Öffentliches Register
Software-GesundheitsberichtSchema 0.27.0 · Metriken 1.13.0 · 2026-07-30 03:35 UTC

stranxik / runward

After the spec: ship and run. A delivery framework for agentic systems — floor first, evolution on evidence, governance from day zero, handover with proof.

TypeScript · JavaScriptMIT★ 1 Stern⑂ 0 Forksseit Juli 2026Auf GitHub ansehen ↗

stranxik/runward erreicht einen Gesundheitsindex von 63 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Engineering Quality (77/100) ab, am schwächsten bei Community & Adoption (47/100). Zuletzt heute aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

63
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

63
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

ThibaultPersönliches Konto
6 Follower15 öffentliche Reposseit März 2017

Dieses Repository gehört einem persönlichen Konto. Ein Projekt mit nur einem Eigentümer trägt ein höheres Kontinuitätsrisiko als ein organisationsgetragenes.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
npmrunward0.22.03.16327vor 8 Tagenagenticai-agentsspec-drivendeliverygovernancellmarchitecture

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

70Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 0 Tagen
2.8/36Commit-Rhythmus — 4/52 Wochen mit Commits
18/18Commit-Volumen — 240 Commits im letzten Jahr
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Verwendete Eingangsdaten
commits_last_year240
human_commit_share1
days_since_last_push0
active_weeks_last_year4
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 26 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 8 Tagen
27/27Release-Rhythmus — ein Release etwa alle 0,6 Tage
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Verwendete Eingangsdaten
releases_count26
latest_release_tagv0.22.0
releases_from_tagsnein
days_since_latest_release8
mean_days_between_releases0,6

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

47Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 1 Stars
0/25Forks — 0 Forks
0/15Watcher — 0 Watcher
Verwendete Eingangsdaten
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
6.3/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templateja
Wie die Bewertung erfolgt
46.7/80Downloads pro Monat — 3.163 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesrunward
dependents
ecosystemsnpm
total_downloads
monthly_downloads3.163
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

54Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
46.8/46.8Issue-Lösungsquote — 100 % der Issues geschlossen
32.4/38.3PR-Annahme — 33/39 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/13 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs33
open_issues0
closed_issues1
issue_closed_ratio1
closed_unmerged_prs6
Wie die Bewertung erfolgt
10/30Organisatorische Trägerschaft — persönliches (Nutzer-)Konto
0/20Verifizierte Domain — für Nutzerkonten nicht anwendbar
6.1/25Reichweite des Inhabers — 6 Follower von stranxik
20.8/25Kontohistorie — 15 öffentliche Repos, Kontoalter ca. 9 Jahre
Verwendete Eingangsdaten
followers6
owner_typeUser
is_verified
owner_loginstranxik
public_repos15
account_age_days3.418
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Verifizierte Domain. Die verbleibenden Gewichte wurden renormalisiert.

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 8 Tagen
20/20Versionshistorie — 27 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesrunward
ecosystemsnpm
any_deprecatednein
min_days_since_publish8

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

77Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 4 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

90Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://runward.dev
10/10Repository-Beschreibung
0/10Topics
10/10Wiki
Verwendete Eingangsdaten
topics
has_wikija
homepagehttps://runward.dev
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

67Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — keine Daten
2.5/2.5CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/13 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,9
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): branch_protection. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
35/35Direkte Abhängigkeiten ohne bekannte Advisories — keine direkte Abhängigkeit trägt ein bekanntes Advisory
25/25Indirekte Abhängigkeiten ohne bekannte Advisories — keine indirekte Abhängigkeit trägt ein bekanntes Advisory
0/40Keine offenen Advisories — kein Advisory trägt ein Veröffentlichungsdatum
Verwendete Eingangsdaten
sourceosv
advisories0
affected_packages0
assessed_packages27
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Keine offenen Advisories. Die verbleibenden Gewichte wurden renormalisiert. Abgeglichen wurde die Laufzeit-Abhängigkeitshülle von npm:runward@0.22.0 — das, was die Installation des veröffentlichten Pakets nach sich zieht — mit 27 Paketen. Erreichbarkeit wird nicht analysiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

72Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — examples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 95 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,95
agent_instruction_filesexamples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md
agent_instruction_max_bytes133.430
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — examples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
5/8Automatisierte Wartung — Abhängigkeits-Automatisierung konfiguriert, in den erfassten Commits nicht beobachtet
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configsexamples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
55/55Handhabbare Dateigrößen — 0/90 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes41.069
source_files_sampled90
oversized_source_files0
Wie die Bewertung erfolgt
0/40API-Schema (OpenAPI/GraphQL/proto)
20/20MCP-Server
40/40Lauffähige Beispiele — examples
Verwendete Eingangsdaten
example_dirsexamples
has_mcp_signalja
api_schema_files

Eckdaten

1GitHub-Sterne
1Mitwirkende
240Commits, letzte 12 Monate
0Tage seit letztem Push
26Releases
1Bus-Faktor
0offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 5.9 / 10
5.9Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-30 03:35 UTC

10Binary-Artifactsno binaries found in the repo
k. A.Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/13 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
8Vulnerabilities2 existing vulnerabilities detected
Direkte Abhängigkeiten 4
RegistryPaketVersionsvorgabeManifest
npmzod^4.4.3floor-ts/package.json
npm@inquirer/prompts^8.5.2package.json
npmchalk^5.6.0package.json
npmcommander^15.0.0package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Abhängigkeits-Advisories 0

Die Installation von npm:runward@0.22.0 zieht 27 Pakete nach sich, direkt und transitiv: 0 tragen bekannte Advisories, davon 0 direkte Abhängigkeiten.

Keine bekannten Advisories betreffen die bewerteten Abhängigkeiten.

Ein Advisory bedeutet, dass die im Abhängigkeitsgraphen erfasste Version in den betroffenen Bereich eines Advisories fällt. Erreichbarkeit wird nicht analysiert, und der Graph enthält Entwicklungs- und Test-Pins — ein Fund kann das Werkzeug betreffen und nicht die ausgelieferte Software.

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2181,
      "has_wiki": true,
      "homepage": "https://runward.dev",
      "languages": {
        "Shell": 633,
        "Python": 1783,
        "JavaScript": 142995,
        "TypeScript": 309690
      },
      "pushed_at": "2026-07-29T09:54:02Z",
      "created_at": "2026-07-05T21:40:41Z",
      "owner_type": "User",
      "updated_at": "2026-07-29T09:55:39Z",
      "description": "After the spec: ship and run. A delivery framework for agentic systems — floor first, evolution on evidence, governance from day zero, handover with proof.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://runward.dev",
      "name": "Thibault",
      "type": "User",
      "login": "stranxik",
      "company": null,
      "location": "France",
      "followers": 6,
      "avatar_url": "https://avatars.githubusercontent.com/u/26541747?v=4",
      "created_at": "2017-03-20T10:42:16Z",
      "is_verified": null,
      "public_repos": 15,
      "account_age_days": 3418
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-21T15:17:35Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-07-21T13:15:11Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-19T19:25:59Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-07-19T13:02:17Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-07-17T12:46:00Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-07-16T10:30:19Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-16T08:23:23Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-07-16T02:51:13Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-16T02:02:49Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-16T00:59:50Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-07-13T15:35:19Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2026-07-13T10:57:52Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-13T10:26:06Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2026-07-12T20:40:53Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-07-12T11:10:38Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-07-12T10:38:32Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-12T09:44:00Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2026-07-11T18:45:46Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-07-11T10:53:17Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-11T08:58:40Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-10T11:48:58Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-10T07:50:45Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-07-09T12:18:06Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-09T12:08:57Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-07T15:05:47Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-07T12:06:36Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9c30a25dd438f14658afbdd5b47b1ec40c06ad63",
          "body": "docs(adr): ratify the brownfield/characterize ADRs (0033–0038)",
          "is_bot": false,
          "headline": "Merge pull request #48 from stranxik/docs/ratify-brownfield-adrs",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-29T09:53:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32a64d13dff1beee9defd4c5a3ca64c9a80df990",
          "body": "…en proof\n\nThe six ADRs from the 2026-07-20 resume-existing audit — ADR-0033 (status\nnames the iterate steady-state and the reopening watch) and ADR-0034..0038\n(characterize sees the whole tree, extracts pinned versions offline, reports\nchurn/bus-factor, detects infra & framework/DB signals, mines d\n[…]\ntion for\n  ADR-0035) — the two ADRs that had unit coverage only.\n- CHANGELOG: a dated Ratification entry naming the drift; no version bump.\n\nSelf-gate green: 109 unit tests, smoke OK, oscal-schema OK.",
          "is_bot": false,
          "headline": "docs(adr): ratify the brownfield/characterize ADRs (0033-0038) + hard…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-29T09:50:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d23c4b05bcc32ad34287ce4f576ab8e4c09e4cb7",
          "body": "chore(release): v0.22.0 — every gate names what it cannot verify",
          "is_bot": false,
          "headline": "Merge pull request #39 from stranxik/release/v0.22.0",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:17:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84e5bb88ec2c9a5d84fed94859136eeaaf857326",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.22.0 — every gate names what it cannot verify",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:16:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc9dfb06d31ebc98809be196a015c9e083aaf2fb",
          "body": "feat(rules): ADR-0040 ratified — per-rule non-scope declaration",
          "is_bot": false,
          "headline": "Merge pull request #38 from stranxik/feat/adr-0040-nonscope",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:04:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6212cf2948a26f6ed01460434af5060c64ef6c81",
          "body": "…-wide default\n\nEvery gate names what it cannot verify. GATE_NON_SCOPE stated once\n(machine surface + explain + ISO readiness draft); per-rule nonScope\nwhere the blind zone is narrower (4 rules seeded). Gate path, manifest\nand ADR-0003 lint untouched — the rule-file carrier made the feared\nmigration unnecessary. 106 tests, self-gate green.",
          "is_bot": false,
          "headline": "feat(rules): ADR-0040 ratified — per-rule non-scope declaration, gate…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:03:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab0f835a1d6b718f08766ad3e1358da05bad4811",
          "body": "docs: survey-grounded pass — third guardrail, change contract, ADR-0040 (proposed), distillation fence",
          "is_bot": false,
          "headline": "Merge pull request #37 from stranxik/docs/survey-actions",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:29:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62dbf698840124eed3d207b0250e7b09a5e8fe9e",
          "body": "…ot a trigger",
          "is_bot": false,
          "headline": "docs(roadmap): AHE loop as the satellite's citable frame — a frame, n…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "612f428d5a61aab91b3a34da7e00e5a4437642e6",
          "body": "…v 2605.18747)",
          "is_bot": false,
          "headline": "merge survey/regulated-adoption (flotte worktrees, confrontation arXi…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5d0a150ad3a9d465139f1ce67cf4c75a1793be3",
          "body": "… 2605.18747)",
          "is_bot": false,
          "headline": "merge survey/adr-0040-nonscope (flotte worktrees, confrontation arXiv…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d14703c8a2d9973816e0420629e97010af15c729",
          "body": "…v 2605.18747)",
          "is_bot": false,
          "headline": "merge survey/adr-0006-amendment (flotte worktrees, confrontation arXi…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fef48ea40931fd643c6d9aa715092600939331a",
          "body": "…18747)",
          "is_bot": false,
          "headline": "merge survey/positioning (flotte worktrees, confrontation arXiv 2605.…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a52b839deefe746ececf177a3389f830e9d7727",
          "body": "…Xiv 2605.18747)\n\n- Compliance guardrails: add the academic pendant to FedRAMP RFC-0024 and\n  Delve — the SWE-bench solved-correctly study (arXiv 2503.15223) cited by\n  the Code-as-Agent-Harness survey for its oracle-adequacy crisis, plus the\n  14-53% step-level failure-attribution range, and the su\n[…]\nsions at delivery, never runtime actions) and 'change contract' in\n  pillar 4 (dated reevaluation triggers + ADR-0006 tracked migrations).\n\nDrift gate: test/unit/positioning-drift.test.js green (5/5).",
          "is_bot": false,
          "headline": "docs(positioning): third guardrail talking point + survey lexicon (ar…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9f3a843e32c1a6938cebdfc3083fee8988529b4",
          "body": "…alising ADR-0005 (status: proposed)",
          "is_bot": false,
          "headline": "docs(adr): ADR-0040 candidate — per-rule non-scope declaration, gener…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:26:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c59a4bd23e401e947953d790ddaa570348c3afa8",
          "body": "…y dated ADR, not promise (arXiv 2605.18747)",
          "is_bot": false,
          "headline": "docs(regulated): the distillation-surface fence — traces stay yours b…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce5c1af7f89f32e4dcc1027a75ffdf04bae4b2ab",
          "body": "…(invariants, falsifier, rollback)",
          "is_bot": false,
          "headline": "docs(adr): amend ADR-0006 — the migration entry as a change contract …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "776f7a671c5853f19412b05cab4eed7eb59ca2d1",
          "body": "chore(release-workflow): migrate deprecated actions/attest-sbom to actions/attest",
          "is_bot": false,
          "headline": "Merge pull request #36 from stranxik/chore/attest-migration",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2fd9935557547ade9f7becabacc1194237068c45",
          "body": "…w action name\n\nThe posture guard pinned the literal 'attest-sbom@<sha>'; the migration to\nactions/attest tripped it (as designed). The guard now asserts the successor\naction SHA-pinned AND the sbom-path binding, preserving the guarded property:\nSBOM SLSA-attested against the published tarball.",
          "is_bot": false,
          "headline": "test(posture): guard follows the attest migration — same property, ne…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:23:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0415e904aaa224a2215de002cb5953a39f05574d",
          "body": "…tions/attest\n\nSurfaced as a deprecation warning in the v0.21.1 publish log. actions/attest\nv4.2.0 accepts sbom-path directly (creates the same SBOM attestation); inputs\nunchanged, SHA-pinned. Real proof lands with the next release run.",
          "is_bot": false,
          "headline": "chore(release-workflow): migrate deprecated actions/attest-sbom to ac…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:20:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4410048ebdf94fd8935578d418974bb507c91f7",
          "body": "chore(release): v0.21.1 — the three tiers, named",
          "is_bot": false,
          "headline": "Merge pull request #35 from stranxik/release/v0.21.1",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:14:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07bb8684b9c5ee3df4cdaf223d049d3d624fb7a5",
          "body": "CHANGELOG block for the docs release (ADR-0039, two site pages, roadmap\ngroom), version stamped across the six distribution manifests, roadmap\nre-groomed at v0.21.1. No CLI change, no gate change.",
          "is_bot": false,
          "headline": "chore(release): v0.21.1 — the three tiers, named",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:13:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59f859ab440e7eedd72e957a82d2244cb9a75c55",
          "body": "docs(adr): ADR-0039 — the operator layer stays outside the CLI",
          "is_bot": false,
          "headline": "Merge pull request #34 from stranxik/docs/operator-layer",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f93267556a5880ff4c08d87c53a587503dd3ce1a",
          "body": "… roadmap\n\nThree tiers named (docs to follow on the site), wiring guide planned,\ninert samples at most, operator tooling never in the MIT CLI, satellite\ndeferred behind the ADR-0028 channel-signal watch.",
          "is_bot": false,
          "headline": "docs(adr): ADR-0039 — the operator layer stays outside the CLI; groom…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:02:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be6567000a99766a938789f91d0e889f559b2632",
          "body": "…tate\n\nfix(brownfield): close the resume-existing audit findings (ADR-0033–0038)",
          "is_bot": false,
          "headline": "Merge pull request #33 from stranxik/adr-0033-status-iterate-steady-s…",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-20T08:03:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b48670efe8b83d599b15f6307e8cbd29fe4c726",
          "body": "A multi-agent audit of the resume-existing lot (adversarially verified,\n47/48 findings confirmed) surfaced three blockers and a set of important\ndefects, all in the code that promises deterministic *facts*. Fixed at\nthe root — no workarounds, no debt — with the ADRs amended to match.\n\nDeterminism (w\n[…]\nckfile fixture per\nclaimed family; scoped-extraction fixtures; the cross-locale determinism\nprobe. Also aligned runward's own ADR-0001 to the mandated trigger\nheading so its dogfooded status is clean.",
          "is_bot": false,
          "headline": "fix(brownfield): close the resume-existing audit findings (0033-0038)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-20T07:55:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8bbef0c5e3f8b05460b9e8b6e03b37893652b0ed",
          "body": "ROADMAP.md had not been touched since v0.14.2: the floor-ts English\npass and the documentation site were both long shipped and still listed\nas ahead. Groomed, and — same fix pattern as the manifest stamps — a\npackaging test now fails the build if the 'Last groomed' stamp lags the\npackage version, so the roadmap can no longer rot silently.",
          "is_bot": false,
          "headline": "chore(roadmap): groom (7 releases late) + stale-roadmap guard",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T20:05:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "504c83823507864146e633f21ad1048bf466bd9b",
          "body": "README: the guiding principle now names its ancestry (information\nhiding, Parnas 1972; ports and adapters, Cockburn 2005) and states the\ndefault-not-requirement status inline, linking when-to-use. when-to-use:\nthe modularity paragraph gains the family map — onion, Clean,\nfunctional core, modular monolith all satisfy the hexa-* rules as\napplied (the rules check substance, never the label); vertical-slice or\ntransaction-script is the healthy deviated case.",
          "is_bot": false,
          "headline": "docs: place the hexagonal default in its fifty-year lineage",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:50:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aaaf41e8a6014a69e9592db37c3ec79080eea04",
          "body": "The structure-neutrality argument existed without its words: the default\nshape is a modular core behind ports and adapters (hexagonal), a sober\ndefault with evolution triggers, never a requirement — the gate checks\nthe decision was confronted, and deviating with a traced ADR passes\ngreen (runward's own mission deviates). Extends the 'One language in\nthe core' neutrality from language to structure.",
          "is_bot": false,
          "headline": "docs(when-to-use): name modularity and the hexagonal default explicitly",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67f924784b2e79915cfec87184ef28aa7b42c2a1",
          "body": "Extend 'runward gates itself' with the supply-chain parallel: publishing\nis a deliberate human gesture, everything downstream is deterministic\nmachinery (OIDC trusted publishing, SLSA provenance, attested SBOM).\nThe deterministic executes; the human decides the crossing.",
          "is_bot": false,
          "headline": "docs(readme): the release runs the same stance as the gate",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:28:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed0ce84186282dcf9b8ba5b3ac58a52a2db81328",
          "body": "One command, the whole chain green: init --example now chains check --strict\non the freshly scaffolded reference mission (deterministic, zero-network,\nskipped under --dry-run), and its next-steps point at the guard demo\n(npm run demo — req-005, fabricated account, refused fail-closed).\n\nREADME accur\n[…]\nced comparison (Spec Kitty), FDE expanded on first use,\nWhy section leads with what runward does, compare + case-study linked from\nthe Documentation list. Example README counts all five demo requests.",
          "is_bot": false,
          "headline": "feat(init): --example ends by running the strict gate itself (v0.21.0)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:10:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7860e9f8cab775e5d37ad8943a77d9db6903422a",
          "body": "docs(readme): surface 'try it' up front + lighten Why",
          "is_bot": false,
          "headline": "Merge pull request #32 from stranxik/docs/readme-try-it-early",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:47:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9117417b74edceb8325a362ad876519f2a9e6d48",
          "body": "Since the repo is the Show HN landing and the post's angle is 'go test it',\nmove the one-command trial up front (right after the entry, before the dense\nWhy section) instead of burying it ~50 lines down under Install. Show both:\n'npx runward init --example' (watch the chain go green + the guard catc\n[…]\nricated value) and 'npx runward init' (start your own project). Also\ncondense the densest Why paragraph (dropped the five-gestures enumeration;\nthe detail lives in the method/differentiator sections).",
          "is_bot": false,
          "headline": "docs(readme): surface 'try it' right after the entry + lighten Why",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:47:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c47997443e95d1d02ee35306b5a44125c8ce6ac7",
          "body": "fix(readme): self-host the npm badge (no shields/camo flap)",
          "is_bot": false,
          "headline": "Merge pull request #31 from stranxik/fix/npm-badge-self-hosted",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:14:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7949cf90a9d122863d7c54573a2d2eb1a0d0032",
          "body": "The npm badge kept flapping (broken then delayed) — GitHub's camo proxy\nfetching img.shields.io at cold cache. It was the only dynamic badge; even\nmade static, it depends on the flaky camo<->shields path. Serve it from the\nrepo instead (raw.githubusercontent, GitHub's own domain, like the banner):\nrenders reliably, zero external dependency, no flap on launch day. Rendered\nat 2x, displayed at height 28 to match the shields for-the-badge row.",
          "is_bot": false,
          "headline": "fix(readme): self-host the npm badge (no more shields/camo flap)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:13:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87724fdf605f9462f214bc0ea6051d9b4896a667",
          "body": "fix(release): SBOM job must not attach to the release (contents:read)",
          "is_bot": false,
          "headline": "Merge pull request #30 from stranxik/fix/release-sbom-no-release-assets",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:01:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "094dc395dda2486581ccabf1c268eb3ad9648c46",
          "body": "The v0.20.0 release failed: anchore/sbom-action defaults to\nupload-release-assets:true, which needs contents:write — but the unprivileged\nSBOM job is contents:read (the whole point of the split). Set it false; the\nSBOM travels as a workflow artifact and the privileged publish job attaches it\nto the release (it has contents:write). Fail-closed worked: nothing published.",
          "is_bot": false,
          "headline": "fix(release): SBOM job must not attach to the release (contents:read)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:00:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e6328ac160d1865b64855faaa8505f2806031dc",
          "body": "chore(release): v0.20.0",
          "is_bot": false,
          "headline": "Merge pull request #29 from stranxik/release/v0.20.0",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:56:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cf26286ff6676291262988cb37888552be83182",
          "body": "Bumps the version across package.json, the six distribution manifests (the\npackaging guard requires them in lockstep), CITATION.cff, the repo's own\nmission stamp and the distribution examples; adds the v0.20.0 CHANGELOG entry.\n\nShips: regulated-adoption evidence + SBOM/provenance (ADR-0031), OSCAL 1\n[…]\nven by a third-party tool (ADR-0032), the security-audit hardening, the\nTypeScript 7 forward-compat, and the docs/README work. Publish happens when\nthe GitHub Release is cut (OIDC trusted publishing).",
          "is_bot": false,
          "headline": "chore(release): v0.20.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:55:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f45dc122d5229dea4407179f9c1d2fc61fe3ec76",
          "body": "fix(readme): static npm badge (shields live endpoint failing)",
          "is_bot": false,
          "headline": "Merge pull request #28 from stranxik/fix/readme-npm-badge-static",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:52:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbb84304fc28a6b3c57eabe004d9a1334bfa58c4",
          "body": "GitHub's camo returned 'Error Fetching Resource' fetching the dynamic\nimg.shields.io/npm/v/runward badge — shields' live npm-registry lookup was\ndown (the static shields badges rendered fine). Swap to a static npm badge\n(same for-the-badge style + npm logo) that never does a live lookup, so it\nrenders reliably. The version lives on the npm page, Releases and package.json.",
          "is_bot": false,
          "headline": "fix(readme): static npm badge (shields' live npm/v endpoint was failing)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:51:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "823e468c94d7ce7b84ae985e1f4da0db911eb225",
          "body": "fix(readme): broken images (absolute banner URL + npm badge refresh)",
          "is_bot": false,
          "headline": "Merge pull request #27 from stranxik/fix/readme-broken-images",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9032348d794df029225a08090c259ce4aa5d948",
          "body": "…images)\n\n- Banner used a relative path (assets/og-image-en.jpg) that npmjs.com can't\n  resolve (it isn't in the published tarball), so the header image was broken\n  on the npm package page. Point it at the raw GitHub URL — renders everywhere.\n- npm shields badge showed a broken-image icon on GitHub (camo cached a failed\n  shields fetch). Drop the redundant &label=npm (the npm/v badge already labels\n  itself 'npm'), which also changes the URL so GitHub re-fetches it.",
          "is_bot": false,
          "headline": "fix(readme): absolute banner URL + refresh the npm badge URL (broken …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec43c7088ce411b39632ab18e838a9f260accfd7",
          "body": "docs(readme): plainer HN-facing entry + version-less OG banner",
          "is_bot": false,
          "headline": "Merge pull request #26 from stranxik/docs/readme-entry-and-og",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa42216dc9fc59491403f98d6d8cfe85392884d3",
          "body": "Since a Show HN links to the repo, the README is the landing. Rewrite the top\n(tagline + intro) in plain, direct language matching the launch post: lead with\n'AI writes the code — who verifies the engineering decisions behind it?', drop\nthe insider tagline ('the floor / run-grade engineering') and the dense\nthree-doors paragraph from the entry (that depth still lives in the sections\nbelow). Also swap in the evergreen, version-less OG banner.",
          "is_bot": false,
          "headline": "docs(readme): plainer HN-facing entry + version-less OG banner",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:32:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfa702c73388f439a8d9610c874729c9667be398",
          "body": "chore(deps): ignore TypeScript major bumps in Dependabot",
          "is_bot": false,
          "headline": "Merge pull request #23 from stranxik/chore/dependabot-ignore-ts-major",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:45:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f69dd26541c49750b78fcd2a9333ff5a121bf67",
          "body": "Adopting the TS 7 native-compiler preview on a published package is a\ndeliberate, hand-made call, not an automated bump — so Dependabot now\nignores typescript's major-version updates (minor/patch still flow). The\ntsconfig is already TS-7-ready (PR #22, types:[node]); this just stops the\nnoise until TS 7 is GA-stable. Documented in the dependabot.yml comment and\na CHANGELOG Unreleased entry.",
          "is_bot": false,
          "headline": "chore(deps): ignore TypeScript major bumps in Dependabot",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:44:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b7f83f5f3efaa04dfc57108ffb0d99050386e54",
          "body": "chore(build): declare types:[node] in tsconfig (TypeScript 7 forward-compat)",
          "is_bot": false,
          "headline": "Merge pull request #22 from stranxik/chore/tsconfig-explicit-node-types",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96822356398eff923f45c6d4a6c634b38638a825",
          "body": "…compat)\n\nThe tsconfig relied on TypeScript's implicit auto-inclusion of every\n@types/* package. TypeScript 7's native compiler drops that behaviour, so\nthe build failed with 102 errors (TS2591 'Cannot find name node:fs/…',\nplus cascading TS7006 implicit-any once @types/node no longer resolved).\nDec\n[…]\nexplicitly fixes it and is fully backward-compatible\n(TS 5.9.3 still builds with zero errors). Better hygiene regardless; makes\nthe eventual TypeScript 7 bump a clean pass. typescript stays at ^5.9.3.",
          "is_bot": false,
          "headline": "chore(build): declare types:[node] in tsconfig (TypeScript 7 forward-…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19d87513ddbeedba2797ae1fbc834b5fce54e70c",
          "body": "chore(security): move SBOM generation out of the OIDC-privileged publish job",
          "is_bot": false,
          "headline": "Merge pull request #21 from stranxik/chore/release-sbom-least-privilege",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:13:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90e8dc48170e75b7fca6a6993891f35e707383e4",
          "body": "…ish job\n\nAudit finding #1 (low): the third-party anchore/sbom-action ran inside the\nsingle publish job that holds id-token:write + contents:write. Split it into\na separate 'sbom' job with contents:read only; the privileged 'publish' job\nnow downloads that SBOM artifact and attests it. Workflow-leve\n[…]\n-closed: if SBOM\ngeneration or download fails, publish does not run.\n\nPins actions/download-artifact@d3f86a1 (v4). Needs validation on the next\nreal release (the OIDC publish path cannot run on a PR).",
          "is_bot": false,
          "headline": "chore(security): move SBOM generation out of the OIDC-privileged publ…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:12:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9608f450b065a8f09c8fc9060a872728a5c74e",
          "body": "chore(security): hardening from the security audit (CI, engines, ReDoS screen)",
          "is_bot": false,
          "headline": "Merge pull request #20 from stranxik/chore/security-hardening-audit",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:09:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1747efc1f694d7a8892b8b37107cd18c967c26ed",
          "body": "…S screen)\n\n- CI: set persist-credentials:false on every checkout in ci.yml and\n  watch-external-facts.yml, matching release.yml/scorecard.yml (OSSF\n  Scorecard consistency; no token left in the working tree).\n- engines: raise the Node floor to >=22.12.0 (was >=20). Node 20 is EOL\n  since 2026-04 an\n[…]\nscreen missed. Deterministic, zero-dep, in the spirit\n  of ADR-0020; a hostile rule signature can no longer hang check --strict.\n  Adds tests; existing safe signatures stay accepted (self-gate green).",
          "is_bot": false,
          "headline": "chore(security): hardening from the security audit (CI, engines, ReDo…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:03:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "231f18c2e14480eb356c7fde5c229e7e4c4466a9",
          "body": "docs(readme): use language-neutral /docs links",
          "is_bot": false,
          "headline": "Merge pull request #19 from stranxik/docs/readme-neutral-docs-links",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T10:27:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aa8ce8ee3f6a64b99c6f91b1ccb3593f7d5b560",
          "body": "The docs site now auto-routes /docs to the visitor's language (French\nbrowser -> French, otherwise English), so the README no longer needs to\npin /docs/en. Neutral links serve each reader their own language.",
          "is_bot": false,
          "headline": "docs(readme): use language-neutral /docs links",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T10:27:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8d2ef0750f0f9bd870ab3b94e266064f219893f",
          "body": "docs(readme): point doc-site links to the English docs (/docs/en)",
          "is_bot": false,
          "headline": "Merge pull request #18 from stranxik/docs/readme-en-links",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:57:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96d6d646b55407ebab866f2862244063b9934886",
          "body": "The repo is English-only; the hosted /docs root is the French default and\n/docs/en is the English tree. Point the Docs badge and the Documentation\nsection links at /docs/en so they match the repo language. Visible label\nleft as runward.dev/docs.",
          "is_bot": false,
          "headline": "docs(readme): point doc-site links to the English docs (/docs/en)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:57:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34f6b520b4a5f493655ccf8417c8d47103bf79f1",
          "body": "docs(readme): surface the hosted documentation site",
          "is_bot": false,
          "headline": "Merge pull request #17 from stranxik/docs/readme-site-links",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:44:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efec03eae34a791cce3e1258c5fe36b3f128dc57",
          "body": "The README only linked to in-repo markdown. Add a Docs badge and a\nDocumentation section pointing to runward.dev/docs with the key entry\npoints (quickstart, the deterministic gate, six phases, from-an-agent,\ncompliance evidence). In-repo doc links are kept as-is.",
          "is_bot": false,
          "headline": "docs(readme): surface the hosted documentation site",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:40:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2bdc619645b302729e9a979698eef7a7c6011c1",
          "body": "A multi-agent documentation audit flagged small repo-to-world drifts:\n- src/lib/tools.ts: JSDoc said 'four phase skills' but PHASE_SKILLS has\n  five (architect, topology, floor, govern, handover).\n- runward/architecture.md: stamped v0.18.1 and cited 24 / 28 ADRs while\n  the journal holds 32; bumped to v0.19.0 (2026-07-17), counts -> 32.\n- runward/contracts/port-contract.md: the check signature omitted the\n  --json flag the CLI ships.\n\nSelf-gate strict green, 77/77 tests.",
          "is_bot": false,
          "headline": "docs: correct stale factual drifts surfaced by the docs audit",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T19:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea3b8b37f087f3ddadf842712edafd45277e700",
          "body": "The watch (issue #16) flagged runward two OSCAL generations behind NIST.\nA close-look investigation proved the bump trivial and risk-free:\n\n- our exact output validates against the NIST 1.2.2 component-definition\n  schema (runward's own ajv harness), version literal aside;\n- compliance-trestle 4.2.0\n[…]\nthe\n  self-hosting mission deliverables). CHANGELOG left historical.\n- ADR-0032 rewritten + renamed; watch OSCAL message reworded.\n- 77/77 tests green; trestle ingests the fresh 1.2.2 pack end-to-end.",
          "is_bot": false,
          "headline": "feat(oscal): track current OSCAL — bump 1.1.2 -> 1.2.2 (ADR-0032)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T18:18:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fdbc43b7133acfa2ef72f98b0c41d22e52a58b6",
          "body": "runward had silently fallen two OSCAL generations behind NIST (pinned\n1.1.2; NIST is at 1.2.2) with no test reddening — internal drift guards\ncompare repo-to-doc, never repo-to-world.\n\n- ADR-0032: staying on OSCAL 1.1.2 is a deliberate, recorded choice\n  (1.2.x is additive/backward-compatible; a bum\n[…]\n; others annual). It never\n  enters the OSCAL, so the golden is unchanged.\n- regulated-posture drift guard asserts the watch exists and tracks both\n  OSCAL and reviewBy, so silent deletion reddens CI.",
          "is_bot": false,
          "headline": "feat(governance): watch dated external facts out-of-band (ADR-0032)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T18:00:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc60a2ad72a4a042f54e8cb6aa9d9daa0edf0d73",
          "body": "The note describing the guard quoted the forbidden term \"audit-grade\"\nliterally, in a line the negation scanner does not count as negated.\nReword to \"a forbidden overclaim\" so the guard stops biting itself.",
          "is_bot": false,
          "headline": "fix(ci): positioning drift guard tripped on its own meta-note",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1999a78c8671078c1c8bf4e0837fd55948ad1f91",
          "body": "…ompliance-trestle)\n\nCloses the gap flagged as the most visible in regulated review: the OSCAL pack was validated\nonly against our vendored NIST JSON schema. Now every CI run also loads it in a real, independent\nOSCAL tool.\n\n- ci.yml job 'oscal-ingest': emit a pack from the reference mission, then i\n[…]\nRC SaaS ingestion stays the operator's step.\n- Drift guard extended: the oscal-ingest job + script are now enforced, so this proof can't be\n  silently dropped. Self-gate strict green; drift guard 6/6.",
          "is_bot": false,
          "headline": "feat(regulated): prove OSCAL ingestion by a third-party tool in CI (c…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:45:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53b8c6f5178efa94640f8639744b2234892db926",
          "body": "…of truth cannot lie\n\nSame principle as the regulated-adoption guard: pin the verifiable claims of the marketing\nsource of truth so they cannot silently drift or overclaim.\n\ntest/unit/positioning-drift.test.js enforces:\n- the MANDATORY compliance guardrails are present and intact (audit-ready, NOT a\n[…]\nry cited ADR-NNNN exists.\nProven to bite: a stale date or a diluted guardrail fails it. Runs in npm test → in the self-gate.\nSubjective wording stays free. Self-gate strict green; 81 unit checks pass.",
          "is_bot": false,
          "headline": "feat(positioning): drift guard over positioning.md — the copy source …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:37:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db130e7410b5d0a8d3520bb98bd622ee55e4b1c7",
          "body": "…n sheet\n\nTwo things, both the runward principle turned on runward's own governance — the agent\nproduces, a deterministic gate guarantees, the operator decides.\n\n- SBOM on every push/PR (ci.yml, Syft SHA-pinned), not only at release: surfaces a\n  dependency drift between releases as an artifact.\n- t\n[…]\n stale. Proven to bite:\n  un-pinning an action fails the guard. Runs in npm test, so it's in the self-gate.\n- The sheet now states it is enforced by this guard. Self-gate strict green; npm test green.",
          "is_bot": false,
          "headline": "feat(regulated): SBOM in CI + a drift guard that enforces the adoptio…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:31:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc2ed95920e42a3bcf07811b751baaa9cc521a43",
          "body": "…ne, factual corrections\n\nThree-agent adversarial audit of the regulated wedge; all confirmed findings fixed.\n\nSecurity (release workflow):\n- Publish the packed tarball itself (npm publish $TARBALL) so the SBOM attestation binds\n  to the exact artifact downloaded (attested == published) — the integr\n[…]\nis no secret scanner — the true claim is\n  no long-lived Actions secrets at all (OIDC trusted publishing).\n- SECURITY.md now links the regulated-adoption sheet. Self-gate strict green; npm test green.",
          "is_bot": false,
          "headline": "fix(regulated): audit follow-ups — SBOM integrity, supply-chain hygie…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:23:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37bce033360fa15c5e66e357e89c8c89e5c21600",
          "body": "…icence framing (ADR-0031)\n\nA four-agent investigation confirmed runward is usable in regulated environments as a\nwedge (sovereign engineering evidence that feeds a compliance programme), not a validator,\nand that its local/no-data-flow nature makes most vendor due-diligence moot. This closes\nthe *r\n[…]\n, and the honest limits\n  (no runtime logs for art.12, point-in-time, single-maintainer/no-SLA, forkability).\n- Linked from the compliance index and the README. Self-gate strict green; npm test green.",
          "is_bot": false,
          "headline": "feat(regulated): narrow the wedge — SBOM, regulated-adoption sheet, l…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:11:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "228f1f18b1e01a285fbcd8adc385e1009de34a42",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): date v0.19.0 to its release day (2026-07-17)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T12:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4941980f5359b2f75452c359637a4d129da30129",
          "body": "Version bump across package.json, CITATION.cff, and the six distribution manifests\n(packaging.test guard green), plus the CHANGELOG entry and the distribution.md pin\nexamples. ADR-0030 ships: neutral init default, runward wire (read-only harness\ndetection), check --json, hardened non-interactivity.",
          "is_bot": false,
          "headline": "chore(release): bump to 0.19.0 — agent-operable baseline + runward wire",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T14:39:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab4472b3892c930064dc86c5b58bdea25c39a343",
          "body": "…e null-channel path, ADR + doc coherence\n\n- check --json --hooks no longer corrupts the JSON contract: a hook's stdout is\n  routed to stderr (fd 2) under --json, since log() cannot suppress a subprocess\n  (audit finding, machine-contract blocker).\n- wire: when a config-detected harness ships no cha\n[…]\ndsurf → recommendedChannel null, bare-mission → undetermined, and check --json\n  --strict exposes conformance / --json alone omits it. Unit 65, smoke green.\n- README: add the runward wire command row.",
          "is_bot": false,
          "headline": "fix(check,wire): audit follow-ups — no JSON pollution from hooks, wir…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T14:16:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f71b0fb3d97b17c077feee968c56153bd8170140",
          "body": "…ead-only (ADR-0030)\n\n- runward wire: detects the AI harness running the command via verified runtime\n  signals (CLAUDECODE for Claude Code + Cowork, GEMINI_CLI, CURSOR_AGENT), falling\n  back to config-file markers (weaker), then 'undetermined'. Recommends the matching\n  auto-trigger channel and poi\n[…]\n(runtime signal > config file > undetermined).\n- Tests: 6 unit cases (signal precedence, Cursor marker, undetermined, config override,\n  wires:false invariant) + a smoke contract check on wire --json.",
          "is_bot": false,
          "headline": "feat(wire): best-effort harness detection → channel recommendation, r…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T14:09:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88ac7018eacd5cbfdce3f9a443656abd8c95e442",
          "body": "…on, hardened non-interactivity (ADR-0030)\n\n- init with no explicit --tools now writes only the vendor-neutral baseline\n  (AGENTS.md + .agents/skills); --yes no longer defaults to the claude profile\n  and the wizard pre-checks nothing. Closes a standing vendor-neutrality breach.\n- check --json: a st\n[…]\ne operating model: neutral baseline, best-effort harness\n  detection (never a prerequisite, never self-wiring), machine-readable surface.\n- Tests: neutral-default and check --json assertions in smoke.",
          "is_bot": false,
          "headline": "feat(cli): agent-operable baseline — neutral init default, check --js…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T13:58:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "06d9ed68da09f86ca36f9831a2acd4e21813bdcb",
          "body": "…-telemetry (verified)",
          "is_bot": false,
          "headline": "docs(positioning): quote RFC-0024 verbatim on GenAI-not-deterministic…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T12:55:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "191d80c3498fc316872710652cda86b4374d6030",
          "body": "…oundary)\n\nDistribution-comms pass, from a 3-agent investigation.\n- README: the distribution story was told 3× (lines 56/63/88, with a double\n  enumeration of the same siblings). Consolidated into one tier-structured\n  block in Install (hard-CI / hard-turn-end / soft-per-tool / discovery-only),\n  di\n[…]\nunded (MCP tools are model-controlled; the registry needs a\n  runnable package). packaging/mcp/README and distribution.md cite it.\nNo badge added (a Claude-specific one would break vendor-neutrality).",
          "is_bot": false,
          "headline": "docs(dist): consolidate the README install story, add ADR-0029 (MCP b…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T12:52:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "324a08b5e1a6140e6ba835090a58f2124ef27e7e",
          "body": "- Copilot: drop-in install path documented (.github/hooks/ or ~/.copilot/hooks/), no submission.\n- Cursor: consumable via the hooks.json drop-in (advisory stop, soft per-tool).\n- Kiro: published from a thin dedicated repo (stranxik/runward-kiro) because Kiro requires\n  POWER.md at the repo root, wit\n[…]\n: not published, by design — the registry needs a real MCP server package, and an MCP\n  tool is model-controlled (discovery, never a gate). The descriptor documents that stance;\n  no MCP server ships.",
          "is_bot": false,
          "headline": "docs(dist): finalize the last four channels (Copilot, Cursor, Kiro, MCP)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T12:07:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3027840709fabe5d542fa5aa5d21bee1e245f934",
          "body": "Codex: document the git-backed --sparse install (packaging/codex reads\ndirectly, no copy) and note the marketplace.json now matches the documented\nschema; the curated Codex directory is partners-only, the --sparse add is open.\nGemini: gemini extensions install requires the manifest at the repo root,\n[…]\n\nthe extension is published from a thin dedicated repo (stranxik/runward-gemini);\npackaging/gemini/ is the mirrored source, with gemini extensions link for local\ndev. distribution.md updated for both.",
          "is_bot": false,
          "headline": "docs(dist): Codex --sparse install + Gemini dedicated-repo pointer",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T11:56:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f889102d30e0bd1efcb80af08e12bea374425810",
          "body": "…in) to the Install section",
          "is_bot": false,
          "headline": "docs(readme): add wire-the-gate install (CI Action + Claude Code plug…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T11:13:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46ff53108e3c417dfc14df10a4496e3c7c9a3870",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): add GitHub Marketplace badge for the runward gate Action",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T11:09:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f07b59c7189e64cfdb78fa9827ac85d9aff39033",
          "body": null,
          "is_bot": false,
          "headline": "docs(dist): align the CI pin example to 0.18.1",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T10:29:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af3fd86c1bfbfad91987e6ee7032d83a0ce48bb9",
          "body": "…elog, bumps, stamps",
          "is_bot": false,
          "headline": "chore(release): v0.18.1 — security + pre-marketplace hardening; chang…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T10:29:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bcb2c331e94b2c52685d5343e375eb16d61783dd",
          "body": "A 5-agent adversarial audit (security, compliance, code coherence, packagings,\narchitecture) before public marketplace submission. Two real security holes,\nplus polish. Fixed:\n\n- SECURITY — seal traversal (evidence.ts verifyEvidenceLock): the seal writer\n  confined paths (v0.17) but the verifier did\n[…]\nount harmonized to 28 (was 24/26 in four places).\n- Guards: unit tests for the seal-traversal rejection, the ReDoS screen, and a\n  packaging version/hook check that would have caught the 0.17.0 drift.",
          "is_bot": false,
          "headline": "fix(security+dist): close the pre-marketplace audit findings",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T10:26:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d6aaf3ef88736ed6067d861a4f1dd74c34d6267",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README OG banner to v0.18.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:25:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cca5f0e6a5680a7542692bd1d4830044715bfc44",
          "body": "… stamps",
          "is_bot": false,
          "headline": "chore(release): v0.18.0 — distributable packagings; changelog, bumps,…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:22:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9231a86969a45db778fedfd0b4344cf091e39830",
          "body": "…nization, link the honest map)\n\nMerged the packaging/ family (Gemini, Codex, Copilot, Cursor, Kiro, MCP)\nbuilt per ADR-0028, and reconciled it with the core done in parallel:\n- every hook command is npx --yes runward check --strict (robust after a\n  bare plugin install, matching plugins/runward-gat\n[…]\n\nsoft per-tool (Cursor/Kiro), discovery-only for MCP (model-controlled,\nnever a gate). Format-uncertainty flags kept in each channel's README\n(Codex/Cursor/Copilot manifests to confirm at submission).",
          "is_bot": false,
          "headline": "feat(dist): reconcile per-harness packagings with the core (npx harmo…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:20:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be3479cfdd8c16e7a15a62e7715832b31b26252b",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'worktree-agent-aa229ab9b6d1d6a1d'",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:19:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8e51b3f8f854023783963abbd0a2a47675d35a7",
          "body": "…Kiro, MCP descriptor (ADR-0028)",
          "is_bot": false,
          "headline": "feat(dist): per-harness packagings — Gemini, Codex, Copilot, Cursor, …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17b85217b4fd94d8b4dbf429bee9e68c10851409",
          "body": null,
          "is_bot": false,
          "headline": "docs(dist): the honest channel map (docs/distribution.md) + README link",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:12:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32ce06d350fcf7b359186067bee5295d8e67cfaf",
          "body": "…gin+marketplace)",
          "is_bot": false,
          "headline": "wip(dist): ADR-0028 + core packagings (GitHub Action, Claude Code plu…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:11:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd0d8fee80461dcceffc7567e6df55a67d0185db",
          "body": "…ver is gated; OSCAL as a citable spec\n\nThe distribution/message pass: lead the differentiators with the unique\ncombination a code-level benchmark confirmed nobody else pairs (rule-level\ngate with sealed evidence, gated hand-over, published OSCAL mapping); fix\nthe stale '58 craft rules' (now 64); reframe hand-over as a gated\ndeliverable, not a folder; present the OSCAL mapping as the reference,\ncitable mini-spec; add the FedRAMP RFC-0024 / Delve backing for the\nzero-LLM stance.",
          "is_bot": false,
          "headline": "docs(readme): frame the four grounds; fix rule count (58->64); hand-o…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T06:47:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8794f0f69aa2387198f5bf71d3bf2d20b8384858",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README OG banner to v0.17.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:53:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d12483ca8d17f0077fd88b7ad7feeb0b734c2076",
          "body": "…t date\n\nCHANGELOG for the second-audit hardening (traversal, ReDoS, OSCAL/spec\nreconciliation, seal scope, RUNWARD_NOW, doc regressions), the EU AI Act\ndate correction, and the BMAD review-layer adapter; version 0.17.0; mission\nstamps and CITATION.cff bumped.",
          "is_bot": false,
          "headline": "chore(release): v0.17.0 — audit remediation + BMAD adapter + EU AI Ac…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:50:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6593e79d3086ab85173883e6db4810c3a7a18fd",
          "body": "…AD calls (ADR-0027)\n\nA fresh code-level competitive benchmark found a distribution seam: BMAD's\nbmad-code-review exposes a review-layers extension point whose instruction\nmay 'run anything (e.g. an external reviewer via bash)'. templates/adapters/\nbmad-review-layer.toml adds runward's deterministic\n[…]\nileged over the\nother orchestrators (ADR-0027). EXPECTED_ADAPTERS 5 -> 6; README documents\nthe seam; smoke covers the path. Also fixed the compliance unit test that\nhad frozen the pre-Omnibus EU date.",
          "is_bot": false,
          "headline": "feat(adapters): BMAD review-layer adapter — the gate as a reviewer BM…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:49:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d36f4b040622fb4915916c1ed1674dc21f408309",
          "body": "…igital Omnibus)\n\nThe Digital Omnibus on AI (Council final green light 29 June 2026) postponed\nthe Annex III/IV high-risk obligations from 2 August 2026 to 2 December 2027\n— our regime data and docs still carried the stale deadline, which the OSCAL\nreadiness draft printed. Corrected in place (a fact\n[…]\nedRAMP RFC-0024 forbidding GenAI-produced evidence\n(a federal validation of the zero-LLM gate) and the Delve affair (AI-prefilled\nSOC 2 audits) — both arguing that AI-produced evidence is not trusted.",
          "is_bot": false,
          "headline": "fix(compliance): EU AI Act high-risk date 2026-08-02 -> 2027-12-02 (D…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:46:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "669a06d0a1f28e56eb996638e27d5e1a02f9bfd0",
          "body": "…r adapter count, README Kiro/topology)\n\n- first-mission.md: the wizard poses five prompts, not four (the 'What are\n  you building?' seed was undocumented); refreshed the stale output counts\n  (84 -> 119 files, 11 -> 13 deliverables) and the current gate message.\n- doctor + EXPECTED_ADAPTERS: count \n[…]\nng the README; now 5 real adapters).\n- README: execution-topology.md added to the mission tree (a gated\n  deliverable was missing), Kiro added to the tool-profiles list and the\n  adapter-seam comment.",
          "is_bot": false,
          "headline": "docs/fix: doc regressions from the audit (first-mission counts, docto…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:45:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8577b2a2dd73a066d499f3a0bebcdd6d8867b324",
          "body": "…SCAL/spec drift, seal scope\n\nA second adversarial audit (our own method on ourselves) broke four things\nshipped in v0.15/v0.16. Closed, still deterministic, zero-LLM:\n\n- Path traversal (CASSE): file:/etc/hosts and file:../../etc/hosts passed\n  the gate green, contradicting ADR-0019's 'resolves unde\n[…]\ntity across filesystems.\n\nGolden regenerated (href now regime-derived). Unit + smoke cover traversal,\nReDoS, order-independent OSCAL aggregation, the regime-derived link, and the\nRUNWARD_NOW fallback.",
          "is_bot": false,
          "headline": "fix(gate): close the audit's four gate fissures — traversal, ReDoS, O…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:42:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3075231b999376c086272aa3c9d82be155826c9",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README OG banner to v0.16.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:05:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "634783c96dbb8a36fbb28c714c4e36d6e3e9587d",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.16.0 — changelog, version bump, mission stamps",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:01:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7eff24e904a909b87eb155dd33c56db149d4a640",
          "body": "The audit's whitespace finding, executed with ADR-0017's own move: the\npromise 'the hand-over is proven by a real task redone without you' was\nDefinition-of-Done prose no gate verified — the differentiator was the\nleast backed claim in the chain. Now:\n\n- runward/handover.md joins the mission layout \n[…]\nt on both missions.\n- The handover workflow's Outputs/DoD name the gated note; the golden\n  OSCAL is regenerated (the new rules extend ASI08/09/10 coverage);\n  smoke covers the fifth phase end to end.",
          "is_bot": false,
          "headline": "feat(gate): hand-over becomes a gated conformance phase (ADR-0026)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:00:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a6745cef5d8194f83fa64206afb980e0477c6b1",
          "body": "…ec (ADR-0025)\n\ndocs/spec/runward-oscal-mapping.md v1.0 — implementation-independent: the\ndecision -> ADR -> manifest -> OSCAL chain, the component-definition shape,\nthe implementation-status derivation rules (with the paper-coverage\nasymmetry stated), the deterministic UUID seed grammar, the regime\n[…]\nations. The golden fixture\nis promoted to normative example (the conformance suite wins over the\nprose). CITATION.cff at the root makes citing mechanical; README and the\ncompliance docs link the spec.",
          "is_bot": false,
          "headline": "docs(spec): publish the OSCAL mapping as a versioned, citable mini-sp…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T01:53:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0afd80c6c2ceb1207a24323f9abf12e8d996f38c",
          "body": "… gate sample (ADR-0018 amended)\n\n--tools kiro mirrors the phase skills as .kiro/steering/runward-<phase>.md\n(inclusion: auto + name + description — Kiro's relevance idiom, same\nsemantics as the SKILL.md trigger); AGENTS.md is read natively by Kiro so\nthe charter needs no extra file. templates/adapt\n[…]\nne port as the Claude Code hook. EXPECTED_ADAPTERS 5 -> 6;\nadapters README documents both seams; smoke covers profile emission,\nrelevance frontmatter, subordination to the gate, and the adapter count.",
          "is_bot": false,
          "headline": "feat(adapters): Kiro — steering mirror of the phase skills, Stop-hook…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T01:50:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 26,
      "commits_last_year": 240,
      "latest_release_at": "2026-07-21T15:17:35Z",
      "latest_release_tag": "v0.22.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 0.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "runward",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "agentic",
            "ai-agents",
            "spec-driven",
            "delivery",
            "governance",
            "llm",
            "architecture"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/runward",
          "is_deprecated": false,
          "latest_version": "0.22.0",
          "repository_url": "https://github.com/stranxik/runward",
          "versions_count": 27,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3163,
          "first_published_at": "2026-07-06T12:51:50.241000Z",
          "latest_published_at": "2026-07-21T15:18:25.901000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 8
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "examples/request-triage/code/tsconfig.json",
        "floor-ts/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 41069,
      "source_files_sampled": 90,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "examples/request-triage/AGENTS.md",
        "floor-ts/AGENTS.md",
        "templates/targets/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 133430
    },
    "dependencies": {
      "manifests": [
        "floor-ts/package.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 27,
        "malicious_count": 0,
        "assessed_package": "npm:runward@0.22.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "zod",
          "manifest": "floor-ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@inquirer/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.2"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 8,
        "merged_prs": 33,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 1,
        "closed_unmerged_prs": 6
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "stranxik",
          "commits": 200,
          "avatar_url": "https://avatars.githubusercontent.com/u/26541747?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml",
        "scorecard.yml",
        "watch-external-facts.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/13 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9c30a25dd438f14658afbdd5b47b1ec40c06ad63",
        "ran_at": "2026-07-30T03:35:05Z",
        "aggregate_score": 5.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-29T09:54:31Z",
      "oldest_open_prs": [
        {
          "number": 24,
          "created_at": "2026-07-18T19:46:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 40,
          "created_at": "2026-07-22T03:24:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-07-22T03:24:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 43,
          "created_at": "2026-07-29T03:23:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 44,
          "created_at": "2026-07-29T03:23:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 45,
          "created_at": "2026-07-29T03:24:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 46,
          "created_at": "2026-07-29T03:24:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 47,
          "created_at": "2026-07-29T03:24:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-29T09:53:59Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/stranxik/runward",
    "host": "github.com",
    "name": "runward",
    "owner": "stranxik"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 63,
      "inputs": {
        "security": 67,
        "vitality": 70,
        "community": 47,
        "governance": 54,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "commits_last_year": 240,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "240 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 240
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v0.22.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 0.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 47,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "runward"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3163
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,163 downloads/month across npm",
                "points": 46.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3163,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "merged_prs": 33,
              "open_issues": 0,
              "closed_issues": 1,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 6
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "33/39 decided PRs merged",
                "points": 32.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 33,
                      "decided": 39
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "followers": 6,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "stranxik",
              "public_repos": 15,
              "account_age_days": 3418
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "6 followers of stranxik",
                "points": 6.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 6,
                      "login": "stranxik"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "15 public repos, account ~9 yr old",
                "points": 20.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 15
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 9
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "runward"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "27 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 27
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://runward.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://runward.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 67,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:runward@0.22.0 runtime dependency closure — what installing the published package pulls in — 27 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:runward@0.22.0",
                  "assessed": 27
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 27,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 27,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 72,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.95,
              "agent_instruction_files": [
                "examples/request-triage/AGENTS.md",
                "floor-ts/AGENTS.md",
                "templates/targets/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 133430
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "examples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "examples/request-triage/code/tsconfig.json",
                "floor-ts/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "examples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 41069,
              "source_files_sampled": 90,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/90 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 90,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T03:35:19.084065Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/stranxik/runward.svg",
  "full_name": "stranxik/runward",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.27.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.