Öffentliches Register
Software-GesundheitsberichtSchema 0.23.0 · Metriken 1.13.0 · 2026-07-21 18:20 UTC

thrillmade / clud-bug

Claude PR review with project-aware skills. Encode your team standards (brand voice, API contracts, compliance, test discipline) as Markdown skills the bot cites by name on every PR. One-command install: npx clud-bug init.

TypeScript · JavaScriptMIT★ 1 Stern⑂ 0 Forksseit März 2026Auf GitHub ansehen ↗

thrillmade/clud-bug erreicht einen Gesundheitsindex von 58 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (78/100) ab, am schwächsten bei Community & Adoption (33/100). Zuletzt vor 4 Tagen aktualisiert. Ein einzelner Mitwirkender trägt den Großteil der jüngsten Arbeit.

58
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

58
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

thrillmadeOrganisation
0 Follower8 öffentliche Reposseit Mai 2024

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlichtTags
npmclud-bug0.6.343.46972vor 49 Tagenclaudeclaude-codegithub-actioncode-reviewpull-requestaiskills

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

78Gut · 22 % des Gesamtindex
Wie die Bewertung erfolgt
36/36Push-Aktualität — letzter Push vor 4 Tagen
6.9/36Commit-Rhythmus — 10/52 Wochen mit Commits
18/18Commit-Volumen — 199 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year199
human_commit_share0,96
days_since_last_push4
active_weeks_last_year10
Wie die Bewertung erfolgt
16.2/27Liefert Releases aus — 70 Versions-Tags (keine GitHub-Releases)
36/36Release-Aktualität — letztes Release vor 4 Tagen
27/27Release-Rhythmus — ein Release etwa alle 2 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count70
latest_release_tagv0.7.0-rc.24
releases_from_tagsja
days_since_latest_release4
mean_days_between_releases2
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

33Gefährdet · 18 % des Gesamtindex
Wie die Bewertung erfolgt
0/60Stars — 1 Stars
0/25Forks — 0 Forks
0/15Watcher — 1 Watcher
Verwendete Eingangsdaten
forks0
stars1
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
0/18CONTRIBUTING-Leitfaden
0/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingnein
has_issue_templatenein
has_code_of_conductnein
has_pull_request_templatenein
Wie die Bewertung erfolgt
47.2/80Downloads pro Monat — 3.469 Downloads/Monat über npm
0/20Abhängige in der Registry — von diesem Ökosystem nicht ausgewiesen
Verwendete Eingangsdaten
packagesclud-bug
dependents
ecosystemsnpm
total_downloads
monthly_downloads3.469
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Abhängige in der Registry. Die verbleibenden Gewichte wurden renormalisiert.

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

46Gefährdet · 24 % des Gesamtindex
Wie die Bewertung erfolgt
9/54Bus-Faktor — 1 Beitragende decken die Hälfte aller Commits ab
0/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 100 % der Commits
1.4/13.5Breite der Beitragenden — 1 Beitragende
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Verwendete Eingangsdaten
bus_factor1
contributors_sampled1
top_contributor_share1
Wie die Bewertung erfolgt
18.7/46.8Issue-Lösungsquote — 40 % der Issues geschlossen
33.1/38.3PR-Annahme — 198/229 entschiedene PRs gemergt
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs198
open_issues3
closed_issues2
issue_closed_ratio0,4
closed_unmerged_prs31
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
0/25Reichweite des Inhabers — 0 Follower von thrillmade
11.3/25Kontohistorie — 8 öffentliche Repos, Kontoalter ca. 2 Jahre
Verwendete Eingangsdaten
followers0
owner_typeOrganization
is_verified
owner_loginthrillmade
public_repos8
account_age_days796

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf npm
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 49 Tagen
20/20Versionshistorie — 72 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagesclud-bug
ecosystemsnpm
any_deprecatednein
min_days_since_publish49

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

77Gut · 20 % des Gesamtindex
Wie die Bewertung erfolgt
24/24CI-Workflows — 7 Workflow(s)
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Verwendete Eingangsdaten
has_cija
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein

Dokumentation

90Exzellent
Wie die Bewertung erfolgt
30/30README
25/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://cludbug.dev
10/10Repository-Beschreibung
10/10Topics — 13 Topics
0/10Wiki
Verwendete Eingangsdaten
topicsai-code-review, claude, claude-code, cli, code-review, github-actions, npm-package, pr-review, pull-request, skills, skills-sh, skdd, skill-driven-development
has_wikinein
homepagehttps://cludbug.dev
has_readmeja
has_docs_dirja
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

53Mittel · 16 % des Gesamtindex
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,3
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): signed_releases. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

77Gut · 0 % des Gesamtindex
Wie die Bewertung erfolgt
45/45Agentenanweisungen — .cursorrules, AGENTS.md, CLAUDE.md
0/15Maschinenlesbare Doku (llms.txt)
40/40Lesbare Commit-Historie — 96 von 96 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share1
agent_instruction_files.cursorrules, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes2.711
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
11/11Statische Typprüfung — site/tsconfig.json, tsconfig.json
10/10Reproduzierbare Umgebung — lockfile
10/10Belegte Agentenpraxis — 56 der letzten 100 Commits von Agenten verfasst oder ihnen zugeschrieben
8/8Automatisierte Wartung — 4 der letzten 100 Commits sind automatisierte Abhängigkeits-Updates
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfilespackage-lock.json
has_dockerfilenein
typed_languageja
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configssite/tsconfig.json, tsconfig.json
agent_commit_share0,56
toolchain_manifests
dependency_bot_commit_share0,04
Wie die Bewertung erfolgt
45/45Typprüfbarer Code — TypeScript (statisch typisiert)
54.7/55Handhabbare Dateigrößen — 1/159 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languageTypeScript
largest_source_bytes108.699
source_files_sampled159
oversized_source_files1

Eckdaten

1GitHub-Sterne
1Mitwirkende
199Commits, letzte 12 Monate
4Tage seit letztem Push
70Releases
1Bus-Faktor
3offene Issues
npmPaket-Ökosysteme

Warnungen zur Datenerhebung

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Weitere Details

OpenSSF Scorecard 5.3 / 10
5.3Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-21 18:20 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
k. A.Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Direkte Abhängigkeiten 4
RegistryPaketVersionsvorgabeManifest
npmzod^4.4.3package.json
npmnext^16.2.9site/package.json
npmreact^19.2.7site/package.json
npmreact-dom^19.2.7site/package.json
Alle Abhängigkeiten nicht erhoben

Der aufgelöste Abhängigkeitssatz konnte für diesen Bericht nicht erhoben werden: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "ai-code-review",
        "claude",
        "claude-code",
        "cli",
        "code-review",
        "github-actions",
        "npm-package",
        "pr-review",
        "pull-request",
        "skills",
        "skills-sh",
        "skdd",
        "skill-driven-development"
      ],
      "is_fork": false,
      "size_kb": 1928,
      "has_wiki": false,
      "homepage": "https://cludbug.dev",
      "languages": {
        "CSS": 30314,
        "JavaScript": 674035,
        "TypeScript": 756254,
        "Go Template": 116892
      },
      "pushed_at": "2026-07-17T13:23:56Z",
      "created_at": "2026-03-11T05:14:54Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T13:24:36Z",
      "description": "Claude PR review with project-aware skills. Encode your team standards (brand voice, API contracts, compliance, test discipline) as Markdown skills the bot cites by name on every PR. One-command install: npx clud-bug init.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "thrillmade",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/170016379?v=4",
      "created_at": "2024-05-16T14:34:15Z",
      "is_verified": null,
      "public_repos": 8,
      "account_age_days": 796
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.7.0-rc.24",
          "kind": "prerelease",
          "published_at": "2026-07-17T01:29:39Z"
        },
        {
          "tag": "v0.7.0-rc.23",
          "kind": "prerelease",
          "published_at": "2026-07-11T18:48:36Z"
        },
        {
          "tag": "v0.7.0-rc.22",
          "kind": "prerelease",
          "published_at": "2026-07-03T19:04:21Z"
        },
        {
          "tag": "v0.7.0-rc.21",
          "kind": "prerelease",
          "published_at": "2026-06-30T00:18:35Z"
        },
        {
          "tag": "v0.7.0-rc.20",
          "kind": "prerelease",
          "published_at": "2026-06-29T21:47:10Z"
        },
        {
          "tag": "v0.7.0-rc.19",
          "kind": "prerelease",
          "published_at": "2026-06-29T20:12:28Z"
        },
        {
          "tag": "v0.7.0-rc.18",
          "kind": "prerelease",
          "published_at": "2026-06-29T18:08:47Z"
        },
        {
          "tag": "v0.7.0-rc.17",
          "kind": "prerelease",
          "published_at": "2026-06-29T17:33:44Z"
        },
        {
          "tag": "v0.7.0-rc.15",
          "kind": "prerelease",
          "published_at": "2026-06-29T12:37:27Z"
        },
        {
          "tag": "v0.7.0-rc.14",
          "kind": "prerelease",
          "published_at": "2026-06-29T03:57:22Z"
        },
        {
          "tag": "v0.7.0-rc.8",
          "kind": "prerelease",
          "published_at": "2026-06-28T02:42:55Z"
        },
        {
          "tag": "v0.7.0-rc.7",
          "kind": "prerelease",
          "published_at": "2026-06-27T21:45:22Z"
        },
        {
          "tag": "v0.7.0-rc.6",
          "kind": "prerelease",
          "published_at": "2026-06-27T20:23:49Z"
        },
        {
          "tag": "v0.7.0-rc.5",
          "kind": "prerelease",
          "published_at": "2026-06-26T05:11:34Z"
        },
        {
          "tag": "v0.7.0-rc.4",
          "kind": "prerelease",
          "published_at": "2026-06-17T15:19:10Z"
        },
        {
          "tag": "v0.7.0-rc.3",
          "kind": "prerelease",
          "published_at": "2026-06-10T15:17:33Z"
        },
        {
          "tag": "v0.7.0-rc.2",
          "kind": "prerelease",
          "published_at": "2026-06-09T21:36:50Z"
        },
        {
          "tag": "v0.6.34",
          "kind": "patch",
          "published_at": "2026-06-02T18:14:21Z"
        },
        {
          "tag": "v0.6.33",
          "kind": "patch",
          "published_at": "2026-06-01T18:12:24Z"
        },
        {
          "tag": "v0.6.32",
          "kind": "patch",
          "published_at": "2026-06-01T14:15:46Z"
        },
        {
          "tag": "v0.6.31",
          "kind": "patch",
          "published_at": "2026-06-01T12:43:29Z"
        },
        {
          "tag": "v0.6.30",
          "kind": "patch",
          "published_at": "2026-06-01T04:02:58Z"
        },
        {
          "tag": "v0.6.29",
          "kind": "patch",
          "published_at": "2026-05-31T18:01:04Z"
        },
        {
          "tag": "v0.6.28",
          "kind": "patch",
          "published_at": "2026-05-30T23:28:05Z"
        },
        {
          "tag": "v0.6.27",
          "kind": "patch",
          "published_at": "2026-05-30T04:48:50Z"
        },
        {
          "tag": "v0.6.26",
          "kind": "patch",
          "published_at": "2026-05-30T03:21:13Z"
        },
        {
          "tag": "v0.6.25",
          "kind": "patch",
          "published_at": "2026-05-30T02:02:01Z"
        },
        {
          "tag": "v0.6.24",
          "kind": "patch",
          "published_at": "2026-05-29T23:49:03Z"
        },
        {
          "tag": "v0.6.23",
          "kind": "patch",
          "published_at": "2026-05-29T19:12:32Z"
        },
        {
          "tag": "v0.6.22",
          "kind": "patch",
          "published_at": "2026-05-29T15:17:55Z"
        },
        {
          "tag": "v0.6.21",
          "kind": "patch",
          "published_at": "2026-05-29T14:17:35Z"
        },
        {
          "tag": "v0.6.20",
          "kind": "patch",
          "published_at": "2026-05-29T14:08:52Z"
        },
        {
          "tag": "v0.6.19",
          "kind": "patch",
          "published_at": "2026-05-29T13:50:04Z"
        },
        {
          "tag": "v0.6.18",
          "kind": "patch",
          "published_at": "2026-05-29T13:43:42Z"
        },
        {
          "tag": "v0.6.16",
          "kind": "patch",
          "published_at": "2026-05-29T12:59:59Z"
        },
        {
          "tag": "v0.6.15",
          "kind": "patch",
          "published_at": "2026-05-29T05:15:16Z"
        },
        {
          "tag": "v0.6.14",
          "kind": "patch",
          "published_at": "2026-05-29T04:58:37Z"
        },
        {
          "tag": "v0.6.13",
          "kind": "patch",
          "published_at": "2026-05-28T22:08:44Z"
        },
        {
          "tag": "v0.6.12",
          "kind": "patch",
          "published_at": "2026-05-28T17:13:08Z"
        },
        {
          "tag": "v0.6.11",
          "kind": "patch",
          "published_at": "2026-05-28T15:28:39Z"
        },
        {
          "tag": "v0.6.10",
          "kind": "patch",
          "published_at": "2026-05-28T14:01:50Z"
        },
        {
          "tag": "v0.6.8",
          "kind": "patch",
          "published_at": "2026-05-28T13:27:51Z"
        },
        {
          "tag": "v0.6.7",
          "kind": "patch",
          "published_at": "2026-05-28T03:05:03Z"
        },
        {
          "tag": "v0.6.6",
          "kind": "patch",
          "published_at": "2026-05-28T02:43:43Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-05-28T02:32:18Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-05-28T02:24:08Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-05-28T02:08:20Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-05-28T00:48:53Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-05-27T10:37:23Z"
        },
        {
          "tag": "v0.5.16",
          "kind": "patch",
          "published_at": "2026-05-26T21:32:05Z"
        },
        {
          "tag": "v0.5.15",
          "kind": "patch",
          "published_at": "2026-05-26T18:02:02Z"
        },
        {
          "tag": "v0.5.14",
          "kind": "patch",
          "published_at": "2026-05-26T17:42:04Z"
        },
        {
          "tag": "v0.5.13",
          "kind": "patch",
          "published_at": "2026-05-26T17:33:30Z"
        },
        {
          "tag": "v0.5.12",
          "kind": "patch",
          "published_at": "2026-05-26T16:04:07Z"
        },
        {
          "tag": "v0.5.11",
          "kind": "patch",
          "published_at": "2026-05-26T15:38:41Z"
        },
        {
          "tag": "v0.5.10",
          "kind": "patch",
          "published_at": "2026-05-18T22:37:17Z"
        },
        {
          "tag": "v0.5.9",
          "kind": "patch",
          "published_at": "2026-05-18T22:12:17Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-05-18T19:45:13Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-05-18T19:32:16Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-05-18T17:06:09Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-05-18T15:50:50Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-05-18T15:33:25Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-05-15T19:49:20Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-05-15T17:18:07Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-05-15T16:14:50Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-15T15:21:25Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-15T13:44:51Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-15T13:19:50Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-05-15T04:32:54Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-05-15T04:17:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "10ae1dc4c3708546ad49f0d416060cd2d1d40961",
          "body": "…notarize step + init installs both) (#238)\n\n## ZP3 — route the self-hosted GitHub Action through the notary\n\nLocal max mode already notarizes reviews (ZP2), but the self-hosted\nGitHub Action\nposted only a **self-attested** `clud-bug-review` check — so the\nun-forgeable notary\ntrust boundary never co\n[…]\n[Claude Code](https://claude.com/claude-code)\n\nhttps://claude.ai/code/session_01NnvyVPvKfy81AgcS6NFTku\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ZP3: self-hosted Action → notary (build-bundle + base-ref-guarded CI …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-17T13:23:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e95f7c07a6ef726ac1def77f5a7a303a0423dcd",
          "body": "## Summary\n\nPhase ZP2 (CEO decision): flips the local-max-mode notary from\nopt-**in**\n(only engaged when an operator manually set `CLUD_BUG_NOTARY_URL`) to\nopt-**out**, default-ON — a PR-trigger local review now certifies via\nthe\nhosted notary (`https://app.cludbug.dev`) unless the repo says\notherwi\n[…]\n[Claude Code](https://claude.com/claude-code)\n\nhttps://claude.ai/code/session_01NnvyVPvKfy81AgcS6NFTku\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ZP2: notary default-on (config resolver + deterministic §5) (#237)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-17T04:08:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8eadd244c9af62e97eb8a77cd9419debfcbbfe7a",
          "body": "Bumps clud-bug to **0.7.0-rc.24** to ship the Phase Z4 CLI\nchallenge/response handshake (#233) to installs — `post-check-run`\nfetches a single-use nonce from the notary before submitting. Opt-in\n(inert unless `CLUD_BUG_NOTARY_URL` is set). Version pin propagated to\nthe 3 workflow templates + `strict\n[…]\n0.7.0-rc.24` → OIDC publish to `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump to 0.7.0-rc.24 (ships the Z4 CLI notary handshake) (#234)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-17T01:29:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22b24be7aad7308b8f63e08b562659e087e45148",
          "body": "…#233)\n\nThe CLI half of the Z4 notary handshake. `post-check-run`'s\n`submitToNotary` now mints a single-use nonce (SPEC §10.3.3 ①\nreplay-closure) before submitting: `POST {repo, pr, head_sha}` →\n`/notarize/challenge` → echo `{nonce}` in the bundle → `POST /notarize`.\n\n**Adversarial-review fixes fold\n[…]\nbranch\n`feat-notary-z4`, separate PR).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase Z4 (CLI): challenge/response nonce handshake before /notarize (…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-16T21:43:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63ca77d381c0196fcb68d23f980dec3f63da7fb5",
          "body": "…20 runner (#231)\n\n**The v0.7.0-rc.23 publish failed** — not our code, a CI env drift. The\nworkflow runs `npm install -g npm@latest`, but `npm@latest` is now **npm\n12**, whose engine requires Node `>=22.22 / 24.15`. On the workflow's\n**Node 20** runner it `EBADENGINE`-fails *before* the publish step\n[…]\nn's fixed workflow — no re-tag needed.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci): pin npm-publish to npm@11 so OIDC publish works on the Node …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-11T19:01:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "feba3cbd35cf3e18a6bf375aa07cc4948bfb66ea",
          "body": "Bumps clud-bug to **0.7.0-rc.23** to publish the Phase Z3 notary\ncontract so `clud-bug-app` can import it for Z4 (the `/notarize`\nserver).\n\n**Publishes:** `NotaryBundle` / `buildBundle` / `parseBundle` /\n`notaryResponseIsRejection` (notary-bundle) + `validateBundle` /\n`validateCoverage` / `validateG\n[…]\n\nworkflow ships it to dist-tag `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump to 0.7.0-rc.23 (ships Phase Z3 — the CLI notary side) (#230)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-11T18:48:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd59efd3d974af3b909d3189868a88ebaf65d93e",
          "body": "…tation bundle + submit-bundle handshake (#229)\n\n## Phase Z3 — the clud-bug CLI notary side\n\nBuilds the CLI half of the **un-forgeable review notary** (protocol SPEC\n§10.3.3). clud-bug becomes a NOTARY that VALIDATES + CERTIFIES a review\nbefore a green `clud-bug-review` check can gate a merge — the \n[…]\nBundle` + `notaryResponseIsRejection`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase Z3: clud-bug CLI notary side — deterministic validators + attes…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-11T18:33:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa5c627f75910217ba64a25adcdf9fb0506d5c9d",
          "body": "…itic bar) (#224)\n\n## What\n\nAdds `designing-elite-ui` to the CLI design-kit\n(`templates/skills/design/`) as a 4th bundled default `kind: design`\nskill, so the hosted design-critic measures rendered UIs against a\n**concrete elite bar** (one-axis color, APCA-gated contrast,\nfloating/stable chrome, dar\n[…]\ng-elite-ui` alongside the other three.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add designing-elite-ui as a 4th bundled kind: design skill (design-cr…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-04T04:36:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e97c1bd9b1f8bcb4b87d258e6a6104a76264d1e",
          "body": "…rity) (#223)\n\n## What\n\nMigrates `clud-bug configure-github` from the **retired classic\nbranch-protection API** to the **v2 rulesets API**, matching protocol\nSPEC v0.8.0 §7 + reporulez's `skdd` variant.\n\nBefore, the bundled `data/canonical-v1.json` +\n`src/core/configure-github.ts` applied out-of-spe\n[…]\n24 in the two\nconfigure-github files).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "configure-github: classic branch-protection → v2 rulesets (spec §7 pa…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-04T02:58:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5879fad94ec1c4ddd89083355174e8a03ed6b1cf",
          "body": "Bumps `package.json` 0.7.0-rc.21 → **0.7.0-rc.22**. Publishing this\nships the full Phase R review-hardening batch (R1–R7 + benchmark). After\nmerge, cut the release with a tag push (`v0.7.0-rc.22`) —\n`npm-publish.yml` builds/tests/publishes and auto-routes the `-rc`\nversion to the `next` dist-tag. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump to 0.7.0-rc.22 (ships the Phase R hardening batch) (#222)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T19:05:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "878525a1806c6cdde48a67225ecb32cb49f50627",
          "body": "…e, design-critic (#221)\n\nSurfaces the four Marketplace capabilities the homepage never showed, as\nadditive field-guide sections (hero + existing sections untouched;\nrenumbered §I–§X):\n- **§IV Weight of Evidence** — reproduction-as-grounding + the 3 bug\nclasses + the 20-scenario **100% recall / 100%\n[…]\n zero exclamations. Remaining Phase S: 5\nscreenshots (need the live bot) + tagline/category (yours). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase S: landing refresh — max-mode, hardened review, auto-fix/resolv…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T18:55:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "741741a72b3cc96947f1a92663c4fe3a137ab1f6",
          "body": "…ss) (#220)\n\nAdds the `/docs` subtree the Marketplace SUPPORT policy references. Five\npages in the field-guide `.doc` style, each grounded in the real modules\n(no invented options): the index + **skills** (SKILL.md, base-ref load,\nslugs), **config** (every `.clud-bug.json` option incl. the new\n`inva\n[…]\n0-scenario benchmark). Adds a\n`.doc-body pre` code-block style. Build green; all 5 routes prerender. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase S: /docs self-service pages (skills, config, auto-fix, multi-pa…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T18:43:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e10ad82d6cb2394f6329108be68f9dadbbd5f80",
          "body": "…sion (#219)\n\nFinalizes the launch-gate benchmark at **20 scenarios** (14\ntrue-positive across all 3 classes + 6 clean decoys). Scoreboard:\n**42/42 buggy caught (100% recall)**, all reproduction-grounded ·\n**18/18 clean correct (100% precision)**, zero false positives (60\nreviews). **Meets the seeded-benchmark launch criterion.** README +\nRESULTS updated. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R7: 20-scenario benchmark scoreboard — 100% recall + 100% preci…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T17:16:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e94ac1921470e9d5239dbe67c049d03627416a9",
          "body": "Unblocks 3 of the 5 hard Marketplace URL requirements. Ports\n`site/app/{privacy,terms,pricing}/page.tsx` fresh from the held A6a\nbranch (avoiding its stale 11-commit conflict debt) + the 137-line\n`.doc`/`.tier` CSS block. Fixes the pricing-link inconsistency: the\nlanding now points `pricing` at the \n[…]\nr.\nRemaining Phase S: landing-refresh\n(max-mode/design/auto-fix/auto-resolve) + /docs + screenshots. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase S: privacy/terms/pricing pages + pricing-link fix (#218)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T17:13:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0514941adf7eeb9413af1e50e91f1b3102b1663d",
          "body": "… nudge (#217)\n\nVoluntary support for the free tiers (max mode + self-hosted Action run\non the user's own resources — no metered charge fits):\n- **`.github/FUNDING.yml`** — `github: [thrillmade]` (the repo Sponsor\nbutton + a shareable URL). The Stripe 'coffee' link slots into `custom:`\nonce created.\n[…]\nHub Sponsors + create the Stripe Payment Link\n→ I uncomment `custom:`. init tests pass, `tsc` clean. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase M: monetize free tiers — FUNDING.yml (Sponsors) + on-voice init…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T17:06:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "940d38176cd392c19759abe5c95540484129353a",
          "body": "…ecision (#216)\n\nGrows the launch-gate benchmark 3→9 to test **generalization +\nprecision** (both Option B criteria):\n- **3 diverse true-positives** (b4 shared-mutable-state leak · b5\nhalf-open/inclusive boundary · b6 local-time `dayKey` in another module)\n— different mechanisms than the originals.\n\n[…]\n and reported no bug. The hardening\ngeneralizes **and** stays precise. / updated. No `src/` changes. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R7): expand benchmark to 9 scenarios — 100% recall + 100% pr…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T16:52:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6d72fb8b82f605b740cbaababb1ee7508d8ef28",
          "body": "…§3c probe-run step (#215)\n\nConnects R1 (the invariants config + `shouldRunProbes` gate) to the\nlocal recipe. When a repo declares `invariants` in `.clud-bug.json` and\nthis is a `pr` review, the recipe renders a **§3c \"Invariant probes\"**\nstep (mirrors the §3b design step): it lists each invariant a\n[…]\next: R6-action (the Action's sandboxed CI job — the execution\nsurface for untrusted/serverless PRs). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R6-local): wire .clud-bug.json invariants into the recipe's …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T16:34:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c625c4bfa27f50bf5a9bdd7283ee3caff530f0c0",
          "body": "…/9 catch) (#214)\n\nThe **Option B launch gate**: proves clud-bug catches the bugs that live\non no single changed line.\n\n**Harness** (`benchmark/`): 3 faithful, self-contained, reproducible\nplanted-bug scenarios — one per class, modeled on the real misses:\n- `s1-emergent-marker` (emergent, MAJOR ← lo\n[…]\nios + the 10-PR shadow streak before\nthe manual panel comes off. No `src/` changes; 914 tests green. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R7): seeded review-hardening benchmark + first scoreboard (9…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T16:08:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b9a0af80d41fb1c7e2028cb572a2d9f051392bb",
          "body": "…ng (no execution) (#213)\n\nExtends R2's grounding to the **hosted** bot (serverless — patch only,\nno shell). Rule 2 in both hosted system prompts now grounds a finding in\nfile+line OR a **named violated invariant** reasoned from the diff\n(emergent/combinatorial/cross-cutting), names the cross-packag\n[…]\nurface. 914\ngreen, `tsc` clean. Probe execution for this path is the Action's\nsandboxed CI job (R6). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R2-hosted): hosted grounding accepts named-invariant reasoni…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T15:45:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35c0cefb22d7a34cfcde40e061a85c6ee5b7c2e8",
          "body": "… unverified invariant change (#212)\n\nThird slice of review-hardening (**clud-bug-app #87**).\n\n**What:** adds `unverified` to `ReviewVerdict`\n(`src/core/check-verdict.ts`). `deriveCheck` maps it to a **neutral**\ncheck — never `success` (no false-green), never a hard block (no outage\non inability to \n[…]\n-run` → `neutral`. Note: the\nhosted app will add an `unverified` handler at the rc.22 lockstep bump.\n🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R3): the 'unverified' verdict — no false-green 'clean' on an…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T15:41:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "972d6a43a4fcd72735adcb128638b66512c52ca3",
          "body": "…o MAJOR watch-item (#211)\n\nSecond slice of the review-hardening (**clud-bug-app #87**).\n\n**What (local recipe `src/cli/review-prompt.ts`):** the grounding gate\nchanges from *\"quote the exact line or DROP\"* → **ground in a quoted\nline OR a reproduction (command + observed output) OR a named violated\n[…]\n**Tests:** grounding + severity assertions added; 913 green, `tsc`\nclean, recipe renders coherently. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R2): grounding = quote OR reproduction OR named invariant; n…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T15:09:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "feee1d426ce241be365a9265bf66c7e9aa47ddc1",
          "body": "… keystone) (#210)\n\nFirst slice of the review-hardening (**clud-bug-app #87** — retire the\nmanual adversarial panel).\n\n**What:** a new pure module `src/core/invariants.ts` (mirrors\n`design.ts`) that resolves an `.clud-bug.json` `invariants` block into\n`{ enabled, invariants[] }` and exposes `shouldR\n[…]\n probe).\n\n**Tests:** 11 new (`test/core/invariants.test.js`), full suite **913\ngreen**, `tsc` clean. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R1): executable-probe invariants — config module + gate (#87…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T14:27:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e0aaf32bd3e227236be3f3d7b93469e8afcd93a",
          "body": "The last core-dup gap. `buildVerifierPrompt` gains `outputMode: 'json' |\n'structured'` (default json — CLI unchanged); `VERIFIER_SYSTEM`\nrefactored into a shared body + mode tail via\n`buildVerifierSystem(mode)`, with `VERIFIER_SYSTEM =\nbuildVerifierSystem('json')` for back-compat. Verified byte-iden\n[…]\ntep rc.21. **[CEO]** publish `v0.7.0-rc.21` → then\nclud-bug-app deletes its copies + imports core's. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.21 (C1): parameterize verifier prompt/system by outputMode (#207)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-30T00:18:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dacdef843bf8f8d9d88c433b21a43f5fbd232b9",
          "body": "Switches clud-bug's commit-review hook from an exact pin to floating\n`@next` (via `init --local-only` on rc.20). The hook now auto-fetches\nthe latest recipe every commit — delivering H1–H4 + future hardening\nwith no re-pin. Verified: hook pins `clud-bug@next`, zero Action\nworkflows. The last manual re-pin. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "re-pin: float the max-mode hook to @next (auto-update) (#206)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T22:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb646689bfc6fbd3347975efd2f03a80abb85333",
          "body": "…(#205)\n\nThe **effortless-update story**: (1) the max-mode hook floats to\n**`@next`** (auto-fetches the latest recipe — no per-release re-pin;\noverridable for a frozen pin); (2) an **update notifier**\n(brew/gh/vercel pattern — cached daily check, detached background\nrefresh, never blocks, TTY + non-\n[…]\nion. Lockstep rc.20; full suite green. **[CEO]**\npublish `v0.7.0-rc.20`, then I do the final re-pin. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.20: floating @next hook + update notifier + update local-only fix …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T21:47:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae5af78dd744bbf68339ba316f00c6af8cc12d6c",
          "body": "Release bump shipping the hardened max mode: **H1** adversarial recipe\ndepth, **H2** contextual review instructions + anti-injection fence,\n**H3** the `post-check-run` merge-gate + local self-attested check,\n**H4** hook retry + diagnostic marker. Lockstep version pins\n(package.json + 3 templates + strict-mode-gate action);\nrelease-discipline + full suite green. **[CEO]** publish `v0.7.0-rc.19`\nafter merge, then re-pin the 7 repos. 🤖",
          "is_bot": false,
          "headline": "rc.19: batch Phase H max-mode hardening (H1–H4) (#204)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T20:12:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd9c4aa3254750c2fce390538ba25afa45c479a2",
          "body": "…-review check (#203)\n\nLets a max-mode review **gate merge**. New shared\n`core/check-verdict.ts` (`deriveCheck`: clean→success,\ncritical+strict→failure/blocks, critical+non-strict→neutral,\nfailed→neutral) + a `clud-bug post-check-run` verb (posts the\n`clud-bug-review` check via `gh`; best-effort, `-\n[…]\null suite green. Action-path posting deferred (no\nproduction Action users post-F4). No version bump. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H3: merge-gate parity — post-check-run + local self-attested clud-bug…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T20:10:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4499e3c8648718a0dd09426ffa7b5e72deea1506",
          "body": "Two hook-robustness fixes: **retry once** (sleep 1 + re-fetch) on a\ntransient npx/network blip before giving up, and a\n**`.git/clud-bug-review-skipped` diagnostic marker** when the fetch\nultimately fails — so a failed review is distinguishable from a clean\none. Still exit-0 (never blocks the commit). New `sh -n`\nsyntax-validation test. No version bump. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H4: harden the commit hook (retry + diagnostic skip marker) (#202)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T19:51:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "419947a11b32d0e9268ff45c9dc005f1246b663a",
          "body": "…trusted per-PR) (#201)\n\nAdds a **contextual layer** on top of the static skills — the max-mode\ndifferentiator. Three trust tiers: **trusted** `.clud-bug.json`\n`reviewContext` (injected by the local recipe §2b *and* the hosted\nprompt-builder); the **local session-context edge** (the recipe folds in\n\n[…]\ned side passes the\nparams); spec-v0.6.4 (the config key + anti-injection contract). No\nversion bump. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H2: contextual review instructions (trusted reviewContext + fenced un…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T19:42:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a93626d6b1f104809cbac05ea38a0c12b8407db",
          "body": "Makes clud-bug's own review (max mode) match a rigorous adversarial\nreview — the path to retiring ad-hoc adversarial passes. **Recipe text\nonly** (engine untouched; multi-pass was already wired).\n`src/cli/review-prompt.ts`: (1) cross-check pass is now **adversarial**\n— Wasp tries to **refute** pass-\n[…]\n. New test locks it\nfor single + multi pass; full suite green. No version bump (batches into\nrc.19). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H1: harden the max-mode review recipe to adversarial quality (#200)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T19:23:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e60f44d9d5c8090fe42562c99fc9570292521df2",
          "body": "…(#199)\n\nF4 rollout (clud-bug). `clud-bug init --local-only` adds the\n`/clud-bug-review` slash command + the `type: command` commit hook (max\nmode on the session subscription) — **no GitHub Action, no API key**.\nManifest unchanged except the version stamp; no skills dropped; zero\nworkflow files. 🤖 max-mode rollout\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "max mode: init --local-only (slash command + commit hook, no Action) …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T18:23:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9b4f3d2a7ca3bd78103858455d963e525c5f4c9",
          "body": "Adds `clud-bug init --local-only`: installs **max mode** (slash command\n+ the rc.17 commit hook) but **skips the GitHub Action workflows** that\nrun `claude-code-action` with `ANTHROPIC_API_KEY`. The F4 rollout\nprimitive — and a clean product command (clud-bug on your Claude\nsubscription, no key, no \n[…]\n** publish\n`v0.7.0-rc.18` after merge.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.18: init --local-only (max mode, no API-key Action) (#198)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T18:08:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ae06784b13afb2ae1405cd01d7e9d774136d2c5",
          "body": "…) (#197)\n\n## The bug (dogfooding caught it)\n\n`clud-bug init --with-hooks` has **never worked for anyone**. It\nscaffolds a Claude Code **`type: agent`** PostToolUse hook, but agent\nhooks get only Read/Grep/Glob — **no Bash, not configurable** (official\ndocs). So the review subagent could never run t\n[…]\ns`, commit,\nwatch the recipe surface).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.17: fix the broken max-mode commit hook (type:agent → type:command…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T17:33:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14778121c8115695f4c18bdd362dfc73cf2a4ad2",
          "body": "## What\n\nMakes the design-critic **installable in one command** and available on\nthe Action surface — completing \"everywhere.\"\n\n- **`clud-bug init --with-design`** — installs the 3 bundled `kind:\ndesign` skills (`templates/skills/design/*`) via a new bundled-only\n`loadDesignKit` (no network), and fl\n[…]\nprerelease-aware; `latest` untouched).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.16: clud-bug init --with-design + Action browser-MCP opt-in (#195)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T15:41:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df3bb81e03d702a2ead774a573313b8fb79fe4f1",
          "body": "…ep (#194)\n\n## What (rc.15 — local design-critic, the CEO's priority feature)\n\nSecond half of the design-critic lens. Builds on B1a (`kind: design` +\nthe design kit). **Off by default, cost-gated.**\n\n- **`core/design.ts`** — `readDesignConfig` (the `.clud-bug.json`\n`design` block; default `{ enabled\n[…]\nhe hosted Vercel-Sandbox render path).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "design-critic B1b (rc.15): the design pass — config + gated recipe st…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T12:37:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6d962e817307187d3c57c265ef70382c5ff8cb03",
          "body": "## What (foundation for the design-critic, Track B)\n\nFirst half of the design-critic lens. **No version bump** — this is the\nskill-model + content foundation; the pass/config/recipe/installer land\nin B1b (rc.15).\n\n- **`kind: design`** — adds `design` as a third `SkillKind` alongside\n`rule`/`voice` (\n[…]\narse as `kind=design, mode=dedicated`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "design-critic B1a: kind:design skill lens + design baseline kit (#193)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T12:14:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0a5716565cf6be88f672888efb3be00f8c50c4bc",
          "body": "…(#192)\n\n## What\n\nThe marketing landing page had drifted from the shipped product.\nTargeted accuracy fixes (no redesign):\n\n- **\"Pro tier\" → \"Team tier\"** (×2 in `page.tsx`, + the OpenGraph\ndescription in `layout.tsx`). There is no Pro tier — tiers are Trial /\nSolo / Team, and multi-pass is a **Team*\n[…]\nated → none). Vercel preview\ncheck will render it. (When the design-critic lands, I'll run it against\nthis page's preview per the plan.)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "site: reconcile landing copy to shipped pricing + multi-pass reality …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T03:57:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd84e093d51812ec8a90fb34631668f690edd0c3",
          "body": "… prose (#191)\n\n## What (rc.14 — the \"6c\" cut)\n\nShips the conditional **Mantis arbiter** as a pure decision in `core`,\nso the hosted bot and the local recipe share one rule (SPEC §11.5).\n\n- **`shouldEscalate(...)`** (`src/core/multi-pass-aggregate.ts`,\nexported from `core`) — pure gate, true only wh\n[…]\nwiring, which\nbumps the dep to rc.14.)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.14 (6c): conditional Mantis arbiter — pure shouldEscalate + recipe…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T03:48:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a10a1727656dd538899bfd0b1cd72fad13d07889",
          "body": "## What\n\nclud-bug's own `.claude/skills/.clud-bug.json` had `installed: []` while\nthe baseline skill dirs sat on disk, so the dogfood commit-review hook\n(`review-prompt --trigger commit`) resolved **0 skill files**. This\npopulates `installed[]` with the 4 baseline skills, matching what\n`clud-bug ini\n[…]\npackage.json#files`); no\nversion bump.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Dogfood: populate clud-bug's own skill manifest (4 baseline) (#190)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T03:24:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fabe40b6c199839cf8ad4b3e0d6925fe9345096d",
          "body": "…ersion (#189)\n\nrenderMultiPassMarkdown emits the NORMATIVE pass + consensus markers; init --with-hooks pins npx clud-bug@<version>. Adversarial review clean. 843 tests green.",
          "is_bot": false,
          "headline": "rc.13: render SPEC §6.8.1/§6.10.1 markers + pin the hook's clud-bug v…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T22:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89b0b4fb038bc05dc1d55a0f864daf0a0ed3fc60",
          "body": "Scaffolds a native Claude Code type:agent commit-review hook (backgrounded, session-subscription, prompt runs review-prompt + follows it). Review caught + fixed clobbering malformed settings.json + dropping co-located user hooks. 841 tests green.",
          "is_bot": false,
          "headline": "Wave 6b: clud-bug init --with-hooks — native commit-review hook (#188)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T20:41:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9d482b4495ba8874fdd5851389201ff1556b9bd",
          "body": "review-prompt emits the plan-aware local-review recipe (commit → fast single pass; push/pr → multi-pass fan-out) via planReview. 2-lens review caught + fixed 6 issues (rawSkillMd dead override, origin/HEAD empty-diff, cross-check coherence, summary, trigger typo, mode). 831 tests green.",
          "is_bot": false,
          "headline": "Wave 6b: clud-bug review-prompt — plan-aware local-review recipe (#187)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T20:24:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccde109bcd371428cc6d5d2f4934a2d0737937d6",
          "body": "core/plan-review.ts composes resolveReviewPasses + estimateBudget into the single planning entry point every consumer shares; trigger/diff tiering. Review caught + fixed an off-by-one + a tiered-cost overestimate. 825 tests green.",
          "is_bot": false,
          "headline": "Wave 6b: planReview — shared review-plan entry point (SPEC §11.5) (#186)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T19:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d567f95f3100de3604cbef5385a96227498c2af",
          "body": "…185)\n\nShared review engine (review-plan / budget-plan / multi-pass-aggregate) extracted from clud-bug-app/lib into clud-bug/core, behavior-identical (77 App tests ported). Adversarial review caught + fixed a consensus type-erasure regression (now rides core's canonical UnifiedFinding). 816 tests green.",
          "is_bot": false,
          "headline": "Wave 6b PR 0: extract the review engine into clud-bug/core (rc.12) (#…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T18:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a153d84b6b4d36fd96614cdbac65c98f7a8bd88",
          "body": "… (#184)\n\n## Wave 6b — local review mode (slash-command MVP) (rc.11)\n\nThe CEO's highest-priority pre-launch feature, in its first shippable\nform: **local review\nruns inside a Claude Code session using that session's own tokens** — no\nhosted App, no new\nauth.\n\n### What ships\n- **`clud-bug init --with\n[…]\n `v0.7.0-rc.11` → publishes to `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Wave 6b: local-review slash command MVP (--with-local-review) (rc.11)…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T05:56:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd0922645842c0c26d706cabff5d3c5008163961",
          "body": "…load (rc.10) (#183)\n\n## Wave 6a — SPEC v0.5.1 conformance closure (rc.10)\n\nCloses two NORMATIVE gaps from the v0.5.1 audit.\n\n### §6.6 conformance-fixture gate (NORMATIVE release-gate)\n- New `fixtures/reviews/<scenario>/{input.json, expected.md}` for 5\ncanonical scenarios: **clean, critical-only, mi\n[…]\n `v0.7.0-rc.10` → publishes to `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Wave 6a: §6.6 conformance-fixture gate + §3.23.1 configure-github pay…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T05:14:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e42bbd9c8a2a5908a32dcbabf05bd2c779aa98c3",
          "body": "… (#182)\n\n## Wave 5b.1 — rc.9 graceful PAT-or-fallback resolve\n\nWave 5b smoke surfaced that the GraphQL `resolveReviewThread` mutation\nfails with\n`Resource not accessible by integration` under the Actions\n`GITHUB_TOKEN` — a known\nGitHub limitation, not a code bug. This makes auto-resolve\n**PAT-optio\n[…]\nr the\nPAT-path + cached-resolve smoke.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Wave 5b.1: rc.9 graceful PAT-or-fallback resolve + idempotent markers…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T04:43:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dc350085ee91ec0c779a01b24e65956dad415add",
          "body": "## Summary\n\nOSS parity push, part 2 of 2 (builds on Wave 5a rc.7 inline threads). On\nfix-push events, the workflow asks the Anthropic Messages API per\nbot-authored unresolved inline thread whether the new commit addressed\nthe original finding. ADDRESSED threads get auto-resolved (with a marker\nreply\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wave 5b: D.2.6 auto-resolve on fix-push (clud-bug rc.8) (#181)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T02:42:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c649b191fc7370aec083a5421e8d89513416a15",
          "body": "…7) (#180)\n\n## Summary\n\nOSS parity push, part 1 of 2. Brings per-finding inline review threads\n(D.2.X) from the hosted clud-bug-app to the npm `clud-bug` workflow\ntemplate path so self-hosted users get first-class GitHub review threads\nanchored to file+line, instead of one bundled summary comment li\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wave 5a: D.2.X per-finding inline review threads in npm workflow (rc.…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-27T21:45:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8eed01f2fa813819015ffdceafe6e2089aa3242c",
          "body": "## Summary\n\nImplements the consumer-side surface for SPEC v0.5.1 §1.10.1's new\n`applies_to.author` field. Extends `SkillFrontmatter` +\n`parseFrontmatter` to surface `kind` + `voice_scope` +\n`applies_to.author` (the Wave 4d reviewer-flagged silent-drops are now\nfirst-class). Adds new `appliesToAuthor\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.6: applies_to.author filter (Wave 4e.2, SPEC v0.5.1 consumer) (#179)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-27T20:23:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd816c5e673153c568895f6e84a547b736bfbc15",
          "body": "…] (#178)\n\nSlots in the held dependabot bump (#162) as a CTO-curated migration PR.\nPer CEO direction (\\\"is bump typescript in clud bug in our plan? seems\nlike that dependabot PR is key\\\"), TS6 should be in the plan.\n\n## What\n\nBumps `typescript` devDep from `^5.5.0` to `^6.0.3` and applies two\nminor \n[…]\nloat the rc.5\nrelease PR's scope.\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ts): migrate to TypeScript 6 — ignoreDeprecations + types:[node…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-26T05:11:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f51e8c2c5a1e02c4b31c64b1e5913086cc6ab1df",
          "body": "…ookup (#177)\n\nCloses task #234.\n\n## What\n\nReplaces the module-load `readFileSync(package.json)` in\n`src/core/render.ts` with an import from generated\n`src/core/version.ts`. The version is baked by `scripts/gen-version.mjs`\nat every build (`prebuild` hook) and every test run (`pretest` hook).\n\n`src/\n[…]\name flow as rc.1/rc.2/rc.3/rc.4.)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): rc.5 — bake PKG_VERSION at build, remove runtime fs l…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-26T05:08:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "40907445e75319ab0359a1f588663db2abc9c7d1",
          "body": "…0.0 (#173)\n\nBumps\n[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)\nfrom 22.19.20 to 26.0.0.\n<details>\n<summary>Commits</summary>\n<ul>\n<li>See full diff in <a\nhref=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\">compare\nview</a></li>\n[…]\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: thrillmot <devintwilmot@gmail.com>",
          "is_bot": true,
          "headline": "[skip-logmind] chore(deps-dev): bump @types/node from 22.19.20 to 26.…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T03:12:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8267b3259f04f3ea6ce4334102f0488896345a4",
          "body": "Bumps\n[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)\nfrom 2.1.9 to 4.1.9.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/vitest-dev/vitest/releases\">vitest's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v4.1.9</h2>\n<h3>🐞 Bug Fixes</h3>\n[…]\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: thrillmot <devintwilmot@gmail.com>",
          "is_bot": true,
          "headline": "[skip-logmind] chore(deps-dev): bump vitest from 2.1.9 to 4.1.9 (#167)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T03:12:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d8da9a426a779ca227ba47ec704541a02138d39a",
          "body": "… test (#175)\n\nBundles two independent CI fixes that are both required to unblock main.\nPer CTO direction on this PR specifically: the locked \"workflow files in\ntheir own PR\" rule's rationale (Anthropic action validation 401 on\n`clud-bug-review.yml`) doesn't apply on clud-bug — that workflow was\ndel\n[…]\nst 2→4), #173\n(@types/node 22→26)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci): unblock main — drop stale workflow refs + fix time-dependent…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-26T02:47:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "36045c93bb7d7e1446823a4cf014fbf73886467d",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to\n7.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/checkout/releases\">actions/checkout's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v7.0.0</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>blo\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6 to 7 (#172)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T02:27:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb72798aa360f89544a78f6bad68bf9a7dcc1871",
          "body": "… updates (#174)\n\nBumps the minor-and-patch group with 4 updates in the /site directory:\n[next](https://github.com/vercel/next.js),\n[react](https://github.com/facebook/react/tree/HEAD/packages/react),\n[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react)\nand\n[react\n[…]\n of the specified dependency and ignore\nconditions\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the minor-and-patch group across 1 directory with 4…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T02:27:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "673499372469d16a8d17e95c50af14eb39759cc8",
          "body": "Closes the rc.4 publish warning. npm internally normalizes string-form\nbin to object-form during publish; bringing source in line so future\npublishes go through clean. No behavior change.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(package): bin field — string → object shape (#171)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T18:17:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "371ce029e9c889c7aa456e87d9cca007b5856540",
          "body": "… — stop API-key bleed (#170)\n\n## Summary\n\nStops the Anthropic API-key bleed on this repo. Tonight's 4-PR overnight\nwave fired both workflows on every push, generating real billing on the\nuser's direct ANTHROPIC_API_KEY.\n\n**`clud-bug-review.yml`** — npm workflow Action PR review. Phase 5.3\npaused th\n[…]\ncord established. Removed.\n\nWhen App reviews re-enable on this repo (Phase 5.3 exit criteria),\nhosted bot is the sole review path.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(workflows): remove clud-bug-review.yml + claude-code-review.yml…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T15:19:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0be28e7eba1821f688bf2119a817c8400cd968b6",
          "body": "…ded for review (#169)\n\n## Summary\n\nCEO observation tonight after the cludbug.dev rewrite (PR #165 +\nbrand-power follow-up): the brand voice exists in code but isn't encoded\nas a reviewable skill, so future copy changes can drift without signal.\nCloses that gap.\n\n**Local to clud-bug only** — not pus\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(skill): clud-bug-brand-voice — naturalist field-guide voice enco…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T15:05:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ba94ea769e85ca832b73bdec9c00769412015c2",
          "body": "…ng (#166)\n\n## Summary\n\nThree SPEC-aligned core enhancements bundled for the v0.7.0 Marketplace\nprep ship train. All three land in `src/core/` so clud-bug-app's Phase 4\nre-import lands them in one wave.\n\n- **Wave A — `clud-bug configure-github <owner>/<repo>`** (Phase 6 task\n#227). Pure diff + idemp\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rc.4): configure-github + cache comment + resolved findings nami…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T14:59:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5a28ce88de2c261a813d723314d9b72941ad1579",
          "body": "## Summary\n\nApp-first marketing rewrite for cludbug.dev. The clud-bug GitHub App\nwent live earlier today (Phase 5 BOT_MAINTENANCE_MODE flipped false), so\nthe marketing site now leads with the App install CTA. The npm workflow\npath stays as a demoted **§VI — Self-hosted alternative**.\n\n## Messaging s\n[…]\n runtime — pre-existing\nbehavior, unchanged by this PR)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(site): App-first marketing rewrite (G6.c) (#165)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T14:57:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bf0927a634553e39d5c0153dc7120f472336cc2f",
          "body": "…upport) (#164)\n\nBumps the reusable workflow pin to pick up the change from PR #3 on\n`thrillmade/.github` (drops the major-bump early-stop step). After\nmerge, major dependabot bumps in this repo will auto-merge on CI pass\nlike patch/minor already do.\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump dependabot-auto-merge caller pin to 6e1f9df (major-bump s…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-10T15:25:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f43636ff640ac93bd38909b88bee96ee08c1122b",
          "body": "… A) (#163)\n\n## Summary\n\nPhase 7 PR A closes 5 SPEC v0.2.0 conformance gaps in clud-bug core and\nships the workflow-path bridge for formal APPROVE reviews. After this\nlands, clud-bug-app's Phase 7 PR B will consume via dep bump + small\nwiring; the npm workflow path inherits via the new template post\n[…]\normal-review,\nwire author_association.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: v0.7.0-rc.3 — SPEC §1.8.1 + §7.2.1 + §6.7.3 closure (Phase 7 PR…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-10T15:17:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4521938fa4f34f5f2d0dc581eec8b2feb6b8778",
          "body": "…lock) (#158)\n\n## Summary\n\nPhase 4 of the Bug 9 migration (clud-bug-app deletes ~6,500 LOC of\nduplicate code by importing from `clud-bug/core`) needed App-shape\nexports that rc.1 didn't ship. This adds them ADDITIVELY — the CLI-shape\nexports stay first-class.\n\n**Net LOC added to core: +1212 LOC acro\n[…]\now/clud-bug && npm publish --tag next`\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: v0.7.0-rc.2 — add AI-Gateway-shape exports to core (Phase 4 unb…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-09T21:36:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9a067b722505432312bd9abae3233fa43e29e81",
          "body": "…ourcemap fix) (#157)\n\n## Summary\n\nThree coordinated changes that all hinge on the v0.6.35 → v0.7.0-rc.1\nversion bump.\n\n## Changes\n\n### 1. Version bump\n- `package.json` `0.6.35` → `0.7.0-rc.1`\n- All 3 workflow templates' `strict-mode-gate@v0.6.35` → `@v0.7.0-rc.1`\n- `action.yml` header docstring exa\n[…]\ninstalls via `pnpm add clud-bug@next`)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: v0.7.0-rc.1 release prep (version bump + classifier vendor + s…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-09T20:17:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "28ee7a1ccae1af24d1c5abc84799b54d2dbe2178",
          "body": "…ug 9 Phase 2) (#156)\n\n## Summary\n\n**Phase 2 of the Bug 9 mission** (plan §\"Bug 9 mission plan\"). Migrates\nthe entire `lib/*.js` codebase to TypeScript and restructures into\n`src/core/` (pure library) + `src/cli/` (init/update/audit commands),\nexposed via subpath export so consumers can `import { ..\n[…]\nv0.7.0-rc.1`, `npm publish --tag next`\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: v0.7.0 — TypeScript migration + clud-bug/core subpath export (B…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-08T22:48:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0af5ec65b03741e602570168bd247cbaa1822dc8",
          "body": "## The bug\n\n\\`MAX_DIFF_BYTES: '80000'\\` (80KB) at\n\\`templates/workflow.yml.tmpl:404\\` was silently capping diffs via\n\\`head -c\\` before sending to Claude. Real-world PRs over 80KB got\nhalf-reviews — Claude only ever saw the first 80KB of the diff.\n\nThis was the original-author intent (cap input cost\n[…]\nff should NEVER be a blocker or guard\"\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.35: never block on large diffs (MAX_DIFF_BYTES 80K → 5MB) (#153)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-08T19:40:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "09710ab50a07382c4f7b154875dbd5b2ca8bf2ef",
          "body": "Small standalone PR so it can land FIRST, then review all subsequent PRs\n(including PR #153 — the v0.6.35 MAX_DIFF_BYTES fix).\n\n## Why\n- npm clud-bug never had \\`clud-bug-review.yml\\` installed in its own\nrepo. Only \\`claude-code-review.yml\\` ran (stock Claude action, no\nskills, no clud-bug specific\n[…]\nl so its broken state\ncan't interfere.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: dogfood clud-bug on itself (install own review workflow) (#154)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-08T19:34:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7726bcbabb2dddbfb2464b29a8dd2c4423dc9ee",
          "body": "….0 (#152)\n\nFixes CI on all workflows. Migration sweep yesterday hardcoded @v1.0.1\nwhich doesn't exist; only v1.0.0 shipped. One-line fix in 3 workflows.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] fix(setup-logmind): correct broken @v1.0.1 pin → @v1.0…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-07T19:10:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "905d300739eb044b64033105fc3a0bc96dc45fb3",
          "body": "…nfig (#150)\n\n## Summary\n\nMigrates this repo to the v1.1.0 distribution-lock pattern (per master\nplan §Architectural Decisions 2026-06-05).\n\n- Replaces the curl-install block in `check-doc-links.yml` +\n`regen-timeline.yml` with `uses: thrillmade/setup-logmind@v1.0.1`\n(immutable pin).\n- Rewrites `log\n[…]\navored migration commit — no decision file\nrequired.\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: clud-bug[bot] <0+clud-bug[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: migrate to setup-logmind action + Dependabot co…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-06T00:05:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c1e806efe36f9408abcff141b044be1a592549e",
          "body": "…xclude docs/reviews/) (#149)\n\n## Summary\n\nBumps the logmind install pin in `.github/workflows/check-doc-links.yml`\nfrom `v1.0.0` → `v1.0.1` so this repo's CI picks up the orphan-markdown\nfix shipped in [logmind PR\n#145](https://github.com/thrillmade/logmind/pull/145).\n\n## Why\n\nlogmind v1.0.1 (shipp\n[…]\nd with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: clud-bug[bot] <0+clud-bug[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: bump logmind pin v1.0.0 → v1.0.1 (check-links e…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-05T20:16:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d341e990022a8a8e2da25e950051efaec84add63",
          "body": "…Hub App (G3.b) (#147)\n\n## Summary\n\nMigrate this repo's automated PR reviews from the per-repo\n`clud-bug-review.yml` workflow to the `clud-bug[bot]` GitHub App\n(installed at org scope across all `thrillmade/*` repos). This is\n**dogfooding**: the App lives in `thrillmade/clud-bug-app` but its\nreview \n[…]\nstream consumer repos that haven't\ninstalled the App.\n\nGenerated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: clud-bug[bot] <0+clud-bug[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: migrate PR review from workflow to clud-bug Git…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-05T19:01:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7b424ab6e75be805a8b6fc4c9f6f8c4955ae0053",
          "body": "…) (#144)\n\n## Summary\n\n- Adds a tiny caller workflow that delegates Dependabot patch + minor\nauto-merge to the reusable workflow at `thrillmade/.github`.\n- Major bumps are still surfaced for human review.\n\n## Why\n\nPath A from org master plan §8.1 — near-term unblock for org-wide\ndependency hygiene. \n[…]\n next Dependabot patch/minor PR get auto-approved and\nmerged.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: add dependabot auto-merge caller workflow (§8.1…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-04T15:37:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "54c1b2125386122df17be9ebbbae8e62f9287f4a",
          "body": "…nary (#143)\n\n## Summary\n\nMigrate this repo's three logmind-shipped CI workflows off `pip install\n\"logmind==0.6.14\"` (the now-frozen Python wheel) and onto the v1.0 Go\nbinary released at\nhttps://github.com/thrillmade/logmind/releases/tag/v1.0.0. All workflows\nnow bootstrap via `curl -fsSL https://lo\n[…]\nreview on this PR. The clud-bug workflow itself is\nuntouched.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: cut over from pip install logmind to v1.0 Go bi…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-03T18:07:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "682955587aa4fa4c17a2116b729b1b980d538bc2",
          "body": "Follow-up to PR #140. Bump canonical workflow's strict-mode-gate pin\nfrom @v0.6.33 → @v0.6.34 now that the v0.6.34 tag exists.\n\nMatches historical pattern (#93, #115, #119, #126, #128, #130, #132):\nself-propagation always happens in a separate PR after the release tag\nexists, so CI can resolve the a\n[…]\nhrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.34 (#142)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T18:19:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8dc2588411ad13d143e88b34a5ed33f2ee939e5a",
          "body": "…mics Concern 2) (#140)\n\nFix from tokenomics agent's v0.6.14 verification report. Transient\nAnthropic API errors (`Claude encountered an error after 1m 45s`) now\nemit a `neutral` check-run instead of `failure` — PRs no longer get\nblocked when the tool fails without producing content findings.\n\n## Su\n[…]\ne Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.34: clud-bug-review emits neutral on transient AI errors (tokeno…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T18:14:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90db8bb6ebb53d0a87831cf6facd22f80cc0da5b",
          "body": "Automated upgrade from logmind 0.6.13 → 0.6.14.\n\nRefresh mode (v0.2.1+) only touched workflow templates whose `#\nlogmind-template-version:` marker is stale; `docs/`,\n`.logmind/config.yml`, and agent files were left alone.\n\nReview the diff. To stop self-updates after this, add `pinVersion:\n\"0.6.14\"` to `.logmind/config.yml` before merging.\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] logmind self-update: 0.6.13 → 0.6.14 (#139)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T04:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6316fa3e583648826b81cb91f9e6e9004168e7e2",
          "body": "Automated propagation of logmind v0.6.13. PR opened manually because the\nconsumer-repo's current v5 self-update template uses GITHUB_TOKEN for\n`gh pr create` and hit the \"Allow Actions to create PRs\" per-repo gate.\nThe v6 template included in this PR uses the PAT for `gh pr create` too\n— fixes v0.6.14+ propagation.\n\nGenerated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] logmind self-update: 0.6.12 → 0.6.13 (#138)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T02:45:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "427983dd29c3854c5ef28a6ac3c0f602d18a1e7d",
          "body": "Automated upgrade from logmind 0.6.11 → 0.6.12.\n\nPR-creation step in the self-update workflow failed because GitHub\nActions is not permitted to create PRs in this repo. Branch was already\npushed via the PAT; this PR is manually created for it. Adding the PAT\nto the gh pr create step is queued as a v0.6.13 candidate in the plan.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "logmind self-update: 0.6.11 → 0.6.12 (#137)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T01:39:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "60d22ad9d4dba69591bc085ab7a4b8e136eb3e9c",
          "body": "Bootstrap fix for v0.6.11 propagation cycle: refreshes\n\\`logmind-self-update.yml\\` to v5 template (PAT-based push for workflow\nrefreshes). The initial v0.6.11 propagation used \\`logmind agents update\n--apply\\` which only does pin bumps; the v5 template change came in via\na marker bump that requires \n[…]\ne Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: refresh logmind-self-update.yml to v5 (PAT bootstrap) (#136)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T23:30:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a760c3fb3f6d603e01a0e46bfefdb9f57df4da53",
          "body": "Workflow pins v0.6.9 → v0.6.11. Manually propagated.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: refresh logmind v0.6.9 → v0.6.11 (#135)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T23:24:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "134db994580376367d667da9d76f21ea554cf010",
          "body": "Workflow pins from v0.5.13 → v0.6.9. Picks up v0.6.9 `logmind\nfile-structure --check`, v0.6.8 `--with-skdd`, v0.6.7 post-merge\nunstaged fix.\n\nOrg self-update workflow failed at push step (GITHUB_TOKEN lacks\n`workflows: write`). Manually propagated via local logmind v0.6.9 + PAT.\nCaptured as v0.6.10 candidate.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: refresh logmind v0.5.13 → v0.6.9 (#134)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T21:19:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a07f0b2ac60b00e50b72469c71674bd2bc6ca5ef",
          "body": "…mirror) (#133)\n\n## Summary\n\nSymmetric mirror of logmind v0.6.8's `--with-skdd` flag. Node-first\nusers get the same one-command bootstrap as Python-first users:\n\n```bash\nnpx clud-bug init --with-skdd   # clud-bug + logmind, one command\n```\n\nWhichever ecosystem the user starts in, the flag pulls in t\n[…]\nx] Graceful no-Python warning path verified via spawnSync with\nscrubbed PATH\n- [ ] Self-review on this PR via clud-bug-review\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.33: clud-bug init --with-skdd flag (unified install, Node entry …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T18:12:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7cb38487ec742973bf404e66ae6dd530dd0eede",
          "body": "Self-propagation of v0.6.32.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.32 (#132)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T14:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8140fdc54c0027e01dc8745ee836d2b4037f3390",
          "body": "…(#131)\n\n## Summary\n\nLocks in the v0.6.31 hotfix (`include-hidden-files: true`) with a\nrelease-discipline assertion that fails CI if the flag is ever removed\nfrom any workflow template. Also drops the now-stale \"v0.6.30 will add\"\nframing from the dashboard placeholder.\n\n## Why\n\nv0.6.31's fix is a si\n[…]\n1 new release-discipline\nassertion)\n- [x] Smoke-test verified guard fails on regression\n- [ ] Self-review on this PR via clud-bug-review\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.32: release-discipline guard for v0.6.31 + stale dashboard text …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T14:15:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fe56e94a2905c8d7ecb22e2cc15ec85e35f89d1",
          "body": "Self-propagation of v0.6.31 hotfix.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.31 (hotfix) (#130)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T12:45:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7776acf2019f6a127f04c7bb083c6ca988333d3",
          "body": "…ilent breakage) (#129)\n\n## Summary\n\n**Critical hotfix.** v0.6.29's `Upload skill-usage artifact` step has\nbeen silently dropping every artifact across the entire org since\n2026-05-31.\n\n## Root cause\n\n`actions/upload-artifact@v4` excludes hidden files by default.\n`.claude/` (directory) and `.clud-bu\n[…]\n + a step that warns-but-succeeds is a\nsilent-failure pattern. Consider a smoke-test in v0.6.32+ that asserts\nnon-empty artifact upload.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.31: hotfix — upload-artifact excludes hidden files (v0.6.29-30 s…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T12:43:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd17eadff541c05a92ba41850c0a92239373ac93",
          "body": "Self-propagation — clud-bug eats its own templates at pin @v0.6.30.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.30 (cross-review aggregation) (#128)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T04:05:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2690affd67d28b50070886c6779b6450d52d9f9e",
          "body": "…oard (#127)\n\n## Summary\n\nCloses the SkDD usage loop. v0.6.29 wired up per-PR artifact uploads,\nbut the v0.6.28 dashboard still read only the local `.clud-bug.json`\n(always empty unless someone ran `update-skill-usage` locally). v0.6.30\nmakes `clud-bug usage --health` walk workflow artifacts + merge\n[…]\nagainst the v0.6.29 propagation cycle's\naccumulated artifacts → expect real `loads` + `citations` data instead\nof placeholder\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.30: cross-review aggregation reads workflow artifacts into dashb…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T04:02:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "403418eab6c5d19bf6f1ec32e4d96d5dba26d330",
          "body": "Clud-bug eats its own templates — own clud-bug-review workflow now\nwrites skill-usage deltas + uploads artifact like the consumers do.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.29 (skill-usage workflow integration) (#126)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-31T18:23:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbdd97f763864eeec0d723b0616af009e90cdc19",
          "body": "…e (#125)\n\n## Summary\n\n- New CLI subcommand `clud-bug update-skill-usage --stdin` — reads\nstructured-output JSON, computes per-skill delta, merges into\n`.claude/skills/.clud-bug.json` (atomic temp+rename).\n- Two new post-steps in all 3 workflow templates (workflow.yml.tmpl,\nworkflow-ts, workflow-py)\n[…]\nreview) emits a skill-usage\nartifact\n- [ ] Propagation cycle: consumer PRs after merge pull the new templates\n+ write to their workspace\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.29: Component 4 — workflow integration auto-populates skill usag…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-31T18:01:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bfe47299899e0cdaa123b45d768249e17bc78782",
          "body": "… usage --health (#124)\n\n**Components 1+2 of the pragmatic SkDD pivot** (2026-05-30). Replaces\nspeculative recursive-meta-skill direction with deterministic usage\ntracking + human-gated approval.\n\n## What ships\n\n### `lib/skill-usage.js` — pure data layer\n- `computeSkillUsageDelta(reviewJson)` — extr\n[…]\nmoted from v0.6.28 per the pivot)\n- L4 permission-to-continue\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] feat(v0.6.28): skill-usage tracking library + clud-bug…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T23:28:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "074d7e51740684e335ee9a9ca51accd4b38e6b59",
          "body": "…4a) (#122)\n\nStream 4a from the token-cost-compression plan. Surface the two recent\nwins on cludbug.dev in field-guide voice.\n\n## What's added\n\n### §IV — Field Economy\n> _\"Even the largest specimens get a full examination.\"_\n\nSmart review budget tailored to PR diff size:\n- Tiny PR → ~5 turns\n- Large\n[…]\nble.\n- [ ] User async-review approves messaging before merge.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "site: §IV Field Economy + §V Habitat Expansion + version pin (Stream …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T17:56:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b4b1765aa8a867f4f8da4cd7635beb2ce350d315",
          "body": "Stream 5 cleanup. Adds identical 'Part of the thrillmade SkDD toolchain'\nfooter to clud-bug README.md. Parallel commits land on logmind +\nagent-skills.\n\nFooter:\n- Names SkDD (Zak Elfassi's methodology, links his blog)\n- Lists the 4 thrillmade toolchain parts\n- Captures the end-to-end auto-dev loop\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: SkDD toolchain footer for clud-bug README (#123)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T17:46:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "78166ef843f8b288f885fd13bc55b9c27ec4a5e8",
          "body": "…n (#121)\n\n## Summary\n\nPrompt-only addition: the AI must emit a single-line `[budget]`\nheartbeat every 5 tool_uses showing files_reviewed/total,\nturns_used/max, and ok/behind pace. When behind, pivot to one-sentence\nverdicts so every file in the diff gets reviewed before budget runs out\n— silent ski\n[…]\nd as `clud-bug update` output and auto-skips clud-bug-review.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(v0.6.27): Smart Budget Phase 3 — Layer 3 mid-review self-check-i…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T04:48:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "026b8445f5b1fb48714a940b401d01b2827aabc8",
          "body": "…k render-from-inlines (#120)\n\n## Summary\n\nTwo adjacent fixes that ship together. **L5 auto-retry deferred to\nv0.6.27** because it restructures the workflow's job-dependency graph\n(separate concern, bigger surface area).\n\n### 0.0.W² — widen workflow-only-skip allowlist (paths-check)\n\nEvery prior `cl\n[…]\n fires). FIRST\npropagation cycle requiring zero admin-bypass.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(v0.6.26): Smart Budget Phase 2a — 0.0.W² widen skip + L6 fallbac…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T03:21:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "168143b16e60a61a0d166e8fd951c8481597d33f",
          "body": "…) (#119)\n\nRe-renders clud-bug's own workflow against v0.6.25 templates. Without\nthis, clud-bug-review runs on clud-bug PRs with the legacy\nv0.6.22-rendered `--max-turns=15` hardcode, defeating the smart budget\non the repo that SHIPS it.\n\nPR #118 (v0.6.25 itself) hit exactly that — paths-check compu\n[…]\nd), this will be the LAST admin-bypass needed on\nclud-bug self-upgrades.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: clud-bug self-upgrade to v0.6.25 (dogfood Smart Budget Phase 1…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T02:33:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac190404bdfa8aa92dc8226ea4d63f502476c582",
          "body": "…leanups (#118)\n\n## Summary\n\nShips **Phase 1 of the 7-layer Smart Budget System** (full architecture\nin plan §5.5; remaining layers in v0.6.26 / v0.6.27 / v0.6.28 / v0.7.0).\nMotivated by tokenomics PR #21 exhausting v0.6.23's adaptive\n`--max-turns=25` while emitting a structured-output summary on a \n[…]\n4 workflows continue to function — output\nschema is additive.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(v0.6.25): Smart Budget System Phase 1 (Layers 1 + 1.5 + 2) + 3 c…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T02:02:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21224684b03912be0592f936fe422d983de4f208",
          "body": "…rs on private repos under v0.6.23 (#117)\n\n## Summary\n\nv0.6.23 added `actions: read` permission to the `clud-bug-review` job\nfor the bundled `github_ci` MCP server. Forensics on tokenomics show\nthis broke `pull_request` trigger firing on **private** consumer repos:\n\n- **tokenomics** (private): clud-\n[…]\nt-skills repo, v0.6.24 doesn't regress any\nexisting behavior.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "hotfix(v0.6.24): back out 'actions: read' — broke pull_request trigge…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-29T23:49:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 70,
      "commits_last_year": 199,
      "latest_release_at": "2026-07-17T01:29:39Z",
      "latest_release_tag": "v0.7.0-rc.24",
      "releases_from_tags": true,
      "days_since_last_push": 4,
      "active_weeks_last_year": 10,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "clud-bug",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "claude",
            "claude-code",
            "github-action",
            "code-review",
            "pull-request",
            "ai",
            "skills"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/clud-bug",
          "is_deprecated": false,
          "latest_version": "0.6.34",
          "repository_url": "https://github.com/thrillmade/clud-bug",
          "versions_count": 72,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3469,
          "first_published_at": "2026-05-15T04:24:33.379000Z",
          "latest_published_at": "2026-06-02T18:16:52.252000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 49
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [
          {
            "date": "2026-03-25",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_stars": 1
      },
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "site/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 108699,
      "source_files_sampled": 159,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        ".cursorrules",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 2711
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "site/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "next",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.2.9"
        },
        {
          "name": "react",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-dom",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 198,
        "open_issues": 3,
        "closed_ratio": 0.4,
        "closed_issues": 2,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "thrillmot",
          "commits": 191,
          "avatar_url": "https://avatars.githubusercontent.com/u/15040426?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "check-decisions.yml",
        "check-doc-links.yml",
        "ci.yml",
        "dependabot-auto-merge.yml",
        "logmind-self-update.yml",
        "npm-publish.yml",
        "regen-timeline.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "10ae1dc4c3708546ad49f0d416060cd2d1d40961",
        "ran_at": "2026-07-21T18:20:04Z",
        "aggregate_score": 5.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/thrillmade/clud-bug",
    "host": "github.com",
    "name": "clud-bug",
    "owner": "thrillmade"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 53,
        "vitality": 78,
        "community": 33,
        "governance": 46,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 78,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "commits_last_year": 199,
              "human_commit_share": 0.96,
              "days_since_last_push": 4,
              "active_weeks_last_year": 10
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "10/52 weeks with commits",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "199 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 199
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 70,
              "latest_release_tag": "v0.7.0-rc.24",
              "releases_from_tags": true,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "70 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 70
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "clud-bug"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3469
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,469 downloads/month across npm",
                "points": 47.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3469,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "merged_prs": 198,
              "open_issues": 3,
              "closed_issues": 2,
              "issue_closed_ratio": 0.4,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "198/229 decided PRs merged",
                "points": 33.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 198,
                      "decided": 229
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "thrillmade",
              "public_repos": 8,
              "account_age_days": 796
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of thrillmade",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "thrillmade"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "8 public repos, account ~2 yr old",
                "points": 11.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 8
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "clud-bug"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 49
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 49 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 49
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "72 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 72
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai-code-review",
                "claude",
                "claude-code",
                "cli",
                "code-review",
                "github-actions",
                "npm-package",
                "pr-review",
                "pull-request",
                "skills",
                "skills-sh",
                "skdd",
                "skill-driven-development"
              ],
              "has_wiki": false,
              "homepage": "https://cludbug.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://cludbug.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "13 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 53,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 77,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                ".cursorrules",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 2711
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursorrules, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursorrules, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 96 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 96
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "site/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.56,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.04
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "site/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "site/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "56 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 56,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "4 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 4,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 108699,
              "source_files_sampled": 159,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/159 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 159,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T18:20:23.308225Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/thrillmade/clud-bug.svg",
  "full_name": "thrillmade/clud-bug",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.23.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte Statistikennpm.