
"name": "remark-gfm",
"direct": true,
"version": "^4.0.1",
"ecosystem": "npm"
},
{
"name": "resend",
"direct": true,
"version": "^6.9.3",
"ecosystem": "npm"
},
{
"name": "shiki",
"direct": true,
"version": "^4.0.2",
"ecosystem": "npm"
},
{
"name": "sonner",
"direct": true,
"version": "^2.0.7",
"ecosystem": "npm"
},
{
"name": "tailwind-merge",
"direct": true,
"version": "^3.0.2",
"ecosystem": "npm"
},
{
"name": "tailwind-merge",
"direct": true,
"version": "^3.5.0",
"ecosystem": "npm"
},
{
"name": "typescript-eslint",
"direct": true,
"version": "^8",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": true,
"version": "^4.3.6",
"ecosystem": "npm"
},
{
"name": "zustand",
"direct": true,
"version": "^5.0.11",
"ecosystem": "npm"
},
{
"name": "zustand",
"direct": true,
"version": "^5.0.5",
"ecosystem": "npm"
},
{
"name": "@next/bundle-analyzer",
"direct": false,
"version": "^16.2.3",
"ecosystem": "npm"
},
{
"name": "@playwright/test",
"direct": false,
"version": "^1.58.2",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/postcss",
"direct": false,
"version": "^4",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/vite",
"direct": false,
"version": "^4.1.7",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-query-devtools",
"direct": false,
"version": "^5.91.3",
"ecosystem": "npm"
},
{
"name": "@tanstack/router-plugin",
"direct": false,
"version": "^1.120.3",
"ecosystem": "npm"
},
{
"name": "@types/canvas-confetti",
"direct": false,
"version": "^1.9.0",
"ecosystem": "npm"
},
{
"name": "@types/cross-spawn",
"direct": false,
"version": "^6.0.6",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "^22",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "^22.10.10",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "^22.15.0",
"ecosystem": "npm"
},
{
"name": "@types/react",
"direct": false,
"version": "^18.3.12",
"ecosystem": "npm"
},
{
"name": "@types/react",
"direct": false,
"version": "^19",
"ecosystem": "npm"
},
{
"name": "@types/react",
"direct": false,
"version": "^19.1.6",
"ecosystem": "npm"
},
{
"name": "@types/react-dom",
"direct": false,
"version": "^19",
"ecosystem": "npm"
},
{
"name": "@types/react-dom",
"direct": false,
"version": "^19.1.6",
"ecosystem": "npm"
},
{
"name": "@types/vscode",
"direct": false,
"version": "^1.85.0",
"ecosystem": "npm"
},
{
"name": "@vitejs/plugin-react",
"direct": false,
"version": "^4.5.2",
"ecosystem": "npm"
},
{
"name": "@vscode/vsce",
"direct": false,
"version": "^3.7.1",
"ecosystem": "npm"
},
{
"name": "babel-plugin-react-compiler",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "concurrently",
"direct": false,
"version": "^9.1.2",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "^0.19.8",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "^9",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "^9.28.0",
"ecosystem": "npm"
},
{
"name": "eslint-config-next",
"direct": false,
"version": "16.1.6",
"ecosystem": "npm"
},
{
"name": "eslint-config-next",
"direct": false,
"version": "^16.2.10",
"ecosystem": "npm"
},
{
"name": "nodemailer",
"direct": false,
"version": "^9.0.3",
"ecosystem": "npm"
},
{
"name": "npm-run-all",
"direct": false,
"version": "^4.1.5",
"ecosystem": "npm"
},
{
"name": "prettier",
"direct": false,
"version": "^3.6.2",
"ecosystem": "npm"
},
{
"name": "tailwindcss",
"direct": false,
"version": "^4",
"ecosystem": "npm"
},
{
"name": "tailwindcss",
"direct": false,
"version": "^4.1.7",
"ecosystem": "npm"
},
{
"name": "tsup",
"direct": false,
"version": "^8.3.5",
"ecosystem": "npm"
},
{
"name": "turbo",
"direct": false,
"version": "^2",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^5",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^5.3.2",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^5.7.3",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^5.8.3",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "^6.3.5",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "^1.0.0",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "^3.0.4",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 100,
"direct_count": 60,
"indirect_count": 40
}
},
"maintainership": {
"issues": {
"open_prs": 2,
"merged_prs": 147,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 8
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "rafay99-epic",
"commits": 154,
"avatar_url": "https://avatars.githubusercontent.com/u/82662797?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"deploy-action.yml",
"deploy-cli.yml",
"deploy-convex.yml",
"deploy-extension.yml",
"deploy-homebrew.yml",
"deploy-vercel.yml",
"version-tracker.yml"
],
"has_docs_dir": true,
"linter_configs": [
"eslint.config.mjs"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 9,
"reason": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "94 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "311a623aa78b20ef168b3f9e779cca4e961d0274",
"ran_at": "2026-07-25T23:18:51Z",
"aggregate_score": 3.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-20T09:17:27Z",
"oldest_open_prs": [
{
"number": 64,
"created_at": "2026-05-08T18:38:52Z",
"last_comment_at": "2026-07-06T08:09:04Z",
"last_comment_author": "rafay99-epic"
},
{
"number": 157,
"created_at": "2026-07-20T10:30:13Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-20T09:14:22Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/rafay99-epic/envpilot.dev",
"host": "github.com",
"name": "envpilot.dev",
"owner": "rafay99-epic"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"security": 46,
"vitality": 80,
"community": 39,
"governance": 54,
"engineering": 89
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 80,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 73,
"inputs": {
"commits_last_year": 155,
"human_commit_share": 1,
"days_since_last_push": 5,
"active_weeks_last_year": 13
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "13/52 weeks with commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 13
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "155 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 155
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 79,
"latest_release_tag": "v1.43.0+311a623",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.2
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "79 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 79
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.2 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.2
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 39,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 57,
"inputs": {
"packages": [
"@envpilot/cli",
"envpilot"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 2507
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,507 downloads/month across npm",
"points": 45.3,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2507,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 54,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 68,
"inputs": {
"merged_prs": 147,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 8
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "147/155 decided PRs merged",
"points": 36.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 147,
"decided": 155
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 51,
"inputs": {
"followers": 9,
"owner_type": "User",
"is_verified": null,
"owner_login": "rafay99-epic",
"public_repos": 64,
"account_age_days": 1926
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "9 followers of rafay99-epic",
"points": 7.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 9,
"login": "rafay99-epic"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "64 public repos, account ~5 yr old",
"points": 23.5,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 64
}
},
{
"code": "account_age_years",
"params": {
"years": 5
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@envpilot/cli",
"envpilot"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "29 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 29
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 89,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "8 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 8
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.mjs",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
"points": 18,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"cli",
"code",
"convex",
"extension",
"nextjs",
"role-based-access-control",
"vs"
],
"has_wiki": true,
"homepage": "https://envpilot.dev",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://envpilot.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 46,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 32,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 3.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "94 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@envpilot/cli@1.19.0 runtime dependency closure — what installing the published package pulls in — 186 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@envpilot/cli@1.19.0",
"assessed": 186
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 186,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 186,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 63,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.95,
"agent_instruction_files": [
".agents/skills/vercel-react-best-practices/AGENTS.md",
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 105774
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": ".agents/skills/vercel-react-best-practices/AGENTS.md, AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".agents/skills/vercel-react-best-practices/AGENTS.md, AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 95,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"apps/admin/tsconfig.json",
"apps/blog/tsconfig.json",
"apps/cli/tsconfig.json",
"apps/docs/tsconfig.json",
"apps/vscode-extension/tsconfig.json",
"apps/web/tsconfig.json",
"convex/tsconfig.json",
"packages/github-action/tsconfig.json",
"packages/ui/tsconfig.json"
],
"agent_commit_share": 0.02,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.mjs",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "apps/admin/tsconfig.json, apps/blog/tsconfig.json, apps/cli/tsconfig.json, apps/docs/tsconfig.json, apps/vscode-extension/tsconfig.json, apps/web/tsconfig.json, convex/tsconfig.json, packages/github-action/tsconfig.json, packages/ui/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "apps/admin/tsconfig.json, apps/blog/tsconfig.json, apps/cli/tsconfig.json, apps/docs/tsconfig.json, apps/vscode-extension/tsconfig.json, apps/web/tsconfig.json, convex/tsconfig.json, packages/github-action/tsconfig.json, packages/ui/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "2 of the last 100 commits agent-authored or agent-credited",
"points": 4,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 76271,
"source_files_sampled": 697,
"oversized_source_files": 5
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "5/697 source files over 60KB",
"points": 54.6,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 697,
"oversized": 5
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "critical",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [],
"report_type": "repository",
"generated_at": "2026-07-25T23:19:07.099720Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/rafay99-epic/envpilot.dev.svg",
"full_name": "rafay99-epic/envpilot.dev",
"license_state": "standard",
"license_spdx": "MIT"
}