Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 2.3.1 · 2026-08-01 09:24 UTC

solpbc / solstone-journal

Navigate Life Intelligently

PythonAGPL-3.0★ 17 Sterne⑂ 7 Forksseit Mai 2025Auf GitHub ansehen ↗
ArtBibliothekKommandozeilenwerkzeugwie das ermittelt wird

solpbc/solstone-journal erreicht einen Gesundheitsindex von 63 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (96/100) ab, am schwächsten bei Security (25/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

63
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer standardisierten Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr gewichtetes Mittel, kalibriert auf die Verteilung des öffentlichen Registers, sodass die Stufen Perzentilbedeutung tragen; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze Gefährdet von 34.

63
Außergewöhnlich93-100Die Spitzengruppe des Registers (≈ obere 5 %); erfüllt im Wesentlichen alle geprüften Kriterien
Exzellent80-92Durchgehend stark; geringfügige Lücken
Gut65-79Gesund; Lücken sind begrenzt und beherrschbar
Mittel50-64Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Schwach35-49Wesentliche Schwächen in mehreren Bereichen
Gefährdet20-34Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-19Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Der gewichtete Gesamtwert 59 wird auf der veröffentlichten Indexskala auf 63 kalibriert (Register-Kalibrierung 2026-08-02).

Eigentümerschaft

sol pbcOrganisation
5 Follower30 öffentliche Reposseit Jan. 2026

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
PyPIsolstone1.0.216.85178vor 0 Tagenaudiotranscriptionscreenshotmultimodalaigemini

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

96Außergewöhnlich · 21 % des Gesamtindex

Entwicklungsaktivität

100Außergewöhnlich
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
36/36Commit-Rhythmus — 52/52 Wochen mit Commits
18/18Commit-Volumen — 6.213 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year6.213
human_commit_share1
days_since_last_push0
active_weeks_last_year52
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 69 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 1 Tagen
27/27Release-Rhythmus — ein Release etwa alle 1,3 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count69
latest_release_tagv1.0.20
releases_from_tagsnein
days_since_latest_release1
mean_days_between_releases1,3

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

51Mittel · 17 % des Gesamtindex
Wie die Bewertung erfolgt
19.5/60Stars — 17 Stars
6.5/25Forks — 7 Forks
0/15Watcher — 1 Watcher
Verwendete Eingangsdaten
forks7
stars17
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (AGPL-3.0)
18/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
readme_badges
has_contributingja
has_issue_templatenein
has_code_of_conductnein
readme_badge_services
has_pull_request_templatenein
Wie die Bewertung erfolgt
51.1/80Downloads pro Monat — 6.851 Downloads/Monat über pypi
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagessolstone
dependents
ecosystemspypi
total_downloads
monthly_downloads6.851
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

59Mittel · 23 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0.3/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 99 % der Commits
4.1/13.5Breite der Beitragenden — 3 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor1
contributors_sampled3
top_contributor_share0,988
Wie die Bewertung erfolgt
42/42Issue-Lösungsquote — 100 % der Issues geschlossen
29.5/30PR-Annahme — 380/387 entschiedene PRs gemergt
0/13Newcomer PR acceptance — kein PR eines Erstbeitragenden in 30 Tagen entschieden
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs380
open_issues0
closed_issues2
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs7
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): newcomer_pr_acceptance. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
5.6/25Reichweite des Inhabers — 5 Follower von solpbc
12/25Kontohistorie — 30 öffentliche Repos, Kontoalter ca. 0 Jahre
Verwendete Eingangsdaten
followers5
owner_typeOrganization
is_verified
owner_loginsolpbc
public_repos30
account_age_days211

Paketpflege

100Außergewöhnlich
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf pypi
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 0 Tagen
20/20Versionshistorie — 78 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagessolstone
ecosystemspypi
any_deprecatednein
min_days_since_publish0

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

50Mittel · 19 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.

Dokumentation

80Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://solstone.app
10/10Repository-Beschreibung
0/10Topics
0/10Wiki
Verwendete Eingangsdaten
topics
has_wikinein
homepagehttps://solstone.app
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

25Gefährdet · 16 % des Gesamtindex

Sicherheitslage

25Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 4 contributing companies or organizations
0/10Dangerous-Workflow — keine Daten
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — keine Daten
0/7.5Vulnerabilities — 100 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated14
scorecard_versionv5.5.0
checks_inconclusive4
scorecard_aggregate2,5
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, dangerous_workflow, packaging, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Trägt ein bewusst kleines Gewicht (4 %): Agenten-Tooling ist ein echtes Pflegesignal, doch ein Repository ohne jedes Signal kann weiterhin 100/100 erreichen.

67Gut · 4 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — AGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md
0/15Maschinenlesbare Doku (llms.txt)
38.9/40Lesbare Commit-Historie — 73 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,73
agent_instruction_filesAGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md
agent_instruction_max_bytes52.085
Wie die Bewertung erfolgt
18/18Bootstrap mit einem Befehl — Makefile, tests/systemd-test/Makefile
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
10/10Reproduzierbare Umgebung — Dockerfile, lockfile
10/10Belegte Agentenpraxis — 11 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilesCargo.lock, uv.lock
has_dockerfileja
typed_languagenein
bootstrap_filesMakefile, tests/systemd-test/Makefile
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0,11
toolchain_manifestscore/Cargo.toml, core/crates/solstone-core-cli/Cargo.toml, core/crates/solstone-core-indexer-store/Cargo.toml, core/crates/solstone-core-indexer/Cargo.toml, core/crates/solstone-core-journal/Cargo.toml, core/crates/solstone-core-sol-client-cli/Cargo.toml, core/crates/solstone-core-sol-client/Cargo.toml, core/crates/solstone-core-sol-link/Cargo.toml, core/crates/solstone-core-sol/Cargo.toml, core/crates/solstone-core-speakers-analyze/Cargo.toml, core/crates/solstone-core-speakers-onnx/Cargo.toml, core/crates/solstone-core-speakers/Cargo.toml, core/crates/solstone-core-spl/Cargo.toml, core/crates/solstone-core/Cargo.toml
dependency_bot_commit_share0
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — Python ohne Typprüfungs-Konfiguration
52.5/55Handhabbare Dateigrößen — 81/1.751 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languagePython
largest_source_bytes251.353
source_files_sampled1.751
oversized_source_files81

Eckdaten

17GitHub-Sterne
3Mitwirkende
6.213Commits, letzte 12 Monate
0Tage seit letztem Push
69Releases
1Bus-Faktor
0offene Issues
crates.io, PyPIPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index pypi:solstone@1.0.21; advisories assessed against the repository dependency graph instead

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 7 ⇿
0Sterne
7Forks
48Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

1234567712026-012026-042026-07
Major 0Minor 3Patch 45
OpenSSF Scorecard 2.5 / 10
2.5Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-08-01 09:23 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 4 contributing companies or organizations
k. A.Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
k. A.Token-PermissionsNo tokens found
0Vulnerabilities100 existing vulnerabilities detected
Direkte Abhängigkeiten 9
RegistryPaketVersionsvorgabeManifest
PyPIsetproctitlepyproject.toml
PyPItyperpyproject.toml
PyPIrequestspyproject.toml
PyPIpsutilpyproject.toml
PyPIuserpath>=1.9.2,<2pyproject.toml
PyPIsolstone-core==1.0.21pyproject.toml
PyPIsolstone-core==1.0.21pyproject.toml
PyPIsolstone-core==1.0.21pyproject.toml
PyPIsolstone-core-unsupported-platform==1.0.21pyproject.toml
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 73016,
      "has_wiki": false,
      "homepage": "https://solstone.app",
      "languages": {
        "CSS": 145070,
        "HTML": 1711393,
        "Rust": 2194504,
        "Shell": 55059,
        "Swift": 11115,
        "Python": 23243736,
        "Makefile": 49420,
        "Dockerfile": 3089,
        "JavaScript": 933352
      },
      "pushed_at": "2026-08-01T09:23:17Z",
      "created_at": "2025-05-26T02:31:17Z",
      "owner_type": "Organization",
      "updated_at": "2026-08-01T08:51:27Z",
      "description": "Navigate Life Intelligently",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "main",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://solpbc.org/",
      "name": "sol pbc",
      "type": "Organization",
      "login": "solpbc",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/252481466?v=4",
      "created_at": "2026-01-01T17:58:09Z",
      "is_verified": null,
      "public_repos": 30,
      "account_age_days": 211
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.20",
          "kind": "patch",
          "published_at": "2026-07-31T06:45:30Z"
        },
        {
          "tag": "v1.0.19",
          "kind": "patch",
          "published_at": "2026-07-29T06:49:43Z"
        },
        {
          "tag": "v1.0.18",
          "kind": "patch",
          "published_at": "2026-07-28T16:45:37Z"
        },
        {
          "tag": "v1.0.17",
          "kind": "patch",
          "published_at": "2026-07-26T07:44:38Z"
        },
        {
          "tag": "v1.0.16",
          "kind": "patch",
          "published_at": "2026-07-25T23:14:40Z"
        },
        {
          "tag": "v1.0.15",
          "kind": "patch",
          "published_at": "2026-07-25T16:14:54Z"
        },
        {
          "tag": "v1.0.13",
          "kind": "patch",
          "published_at": "2026-07-24T06:24:02Z"
        },
        {
          "tag": "v1.0.12",
          "kind": "patch",
          "published_at": "2026-07-23T05:11:20Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-07-22T16:12:25Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-19T19:25:30Z"
        },
        {
          "tag": "v0.8.9",
          "kind": "patch",
          "published_at": "2026-07-17T06:42:19Z"
        },
        {
          "tag": "v0.8.8",
          "kind": "patch",
          "published_at": "2026-07-16T12:43:02Z"
        },
        {
          "tag": "v0.8.7",
          "kind": "patch",
          "published_at": "2026-07-15T13:32:05Z"
        },
        {
          "tag": "v0.8.6",
          "kind": "patch",
          "published_at": "2026-07-14T12:56:50Z"
        },
        {
          "tag": "v0.8.5",
          "kind": "patch",
          "published_at": "2026-07-14T12:08:11Z"
        },
        {
          "tag": "v0.8.4",
          "kind": "patch",
          "published_at": "2026-07-12T07:02:49Z"
        },
        {
          "tag": "v0.8.3",
          "kind": "patch",
          "published_at": "2026-07-10T17:35:34Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-07-08T05:15:55Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-07-07T05:32:35Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-07T05:10:10Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-05T14:32:07Z"
        },
        {
          "tag": "v0.6.24",
          "kind": "patch",
          "published_at": "2026-07-04T19:35:23Z"
        },
        {
          "tag": "v0.6.23",
          "kind": "patch",
          "published_at": "2026-07-04T17:19:14Z"
        },
        {
          "tag": "v0.6.22",
          "kind": "patch",
          "published_at": "2026-07-03T07:49:35Z"
        },
        {
          "tag": "v0.6.21",
          "kind": "patch",
          "published_at": "2026-07-02T06:53:29Z"
        },
        {
          "tag": "v0.6.20",
          "kind": "patch",
          "published_at": "2026-07-02T01:33:00Z"
        },
        {
          "tag": "v0.6.19",
          "kind": "patch",
          "published_at": "2026-07-01T05:48:56Z"
        },
        {
          "tag": "v0.6.18",
          "kind": "patch",
          "published_at": "2026-06-30T09:06:35Z"
        },
        {
          "tag": "v0.6.17",
          "kind": "patch",
          "published_at": "2026-06-29T14:55:22Z"
        },
        {
          "tag": "v0.6.16",
          "kind": "patch",
          "published_at": "2026-06-28T07:02:25Z"
        },
        {
          "tag": "v0.6.15",
          "kind": "patch",
          "published_at": "2026-06-27T05:50:04Z"
        },
        {
          "tag": "v0.6.14",
          "kind": "patch",
          "published_at": "2026-06-26T05:35:17Z"
        },
        {
          "tag": "v0.6.13",
          "kind": "patch",
          "published_at": "2026-06-25T04:57:23Z"
        },
        {
          "tag": "v0.6.12",
          "kind": "patch",
          "published_at": "2026-06-24T04:27:47Z"
        },
        {
          "tag": "v0.6.11",
          "kind": "patch",
          "published_at": "2026-06-23T01:20:46Z"
        },
        {
          "tag": "v0.6.10",
          "kind": "patch",
          "published_at": "2026-06-22T05:38:56Z"
        },
        {
          "tag": "v0.6.9",
          "kind": "patch",
          "published_at": "2026-06-20T02:36:03Z"
        },
        {
          "tag": "v0.6.8",
          "kind": "patch",
          "published_at": "2026-06-19T05:15:00Z"
        },
        {
          "tag": "v0.6.7",
          "kind": "patch",
          "published_at": "2026-06-18T04:08:59Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-06-17T06:39:19Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-06-15T19:49:01Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-06-15T04:59:25Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-06-15T03:36:29Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-06-15T01:04:03Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-14T23:42:48Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-06-14T17:48:03Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-06-14T05:16:26Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-06-12T20:40:31Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-06-10T07:11:28Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-06-06T05:24:39Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-06-05T13:26:24Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-06-05T13:11:29Z"
        },
        {
          "tag": "v0.4.10",
          "kind": "patch",
          "published_at": "2026-06-02T22:19:23Z"
        },
        {
          "tag": "v0.4.9",
          "kind": "patch",
          "published_at": "2026-06-02T02:27:34Z"
        },
        {
          "tag": "v0.4.8",
          "kind": "patch",
          "published_at": "2026-06-01T05:56:31Z"
        },
        {
          "tag": "v0.4.7",
          "kind": "patch",
          "published_at": "2026-06-01T03:14:53Z"
        },
        {
          "tag": "v0.4.6",
          "kind": "patch",
          "published_at": "2026-05-31T15:58:30Z"
        },
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-05-30T17:32:40Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-05-28T05:16:38Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-05-27T06:48:42Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-05-27T02:26:16Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-27T00:14:08Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-26T22:39:11Z"
        },
        {
          "tag": "v0.3.9",
          "kind": "patch",
          "published_at": "2026-05-25T19:34:26Z"
        },
        {
          "tag": "v0.3.8",
          "kind": "patch",
          "published_at": "2026-05-22T05:46:22Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2026-05-18T15:58:41Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2026-05-18T01:15:46Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2026-05-16T22:48:36Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-05-16T15:20:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "827cd6fe1a0ecaa44c79812d4eb3cdba6b041037",
          "body": "Bump the workspace, the Python packages and the tombstone sdist to 1.0.21,\nregenerate both lockfiles, and land the release notes for this cut.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(packaging): cut release metadata to 1.0.21",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T08:42:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "70785e18ecd09be0874b660bd461e9d00235edcd",
          "body": "device_superseded no longer exists as a producer or a documented event, so asserting it is not emitted is vacuously true for every input. The two test_duplicate_label_pair_keeps_predecessor_authorized_* tests already fail if auto-retire is reintroduced, and they fail on the certificate that actually got revoked rather than on an event name.\n\ndevice_superseded now has zero matches repo-wide. Also annotate the label-addressed unpair helper with the Flask test-client response type.",
          "is_bot": false,
          "headline": "test(network): drop stale device-superseded assertion",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T08:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46657e99153bf8d99c6f1af2929c2798f2902506",
          "body": "Resolve label-addressed unpair against display_label multiplicity instead of base-label equality. A name the owner can see remains usable when it is unique after migration; only an un-migrated or hand-edited ledger can still be ambiguous. The lookup deliberately widens blank assigned labels too: bec\n[…]\n_only compares enum lists by equality. link.unpair and link.devices are not among the bundle's 8 projected operations, so only the fragment.link source digest and projection-builder self-digest moved.",
          "is_bot": false,
          "headline": "fix(link): stop revoking device certs on a bare label match",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T08:10:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e38f0520485f585a40e33b2cec072a70a045e46",
          "body": "The auth.py docstring's label_ordinal entry now states the rule the code enforces: optional positive int, absent or invalid loads as 1, and omitted from the payload when 1. It also lines up with the JSON example block's comment column.\n\nrename()'s not-paired branch now tests updated is None rather than relying on ClientEntry truthiness. No behavior change.",
          "is_bot": false,
          "headline": "style(link): state the label_ordinal contract and the rename null check",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T06:52:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f94d88d31b095cbe0058f0b5aeed1d5f7e08385",
          "body": "…tion\n\nDeclare the link.devices 200 response item schema, including display_label and device_label, so paired-device payloads have a concrete generated contract.\n\nAdd the first OperationSpec for POST /app/network/rename, covering the persisted label response and the route's structured error reason c\n[…]\nenAPI artifacts with the network contract update. Bump the observer client bundle semver to 5.0.7 because the bundle compatibility gate requires a version change when generated bundle content changes.",
          "is_bot": false,
          "headline": "feat(network): declare link.devices item schema and link.rename opera…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T06:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b9deebbc1394f75568c11d59f797013c5b8983a",
          "body": "Store label_ordinal on ClientEntry and persist it through the authorized_clients.json writer, omitting the field when the ordinal is 1.\n\nAllocate ordinals inside the existing hold_lock window in add, add_browser, and update_label so concurrent writers and secure-listener touch_last_seen preserve per\n[…]\nsuffix remains renameable.\n\nReturn persisted labels from /rename and link pair_complete, and add an explicit idempotent backfill_label_ordinals repair invoked once per process from start_link_runtime.",
          "is_bot": false,
          "headline": "feat(link): stored label ordinal disambiguates same-named devices",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T06:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "288471c48f98f501fe884238731433c285ff52e6",
          "body": "…m anywhere\n\nThe secure listener reports a loopback peer the same way it reports a relay\ntunnel, because a relay tunnel terminates on loopback. Reach derived from the\npeer therefore read as anywhere for a machine pairing with itself, so the\nowners own computer would have appeared in their device lis\n[…]\nver-correct.\n\nAlso stop rebuilding the nonce field by field when marking it used: that\nreconstruction silently dropped every field added after it was written, which\nis exactly what it did to this one.",
          "is_bot": false,
          "headline": "fix(link): a machine paired with itself is at home, not reachable fro…",
          "author_name": "Jer Miller",
          "author_login": null,
          "committed_at": "2026-08-01T06:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "366969b02e5d096786122117e933911c321d0be7",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into spl-rust-lane-a",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T05:31:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc1de8f7b76d790688a85ab2334b2c00413dfbbb",
          "body": "A completed conversion wave declares the Python roots it removed. The check\nasked the filesystem whether those directories still existed, so a checkout\nthat deleted the sources but left ignored build output behind reported the\nwave as unfinished. The failure named the wave rather than the working tr\n[…]\nunt, so a\ngenuine leftover fails exactly as before, and the message now names an\noffending file. When git cannot answer, fall back to the on-disk test rather\nthan passing a retirement we cannot prove.",
          "is_bot": false,
          "headline": "fix(checks): retirement is a repository fact, not a disk fact",
          "author_name": "Jer Miller",
          "author_login": null,
          "committed_at": "2026-08-01T05:26:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1bfb49f05967cd5454ed91214ad9a3707cab2275",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into spl-rust-lane-a",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T05:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5f3da4ccb4faba3638bff61a8908a90926715ff",
          "body": "A connected home stopped re-reporting its health snapshot once it went quiet.\nThe web layer treats a snapshot older than its freshness window as evidence the\nlink is down, so `_derive_spl_relay_state` returned `offline` for a perfectly\nhealthy connected link — and nothing else re-emits between tunne\n[…]\nconfigurable so tests that\nassert exact event sequences are unaffected. The regression test drives a real\nlisten socket that never sends a control frame and was watched failing with the\nloop disabled.",
          "is_bot": false,
          "headline": "fix(spl): keep refreshing health while the listen socket is up",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T05:13:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "38f47fb5857844a254bb5f2a748278facd2a42aa",
          "body": "Assert the shared bound-observer registration helper writes a cert-class device binding with the expected fingerprint. This prevents helper regressions from silently minting unbound records while downstream tests continue authenticating on bearer keys.",
          "is_bot": false,
          "headline": "test(observer): guard bound registration helper",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21125838e05718acdf69043c01486928ad2248fd",
          "body": "Update the network operation contract for same_machine pair-start requests and revoked observer details on unpair. Regenerate the observer client bundle and OpenAPI artifacts with the patch semver bump.",
          "is_bot": false,
          "headline": "chore(contract): refresh observer client contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19d29f6f1d2996bbfd73be5569a1ad56c2aa2910",
          "body": "Keep the observer create route but return the retired-operation response, remove the workspace add form, and migrate tests to registration helpers that preserve bound and unbound shapes. Refuse URL export destinations and keep peer-label export coverage on the live path.",
          "is_bot": false,
          "headline": "fix(observer): refuse manual observer minting",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8650467c26ef9018ce514da05a32125c5d227327",
          "body": "Expose device_binding_kind across observer CLI and capture health surfaces without changing status semantics. Return revoked observer stream details from unpair, carry partial failure payloads, and render the new response in the native command.",
          "is_bot": false,
          "headline": "feat(observer): surface bindings in observer health",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1f9b4aec969574feac47407eac22594e6933455",
          "body": "Allow local callers to request a loopback pair link explicitly with same_machine while preserving the existing posture-based paths when the field is absent. Harden the shared loopback predicate for pair-start and local-endpoints by rejecting proxy-forwarding headers.",
          "is_bot": false,
          "headline": "feat(network): add same-machine pair links",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22c01091f5f87d1abffff17ac4e1d3d94f9cca94",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into spl-rust-lane-a",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T03:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b6e9b3af8b8f76795eba91ab5b520118aaae6ae",
          "body": "The verbose and debug flags were parsed and never read. A complete successful\nlifecycle — start, listen open, tunnel brokered, bytes both ways, posture flip,\nclean shutdown — produced zero bytes of output, while the Python it replaces\nlogged thirty-three lifecycle messages. The supervisor launches t\n[…]\ng for.\n\nVerified live: the reconnect loop this immediately exposed turned out to be two\ndaemons sharing one instance id in the test rig, which is precisely the class of\nproblem the silence was hiding.",
          "is_bot": false,
          "headline": "fix(spl): make the supervised service observable at -v",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T03:39:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab0fdd88925ef02a1acfdba8ea720105fd7f24a8",
          "body": "…tory\n\nThe zero-unsafe inventory gate matches the bare substring, so prose using the\nword tripped it. Reworded rather than loosened: making the gate token-precise\nwould suit one crate's comment at every crate's expense, and the invariant it\nguards is real — the workspace forbids unsafe outright, and\n[…]\ncontains any.\n\nThe replacement also says more than the original: an unreadable posture fails\nclosed and does not open the listener, which is the gate's security property\nrather than an aside about it.",
          "is_bot": false,
          "headline": "docs(spl): reword the posture-read comment away from the unsafe inven…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:26:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9527c8e500ea8f2a734abfea2fd3eb16c6baf03e",
          "body": "The health vocabulary moved from the spl package to the link package, which\nchanges where those imports sort. Import ordering is enforced by the lint gate,\nwhich is a separate step from the formatter and from a focused per-file run.",
          "is_bot": false,
          "headline": "style(spl): reorder the link-health imports after the module move",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:09:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0fbe51e7d2f92471f16216df5fe8a32e5aa6c47",
          "body": "Caught by the repository formatting gate — the same step that caught the\nforwarding test. Behaviour unchanged; re-verified green against both sources\nafter reformatting.",
          "is_bot": false,
          "headline": "style(spl): format the health-vocabulary gate",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:08:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54784057a2e90a2feb0ffd9c79c22cb1c0062844",
          "body": "The formatter wraps the handshake-result lambda across three lines. Caught by the\nrepository formatting gate, which is a separate step from the lint run.",
          "is_bot": false,
          "headline": "style(spl): format the native-service forwarding test",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:06:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c9f777a08e5e8a26bf7789659b53b864ff3247a",
          "body": "After the native cutover the reason codes, the callosum event name, and the\noffline subset live in two languages: the native service emits them, and the web\nlayer consumes them to classify link state into owner-visible copy. Nothing else\nmakes them agree, and drift is silent — a reason code that sto\n[…]\nr reason\ndrift, a language-only reason, an event-name change, an offline-subset change,\nand a missing source file. The last matters most — renaming a source cannot\nsilently turn the gate into a no-op.",
          "is_bot": false,
          "headline": "test(spl): gate the link-health vocabulary across both implementations",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:06:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d34d55390c0025bfd04942468cbb049e6b83da26",
          "body": "The lane's running work log is operator-process instrumentation — accepted-unit\nhistory, delegate review outcomes, contract-rework accounting — not a product\nartifact, and every publicly visible file in this repo is public surface.\n\nIt also carried an operator-role reference in its own text, which i\n[…]\nxactly the\nclass the public-file rule covers. Preserved operator-side; nothing about the\nconversion's result is lost from this repo, which records it in the code, the\ntests, and the divergence ledger.",
          "is_bot": false,
          "headline": "chore(spl): keep the conversion work log out of the product tree",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:04:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db4b26dfdab76c5e0943651a6226338754c2c15a",
          "body": "…oad key\n\nThe browser transport removal deleted solstone/think/link/upload_key.py, but the\njournal-io access gate still listed it as a direct owner. OWNER_FILES is a plain\nmembership set with no staleness check, so the entry never matches and never\nflags — it rots silently rather than failing.\n\nHarmless in isolation, since an allowlist entry for a file that does not exist\npermits nothing. Removed so the list keeps describing the tree it gates.",
          "is_bot": false,
          "headline": "chore(spl): drop the stale journal-io owner entry for the removed upl…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:03:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3c3a3c6a71f1b4d2635365321f19f191e487f1f",
          "body": null,
          "is_bot": false,
          "headline": "Complete U6 SPL transport cutover",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:01:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d30a4abf49d557d2fdae2b3c90a2ea4489c429e",
          "body": null,
          "is_bot": false,
          "headline": "Add U5 native service composition",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:57:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02358be5d583d9c3d685782f0ba153f3edc004cc",
          "body": null,
          "is_bot": false,
          "headline": "Fix U4 relay lifecycle events",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:33:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a158aa5c2112776885068668b2b477fbe46ead8e",
          "body": null,
          "is_bot": false,
          "headline": "Update U4 transport scope docs",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:11:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0501b86a9afb23075e625ef6eb0bd51dbe84770",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 TLS relay client",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:11:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e32fb0c49d21e09ad34475ee89f3e8812929fe17",
          "body": null,
          "is_bot": false,
          "headline": "Record SPL scope redirect",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:03:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be77c444cc65f21c7c11c8491e679f3435ec638f",
          "body": null,
          "is_bot": false,
          "headline": "Checkpoint held U2 dependency rework",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:55:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79f28f842df59f4754415490d402dd8fcf2e8e4e",
          "body": null,
          "is_bot": false,
          "headline": "Checkpoint U2 BlobDeps contract rework",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2f546b5cd5dc9c17a538ed127519002d49c1ad8",
          "body": "Adds a passing case for a member entry that renames an inherited SPL dependency (package set, workspace = true, no source or selector keys). It is accepted because the entry draws its source and tag from the workspace pin and its lockfile record is keyed by the real package name, so both remain governed by the existing workspace and lockfile checks.\n\nRecords that boundary as an invariant so the guard is not later tightened into a false positive.\n\nRemoves an unused test helper.",
          "is_bot": false,
          "headline": "test(rust): pin the SPL guard's member-inheritance boundary",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:31:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a788551edbffa6232f64c284fd0d525b06f5dddf",
          "body": "Add a repository guard that derives the approved SPL source and tag from core/Cargo.toml [workspace.dependencies], keeping the tag value out of the guard as a literal.\n\nBind both core/Cargo.lock SPL records to that derived tag and to one shared resolved commit.\n\nRequire member manifests to inherit v\n[…]\ncement, and tracked in-tree SPL package copies.\n\nThe existing pin, lockfile, and cargo-deny source rail are unchanged. The guard is wired into install-checks, so make ci and make verify both cover it.",
          "is_bot": false,
          "headline": "feat(rust): guard the workspace-owned SPL tag pin",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:31:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aac8b4b3b35b2f3da62fd15d10812fdf7be3471f",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 HPKE process dispatch",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:07:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a53e68941c617ffeb3948b01d32a753de6c0aa8",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 WebSocket transport halves",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:04:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dad8b4a155a912dd222c192191947c8b5a88c832",
          "body": "…essages\n\nMalformed requirement strings in the derived pin now raise the installer error instead of surfacing an InvalidRequirement traceback during make install.\n\nThe malformed-metadata error names what project.dependencies actually contained, and the interpreter guard that binds marker evaluation to the target venv now has negative test coverage.",
          "is_bot": false,
          "headline": "fix(install): speakers-analyze helper installer fails with specific m…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:59:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6edc225a7def406524b3f40435178ff7dcde9697",
          "body": null,
          "is_bot": false,
          "headline": "Add U5 service supervisor",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:56:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "400d5eb47b048ec99ae241c5cdcb883f1c57c822",
          "body": "… helper\n\nuv sync prunes the workspace-excluded helper, leaving source checkouts with a journal doctor blocker and an EX_CONFIG supervisor exit.\n\nAdd make speakers-analyze-helper to reinstall the published wheel using a pin derived at run time from packages/solstone-journal/pyproject.toml and uv pip\n[…]\nter uv syncs do not prune it.\n\nUpdate the speakers-analyze repair text to keep the packaged message unchanged while source checkouts point contributors to make speakers-analyze-helper or make install.",
          "is_bot": false,
          "headline": "fix(install): source checkouts install the published speakers-analyze…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e937b1cfe89ccd782ee251b4fb30a8e4eaa6c147",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 split tunnel pipe",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:50:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc4481dfa5572b846343e73a6c87d5e76e438e30",
          "body": null,
          "is_bot": false,
          "headline": "Add SPL parity corpus fixtures",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:48:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ddf7653564b5e8223413b8019e53eb8f7c74580",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 blob receiver",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:47:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "deb8238ad09e2586e3a4410ab3aa352721616d14",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 framed HPKE command core",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:36:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a98a4dd6c14341ebd627e72616ff0f67d51e292",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 split WebSocket sink",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:33:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "440e3f3efbfce0f44986b2240397c38df2a0e5e6",
          "body": null,
          "is_bot": false,
          "headline": "Register accepted SPL conversion units",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84a4dd30137deda8c931ed6ea439fd7655322edb",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 SPL command parsing",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61c149a5e2ab4e6df6604bd4b2be7f460f317d44",
          "body": null,
          "is_bot": false,
          "headline": "Add U5 supervision support",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51514ba56b5db84db6bd76bd7619450677c90408",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 relay dispatch support",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ff0a344b43618e29315d9be8fd9eb27b2ca4940",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 blob preparation units",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3600657960ce73bf3f7e91721c7e93dad559541b",
          "body": null,
          "is_bot": false,
          "headline": "Add U3 buffering admission and health",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3c009c0ab1664cc581186d783639139b7411a69",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 blob wire framing",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f7c313c13e7e70c302d42a942853f33c0db88cb",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 HPKE base and auth primitives",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:30:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7349edf5ef1d7a9b273eb07e419ada4998e6ff0",
          "body": null,
          "is_bot": false,
          "headline": "docs: align owner-facing terminology canon",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T21:31:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f4804a354a2fb372cbd46a734864454c530b62f",
          "body": null,
          "is_bot": false,
          "headline": "docs: retire customer-facing observer wording",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T21:24:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ed4dacb8012d2af862ab7b9ec9b17afd0d60e67",
          "body": "…provider\n\nThe 60s provider truth observation re-ran while the local model server was running and compared available system RAM against the 13.00 GiB MLX admission floor, after the provider's own approximately 9.74 GiB resident footprint had already been subtracted from that available-memory reading\n[…]\nng this removes; the eviction was accidental and fired at 13 GiB available, nowhere near OOM, so the OS now handles memory pressure.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(providers): admission-only block reasons no longer evict a ready …",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T20:51:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c3b7cc6e50961fb36981bcaa7103aa8ff510c400",
          "body": "The direct dial previously bounded only reaching the peer, so a peer that\naccepted the connection and never spoke TLS could hold a dial open for the\ncallers whole budget instead of failing over. v0.4.1 bounds the handshake\nitself on both the direct and control-plane dials.\n\nNo wire behavior, framing, flow control, pinning, or API change.",
          "is_bot": false,
          "headline": "chore(deps): adopt spl-rust v0.4.1",
          "author_name": "Jer Miller",
          "author_login": null,
          "committed_at": "2026-07-31T20:28:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bc42ee10275d7b4c84b6c5ffdebcafd8efd9e55",
          "body": "statement_embeddings.payload_format and statement_embeddings.dtype were validated against legacy Python literals. The Rust helper emits raw-f32le-row-major-v1 and float32-le, while the adapter wrongly required f32le and float32.\n\ncore/crates/solstone-core-speakers-analyze/src/lib.rs remains the sour\n[…]\nscripts/release_install_smoke.py now share one constant pair in solstone/apps/speakers/encoder_config.py, pinned to that Rust source by tests/test_speakers_analyze_wire_constants.py.\n\nCarrier: vpe-98.",
          "is_bot": false,
          "headline": "fix(speakers): align analyze wire literals",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T19:45:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adf2e9c5ff88d63aa03872c53bfe08cee7017bc3",
          "body": "Follow-on to #391. The detail endpoint's second metadata read sat outside\nthe not-found guard, so an import removed between the two reads raised\ninstead of returning import_not_found. Both reads now share the guard;\nstatus resolution stays outside it, since it touches no filesystem.\n\nAdds the server\n[…]\nitself\nreturns status, error and error_stage — the half a later refactor drops\nsilently. Two tests now pin it: an unfinished import reads running, and a\nfailed one carries its error and stage through.",
          "is_bot": false,
          "headline": "fix(import): guard both detail reads and pin the status contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T16:12:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a114a2ce85427915d91a018043b9d4918fe521d8",
          "body": null,
          "is_bot": false,
          "headline": "feat(import): enhance import status handling and UI updates.",
          "author_name": "ha-ye",
          "author_login": "ha-ye",
          "committed_at": "2026-07-31T12:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d44ef202b64f1ad0729dd6faddae5eeee7ac4a86",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): witness transparency for 1.0.20",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T06:50:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "354c775f6602ac207ce37160a0fc4ceeb9569c2c",
          "body": "The differential harness proof deliberately creates a run directory under the\nrepository tmp/ scratch root, because proving the oracle ignores concurrent\n__pycache__ churn requires an in-repo location. Under xdist that directory\nappears and disappears inside an unrelated consumer window, so the verd\n[…]\n and joins the existing\nruntime-directory exclusions for the same reason each of those was added. The\nin-repo write invariant remains asserted directly by the harness in-repo\ndestination refusal test.",
          "is_bot": false,
          "headline": "test(speakers): exclude gitignored repo scratch from the no-write oracle",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T02:56:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57432d517e92dd6059d107377d77a22857f1cc7b",
          "body": null,
          "is_bot": false,
          "headline": "feat(packaging): cut release metadata to 1.0.20",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T02:43:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73af7c07741ab7a73ec87e74a5b202ffe6132439",
          "body": "Bump BUNDLE_SEMVER 5.0.4 -> 5.0.5 after the reason-code vocabulary text moved. That file is a digest-pinned producer, so the manifest must record the new producer digest even though the route projection is unchanged.\n\nRegenerated the contract bundle; projection, vectors, and wire-behavior fixtures regenerated byte-identical, so only the manifest moved.",
          "is_bot": false,
          "headline": "chore(observer): re-pin observer client contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:57:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6104e6b4d386912d511e322c19eb7351a6d24e3b",
          "body": "local_request_only is used for callers that fail register admission and for admitted callers that target a stream already bound elsewhere. Keep the shared owner-facing error general enough for both cases, while the response detail names the specific refusal.\n\nUpdate the retired observer create guidance and unreleased notes so they describe the shipping behavior: local observers can register directly, remote observers use pairing, and existing streams cannot be taken over by another device.",
          "is_bot": false,
          "headline": "fix(observer): clarify register refusal copy",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:56:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27412a72294c9fa4167473803293e30ec58d136e",
          "body": "Bump BUNDLE_SEMVER 5.0.3 -> 5.0.4 after the register admission and observer auth changes moved digest-pinned producers. The manifest now records updated digests for observer_bundle.py, the observer contract fragment and extension, observer routes, observer utils, root SSE, and the reason-code vocabu\n[…]\ncription matches the local/device admission behavior. The recorded vectors and wire-behavior fixtures regenerated byte-identical and are not changed, keeping the bound-record recording surface stable.",
          "is_bot": false,
          "headline": "chore(observer): re-pin observer client contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:43:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b35189d1ea87170fe1433f8f91c54ff36f7f15a",
          "body": "Unbound records are valid handle-authenticated observers, so operator surfaces should not treat a missing device binding as degraded or as a separate status. Capture health now derives freshness and ingest rejection state without adding an unbound degradation.\n\nDoctor and the observer CLI no longer read or count unbound state. A fresh unbound observer reports connected like any other active observer, while revoked and disconnected states keep their existing meanings.",
          "is_bot": false,
          "headline": "fix(observer): remove unbound operator warnings",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:42:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fea0b8a8df15eb5a6c50da8474c97f2b87a26920",
          "body": "Enforce device bindings only when an observer record has one. Unbound records now authenticate after the existing handle, revoked, and disabled checks, so records without a binding keep handle-based behavior while bound records still require the matching cert or browser pairing.\n\nRestore register's \n[…]\necord in place and preserve the key, created_at, stats, and history. SSE streams on unbound records skip only device-level rechecks; observer-level revoked and disabled checks still run each interval.",
          "is_bot": false,
          "headline": "fix(observer): relax unbound observer auth",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:42:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04543c5a96fb15cc4be0fac1e62d36878b0c83f2",
          "body": "Update the owner-facing refusal copy and API contract description for observer self-registration when the required device pairing is missing or mismatched.\n\nThe reason code remains local_request_only, and the observer client contract bundle takes a patch bump to 5.0.3.",
          "is_bot": false,
          "headline": "fix(observer): say a device pairing is required on register refusal",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T23:22:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bd97eefcad89024eccc0570eee20c0872bd09b8",
          "body": "Re-register journal observer create as a write-free refusal so old invocations see pairing guidance instead of argparse usage output.\n\nAccept a trailing --json flag and a bare create command on the retired path, but keep one terminal stderr contract and exit 2.",
          "is_bot": false,
          "headline": "fix(observer): explain why manual observer creation is retired",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T23:22:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfbc7522f104be74cfab909748486936688e5039",
          "body": "Pin both spl-core and spl-transport to the v0.4.0 tag.\n\nBoth crates resolve to 742bc9dc789c5a75658844849a04d75033aeb6e3.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): pin spl-rust to v0.4.0",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:44:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e38889cf7c6ec041ef23548c0209f03cd40bd542",
          "body": "Remove a dead helper left behind by the register rewrite. The register route now resolves device binding directly, so keeping a caller-free trust helper would make future edits look for an authorization seam that no longer exists.\n\nThe observer-client-contract manifest pins solstone/apps/observer/ro\n[…]\ne-visible surface moved.\n\nPrecedent: bac06ff57 and f7cfe2a85 did the same re-pin after earlier changes to\nthe pinned producer files.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(observer): remove stale register trust helper",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:34:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fdb5bd99fe6268deda0a5afb2bd4665ca3276f0f",
          "body": "Shared fixtures and contract recording now need the same verified device proof as real observer registration. Seed bound observer records with matching ledger entries, stamp contract recorder requests with request-scoped identity, and regenerate the observer client bundle manifest without changing reason-code sets.",
          "is_bot": false,
          "headline": "test(observer): bind fixtures for contract recording",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:23:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ea28d164afa81af3ce203efdf15af5a4866af28",
          "body": "Unbound records remain loadable for inspection but are refused at auth time. Show that state in observer status output and escalate it through the existing capture-health degraded path so operators can see why capture is not healthy.",
          "is_bot": false,
          "headline": "feat(observer): surface unbound records",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d5149a2bbe921c9be8671c59444c401f7d3f42f",
          "body": "Observer records now require verified device binding at registration time, so a local CLI command that minted bearer-only records would create unusable credentials. Remove the create subcommand and its reuse path, letting argparse report the clean break while docs point operators to paired observer installers.",
          "is_bot": false,
          "headline": "feat(observer): retire manual observer creation",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:23:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea5392476134c62c7f2ba2e7da69247b89f7521",
          "body": "Unpair removes the device from the paired-device ledger first, then asks the observer owner to revoke records bound to that device. This keeps the network app out of direct observer-record writes while making device removal take effect for observer streams.",
          "is_bot": false,
          "headline": "feat(network): revoke bound observers on unpair",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:21:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15518d1229cc3205b063cde30090019a9348b870",
          "body": "Browser pairing needs the ledger entry to exist before observer registration can prove device ownership. Allow pending browser entries without an observer handle, then attach the handle under the authorized-client writer once register succeeds.",
          "is_bot": false,
          "headline": "feat(link): attach browser observer handles after register",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:21:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2d623e98051be8f08b483ee1bb09a8328d567bc",
          "body": "Observer handles were portable bearer credentials. Store the owning device class and identifier on each observer record, require the bound device in the shared identity resolver, and make register mint records only from verified device proof so the handle becomes only a per-stream selector.\n\nThe SSE stream now rechecks the bound device on a bounded interval so revocation closes busy streams without waiting for an idle heartbeat.",
          "is_bot": false,
          "headline": "feat(observer): bind records to verified devices",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:21:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f6753328eae83d7db8bc517127a1271f6ab5b3d",
          "body": "Defect B was that _release_provider_startup_gate_if_ready released the buffered TaskQueue after a 60s wall-clock window while _start_llama_local_server is allowed 300s to load a model. The gate only learned about a provider through gate.terminal, and launch outcomes only reached that set after the r\n[…]\n nine steps inside a boundary that swallows every non-fatal exception, so a deterministic raise in any earlier step meant neither backstop ever fired.\n\nCo-Authored-By: GPT-5 Codex <noreply@openai.com>",
          "is_bot": false,
          "headline": "fix(supervisor): release the startup gate on the first concluded launch",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T19:35:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4dc8bd237bb79fd928c0563ae402780109e2ab73",
          "body": "Dropped the unreachable has_execution_error arm from summary_counts' failed count; probe.run_check already builds error results with status fail, so errors are a subset of failed by construction.\n\nAdded probe.results_failed, the single aggregate rule for any execution error or any blocker-severity f\n[…]\nsummary_status, and preflight.main instead of duplicated conditions.\n\nAdded preflight --json coverage asserting the structured execution_error payload and a nonzero exit for an advisory raising check.",
          "is_bot": false,
          "headline": "refactor(doctor): share the aggregate failure predicate",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T18:46:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e103c98ad71b948277543b7cda41e5f5f8dc5ce4",
          "body": "An ordinary Exception from one check now becomes that check's own fail result carrying an additive execution_error payload: exception type plus a message truncated to 512 chars, with no traceback. The fan-out continues in original order.\n\nThe shared boundary is probe.run_check, used by doctor's batt\n[…]\nconflict execution error now takes the unknown-topology fix policy so repair guidance cannot render 'first: None'.\n\nNo new status value, event type, or error code is added; setup.py remains unchanged.",
          "is_bot": false,
          "headline": "fix(doctor): isolate check execution failures from the battery",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T18:46:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85f81dc18d72e0fbd988dc8e23d6172309ce2de2",
          "body": "Add the owner-facing held-by-backoff reason and route/client handling so process-now reports the held state instead of queued.\n\nRegenerate the Convey OpenAPI and observer-client projection, and bump BUNDLE_SEMVER from 4.0.2 to 5.0.0. An Error.reason_code enum change is a changed component schema; the compatibility gate requires exact list equality for additive-only, so it classifies MAJOR.",
          "is_bot": false,
          "headline": "surface held process-now refusals",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:54:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1df190213ed4de48a51c79031384ae64d5286fb8",
          "body": "Add a catchup-state read helper that proves when a day is held by daily catchup or segment repair backoff from one snapshot, with active records falling through to status quo behavior.\n\nHave reprocess_day return HELD_BY_BACKOFF before sending the supervisor drain request, and pin the CLI/process-now behavior plus the forced-drain regression guard.",
          "is_bot": false,
          "headline": "refuse held process-now drains",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:53:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40d71831d69f77bff46f1fd8f39cbfd9d0acde97",
          "body": null,
          "is_bot": false,
          "headline": "test: split release checks from development ci",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:44:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cfb735886bf97cbc0600bbae89dc819581a95b9",
          "body": "Four owner-facing entries under [Unreleased]: refused arrivals now leave a trace,\nimports queue instead of silently vanishing, a slow chat reply is no longer read\nas a stopped one, and a passing readiness check no longer leaves a third-party\nerror line in the error list and support diagnostics.\n\nDrafted through the changelog recipe. The refusal-recording entry describes what\nyour journal accepts and refuses, so it carries a sensitive-content flag and needs\napproval before this publishes.",
          "is_bot": false,
          "headline": "docs(changelog): record the batch-18 fix arc",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:15:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "346bdeb1ec59a92a2e13936e8fd8a41d27a6e022",
          "body": null,
          "is_bot": false,
          "headline": "test: remove remaining non-unit journal groups",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T16:59:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a219df21a0d84ce12532c513244452f7fa179605",
          "body": "connect() now raises local_model_loading when the health probe reports STATE_LOADING instead of collapsing that state into local_model_not_ready. The owner-facing message is unchanged because LOCAL_MODEL_NOT_READY_COPY is reused; the no-port and STATE_FAILED paths remain local_model_not_ready.\n\ntest\n[…]\nn _STARTUP_REASON_CODES, so is_blocking_reason and backlog_reason_category, and every rendered surface downstream of them, are unchanged. This changes what the system knows, not what any surface says.",
          "is_bot": false,
          "headline": "fix(local): raise loading reason for loading server",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T16:38:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57ca91bb2945520b5fb290d26770b6b44ef931cd",
          "body": null,
          "is_bot": false,
          "headline": "test: trim scaffolding and checker self-tests",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T16:28:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6c7903dbf392b6dde592e230954b2daf386da66",
          "body": "The concurrency test for JSONEventWriter.emit passed with the emit lock removed.\nThe lock is correct; the test could not detect its absence.\n\nCause is the test double, not the assertions. _CollectingStdout.write is a bare\nlist append, so print()'s two writes - payload then newline - never interleave\n[…]\nis the terminal finish event, the answer is dropped and the use hangs\nto a 600s kill. That is the original defect made worse and silent, and this is\nthe only test standing between it and a regression.",
          "is_bot": false,
          "headline": "test(talents): make the concurrent-emit gate able to fail",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T15:33:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bac06ff57eeb3e2cec2cbaba6c81a835540dbbcb",
          "body": "…n log\n\nThe observer-client-contract manifest pins solstone/apps/observer/routes.py and\nsolstone/apps/observer/utils.py by digest under producer.observer_routes and\nproducer.observer_utils. Routing ingest auth rejections through the accountant\nchanges both hashes, so `make check-openapi` goes red wi\n[…]\nfe2a85 did the same re-pin after the chat watchdog change, and\n996a67fa4 after an earlier change to solstone/apps/observer/utils.py.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(convey): re-pin observer producer digests for the ingest rejectio…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:47:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7be059b51d314b13a42e598dbe9ee1a3855517ba",
          "body": "Follow up the audit by adding the return type annotation on the new _rejection_response helper.",
          "is_bot": false,
          "headline": "Annotate observer rejection response helper",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06b7cc6421081a8a7b046a623e0f7f55fe715d5c",
          "body": "Note that observer ingest auth failures now produce an in-memory, rate-limited operational log signal: periodic WARNING records during a live burst and a quiet-close ERROR carrying active_count for support diagnostics.",
          "is_bot": false,
          "headline": "Document observer auth rejection signal",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84b3904ad1bb471854370ae2e7b17feeb9329853",
          "body": "Split observer identity resolution into one authoritative _resolve_identity()\ncore and two named entry points: resolve_observer_identity() keeps the exact\nexisting 3-tuple contract, while resolve_ingest_identity(surface) adds the\nin-memory burst sweep and rejection accounting. This was chosen over w\n[…]\nt contract\ncompatibility failed: bundle content changed without a version bump from\n2.1.9\". Clearing that would require bumping a shipped-client wire-contract\nbundle version, which this scope forbids.",
          "is_bot": false,
          "headline": "Route observer ingest auth rejections to logs",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39fe1dc5b3e88d92bc3d2973a391e11bc9609bea",
          "body": "Add the in-memory observer auth rejection accounting module with the 300 second warning window, 300 second quiet-close threshold, 64 bucket cap, keyless sentinel, lock-protected table, sweep, reset seam, and the single WARNING/ERROR emission sites.\n\nThe module keeps the signal slash-free and prefix-only: one WARNING per bucket per window while a rejection burst remains live, and one ERROR on time-based close carrying active_count. It has no persisted file and no config key.",
          "is_bot": false,
          "headline": "Add observer auth rejection accountant",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7cfe2a85ddf65b3fecbe0fb3767091a75745f51",
          "body": "…ange\n\nThe observer-client-contract manifest pins solstone/convey/chat.py by digest\nunder producer.chat_routes. Adding the watchdog cancel path to that file\nchanges its hash, so `make check-openapi` goes red without regenerating the\nbundle.\n\nBump bundle_semver 4.0.0 -> 4.0.1 and regenerate. The chan\n[…]\ne\nidentical, so no wire-visible surface moved.\n\nPrecedent: 996a67fa4 did the same re-pin after dfad79db2 changed\nsolstone/apps/observer/utils.py.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(convey): re-pin observer producer digest for the chat watchdog ch…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ede18852f27be4334db559dfd91be290df5c03bb",
          "body": "The coupling assertion previously ran against a monkeypatched interval, so it could not catch the production constant being widened past the chat watchdog cap.\n\nMove the guard into a dedicated test that imports the production talents interval and convey watchdog timeouts directly. The failure messag\n[…]\nnstead of a line number, and removes the unsent ts field from the docs cancel example so the documented wire shape matches the code.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(talents): bind the liveness interval to the watchdog cap",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "249b41979538907688d10c9b087416c930b3e686",
          "body": "When the chat watchdog tripped, convey abandoned the raw use and discarded its result, but the talent ran to completion holding its slot.\n\nThe watchdog now issues a cortex cancel for the abandoned raw use: chat kind only, after the owner-visible error and before any queued turn is spawned, guarded s\n[…]\nd like the abandoned-use map and evicted wherever a turn ends. This also corrects a stale code citation for cortex's inbound filter.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(chat): cancel the abandoned use when the watchdog fires",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ba83ee57d0ca743f2ee35f922e740ead3213900",
          "body": "Cortex's inbound filter accepted only event=request, so a cancel was silently dropped. The filter now also accepts event=cancel, and the work is queued to a dedicated FIFO worker rather than handled inline.\n\nTalentProcess.stop() blocks in process.wait(timeout=10), and the talent cannot service SIGTE\n[…]\n after the cancel terminal. The file is still completed exactly once and the use is already abandoned, so nothing reaches the owner.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cortex): accept a cancel request off the receive thread",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5178a8941acfb7b6641f2cd1adeb7431ac66fb55",
          "body": "_execute_generate calls generate_with_result synchronously, so the event loop is blocked for the whole generation and it emitted nothing between start and its terminal event. The 30 s chat watchdog was therefore measuring latency, not silence.\n\nA daemon OS thread now emits a progress event every _GE\n[…]\n would drop the answer entirely.\n\nOn the reported chat path the watchdog fired at roughly a quarter of the generation's own timeout.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(talents): emit liveness progress during blocking generation",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee0dee0be5dafcb92043c5e38b256408f754727d",
          "body": "The brain readiness probe runs a canned cogitate prompt with a deliberate 2-turn ceiling, so the vendored OpenHands SDK logs `Agent reached maximum iterations limit (N).` at ERROR while our layer treats the run as a success and brain reports ready.\n\nAdd a diagnostic-only context manager that install\n[…]\ndiagnostics still behave as before, while the demoted line no longer carries an ERROR token. Two golden fixture rows pin both forms.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(providers): demote the readiness probe's max-iterations ERROR",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T13:53:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 69,
      "commits_last_year": 6213,
      "latest_release_at": "2026-07-31T06:45:30Z",
      "latest_release_tag": "v1.0.20",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 52,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 1.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "solstone",
          "exists": true,
          "license": "AGPL-3.0-only",
          "keywords": [
            "audio",
            "transcription",
            "screenshot",
            "multimodal",
            "ai",
            "gemini",
            "Development Status :: 3 - Alpha",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: GNU Affero General Public License v3",
            "Operating System :: MacOS :: MacOS X",
            "Operating System :: POSIX :: Linux",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Topic :: Multimedia :: Graphics :: Capture :: Screen Capture",
            "Topic :: Multimedia :: Sound/Audio :: Analysis",
            "Topic :: Scientific/Engineering :: Artificial Intelligence"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/solstone/",
          "is_deprecated": false,
          "latest_version": "1.0.21",
          "repository_url": "https://github.com/solpbc/solstone-journal",
          "versions_count": 78,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 6851,
          "first_published_at": "2026-05-07T04:05:48.769890Z",
          "latest_published_at": "2026-08-01T09:22:36.902583Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 7,
      "stars": 17,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-04-05",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-05-14",
            "count": 1
          },
          {
            "date": "2026-05-27",
            "count": 1
          },
          {
            "date": "2026-06-12",
            "count": 1
          },
          {
            "date": "2026-07-05",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 7,
        "total_forks": 7
      },
      "star_history": null,
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "tests/systemd-test/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "core/Cargo.toml",
        "core/crates/solstone-core-cli/Cargo.toml",
        "core/crates/solstone-core-indexer-store/Cargo.toml",
        "core/crates/solstone-core-indexer/Cargo.toml",
        "core/crates/solstone-core-journal/Cargo.toml",
        "core/crates/solstone-core-sol-client-cli/Cargo.toml",
        "core/crates/solstone-core-sol-client/Cargo.toml",
        "core/crates/solstone-core-sol-link/Cargo.toml",
        "core/crates/solstone-core-sol/Cargo.toml",
        "core/crates/solstone-core-speakers-analyze/Cargo.toml",
        "core/crates/solstone-core-speakers-onnx/Cargo.toml",
        "core/crates/solstone-core-speakers/Cargo.toml",
        "core/crates/solstone-core-spl/Cargo.toml",
        "core/crates/solstone-core/Cargo.toml"
      ],
      "largest_source_bytes": 251353,
      "source_files_sampled": 1751,
      "oversized_source_files": 81,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "GEMINI.md",
        "journal/AGENTS.md",
        "journal/CLAUDE.md",
        "journal/GEMINI.md",
        "solstone/apps/import/guides/claude.md",
        "solstone/apps/import/guides/gemini.md",
        "tests/fixtures/journal/AGENTS.md",
        "tests/fixtures/journal/CLAUDE.md",
        "tests/fixtures/journal/GEMINI.md"
      ],
      "agent_instruction_max_bytes": 52085
    },
    "dependencies": {
      "manifests": [
        "core/Cargo.toml",
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "setproctitle",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "requests",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "psutil",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "userpath",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.9.2,<2"
        },
        {
          "name": "solstone-core",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        },
        {
          "name": "solstone-core",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        },
        {
          "name": "solstone-core",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        },
        {
          "name": "solstone-core-unsupported-platform",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 380,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 2,
        "closed_unmerged_prs": 7
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "quartzjer",
          "commits": 7184,
          "avatar_url": "https://avatars.githubusercontent.com/u/61632?v=4"
        },
        {
          "type": "User",
          "login": "maxspeed27",
          "commits": 85,
          "avatar_url": "https://avatars.githubusercontent.com/u/129209864?v=4"
        },
        {
          "type": "User",
          "login": "ha-ye",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/58130581?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.988
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 4 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "100 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "827cd6fe1a0ecaa44c79812d4eb3cdba6b041037",
        "ran_at": "2026-08-01T09:23:51Z",
        "aggregate_score": 2.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-08-01T08:51:24Z",
      "oldest_open_prs": [
        {
          "number": 386,
          "created_at": "2026-05-11T14:55:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 389,
          "created_at": "2026-06-30T19:53:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-31T16:12:42Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/solpbc/solstone-journal",
    "host": "github.com",
    "name": "solstone-journal",
    "owner": "solpbc"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 59 is calibrated to 63 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 59,
            "calibrated": 63,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 63,
      "inputs": {
        "security": 25,
        "vitality": 96,
        "community": 51,
        "governance": 59,
        "calibration": "2026-08-02",
        "engineering": 50,
        "ai_readiness": 67,
        "weighted_overall_raw": 59
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "exceptional",
        "name": "Vitality",
        "value": 96,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "exceptional",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "commits_last_year": 6213,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 52
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "52/52 weeks with commits",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 52
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "6213 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 6213
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 69,
              "latest_release_tag": "v1.0.20",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 1.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "69 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 69
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 51,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "forks": 7,
              "stars": 17,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "17 stars",
                "points": 19.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "7 forks",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "solstone"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 6851
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "6,851 downloads/month across pypi",
                "points": 51.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 6851,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.988
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 82,
            "inputs": {
              "merged_prs": 380,
              "open_issues": 0,
              "closed_issues": 2,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 7,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "380/387 decided PRs merged",
                "points": 29.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 380,
                      "decided": 387
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "followers": 5,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "solpbc",
              "public_repos": 30,
              "account_age_days": 211
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of solpbc",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "solpbc"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "30 public repos, account ~0 yr old",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 30
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "solstone"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "78 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 78
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 50,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://solstone.app",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://solstone.app",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 25,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 25,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 14,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 4,
              "scorecard_aggregate": 2.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "100 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 67,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.73,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "GEMINI.md",
                "journal/AGENTS.md",
                "journal/CLAUDE.md",
                "journal/GEMINI.md",
                "solstone/apps/import/guides/claude.md",
                "solstone/apps/import/guides/gemini.md",
                "tests/fixtures/journal/AGENTS.md",
                "tests/fixtures/journal/CLAUDE.md",
                "tests/fixtures/journal/GEMINI.md"
              ],
              "agent_instruction_max_bytes": 52085
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "73 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 38.9,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 73,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "Makefile",
                "tests/systemd-test/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.11,
              "toolchain_manifests": [
                "core/Cargo.toml",
                "core/crates/solstone-core-cli/Cargo.toml",
                "core/crates/solstone-core-indexer-store/Cargo.toml",
                "core/crates/solstone-core-indexer/Cargo.toml",
                "core/crates/solstone-core-journal/Cargo.toml",
                "core/crates/solstone-core-sol-client-cli/Cargo.toml",
                "core/crates/solstone-core-sol-client/Cargo.toml",
                "core/crates/solstone-core-sol-link/Cargo.toml",
                "core/crates/solstone-core-sol/Cargo.toml",
                "core/crates/solstone-core-speakers-analyze/Cargo.toml",
                "core/crates/solstone-core-speakers-onnx/Cargo.toml",
                "core/crates/solstone-core-speakers/Cargo.toml",
                "core/crates/solstone-core-spl/Cargo.toml",
                "core/crates/solstone-core/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, tests/systemd-test/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, tests/systemd-test/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "11 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 11,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 251353,
              "source_files_sampled": 1751,
              "oversized_source_files": 81
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "81/1751 source files over 60KB",
                "points": 52.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1751,
                      "oversized": 81
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "library",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 6
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:pypi",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:typer",
          "weight": 4
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index pypi:solstone@1.0.21; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-01T09:24:01.850966Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/solpbc/solstone-journal.svg",
  "full_name": "solpbc/solstone-journal",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v2.3.1, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenPyPI.