Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-26 17:06 UTC

DanceNitra / inspeximus

Zero-dependency agent memory + MCP server. Value-ranked recall, consolidation, and a first-class correction & erasure channel (revert, lineage-aware retraction, tamper-evident receipts). Measured integrity vs mem0/Graphiti.

PythonMIT★ 5 estrellas⑂ 0 forksdesde jul 2026Ver en GitHub ↗

DanceNitra/inspeximus tiene un índice de salud de 52 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Engineering Quality (76/100) y la más baja, Security (36/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

52
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

52
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Rastislav DrahošCuenta personal
5 seguidores43 repositorios públicosdesde jul 2018

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
PyPIinspeximus1.74.0483556hace 0 díasllmagentmemoryragrecallconsolidationmcpembeddingssecond-brain

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

73Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
1.4/36Cadencia de commits — 2/52 semanas con commits
18/18Volumen de commits — 199 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year199
human_commit_share1
days_since_last_push0
active_weeks_last_year2
Cómo se puntúa
27/27Publica versiones — 7 versiones publicadas
36/36Recencia de las versiones — última versión hace 12 días
27/27Cadencia de publicación — una versión cada ~0,2 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count7
latest_release_tagv1.5.0
releases_from_tagsno
days_since_latest_release12
mean_days_between_releases0,2
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

37En riesgo · 18% del índice global
Cómo se puntúa
9.8/60Estrellas — 5 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars5
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
49.1/80Descargas mensuales — 4835 descargas/mes en pypi
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesinspeximus
dependents
ecosystemspypi
total_downloads
monthly_downloads4835
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

36En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — 0% de issues cerradas
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
5.6/25Alcance del propietario — 5 seguidores de DanceNitra
24/25Trayectoria — 43 repos públicos, cuenta de ~8 años
Datos de entrada utilizados
followers5
owner_typeUser
is_verified
owner_loginDanceNitra
public_repos43
account_age_days2922
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en pypi
35/35Recencia de publicación — última publicación hace 0 días
20/20Historial de versiones — 56 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesinspeximus
ecosystemspypi
any_deprecatedno
min_days_since_publish0

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

76Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 3 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

100Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://dancenitra.github.io/inspeximus/
10/10Descripción del repositorio
10/10Topics — 14 topics
10/10Wiki
Datos de entrada utilizados
topicsagent-memory, llm, mcp, mcp-server, model-context-protocol, rag, ai-memory, eu-ai-act, gdpr, llm-memory, long-term-memory, mem0-alternative, zero-dependency, self-correcting-memory
has_wiki
homepagehttps://dancenitra.github.io/inspeximus/
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

36En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,6
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

54Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 99 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,99
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — site/tsconfig.json
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 77 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configssite/tsconfig.json
agent_commit_share0,77
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
27/45Código verificable por tipos — Python con configuración de verificación de tipos (site/tsconfig.json)
54.4/55Tamaños de archivo manejables — 3/257 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePython
largest_source_bytes504.709
source_files_sampled257
oversized_source_files3
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signal
api_schema_files

Datos clave

5estrellas de GitHub
1contribuidores
199commits en los últimos 12 meses
0días desde el último push
7versiones publicadas
1factor bus
1issues abiertas
npm, PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index pypi:inspeximus@1.74.0; advisories assessed against the repository dependency graph instead

Más detalle

OpenSSF Scorecard 3.6 / 10
3.6agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-26 17:06 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
Dependencias directas 3
RegistroPaqueteRestricción de versiónManifiesto
npmgsap^3.12.5site/package.json
npmlenis^1.1.14site/package.json
npmthree^0.169.0site/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "agent-memory",
        "llm",
        "mcp",
        "mcp-server",
        "model-context-protocol",
        "rag",
        "ai-memory",
        "eu-ai-act",
        "gdpr",
        "llm-memory",
        "long-term-memory",
        "mem0-alternative",
        "zero-dependency",
        "self-correcting-memory"
      ],
      "is_fork": false,
      "size_kb": 7688,
      "has_wiki": true,
      "homepage": "https://dancenitra.github.io/inspeximus/",
      "languages": {
        "CSS": 18672,
        "HTML": 68434,
        "Shell": 514,
        "Python": 2163777,
        "Dockerfile": 513,
        "TypeScript": 29938
      },
      "pushed_at": "2026-07-26T17:05:12Z",
      "created_at": "2026-07-13T07:32:52Z",
      "owner_type": "User",
      "updated_at": "2026-07-26T17:05:16Z",
      "description": "Zero-dependency agent memory + MCP server. Value-ranked recall, consolidation, and a first-class correction & erasure channel (revert, lineage-aware retraction, tamper-evident receipts). Measured integrity vs mem0/Graphiti.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Rastislav Drahoš",
      "type": "User",
      "login": "DanceNitra",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/41733909?v=4",
      "created_at": "2018-07-26T09:54:30Z",
      "is_verified": null,
      "public_repos": 43,
      "account_age_days": 2922
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-07-14T08:21:11Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-07-14T07:34:56Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-07-13T19:31:00Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-07-13T15:56:31Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-13T15:34:10Z"
        },
        {
          "tag": "v0.7.22",
          "kind": "patch",
          "published_at": "2026-07-13T14:53:42Z"
        },
        {
          "tag": "v0.7.20",
          "kind": "patch",
          "published_at": "2026-07-13T08:03:59Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a39ad1682e1d3d2d634bbd3a68252d3beb6bc8d1",
          "body": "An adversarial review of our own audit story found the real gap: no artifact\nbound content across time for anyone outside the store. verify_bundle proves the\nchain re-walks and matches the anchor; the bundle is content-free by design, so\na clean chain over substituted content verifies fine.\n\nbind_co\n[…]\nomise entries being\nattacker-chosen. The contribution is that the check is now runnable.\n\n794 tests, five mutations verified to die.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.74.0: bind_content — an auditor can check content, not just the chain",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T17:05:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f400261e350093ace270891bbdfa4050c485091a",
          "body": "…d see\n\nThe <=1.67 laundering (fixed in 1.68.0) appended a well-formed receipt committing\nto the forged text. Nothing in the past was rewritten, so append-only held, the\nchain stayed internally consistent, and an externally witnessed anchor still\nre-derived its prefix intact -- measured: \"prefix int\n[…]\nding is part of the fix and has its own test.\n\nStores written by 1.68.0+ are unaffected.\n\n786 tests, five mutations verified to die.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.73.0: detect a tamper laundered under <=1.67, which no upgrade coul…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T16:50:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f701c966c50eb493f90eb2d099696a49b9e6c4aa",
          "body": "… fixture\n\n1.72.0's entry claimed anchor() committed to a truncated chain, \"n_writes = 1\nwith TWO receipts present\". That is false. The fixture behind it used a record\nthat never graduated, so slash() changed no committed field, no amendment was\nemitted, and the store genuinely held ONE receipt. I r\n[…]\np of the standing gate against installed\npackages before writing anything public -- which is the entire reason that step\nruns first.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "correction: the anchor was never truncating — I misread a one-receipt…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T16:33:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dc9dcc2a12f8e0fb7fd157d8480c015f0fac4103",
          "body": "1.68.0 added `amends` to a write receipt's hash. _emit_write_receipt and\nverify_writes got it; _chain_core -- used by anchor() and the offline bundle\nverifier -- did not, and neither did _content_free_writes, which decides what\ntravels in the bundle. After a single slash():\n\n  verify_writes()  -> Tr\n[…]\nt\nnever amended is unaffected, and that has its own test.\n\nFound by auditing the day's own fixes rather than a new area.\n\n779 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.72.0: one hash preimage had four definitions and the fix reached two",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T16:22:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bb30bcc4ec431749566645cba8104b29c2746a69",
          "body": "No release: tests only. Coverage is now 34 -> 24 of 373 with no executed body\nline, and what remains is deliberate (see HANDOFF).\n\npydantic_ai check_conflict, openai_agents pop_item and forget_subject were the\nonly ones left where a test could catch anything: conflict detection is real\nlogic, pop_it\n[…]\not to 04:00\"      -> 1 conflict with the key, 0 without\n\nOnly the reworded pair discriminates, and that is now the test.\n\n772 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: the last three uncovered functions worth covering",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T16:12:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8be5f318f84ab57513d418b9440c4ee4ad57eb35",
          "body": "… integrations\n\nNo release: tests only.\n\nThirteen functions with no executed body line. Both are async protocols and both\ncarry surfaces the package is sold on.\n\nADK: search must not leak across users OR across apps -- two separate filters,\ntested separately, because a mutation that drops either one\n[…]\nin\nstrings stored empty text and every search returned [] -- a broken fixture that\nlooked exactly like a broken adapter.\n\n748 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: cover the Google ADK and AutoGen adapters — the last uncovered…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T16:02:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34ec40f0acd8c45e8c6bc953b55c69a16ac086ea",
          "body": "…adapters\n\nNo release: tests only.\n\nEleven functions with no executed body line between them. Each block carries its\nown importorskip, so the file degrades to skips where only some optional\ndependencies are present.\n\nAll three adapters sell the same thing, and each block tests it rather than\nrepeati\n[…]\n empty string and\nread the design as a failure. It is now its own test: no query means no injected\ncontext, not a guess.\n\n734 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: cover CrewAI, Pydantic AI and LlamaIndex — the last framework …",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:56:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1fc99af03c67de124952eee871ab4ede415093a",
          "body": "No release: tests only.\n\nEight functions with no executed body line, including write_documents at 31 --\nthe largest single uncovered function in the package.\n\nThe module's two claims are now measured rather than asserted. Parity is checked\nagainst the REAL InMemoryDocumentStore, side by side, on wri\n[…]\nurvived: a pipeline handing in the wrong shape\n  would have been told \"wrote 0\" and carried on.\n\nFive mutations now die.\n\n722 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: cover the Haystack DocumentStore adapter",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:48:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c05d44d60538d48a9b3231ca0ffff8a9319160fa",
          "body": "No release: tests only.\n\nInspeximusSaver is a BaseCheckpointSaver -- LangGraph writes a graph's execution\nstate through it, so a wrapper that drops a checkpoint, returns the wrong one or\nloses pending writes corrupts a user's agent run, and 12 of its functions had no\nexecuted body line. Covered: the\n[…]\ns length: reversing the newest-first sort survived a count-only\nassertion, and \"newest-first\" is what consumers rely on.\n\n695 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: cover the LangGraph adapters (the largest uncovered module)",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:42:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c0f443d9209c1e34b8e33e179d5e0c76a602a4bf",
          "body": "…y lines\n\nNo release: tests only, per RELEASING.md.\n\ncheck_for_update (38 body lines, network-facing) is driven with a stubbed\nurlopen -- it exists to make one request, so a test that needs PyPI reachable\nwould be a flaky test rather than a test. Covered: it reports a newer release,\nstays quiet when\n[…]\n verify() takes the manifest rather than a subject; I had\nlisted the method names when probing and not their parameters.\n\n685 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: cover the remaining first-party functions with no executed bod…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:34:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c319da1e85fe381732e60d8a94e437f855b07e2",
          "body": "…n on both\n\nWritten from what actually went wrong rather than from a principle: batching is\nnot the risk, shipping a fix without a mutation-verified test is. Every defect\nfound today was created inside the previous fix, and neither a bigger nor a\nsmaller batch would have changed that.\n\nVersion count\n[…]\nurity ship alone and immediately; behaviour changes ship\nalone and flagged; ordinary fixes batch; tests-only ship no release at all.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: RELEASING.md — what ships alone, what batches, and the conditio…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:29:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8eb1726831d13edd8b94e96c5eee572e1a207c52",
          "body": "…t parse\n\ninstall() fell back to `cfg = {}` on any parse error and then WROTE it, so a\ntrailing comma in ./.claude/settings.json cost the user their model, their\npermissions and their own hooks -- from a function documented as \"merging, not\nclobbering\". uninstall() then raised on the same file, so i\n[…]\n by re-measuring coverage instead of trusting the carried number: 77/373\n(21%) uncovered, not the recorded 56/318 (18%).\n\n659 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.71.0: the Claude Code installer overwrote settings.json it could no…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:22:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac30e529bd500ab2e3978792af706d469fa93bb7",
          "body": "Coverage re-measured rather than trusted: 85 of 373 public functions (23%) have\nno executed body line, not the carried 56/318 (18%) -- stale in both directions.\nNine of them are in core.py itself, the product rather than an optional\nintegration, and this covers the four largest.\n\nclassify_reversion \n[…]\ncessor is the one thing this product must never do.\n\nAlso corrected: classify_reversion returns `intent`, not `verdict`.\n\n641 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: cover the nine core functions that had zero executed body lines",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:10:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d39ae69cfa53aa9e16fe91c6381bddc8ffcf0b7",
          "body": "… never ran\n\nverify_erasure_certificate's verdict read `store_absent is not False`, so a check\nthat never executed counted as a pass. An auditor who typo'd store_path -- or\npointed it at an encrypted store -- got valid=True with the \"read the raw store\"\nproof silently skipped. The explanation sat in\n[…]\nuding one asserting\nthe proof reads the RAW FILE and not the live process -- which is the only reason\nstore_path exists.\n\n619 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.70.0: the erasure certificate reported valid when the absence proof…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T15:02:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1991255d5608dde942163398f24196c2649fac18",
          "body": "test_mcp_surface.py drives all 55 tools and asserts only \"did not raise\" and\n\"JSON-serialisable\". Measured, five plausible sabotages of the server all pass\nit: recall ignoring k, get returning some other record, forget reporting success\nwithout deleting, verify_writes hard-coded to clean, and memory\n[…]\ns a characterisation test), `history` returns a\ndict not a list, and `get` returns {} rather than None for a missing id.\n\n612 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: make the MCP surface verification, not just coverage",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T14:50:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4355712b261c3183651a5e8a65e088c731b83609",
          "body": "… writes\n\nThe single-writer guard shipped in 1.67.0. A handle from an older release does\nnot have it and saves anyway, erasing whatever the newer one wrote. Measured\nwith real installs, 1.51.0 alongside 1.69.0 on one file:\n\n  1.51.0 opens -> 1.69.0 writes+flushes -> 1.51.0 flushes\n  final: ['baselin\n[…]\n immediately, so it fires on remember() and not on the later flush()\nthat two earlier versions wrapped in pytest.raises.\n\n599 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security-docs: mixed library versions on one store file silently lose…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T14:36:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f2621b7f67a523a451f9a3b433c1ef9cda76839e",
          "body": "…iminate\n\nTen tests closing the remaining named survivors: detect_split_view's\nboth_cosigned, believed_at's key filter and transaction-time cutoff, the\ncoherence gate's off-topic drop, spend_irreversible's require_earned, and\ncompliance's controls_with_evidence. Seven mutations of that logic each fa\n[…]\ntect_split_view is a staticmethod on Inspeximus, and\ncompliance_report lives in inspeximus.compliance, not on the store.\n\n595 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: the runner-up mutation survivors, with the fixtures that discr…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T14:27:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "24924e6cdb30363c07fa5394d756a262eec72913",
          "body": "submit_revert's absolute branch ended in derived_from=[tgt[\"id\"]], but `tgt` is\nbound only in the relative branch, which returns before reaching it. Every\nabsolute restore to an existing, non-current target raised UnboundLocalError,\nand restore_now -- the documented \"mint + submit in ONE call\" liven\n[…]\n vacuously -- the nonce \"echo01\" is not hex, so the intent was\nmalformed, and the assertions sat behind `if res[\"ok\"]:`.\n\n585 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.69.0: fix UnboundLocalError that made every absolute revert crash",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T14:13:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7902bdae997252eace3cae5a39ab0039fe209610",
          "body": "…s corrected\n\nFrom the 47 triaged real mutation gaps. Each test is written from the BEHAVIOUR\na mutant breaks, never from the line, because the recorded line numbers were\nalready stale -- core.py:3662 shifted in 1.68.0 and is now a comment.\n\nFive of the triage entries turned out to be wrong about th\n[…]\nd is dropped by the corroboration term\nand the retraction term is never exercised -- standing has to be re-earned first.\n\n572 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: 12 tests written from the surviving mutants, and 5 triage line…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T14:04:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e6b82f90d93d847e515421583bf51f20068806c",
          "body": "…e view\n\nThe blind registry reader shipped because nothing covered these scripts -- the\nonly detector was a red release. Seven offline tests with a stubbed two-page\nregistry now cover both readers; four mutations (drop the cursor loop in either\nscript, answer from a truncated view, drop the name fil\n[…]\nhe v1.68.0 tag itself still points at the old script, so\nthat run stays red -- 1.68.0 published correctly, only the check was blind.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: test the release scripts, and refuse to answer from a partial pag…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T12:43:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f05e941b8ab366ba03b276b6a5b5ff4f586ceb82",
          "body": "Both surfaced by the red 1.68.0 release, neither by the test suite.\n\n1. session drop-in (audit job). Two InspeximusSession(path=same_file) built two\nindependent Inspeximus handles, so the single-writer guard raised\nStoreChangedOnDisk on the second session's first write and session_audit\nreported \"NO\n[…]\nect fetch fails.\n\n1.68.0 itself published fine: PyPI serves it and the registry already marks it\nlatest. Only our checks were blind.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: two checks that had silently stopped covering what they claimed",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T12:33:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eb96e58b175c9f7c1e74b9bf209177e9e4b0b9b1",
          "body": "…erify_writes()\n\n1.67.0 let slash()/restore() amend the receipt chain so a legitimate mtype\nrewrite would stop raising a tamper alarm, and had verification bind only the\nlatest receipt. The commit was one hash over text+key+mtype, so \"only the latest\nbinds\" forgave the text as well: edit the stored \n[…]\non exists to catch; dropping that check\nsurvived all 541 tests. Six mutations of the new logic each fail their own test.\n\n546 tests.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "security: a public slash() could launder an out-of-band tamper past v…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-26T12:21:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d6543224cdcec623b33b423eb78f7f3b3003eee",
          "body": "…recent fixes\n\nEight rounds tested functions. This one tested sequences: 2,700 random operations with\neight invariants re-checked after every one. Two findings no unit test had.\n\nreload() RETIRED ANOTHER TENANT'S VALUE. Its LWW keyed on `key` alone, so tenant A's\ncurrent value was superseded because\n[…]\n marker; older certificates still\nverify.\n\nInvariants that HELD across 2,700 ops are recorded in the changelog as a result, not just\nthe failures.\n\n529 passed; 7 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.67.0: what testing SEQUENCES found, and four defects inside my own …",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T23:21:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "597ea5462763238f3f1c761bdc802360c9d2f4cc",
          "body": "All four were reported by an adversarial review and carried as UNVERIFIED. Reproduced each\nfirst; all four hold. Three are inherent to a store with no writer identity and get an\naccurate disclosure plus a test keeping it true; the fourth got code.\n\nONE HOSTILE WRITE BLOCKED EVERY LATER DSAR. A junk \n[…]\nated where it is made.\n\n516 passed; 4 mutations each killed by its own test, after two had to be redone because\nthey replaced a disclosure's opening line while the test asserted a phrase further down.",
          "is_bot": false,
          "headline": "1.66.0: four attacker findings, verified before acting",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T21:31:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59d08b35e033ebcfd8f0fba8c26df183e071471c",
          "body": "… not see it\n\nCaught while verifying 1.65.0 from the published wheel: the run printed `trusted_only: []`\nwhere I expected the true value.\n\n1.65.0 disclosed that supersession is unauthenticated and named trust_seeds +\nrecall(trusted_only=True) as the mitigation. Only half true -- the attacker's write\n[…]\ne this series keeps finding, this time guarding a security claim. It now pins all\nthree facts: the poison is not served, the truth is not served either, and the truth\nsurvives as history.\n\n509 passed.",
          "is_bot": false,
          "headline": "1.65.1: the mitigation I documented was overstated, and my test could…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T20:51:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "10b264cd68efa66714e02721c19c5879766626cb",
          "body": "os.PathLike AND bytes PATHS WERE SILENTLY CORRUPTED. 1.64.0 added expanduser via\nstr(path), and str() repr's an os.PathLike into \"<object at 0x...>\" and bytes into\n\"b'...'\". Path(x) had honoured __fspath__ correctly before, so the fix that made the\ndocumented install paths work broke callers who wer\n[…]\n3 mutations killed by their own tests. A fourth survives and is an EQUIVALENT\nmutant (with no seeds the trusted closure is empty, so both branches return nothing) --\nrecorded rather than papered over.",
          "is_bot": false,
          "headline": "1.65.0: a path regression of mine, and the first attacker-model pass",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T20:46:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c03340147503c1fe5c48975ef61a6fb51d845e09",
          "body": "Six rounds audited the source. This one audited the SHIPPED WHEEL as a new user meets it:\ninstall from PyPI into a clean venv, follow the README verbatim, never look at the\ncheckout. Two findings mean the product forgot everything between sessions on the paths\nits own docs tell you to use, with no e\n[…]\ns version (1.28.1) as inspeximus's; and the LlamaIndex\nadapter failed on `pydantic` before reaching llama_index, so it named the wrong dependency.\n\n500 passed; 6 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.64.0: the documented install path silently lost everything",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T20:27:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25a61e3b0cb38d677dfa16f8b3718b786f732183",
          "body": "…could be forged\n\nTHE ERASURE CERTIFICATE'S SUMMARY WAS FORGEABLE. Found on the first call while writing a\ntest for it: verify_erasure_certificate echoed count, erased_memory_ids and request_ids\nstraight from the certificate and never re-derived them from the tombstones, which ARE\nhash-chained and s\n[…]\nrted 92.5% because a previous\noverlapping run had left three files mutated, so the suite was already red and every\nmutant looked killed. It now refuses to start unless the suite is green.\n\n487 passed.",
          "is_bot": false,
          "headline": "1.63.0: cover the untested surfaces, and a certificate whose summary …",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T18:41:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b19dcff0525e9bb9214cf9a605a690ac1491d167",
          "body": "…ummary must follow from the tombstones\n\nMeasured with coverage at 1.62.0, counting only BODY lines (the def line executes at\nimport, so including it makes every function look covered -- my first measurement said 2%\nuncovered instead of 42%): 132 of 318 public functions had ZERO executed body lines.\n[…]\nNow wired in, plus a new\noptional-adapters job installing crewai and llama-index-core so those skips un-skip\nsomewhere.\n\nZero-body-coverage public functions: 132/318 (42%) -> 56/318 (18%). 487 passed.",
          "is_bot": false,
          "headline": "coverage: drive the crypto/capability and MCP surfaces; certificate s…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T17:42:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24968aefec04591528a341f9600d4d9f54226eb4",
          "body": "…tion run said about the tests\n\nTHE 1.60.0 ERASURE FIX TURNED UNDER-ERASURE INTO OVER-ERASURE. Giving adapter writes a\nsource= made them erasable, and two subjects were not namespaced: a Haystack document\nwhose id was \"user_42\" and a CrewAI store whose default tag is the bare word \"crewai\".\nforget_s\n[…]\na\nSPELLING -- \"CLI and MCP agree on the echo guard\" grepped for the env-var name, which is\nwhy flipping the default survived.\n\n466 passed. The number to carry forward is not that one; it is the 32.8%.",
          "is_bot": false,
          "headline": "1.62.0: three regressions from the last two releases, and what a muta…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T16:48:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d54892c3a3f6cb906fa5537ff3e047973fb8c365",
          "body": "The last of round four's sweep. Each silently granted what it exists to withhold, and its\npresence is what stopped anyone looking.\n\nTHE VALUE SIGNATURE ERASED WHOLE WRITING SYSTEMS. _obj_sig normalised with [^a-z0-9],\nwhich deletes every non-Latin character, so two different CJK values both became t\n[…]\ner alone leaves the tests green --\nthe Unicode regex and the fallback each cover the other, and only reverting both kills\nthem. A single mutation reporting \"no teeth\" is not proof a test is toothless.",
          "is_bot": false,
          "headline": "1.61.0: three controls that failed OPEN",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T16:12:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6036f5c2b2ae5e0353c76899a414474e41c7911",
          "body": "Four rounds hardened core.py. Everything here is one step out from it and shares a shape:\nthe library was correct and the thing the user actually touches was not.\n\nECHO GUARD. cli.py and mcp_server.py are documented as sharing one store, and the guard\nwas ON in the MCP and OFF in the CLI, so one CLI\n[…]\n None on tools sold as Art.17 evidence), and `remember --source`\nexists -- forget-subject's help had pointed at it for a release while it did not.\n\n442 passed; 5 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.60.0: the surfaces, brought in line with the library",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T16:00:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be22ad7441421f8dbd1a61cb606f125c325bde65",
          "body": "…s that signed an untruth\n\nTHE CONCURRENCY GUARD HAD THE SHAPE OF THE BUG IT REPLACED. _file_sig=None meant both\n\"no path\" and \"the file is not there yet\", and _save skipped the guard on None -- so two\nhandles opening a store that does not exist yet (two workers starting together, the\ncommonest conc\n[…]\nsource'); and route() matched a key\ninside a longer word and executed on it -- \"the earlier heart condition\" reverted the key\n`art`, unconfirmed.\n\n433 passed; 10 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.59.0: round four — three regressions from 1.58.0, and three verdict…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T15:31:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7738c63bf05a1873a4002af1e595028386c6539",
          "body": "Every item was reported, reproduced and carried in the handoff as known-and-unfixed for\nthree releases because each needed a change larger than the release it was found in.\n\nCROSS-PROCESS DATA LOSS. One JSON file written whole, read once at open, no lock, no\nre-check -- so a second handle won by wri\n[…]\noogle_adk.forget_subject_for and openai_agents.forget_subject gained allow_ambiguous --\nwithout it a legitimate erasure was unreachable there too.\n\n420 passed; 6 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.58.0: the known-and-unfixed list, cleared",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T14:56:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "afa15c0eedd1d2c5a2d24ac630929d665a1f7146",
          "body": "…oduced\n\nThe pattern held a third time and I was the source of half of it. A fix is new code and\ncarries the same defect rate as any other; the round that audits the fix is not optional.\n\nREGRESSIONS FROM 1.56.0:\n- view.items.append(rec) planted a PHANTOM record. The scoped view was cached as a list\n[…]\npromise cross-session state in their docstrings and both lost it without a word, so a\nrestart reset the lifetime cap the budget exists to enforce.\n\n403 passed; 5 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.57.0: round three — including two regressions the previous fix intr…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T14:35:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec3fb3ef776995c7edae3637cf329809fef6b7da",
          "body": "Two rounds of patching leaks one method at a time kept finding more, because the shape\nwas wrong: self.items was a plain attribute holding every tenant's records and 46 methods\nread it directly, so isolation depended on each of them remembering to filter. 1.55.0\nshipped with that as a stated limitat\n[…]\nis isolates your own workloads on one store, not mutually distrusting\nparties -- the file, receipt chain, anchor and encryption key remain shared.\n\n391 passed; 6 mutations each killed by its own test.",
          "is_bot": false,
          "headline": "1.56.0: tenant isolation, structurally",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T14:01:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a68feffe12ba478196c1e41fb3eb2b5977dd9b43",
          "body": "…class survived\n\nRe-ran the audit on the fixed code. That is the finding; the defects are its evidence.\n\nTENANT: the default-deny allow-list I added in 1.54.0 itself listed apply_retention,\nshred, sleep, grade and erasure_certificate as store-level passthroughs — all iterate the\nwhole store, so a te\n[…]\nur own workloads, not a security boundary between distrusting parties.\n\n379 passed; 7 mutations each killed by its own test, including one that exposed a test\ncovering only half the branch it claimed.",
          "is_bot": false,
          "headline": "1.55.0: round two of the audit — every fix held at the instance, the …",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T13:40:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7df1a136872502396045fcf3063a40800eae84ee",
          "body": "Audited the whole package for the defect CLASS fixed in 1.53.0 rather than the defect.\nEvery finding has the same shape: an instrument reported safe while the guarantee it\nmeasured was broken. All reproduced before fixing; each fix pinned by a mutation-killed\ntest.\n\nTENANT ISOLATION was enforced in \n[…]\nproducible. Marked reported-not-\nreproducible and the promise reworded. Probe paths, claims_audit package name, version\nline, recall() return type and the \"one file\" claim also corrected.\n\n368 passed.",
          "is_bot": false,
          "headline": "1.54.0: what a full codebase audit found",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T13:23:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b82ab65c4e673c7ff5f2a46a948875fea2e63721",
          "body": "…n guard on every destructive path\n\nFound by auditing for the defect class fixed in 1.53.0. All three had that same shape:\nan instrument reported safe while the guarantee was broken.\n\nTENANT ISOLATION. _TenantView rebound 25 of 79 public methods and forwarded the rest to\nthe parent, which runs as te\n[…]\n All subject resolution now goes through _resolve_subject(),\nwhich carries the guard, and a test caps how many sites may inline it.\n\n19 new tests; 7 mutations, each killed by its own test. 354 passed.",
          "is_bot": false,
          "headline": "CRITICAL: tenant isolation, silent persistence loss, and the collisio…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T13:12:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "656699c9524b7cdaefc073efbf849e952b6facd8",
          "body": "…t gains dry_run\n\nThe preview was the intended work. Reviewing it found a data-loss defect in the erasure\npath itself, which is the headline.\n\n_canon_source keeps only the host -- it exists to collapse sybil variants of one\nPUBLISHER into one attribution key, and for that it is right. As an erasure \n[…]\ns a subject\nform -- _rec_sources has never emitted it, so such a call silently erased nothing.\n\n335 passed; four mutations on the collision guard and four on the preview each killed by\ntheir own test.",
          "is_bot": false,
          "headline": "1.53.0: a DSAR for one person no longer erases another; forget_subjec…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T12:44:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8082377d104886e1f102d854d418e234ebc961e",
          "body": "…rd is dropped\n\nTwo internal write sites of the same shape 1.51.0 fixed in revert().\n\nrederive() builds new text out of a demoted record but declared only the corrected root,\nfiling the text parent in meta['rederived_from'] where nothing traverses it. Measured\npre-fix: forget_subject reported erased\n[…]\ninstance of\nknown work -- deletion propagation (Buneman PODS 2002), under-tainting (DTA++ NDSS 2011),\ntaint-propagator lint (Checker Framework, Semgrep) -- credited as such, not a result.\n\n323 passed.",
          "is_bot": false,
          "headline": "1.52.0: rederive declares its text parent; the stale rederived_to gua…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T11:55:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5b6fbbc4387f5d321b30d53e4b1535837110aa5",
          "body": "…ecall\n\nAn adversarial review injected four offending write sites into core.py. The regex guard\ncaught two, was blind to a multi-line call and to a local whose name was not on its\nhard-coded three-name list, and raised a FALSE POSITIVE on the legitimate\n`pid = r['id']; derived_from=[pid]`. Independe\n[…]\nt by being judged safe. The test records that\nforget_subject() has no dry_run, so there is no preview of the widened blast radius.\n\n323 passed. The three code mutations each still kill their own test.",
          "is_bot": false,
          "headline": "guard: replace the regex lineage check with an AST one, and pin its r…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T11:53:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccb3edd6668bfd97ab5cca7e6177f3d0c95e18c9",
          "body": "…in a test\n\nStep 2 -- rederived_to. Of the seven id-bearing fields that survive erasure, exactly\none GATES BEHAVIOUR: meta['rederived_to'] is rederive()'s single-shot guard. Erase the\nrederived copy and the pointer outlived it, freezing the derived record on the value we\nhad just corrected away, wit\n[…]\nrederived_from': ...} -- accepting a parent\nfiled where nothing traverses, the very defect. Bounded to the derived_from list; it now\nfails on both the original bug and the parent-hidden-in-meta shape.",
          "is_bot": false,
          "headline": "forget: drop the stale rederived_to guard; pin the text-parent class …",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T11:31:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa6e58cc5d57f21e77558683c14db0fc06f7b481",
          "body": "rederive() builds its new text out of a demoted record (rewrite(r['text'], old, new))\nbut declared only the corrected root as parent, filing the real text parent in\nmeta['rederived_from'] -- a field no lineage check traverses.\n\nMeasured before the fix: forget_subject on the subject the text came fro\n[…]\nx declares both parents. Two tests: one pins the erasure path (fails under mutation),\none pins that the correction still rederives and stays recallable, so over-tainting\ncannot be mistaken for a pass.",
          "is_bot": false,
          "headline": "rederive: declare the record the new text was rewritten FROM",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T11:14:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfda5ab91a31d387be30134074b11c1f680e2e4f",
          "body": "Third attempt at one problem and the first that is exact. Declared lineage\nmeasured 0.00% across 27,290 real records (1.49.0). Inferring it from content was\nwithdrawn at precision 0.06-0.23 (1.50.0). This does neither: at a write site\ninside the library the store already knows the parent, so it stat\n[…]\n set.\n\n5 new tests including the erasure hole as a regression. 316 passed. No behaviour\nchange to any write a caller makes directly.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.51.0: the store declares lineage where it owns the write",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T10:51:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80f032e6a5400e6f5e90a9495ae55ad7619f2b15",
          "body": "… it fails\n\n1.49.0 shipped four hours ago and oversold this. It reported a FIRING RATE\n(~22% of writes stamped on our own 27,290-record deployment, stable across\nthresholds) and called it calibrated. A firing rate is not an accuracy. The\nrelease notes said there was no ground truth in that corpus, a\n[…]\n43 days while store-computed fields run at\n88-90%. The problem is real. This attempt is not the answer.\n\n311 passed, no regressions.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.50.0: CORRECTION - infer_lineage measured against ground truth, and…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T07:38:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22921a6a1529a17c9ce27b831e76ddd69214f608",
          "body": "…iter\n\nremember(derived=True) already auto-stamps the last recall as a write's parents,\nand that is the right shape: the store carries the edge, the untrusted model\nnever holds the switch. Wrong trigger, though. The flag is writer-set, and\nmeasured on our own 8-agent, 43-day, 27,290-record deploymen\n[…]\nocabulary alone must not earn an edge) and a check that taint rides the inferred\nedge into provenance(). 311 passed, no regressions.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.49.0: infer_lineage - stamp a derivation edge without asking the wr…",
          "author_name": "Rastislav Drahoš",
          "author_login": "DanceNitra",
          "committed_at": "2026-07-25T00:48:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "97eb81f70c9f91bd479c2e763ec7537d1c0efe21",
          "body": "…ys survived\n\nErasing the record is the easy half. The half that bites is the summary built\nfrom it, which no longer resembles the subject's data, so a text-match delete\nwalks past it. erasure_audit(subject=, values=) reports what survived:\nsubject_still_attributable, taint_without_origin, dangling_\n[…]\n() now detects an existing .receipts.json sidecar.\n\n10 new tests. No behavior change to forget, forget_subject or any existing call.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.48.0: erasure_audit() — after a deletion, check what the lineage sa…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T21:41:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "415dd7a380a746c664373dbe6331944af4328bdc",
          "body": "….47.0 claims\n\nThe standing validate/storm/audit/verify gate caught two things before this\nwent out.\n\n1. Regulation (EU) 2026/1744 (Digital Omnibus on AI) was published in the OJ\n   TODAY, 24 Jul 2026, in force 27 Jul. It defers the Annex III high-risk\n   obligations from 2 Aug 2026 to 2 Dec 2027 (A\n[…]\ne only open agent-memory library\"; scoped to the five we read.\n   - fixed provider vs deployer, and the Fake-Picasso citation title.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "gate: correct the EU AI Act dates (Reg. 2026/1744) + scope back the 1…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T21:14:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4576ce66d51c983e2a07845f734a33b908f7b226",
          "body": "The parts already existed (source + derived_from taint, attestation, grade,\nhistory, verify_attribution, anchor) but answering the most-asked question of a\nmemory layer meant calling six of them in the right order. provenance(key=) /\n(id=) assembles them for one fact: origin, trust, timeline, integr\n[…]\new tests; the mixin test also runs in the four CI audit jobs that install a\nreal framework. No behavior change to any existing call.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.47.0: provenance() — one answer to \"where did this fact come from?\"",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T20:46:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f71b6fefbfd3438c56fa749166ace42665a17d31",
          "body": "A safety valve on the one irreversible op. forget(..., dry_run=True) returns\n{would_forget, ids, sample, dry_run:True} — a count + a few matched record texts\nso you can eyeball what a bulk where=/--contains selector caught — and deletes\nNOTHING (no delete, no tombstone, no save). Exposed on the CLI\n\n[…]\nhe docs call a moat: review before you erase.\n2 tests. No behavior change to a normal forget (dry_run defaults False). 276 passed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.46.0: forget(dry_run=True) — preview a bulk delete before committing",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T20:20:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e4d605d892270bcd31ca8bb8dc255108b6b6205d",
          "body": "CI installs only `pytest cryptography` (not the [mcp] extra), so importing\ninspeximus.mcp_server raised ModuleNotFoundError: No module named 'mcp' and\nfailed the run. Guard with pytest.importorskip(\"mcp.server.fastmcp\") (and a\nstandalone fallback). Test-only; the 1.45.0 package is unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "tests: skip the MCP compliance-tools test when the MCP SDK is absent",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T18:10:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9393b6e0c1cd2866333367e7e4cda16fa2287f2a",
          "body": "Five new MCP tools delegating to the free modules — compliance_report,\ncompliance_check, retention, audit_bundle, verify_audit_bundle — so any MCP\nclient (Claude Code, Cursor) can produce and verify its own AI-Act evidence\nin-loop.\n\nNew env INSPEXIMUS_RECEIPTS=1 (opt-in, default off) turns on the ta\n[…]\n sidecar unexpectedly. docs/AI_ACT.md notes the MCP surface.\n2 tests. No behavior change to existing tools. 274 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.45.0: the EU AI Act compliance surface over MCP",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T18:02:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3cbbd725ab5038bf020dfca3ff4281252968b329",
          "body": "…emap\n\nREADME: new \"What you install, and what it does that others don't\" section with\nan honest at-a-glance comparison vs mem0/cognee/Zep-Graphiti (every cell from the\nverified 9-competitor scan) + pointer to the measured integrity table.\n\nai-act.html SEO: trim over-long meta description (~290->155\n[…]\nhe\nstale JSON-LD softwareVersion 1.9.9 -> 1.44.0.\n\nNew: ai-act-og.png (1200x630, 92KB), sitemap.xml (/, /ai-act.html), robots.txt.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "seo+readme: first-screen comparison table, landing social/schema, sit…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T17:56:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7f06e96aaafbd53f769e5d49d575d61ac8efa720",
          "body": "New inspeximus.integrations.governance.ComplianceMixin: an integration store\nthat holds an inspeximus in self.store gains the EU AI Act evidence ops on the\nSAME object the framework uses as memory (pure delegation to the free\ncompliance/audit APIs): compliance_report, write_compliance_report,\ncompli\n[…]\nk's memory now produces auditor-ready AI-Act\nevidence with zero extra wiring. 4 tests (LangGraph skipped when absent). 272 passed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.44.0: compliance-aware framework integrations (LangGraph / CrewAI)",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T16:50:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "57671ea53b7da30f7dbd6207414682e867a97b74",
          "body": "…ion)\n\nThe enforce-side of compliance --check's pii_over_retention flag; closes the\ndetect->enforce loop for GDPR Art.5(1)(e).\n\ncompliance.retention_sweep(store, max_age_days, now_ts=, pii_only=True,\napply=False, basis=, request_id=): finds ACTIVE records older than the window\nand, with apply=True, \n[…]\n-all = every record, default PII-only). Deterministic, no LLM. 4 tests,\ndocs/AI_ACT.md enforcement snippet. 268 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.43.0: retention enforcement — inspeximus retention (storage limitat…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T16:41:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "efe8afa33673dcaa21f5635554f9cf121eabbe1c",
          "body": "Turn the point-in-time compliance overlay into an enforceable CI gate (same\npattern as check-code), for the EU AI Act agent-memory posture.\n\ncompliance.compliance_check(store, require_receipts=, max_pii_age_days=,\nprior_anchor=, now_ts=) -> {ok, violations, checked}:\n- receipts_disabled  (Art.12/19)\n[…]\nxits non-zero on any violation; pre-commit hook\nid: inspeximus-compliance-check. 5 tests, docs/AI_ACT.md gate section. 264 passed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.42.0: continuous compliance gate — inspeximus compliance --check",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T16:24:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "797e66faaded779b529eadf448a6b222e9ed29d3",
          "body": "A \"For auditors & compliance teams\" section pitching the inspeximus-pro\nevidence-pack add-on (org-wide dossier, verifiable with the free CLI, open-core).\nCTA is an honest \"Request the evidence pack\" -> a prefilled GitHub issue (works\ntoday); swap the href to the Polar checkout once it's live. No fake payment link.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "site: add \"For auditors\" inspeximus-pro CTA to the AI Act landing",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T15:16:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cfdb8379fc48af5df612fa29453f3fb667925728",
          "body": "A standalone, self-contained landing for the agent-memory compliance-evidence\npositioning, served on the site at /ai-act.html and linked from the homepage nav\n+ footer. Charter/seal visual identity (the \"inspeximus — we have inspected\"\norigin); competitor-gap table, the three memory duties (AI Act A\n[…]\nASS), the honest boundary, verified primary\nsources. Theme-aware, no external assets. Content mirrors the verified\ndocs/AI_ACT.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "site: add EU AI Act landing page (ai-act.html) + link from homepage",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T14:10:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4e14d3578be03be4689e654f12680ef758be21b1",
          "body": "Position inspeximus as the compliance-EVIDENCE layer for the AGENT-MEMORY slice\nof the EU AI Act (honest scope: memory slice only, evidence not certification,\nobligations bind the deployer not the library).\n\n- README: new hero section pointing at the overlay (inspeximus compliance /\n  audit-build) +\n[…]\ndated OJ texts (Reg (EU) 2024/1689 and 2016/679). Every number in the\ncopy is produced by the runnable overlay, re-run this cycle.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: EU AI Act agent-memory compliance-evidence positioning",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T14:00:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7fd03c6bb362f2e17dc3901218d237f5ff4abb70",
          "body": "The runnable, honest EU-AI-Act-memory-slice overlay: turn a live store into an\narticle-labelled EVIDENCE report with LIVE counts, so the mapping is\ndemonstrable per store, not asserted.\n\nNew inspeximus.compliance:\n- compliance_report(store): per memory-relevant control (AI Act Art.12\n  record-keepin\n[…]\nr Annex III systems, not the whole Act at once).\ntest_compliance.py (6), examples/10_compliance_overlay.py. 259 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.41.0: agent-memory compliance overlay — inspeximus compliance",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T13:03:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6ce013bcfd997036a5ae72c081b8d04338c781f",
          "body": "…offline\n\nThe governance / EU AI Act Art.12 wedge: a portable, content-free record-keeping\nartifact + a standalone verifier that needs neither the live store nor the\nreceipt key.\n\nNew inspeximus.audit_bundle:\n- build_bundle(store, expected_pubkey=, sign=): serialise the store's\n  record-keeping stat\n[…]\nACT, not a\ncompliance certification. test_audit_bundle.py (9), examples/09_audit_bundle.py,\nREADME section. 253 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.40.0: portable audit bundle — hand an auditor one file they verify …",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T12:35:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e97dac9cf2136b413b7b26cfcd229de0a742a9f",
          "body": "…hook\n\nTurn the 1.38.0 coding-agent guard from a library call into an enforceable build\ngate (the distribution wedge):\n\n- code_guard.scan_lines(store, code): per-occurrence view of check_code with\n  1-based line numbers — the CI-grade output shape.\n- inspeximus deprecate <old> <new> [--reason]: reco\n[…]\nreproduces. New tests (scan_lines line numbers, CLI\nexit-code contract), README \"Enforce it in CI\" section. 245 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.39.0: code_guard as a CI gate — inspeximus check-code + pre-commit …",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T12:22:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56a16a124ab133683b0710c6851206424e802094",
          "body": "…I\" wedge\n\nShape keyed supersession for the coding loop, where agent memory most commonly\nfails: a refactor renamed/removed a function but the model re-emits the old call\nbecause the old signature is still in its context.\n\nNew inspeximus.code_guard + three MCP tools:\n- deprecate_symbol(store, old, n\n[…]\ne_guard.py, README \"For coding agents\" section. Serves the\nvendor-abandoned need behind Claude Code #14227. 242 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.38.0: code_guard — the coding-agent \"don't resurrect the deleted AP…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T12:14:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "88aa9ae5b8c88381c17927202114fc3f81d016b9",
          "body": "Turn the 1.36.0 witness pool into a deployable operator-adversarial layer with\nzero new dependencies (stdlib http.server + urllib):\n\n- inspeximus.witness_server: a runnable reference witness\n  (python -m inspeximus.witness_server --port 9700 --state witness.json).\n  GET /pubkey; POST /cosign -> 200 \n[…]\ned head refused with 409 over HTTP), README \"Witness network\" section.\nNo behavior change to existing APIs. 234 passed, 2 skipped.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.37.0: reference witness server — stand up your own witness network",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T12:00:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1a1cf1b58b1531166210e4ab76fcae08f8e068d",
          "body": "…nse)\n\nNew inspeximus.witness_pool turns the 1.34.0 primitives into a runnable gossip\nlayer so a compromised host cannot show two different memory histories to\ndifferent clients:\n  - Witness: an independent co-signer that remembers (persistently, atomic\n    json) the last head it signed per store an\n[…]\n such layer in the field.\nexample 07_witness_pool.py; 7 tests incl persistence + split-view proof; suite\ngreen (233). No new deps.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.36.0: witness pool — k-of-n co-signing made usable (split-view defe…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-24T11:52:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd47db41f3e131b5f5b55b629a5d7e741801756e",
          "body": "…ixes\n\nNew: selection_integrity(query, k) — make selection-level manipulation\nauditable (untrusted writes rerouting which trusted facts reach top-k;\narXiv 2606.12290). Flags, never rewrites; stable=None when blind.\nDocs: docs/COMPLIANCE.md — honest control mapping (NIST 800-53/218A/600-1/88,\nOWASP L\n[…]\nselection_integrity: stable=None (not True) when no trust root.\nMCP tools 46 -> 47. New tests all areas; suite green (226 passed).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.35.0: selection_integrity + compliance mapping + adversarial-gate f…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T22:29:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ba953065fec914c962e4a06f37787619637cdf4",
          "body": "anchor()/verify_consistency catch a rewrite on ONE timeline; a compromised\noperator can still show divergent histories to different clients (split-view).\nThis adds external witness co-signing, k-of-n:\n  - witness_cosign(sk, anchor, prior): witness signs the sth_hash and REFUSES an\n    obvious fork/r\n[…]\nmory, mnemosyne-guard) provide. No new deps. MCP tools 44 -> 46. 13\ntests incl. the split-view scenario; suite green (217 passed).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.34.0: witness co-signing — split-view detection (CT gossip layer)",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T22:14:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30b343fd8ad9bdc6d3badf601071b315b88dcb4a",
          "body": "…the store\n\nDeterministic zero-LLM write-gate: flags candidate writes that are the ASSISTANT\nnarrating its own reasoning/state (\"as an AI...\", \"I think...\", \"I remember\nthat...\") rather than a fact about the user, which an LLM memory-writer commonly\nstores as if it were user truth. Returns {self_nar\n[…]\nhed. Library + MCP tool (44 tools). 8 tests; suite\ngreen (204 passed). Origin-binding gap noted as already covered by attestation.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.33.0: check_self_narration — keep the assistant's self-talk out of …",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T22:07:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ca7d0705e8e8f71500a1667efb0bd90228150ac",
          "body": "The output-side complement to check_conflict: verify_claim(text, key, object)\nchecks a memory-claim an agent is about to ASSERT (\"you told me X\") against\nCURRENT stored truth. Deterministic, read-only, supersession-aware. Verdicts:\nsupported / stale_superseded (reply cites a corrected fact) / contra\n[…]\niator a write-gate or an\nLLM/cosine grounding judge misses. Library + MCP tool (43 tools). 8 tests; full\nsuite green (196 passed).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.32.0: verify_claim — read-time grounding, supersession-aware",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T22:01:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "638b768be4433573688793c3108d09cfc97cc969",
          "body": "…/audit tools)\n\nerasure_certificate / erasure_report / state_digest / history / as_of / verify_attribution /\nirreversible_budget_report / memory_report — all read-only, deterministic. Mutating governance actions\nleft to the library API on purpose. MCP tools 32 -> 42. Verified all eight end-to-end; audits pass.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 1.31.0 — expose the auditor's toolkit over MCP (8 governance…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T15:52:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "22dacb244e10934bee0db9e50543ac17b73a7aa7",
          "body": "…adversarial provenance)\n\nExposes the two provenance primitives that survive an adversarial operator (CT-style signed tree head +\nconsistency proof, RFC 6962) as MCP tools; they existed in the core but were unreachable over MCP.\nCorrects two stale claim strings (revert is rare, not unique — Letta has an engine-level checkpoint-undo).\nAudits pass locally; falsification control fails as required.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: 1.30.0 — anchor() + verify_consistency() over MCP (operator-…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T15:43:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b2dfbe7cce9d731d8694f7b6904758bbc2e4474c",
          "body": "…arial provenance)\n\nThe two primitives that close the one hole verify_writes() cannot — an operator who holds the receipt\nkey can rewrite AND re-sign the whole history so it verifies internally, but cannot make the rewritten\ntip equal a Certificate-Transparency-style anchor an outsider already witne\n[…]\nuditors can\nrun the operator-adversarial check. Verified: anchor->forward-extension consistent=True, tampered tip\ndetected (fork).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "mcp: expose anchor() + verify_consistency() as tools (operator-advers…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T15:39:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b52f2db496dd72fe1a116cc55aad002436c0fcc5",
          "body": "A runnable end-to-end DSAR flow: erase everything about a subject (following derived-from taint so a\nbuilt-from summary goes too) and emit an Ed25519-signed, hash-chained, content-free tombstone per row,\ngrouped by request id. Provable via verify_writes() + governance_report() (erasures_total, by_re\n[…]\n chain head externally for operator-adversarial audit).\n\nVerified: forget 3 / tombstones 3 / verify_writes True / all_signed True.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "examples: signed GDPR/EU-AI-Act erasure receipt (06)",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-23T15:12:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d6ed2c0604545cda9ebd9cd81fc646c0bd1c903a",
          "body": "A core docstring referenced agora_output/lab/memops/keying_recall.py -- an internal path that means\nnothing outside the private repo and should not ship in a public package. Now just \"(measured)\". No\ncode or behaviour change. Found while re-vendoring this core into a public benchmark and grepping it\nfor internal references; the whole package was re-scanned and no other internal path, secret, or\nidentifier leaks.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.29.1: remove an internal repo path leaked in a core docstring",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-22T14:47:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "181b75c1eb4c7f1c4885852a6e761fe104488166",
          "body": "Now that the registry holds more than one version, two latent bugs surfaced:\n- the idempotency check compared only the FIRST listed entry (the oldest) to ours, so the next release\n  would see \"not listed\" and hit the duplicate-version 400 it exists to prevent. It now checks whether\n  our version is \n[…]\nblock reintroduces the indentation break that has bitten this workflow before). server.json\npinned to 1.29.0 to match the release.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "registry automation: handle multiple published versions correctly",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-22T12:42:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f9b4e7d92ebb5c9b3b4cdbd2f46fc8b2e04f8f17",
          "body": "InspeximusDocumentStore implements Haystack's DocumentStore protocol as a drop-in for\nInMemoryDocumentStore: persistent, and its delete removes the value from disk. Duplicate policies\n(SKIP/OVERWRITE/NONE/FAIL) match the reference exactly -- captured empirically from InMemoryDocumentStore\nrather tha\n[…]\ns, no-op delete, reopen, on-disk erasure, and\nto_dict/from_dict. Added to CI. importing inspeximus still does not import haystack.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.29.0: a Haystack DocumentStore, audited against Haystack's own",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-22T12:38:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3fd8ecd185287e1a3d7a54f52eee142f513c3034",
          "body": "urllib requests to registry.modelcontextprotocol.io time out on a GitHub runner and locally, while\ncurl and the Go publisher both succeed, so the check silently fell through to 'assuming not listed'\nand the publish step hit the duplicate-version 400 it was meant to avoid. The caller now fetches with\nthe client that demonstrably works and the script only parses.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fetch the registry state with curl; urllib times out against that host",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T21:01:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a5e896bd08ab650d7fa27f36e5470250f7d69537",
          "body": "The registry rejects a duplicate version with a 400, which is right on its side but meant any re-run\nfailed -- including a re-run of a release that had already succeeded. The job now asks the registry\nwhat it holds and skips publishing when the exact version is already listed, instead of making the\npublish step swallow errors it should not.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "make the registry publish idempotent",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T20:57:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0ad6834d355cbd76a1080ffa3defb50b10289241",
          "body": "The publish succeeded and the listing is live (io.github.DanceNitra/inspeximus 1.28.1, status\nactive), but the verification step checked 15 seconds after publishing and the search index had not\ncaught up, so it failed a release that had actually worked. Polls for up to five minutes now.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "poll for the registry index instead of guessing a sleep",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T20:53:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "512da2127346a1171cf60ebabca70172b8013abc",
          "body": "We were never in the official registry despite already having server.json and the ownership marker in\nthe published PyPI README. The documented route is an interactive device-flow login, which puts a\nhuman in the loop on every release; GitHub Actions OIDC authenticates as the repository owner instea\n[…]\ncy\nblocks the dependent job. \"PyPI is serving this version\" is the real precondition, and the wait step\nenforces it on both paths.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "publish the MCP registry listing from CI via OIDC, not by hand",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T20:48:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80f50631058e761ad6c1c02a10b5fb6a259f4606",
          "body": "Passing receipt_key without receipt_pubkey signed every receipt with \"pubkey\": None, so\nverify_writes() reported \"invalid signature\" on records the store had just written itself. The data\nwas intact; the integrity report was accusing its own output of tampering. For the layer we sell as\nthe reason t\n[…]\nnd edit, so the fix cannot be a rubber stamp.\n\nFound while verifying a claim before writing it into a pull request, not by a test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.28.1: receipts signed with receipt_key alone could never be verified",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T20:44:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82ebb9d5b218bc3acfd753feaba23d955773d913",
          "body": "session_audit.py checks InspeximusSession against the Agents SDK's own SQLiteSession -- seven\nscenarios, three repeats, SESSION_FALSIFY=1 as the control that must fail (it does, 8 mismatches).\nUnlike the ADK adapter this one needed no fixes: 13 checks, full parity.\n\nMCP_LISTINGS.md was telling peopl\n[…]\njson was pinned at 1.24.4 while the released package is 1.28.0, so the listing would have\npointed at a version nobody can install.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "session parity audit; correct three false statements in MCP_LISTINGS.md",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T20:41:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f710e85e80531dfe23da8cf79d4068d94bafdb4",
          "body": "…it caught\n\nADK ships no conformance suite for BaseMemoryService, so \"drop-in replacement for\nInMemoryMemoryService\" was an unchecked claim. adk_audit.py checks it: eight scenarios against their\nservice and ours, three repeats, with ADK_FALSIFY=1 as the control that must fail.\n\nIt caught two real de\n[…]\nhips instead of transforming its\ndistribution name -- that transform turned adk-inspeximus into the non-existent \"adk.inspeximus\".\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.28.0: audit the ADK memory service against ADK's own, and fix what …",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T20:16:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "536264405ddac949e89ceefbf000ef8720515065",
          "body": "…cter behaviour\n\nThe store dropped a namespace once its last key was deleted; InMemoryStore keeps listing it. A\nred-team of the docs PR made the case plainly: a store that claims to work anywhere InMemoryStore\ndoes, and then declares a philosophical exception, gives a reviewer a clean reason to reje\n[…]\nhat ('user','42') is itself an identifier -- offered,\nnot imposed.\n\nCaught before opening the PR rather than in review. 185 tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.27.2: match the reference on namespace lifetime, and offer the stri…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T19:37:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "55c3c19f4b3d058ff666bd04c7c635afafaa73f9",
          "body": "Trusted Publishing was configured for both new PyPI projects, but nothing in CI could use it: the\nrelease workflow builds the repo root only, so the two wrapper distributions were unreachable from\nthe pipeline and would have stayed manual uploads forever.\n\nThey now publish from their own tags (langg\n[…]\n__all__ before publishing, so a\ndistribution that installs but does not re-export what it claims fails the build rather than PyPI.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: publish the LangGraph wrapper packages from their own tags",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T19:32:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4706e884df1241306429ef346ee16d4fafb2b42",
          "body": "Publishes langgraph-checkpoint-inspeximus and langgraph-store-inspeximus, mirroring the shape the\nLangChain docs' own third-party precedent uses (Aerospike ships a checkpointer and a store as two\npackages under the langgraph.* PEP 420 namespace). Both are thin re-exports of\ninspeximus.integrations.l\n[…]\n, get_state_history\nreturns 6 entries, and store.history() returns both values where InMemoryStore would have discarded\nthe first.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.27.1 + the two LangGraph distributions",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T19:08:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a91ce44a82bbec9e9ff05ae128ecfc064d0c502f",
          "body": "…ps the audit never asked about\n\nGroundwork for listing the LangGraph integration. Before publishing anything, both official\nverification routes were run -- and both found real bugs.\n\nLangGraph's docs prescribe two different bars: a conformance suite for checkpointers (\"run it as\npart of your CI bef\n[…]\nked for -- re-checked, still 5/12 vs 3/12, unchanged.\n\nConformance now runs in CI and exits non-zero on a base failure. 175 tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "langgraph: pass the official conformance suite, and fix two parity ga…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T18:57:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9b26baa49170ab23ca6df47c8dcdf58bceb0ade4",
          "body": "Phase 0.1 of the roadmap: the bottleneck was never capability, it was that wiring the thing up took\nreading docs. One command now writes the MCP server block into claude, cursor, windsurf, codex or\ncline, with --dry-run printing the exact diff.\n\nWritten defensively because it edits files it did not \n[…]\nscope. uvx is resolved to an absolute path because GUI-launched editors do\nnot necessarily inherit PATH.\n\n13 new tests, 173 total.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.27.0: `inspeximus install --ide <host>`",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T18:39:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "936bf7cd7645166fdd9973413258dc4b1872101b",
          "body": "Renaming mnemo_mcp.py -> mcp.py in 1.26.0 collided with the `mcp` SDK package, because that file\nstill carried a line inserting its own package directory onto sys.path so it could be run as a\nloose script. Under the old name that was merely untidy. Under the new one it made the module\nimportable as \n[…]\nhe server, but reported \"Failed to connect\". Writing the config and\nassuming it works is exactly what that test exists to prevent.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.26.1: the MCP server shadowed its own SDK and could not start",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T18:33:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "99c4343e95a82c14fe7eeabd824d7421dfa37b96",
          "body": "The rename sweep rewrote the string mnemo.py -> inspeximus.py, but the file is core.py, so the\nzero-dependency check raised FileNotFoundError and the release workflow would have failed on it.\nCaught by running the release gates locally before tagging. Back to 13 passed / 0 FAILED.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: claims_audit pointed at the pre-rename core filename",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T17:45:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "eb312a132415d86e15d169a5d51e2004e325d832",
          "body": "1.25.0 renamed the distribution and kept the old name everywhere it actually mattered - the core\nclass, two modules, an alias package, the env var, the store filename and the encrypted-store\nmagic. The justification was backwards compatibility for an installed base that this project's own\nadoption m\n[…]\ncript, no\nkeyframe, verified by diff.\n\n160 tests, claims and governance audits pass, falsification control still fails as it must.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.26.0: remove the old name from the code, not just the label",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T17:44:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e4959a5b4d249093ec6b6625e030520ee4f71d1",
          "body": "… plugin, CLI strings)\n\nFollows the code rename. Only the product surface moves; the data surface deliberately does not.\n\n- README/docs/site/plugin manifests/pyproject URLs -> inspeximus. The old GitHub Pages URL now\n  404s after the repo rename, so every homepage link in the README was already brok\n[…]\nied: 160 tests, wheel builds as inspeximus-1.25.0 carrying both packages, and a clean venv\ninstalls it with alias identity intact.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "brand: rebrand the product surface to inspeximus (README, docs, site,…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T16:58:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "54a253eca7aae932a93c40dd5529e47ab8546c80",
          "body": "… compat alias\n\nThe plan's own gating decision: 0.1 (`install`) and 0.2 (catalogue listings) bake the name into\ninstall commands and package registries, so the rename has to land before them or be paid for\ntwice. Adoption was measured at no organic signal, so there is no installed base to disrupt.\n\n\n[…]\nn: PyPI Trusted Publishing must be configured for the new\nproject name before any release, and the GitHub repo rename is separate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "rename: mnemo -> inspeximus (code + distribution), with a same-object…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T16:45:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a22d200c482d410cde722149546f4227c1124609",
          "body": "Keyed last-write-wins retired any active same-key record, including one asserting the SAME\nvalue, so a restatement retired the record it agrees with and each key kept exactly one\nactive record however often the value was confirmed.\n\nThat is harmless while only the user's own \"my X is Y\" sentence is \n[…]\n past change reads as a new change, and\nthe echo guard then makes it permanent). The extractor does not ship until that is closed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "supersession: agreement is not correction",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T14:59:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "513befd7de37f6a33e3e0a1cfde50977242445d9",
          "body": "Supersession retires a RECORD, not a VALUE. In prose one corrected value is smeared across a\ndozen sentences and retiring the single keyed row leaves the rest active and retrievable\n(measured on the MemOps corpus: 5.2% of records keyed, 0.33% superseded, `Junior Data Analyst`\nalive in fifteen record\n[…]\nacross the corpus, zero loss of current-value\ncoverage (5/12 before and after). 155 tests pass; MnemoStore parity audit unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "recall: value-level stale suppression (opt-in, zero-LLM)",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T14:30:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "acd44d7ccf48a403f732a1001a07012966afbebb",
          "body": "…version string\n\nThe page claimed \"600-730 s of LLM extraction per scenario\". That came from two numbers I\nhappened to see in the run log; the actual distribution across all 24 scenarios is\n519-917 s, median 606, mean 637. Same conclusion, honest spread — and it is the number a\nreader can check against benchmarks/memops/results.\n\nHeader also still said v1.24.1 while PyPI is at 1.24.4.",
          "is_bot": false,
          "headline": "README: correct the extraction-cost range I had wrong, and the stale …",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T00:54:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bd54965141c45d7c01df63e288698d8741fd251",
          "body": "/plugin marketplace add DanceNitra/mnemo -> /plugin install mnemo@mnemo. Star forensics\novernight said this is the highest-leverage move available to us: claude-mem reached 88k\nstars on installability (four GitHub Trending re-entries tied to version bumps, 2 HN\npoints lifetime, and it is in the COMM\n[…]\neclared command from a clean\nenvironment rather than assuming; it now declares the  extra and answers an MCP\ninitialize handshake.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ship the repo as its own Claude Code plugin marketplace",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-21T00:54:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3742fbef52808be8e74fa4fd2f5f99dd06a7cfd2",
          "body": "…raw results\n\nThe post says 'happy to share the harness, the pre-registration and the raw results'.\nThey lived in a gitignored lab directory, so the honest answer to anyone who asked would\nhave been a 404 — for a piece whose whole argument is measurement discipline, the worst\npossible failure.\n\nThe \n[…]\nhack into a sibling checkout is gone (pip install agora-mnemo).\nThe dataset is not redistributed — it is MemTensor's, MIT, linked.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "benchmarks/memops: publish the harness, the pre-registration and the …",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-20T22:04:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1ce69245215e603d88ea892788dcd151b71ebe3",
          "body": "… release\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "1.24.4: runnable trust-is-not-truth example; first trusted-publishing…",
          "author_name": "agora-builder",
          "author_login": null,
          "committed_at": "2026-07-20T21:51:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 7,
      "commits_last_year": 199,
      "latest_release_at": "2026-07-14T08:21:11Z",
      "latest_release_tag": "v1.5.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 2,
      "days_since_latest_release": 12,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "inspeximus",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "llm",
            "agent",
            "memory",
            "rag",
            "recall",
            "consolidation",
            "mcp",
            "embeddings",
            "second-brain",
            "Intended Audience :: Science/Research",
            "Programming Language :: Python :: 3",
            "Topic :: Scientific/Engineering :: Artificial Intelligence"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/inspeximus/",
          "is_deprecated": false,
          "latest_version": "1.74.0",
          "repository_url": "https://github.com/DanceNitra/inspeximus",
          "versions_count": 56,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 4835,
          "first_published_at": "2026-07-21T17:00:35.247365Z",
          "latest_published_at": "2026-07-26T17:05:55.950494Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 5,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "site/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 504709,
      "source_files_sampled": 257,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml",
        "site/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "gsap",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.12.5"
        },
        {
          "name": "lenis",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.14"
        },
        {
          "name": "three",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.169.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "DanceNitra",
          "commits": 47,
          "avatar_url": "https://avatars.githubusercontent.com/u/41733909?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "audit.yml",
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a39ad1682e1d3d2d634bbd3a68252d3beb6bc8d1",
        "ran_at": "2026-07-26T17:06:44Z",
        "aggregate_score": 3.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T17:05:36Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 1,
          "created_at": "2026-07-15T13:18:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/DanceNitra/inspeximus",
    "host": "github.com",
    "name": "inspeximus",
    "owner": "DanceNitra"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 52,
      "inputs": {
        "security": 36,
        "vitality": 73,
        "community": 37,
        "governance": 36,
        "engineering": 76
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 73,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "commits_last_year": 199,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 2
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "2/52 weeks with commits",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "199 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 199
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 7,
              "latest_release_tag": "v1.5.0",
              "releases_from_tags": false,
              "days_since_latest_release": 12,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "7 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 12 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 37,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 0,
              "stars": 5,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "inspeximus"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 4835
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,835 downloads/month across pypi",
                "points": 49.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4835,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 36,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "followers": 5,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "DanceNitra",
              "public_repos": 43,
              "account_age_days": 2922
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of DanceNitra",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "DanceNitra"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "43 public repos, account ~8 yr old",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 43
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 8
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "inspeximus"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "56 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 56
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 76,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "agent-memory",
                "llm",
                "mcp",
                "mcp-server",
                "model-context-protocol",
                "rag",
                "ai-memory",
                "eu-ai-act",
                "gdpr",
                "llm-memory",
                "long-term-memory",
                "mem0-alternative",
                "zero-dependency",
                "self-correcting-memory"
              ],
              "has_wiki": true,
              "homepage": "https://dancenitra.github.io/inspeximus/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://dancenitra.github.io/inspeximus/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "14 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 36,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 36,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 54,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "site/tsconfig.json"
              ],
              "agent_commit_share": 0.77,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "site/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "site/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "77 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 77,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 504709,
              "source_files_sampled": 257,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (site/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "site/tsconfig.json",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/257 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 257,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index pypi:inspeximus@1.74.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T17:06:50.419253Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/DanceNitra/inspeximus.svg",
  "full_name": "DanceNitra/inspeximus",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasPyPI.