Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-25 12:18 UTC

EffortlessMetrics / cargo-allow

Repo Allowlist for Rust

RustApache-2.0★ 0 estrellas⑂ 2 forksdesde may 2026Ver en GitHub ↗

EffortlessMetrics/cargo-allow tiene un índice de salud de 62 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es AI Readiness (80/100) y la más baja, Community & Adoption (50/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

62
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

62
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

EffortlessMetricsOrganización
7 seguidores75 repositorios públicosdesde mar 2024

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
crates.ioallow-core0.1.11202112hace 7 díasauditgovernancepolicyrustscannerdevelopment-tools
crates.ioallow-diff0.1.11188512hace 7 díasauditgovernancepolicyrustscannerdevelopment-tools
crates.ioallow-rust0.1.11190112hace 7 díasauditgovernancepolicyrustscannerdevelopment-tools
crates.ioallow-files0.1.11189912hace 7 díasauditgovernancepolicyrustscannerdevelopment-tools
crates.ioallow-match0.1.11189012hace 7 díasauditgovernancepolicyrustscannerdevelopment-tools
crates.iocargo-allow0.1.11186912hace 7 díasauditgovernancepolicyrustscannercommand-line-utilitiesdevelopment-tools

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

76Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
6.2/36Cadencia de commits — 9/52 semanas con commits
18/18Volumen de commits — 2295 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year2295
human_commit_share0,87
days_since_last_push0
active_weeks_last_year9
Cómo se puntúa
27/27Publica versiones — 5 versiones publicadas
36/36Recencia de las versiones — última versión hace 7 días
27/27Cadencia de publicación — una versión cada ~8,8 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count5
latest_release_tagv0.1.11
releases_from_tagsno
days_since_latest_release7
mean_days_between_releases8,8
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

50Moderado · 18% del índice global
Cómo se puntúa
0/60Estrellas — 0 estrellas
0/25Forks — 2 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks2
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template
Cómo se puntúa
54.1/80Descargas mensuales — 11.465 descargas/mes en crates
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesallow-core, allow-diff, allow-rust, allow-files, allow-match, cargo-allow
dependents
ecosystemscrates
total_downloads34.397
monthly_downloads11.465
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

53Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
19.2/46.8Resolución de issues — 41% de issues cerradas
37.5/38.3Aceptación de PR — 2077/2116 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/12 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs2077
open_issues405
closed_issues281
issue_closed_ratio0,41
closed_unmerged_prs39
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
6.5/25Alcance del propietario — 7 seguidores de EffortlessMetrics
17.7/25Trayectoria — 75 repos públicos, cuenta de ~2 años
Datos de entrada utilizados
followers7
owner_typeOrganization
is_verified
owner_loginEffortlessMetrics
public_repos75
account_age_days852
Cómo se puntúa
25/25Publicado y resoluble — 6 paquete(s) en crates
35/35Recencia de publicación — última publicación hace 7 días
20/20Historial de versiones — 12 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesallow-core, allow-diff, allow-rust, allow-files, allow-match, cargo-allow
ecosystemscrates
any_deprecatedno
min_days_since_publish7

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

74Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 3 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfig
has_linter_configno
has_precommit_configno
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

56Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/12 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,6
Excluidos de la puntuación (sin datos o no aplicable): signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

80Bueno · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — AGENTS.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 87 de 87 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes5031
Cómo se puntúa
18/18Arranque con un solo comando — justfile
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — Rust (tipado estático)
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 48 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 13 de los últimos 100 commits son actualizaciones automáticas de dependencias
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Datos de entrada utilizados
has_nixno
has_tests
lockfilesCargo.lock
has_dockerfileno
typed_language
bootstrap_filesjustfile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0,48
toolchain_manifestsCargo.toml, crates/allow-core/Cargo.toml, crates/allow-diff/Cargo.toml, crates/allow-files/Cargo.toml, crates/allow-inventory/Cargo.toml, crates/allow-match/Cargo.toml, crates/allow-policy-legacy/Cargo.toml, crates/allow-policy/Cargo.toml, crates/allow-report/Cargo.toml, crates/allow-rust/Cargo.toml, crates/cargo-allow/Cargo.toml, crates/cargo-intent/Cargo.toml, crates/cargo-proof/Cargo.toml, crates/intent-edit/Cargo.toml, crates/intent-engine/Cargo.toml, crates/intent-model/Cargo.toml, crates/intent-protocol/Cargo.toml, crates/proof-adapter-cargo-allow/Cargo.toml, crates/proof-adapter-command/Cargo.toml, crates/proof-adapter-hawk/Cargo.toml, crates/proof-adapter-ripr/Cargo.toml, crates/proof-engine/Cargo.toml, crates/proof-protocol/Cargo.toml, crates/proof-provider-api/Cargo.toml, crates/repo-edit/Cargo.toml, crates/repo-protocol/Cargo.toml, crates/repo-snapshot/Cargo.toml, crates/rust-source-index/Cargo.toml
dependency_bot_commit_share0,13
Cómo se puntúa
45/45Código verificable por tipos — Rust (tipado estático)
54.8/55Tamaños de archivo manejables — 4/1010 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageRust
largest_source_bytes229.120
source_files_sampled1010
oversized_source_files4
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
0/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signalno
api_schema_files

Datos clave

0estrellas de GitHub
1contribuidores
2295commits en los últimos 12 meses
0días desde el último push
5versiones publicadas
1factor bus
405issues abiertas
crates.ioecosistemas de paquetes

Advertencias de recopilación de datos

  • Could not fetch crates package 'cargo-proof' from its registry
  • Could not fetch crates package 'intent-edit' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 5.6 / 10
5.6agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-25 12:18 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/12 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Dependencias directas 89
RegistroPaqueteRestricción de versiónManifiesto
crates.iosha2crates/allow-core/Cargo.toml
crates.ioallow-corecrates/allow-diff/Cargo.toml
crates.ioallow-filescrates/allow-diff/Cargo.toml
crates.ioallow-policy-legacycrates/allow-diff/Cargo.toml
crates.ioallow-policycrates/allow-diff/Cargo.toml
crates.ioallow-rustcrates/allow-diff/Cargo.toml
crates.iosha2crates/allow-diff/Cargo.toml
crates.ioallow-corecrates/allow-files/Cargo.toml
crates.ioallow-corecrates/allow-inventory/Cargo.toml
crates.ioallow-corecrates/allow-match/Cargo.toml
crates.ioallow-corecrates/allow-policy-legacy/Cargo.toml
crates.ioallow-policycrates/allow-policy-legacy/Cargo.toml
crates.iotomlcrates/allow-policy-legacy/Cargo.toml
crates.ioallow-corecrates/allow-policy/Cargo.toml
crates.ioserdecrates/allow-policy/Cargo.toml
crates.iotomlcrates/allow-policy/Cargo.toml
crates.ioallow-corecrates/allow-report/Cargo.toml
crates.ioallow-policy-legacycrates/allow-report/Cargo.toml
crates.ioserdecrates/allow-report/Cargo.toml
crates.ioserde_jsoncrates/allow-report/Cargo.toml
crates.ioallow-corecrates/allow-rust/Cargo.toml
crates.iotomlcrates/allow-rust/Cargo.toml
crates.iotree-sittercrates/allow-rust/Cargo.toml
crates.iotree-sitter-rustcrates/allow-rust/Cargo.toml
crates.ioallow-corecrates/cargo-allow/Cargo.toml
crates.ioallow-policycrates/cargo-allow/Cargo.toml
crates.ioallow-inventorycrates/cargo-allow/Cargo.toml
crates.ioallow-filescrates/cargo-allow/Cargo.toml
crates.ioallow-rustcrates/cargo-allow/Cargo.toml
crates.ioallow-matchcrates/cargo-allow/Cargo.toml
crates.ioallow-reportcrates/cargo-allow/Cargo.toml
crates.ioallow-diffcrates/cargo-allow/Cargo.toml
crates.ioallow-policy-legacycrates/cargo-allow/Cargo.toml
crates.iorepo-protocolcrates/cargo-allow/Cargo.toml
crates.iorepo-editcrates/cargo-allow/Cargo.toml
crates.ioclapcrates/cargo-allow/Cargo.toml
crates.iotomlcrates/cargo-allow/Cargo.toml
crates.ioserdecrates/cargo-allow/Cargo.toml
crates.ioserde_jsoncrates/cargo-allow/Cargo.toml
crates.ioclapcrates/cargo-intent/Cargo.toml
crates.iointent-enginecrates/cargo-intent/Cargo.toml
crates.iointent-protocolcrates/cargo-intent/Cargo.toml
crates.iorepo-protocolcrates/cargo-intent/Cargo.toml
crates.iorepo-snapshotcrates/cargo-intent/Cargo.toml
crates.ioserdecrates/cargo-intent/Cargo.toml
crates.ioserde_jsoncrates/cargo-intent/Cargo.toml
crates.iotomlcrates/cargo-intent/Cargo.toml
crates.ioclapcrates/cargo-proof/Cargo.toml
crates.ioproof-enginecrates/cargo-proof/Cargo.toml
crates.ioproof-protocolcrates/cargo-proof/Cargo.toml
crates.ioproof-provider-apicrates/cargo-proof/Cargo.toml
crates.ioserdecrates/cargo-proof/Cargo.toml
crates.ioserde_jsoncrates/cargo-proof/Cargo.toml
crates.iotomlcrates/cargo-proof/Cargo.toml
crates.iorepo-editcrates/intent-edit/Cargo.toml
crates.iorepo-protocolcrates/intent-edit/Cargo.toml
crates.ioserdecrates/intent-edit/Cargo.toml
crates.iotomlcrates/intent-edit/Cargo.toml
crates.ioserdecrates/intent-engine/Cargo.toml
crates.ioserde_jsoncrates/intent-engine/Cargo.toml
crates.iotomlcrates/intent-engine/Cargo.toml
crates.ioallow-corecrates/intent-model/Cargo.toml
crates.ioserdecrates/intent-model/Cargo.toml
crates.iotomlcrates/intent-model/Cargo.toml
crates.ioserdecrates/intent-protocol/Cargo.toml
crates.ioserde_jsoncrates/intent-protocol/Cargo.toml
crates.iotomlcrates/intent-protocol/Cargo.toml
crates.ioproof-adapter-commandcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-cargo-allow/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioserdecrates/proof-adapter-cargo-allow/Cargo.toml
crates.iosha2crates/proof-adapter-cargo-allow/Cargo.toml
crates.iotomlcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-command/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-command/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-command/Cargo.toml
crates.ioserdecrates/proof-adapter-command/Cargo.toml
crates.iotomlcrates/proof-adapter-command/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-hawk/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-hawk/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-hawk/Cargo.toml
crates.ioserdecrates/proof-adapter-hawk/Cargo.toml
crates.iotomlcrates/proof-adapter-hawk/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-ripr/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-ripr/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-ripr/Cargo.toml
crates.ioserdecrates/proof-adapter-ripr/Cargo.toml
crates.iotomlcrates/proof-adapter-ripr/Cargo.toml
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 7498,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Just": 1122,
        "Rust": 6577477,
        "Shell": 189890,
        "Python": 12830
      },
      "pushed_at": "2026-07-25T11:55:46Z",
      "created_at": "2026-05-26T00:18:24Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-25T11:39:35Z",
      "description": "Repo Allowlist for Rust",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "effortlesssteven.com",
      "name": "EffortlessMetrics",
      "type": "Organization",
      "login": "EffortlessMetrics",
      "company": null,
      "location": "Canada",
      "followers": 7,
      "avatar_url": "https://avatars.githubusercontent.com/u/164865351?v=4",
      "created_at": "2024-03-25T09:34:01Z",
      "is_verified": null,
      "public_repos": 75,
      "account_age_days": 852
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.11",
          "kind": "patch",
          "published_at": "2026-07-18T00:52:46Z"
        },
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-07-09T00:19:59Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-06-16T04:04:39Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-06-12T21:40:24Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-06-12T20:35:17Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3366897b078191bee344d03af2d27bf635e322fd",
          "body": "…#2804)\n\n* fix(scanner): surface tree-sitter parse errors in scan completeness\n\nTrack files_with_parse_errors in RustScanResult and fail closed in check --mode no-new when partial parses are present, matching the files_skipped precedent (#2658).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* st\n[…]\n only; stderr warnings break the quiet artifact-output contract in audit integration tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(scanner): surface tree-sitter parse errors in scan completeness (…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T11:39:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "886e268f6f5e140cd816f4ffd8c1f79ebb17591e",
          "body": "* deps: bump fs4 from 0.13.1 to 1.1.0\n\nBumps [fs4](https://github.com/al8n/fs4) from 0.13.1 to 1.1.0.\n- [Release notes](https://github.com/al8n/fs4/releases)\n- [Changelog](https://github.com/al8n/fs4/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/al8n/fs4/commits/1.1.0)\n\n---\nupdated-dependen\n[…]\nbot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Steven Zimmerman, CPA <15812269+EffortlessSteven@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump fs4 from 0.13.1 to 1.1.0 (#2769)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T11:36:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d820b2414f4fb37548cd9b2c61403e3e80ac99d",
          "body": "* feat(migrate): add bespoke-ledger importer adapter (xtask/ripr)\n\nIntroduce a read-only xtask-ripr bespoke ledger dialect importer and wire\nmigrate --from to detect dialect=xtask-ripr before legacy dispatch.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* style: apply rustfmt for bespoke importer lane\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(migrate): bespoke-ledger importer adapter (xtask/ripr) (#2803)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T10:51:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2ac2b669d5a2e4efd7d38bdcab2ffc8da9494eb6",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v5...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/checkout from 5 to 7 (#2767)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:37:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "780d6a0bdbe6b1b64a6c8ea508640f69fe71a9d4",
          "body": "Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 96b4a1ef7235a096b17240c259729fdd70c83d45 to e8998f949152b193b063cb0ec769d69d929409be.\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://github.com/actio\n[…]\n63cb0ec769d69d929409be\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/attest-build-provenance (#2766)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:34:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fea3c82cac4015c1713db7d785194b36f73f2726",
          "body": "Bumps [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) from 42dc69e1aa15d09112580998cf2ef0119e2e91ae to e18b497796c12c097a38f9edb9d0641fb99eee32.\n- [Release notes](https://github.com/swatinem/rust-cache/releases)\n- [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG\n[…]\n38f9edb9d0641fb99eee32\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump Swatinem/rust-cache (#2765)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:30:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7032bd0f0b690ce956077a6273ce04ca62da6ca2",
          "body": "Bumps [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) from c3bbe7e4e3f7baeee1a3dd9aec0a3b2aded580fb to 3c6349835b2b7b196a839186cb8b78e02f7b5f25.\n- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)\n- [Commits](https://github.com/embarks\n[…]\n839186cb8b78e02f7b5f25\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump EmbarkStudios/cargo-deny-action (#2764)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:25:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fdb165f56a8ba40ff27de95c741f3b6ea791183d",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 4650159d642e33fdc30954ca22638caf0df6cac8 to 18283e04ce6e62d37312384ff67231eb8fd56d24.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main\n[…]\n12384ff67231eb8fd56d24\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump codecov/codecov-action (#2763)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:20:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c885ff732e2749027cd2b9dd8543b35307786892",
          "body": "Bumps [EffortlessMetrics/ub-review](https://github.com/effortlessmetrics/ub-review) from f0620c358f4a9032d3f832fda92488fd198ab6e9 to a1e64c65e39aadf341f4e5cb14094b9a87f592ad.\n- [Release notes](https://github.com/effortlessmetrics/ub-review/releases)\n- [Changelog](https://github.com/EffortlessMetrics\n[…]\nf4e5cb14094b9a87f592ad\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump EffortlessMetrics/ub-review (#2762)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:12:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2106a2232cc7f7be062003784eb438d9c7b86a2",
          "body": "Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.25.10 to 0.26.11.\n- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)\n- [Commits](https://github.com/tree-sitter/tree-sitter/compare/v0.25.10...v0.26.11)\n\n---\nupdated-dependencies:\n- dependency-name: tree-sitte\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump tree-sitter from 0.25.10 to 0.26.11 (#2770)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:08:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c18f384b48da5f22af8f8f86c77dc7def0d9620d",
          "body": "…-test\n\ntest: add tool command integration test (#2795)",
          "is_bot": false,
          "headline": "Merge pull request #2798 from EffortlessMetrics/test/tool-integration…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T08:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0d582eeacb52991c49044b7a5242bbc8399d687",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T08:41:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b6f60b9c12f9531f3ebd6d5194a91b0b8304681",
          "body": null,
          "is_bot": false,
          "headline": "test: restore Command import in tool_output",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T08:29:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8890d7f0a5a0b07b2dc93f318ef98c47a2ea521",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T08:23:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07888aded693d59d4e46c2b01cc7d1e61e8f039e",
          "body": "Bumps the patch-updates group with 4 updates in the / directory: [serde](https://github.com/serde-rs/serde), [serde_json](https://github.com/serde-rs/json), [toml](https://github.com/toml-rs/toml) and [clap](https://github.com/clap-rs/clap).\n\n\nUpdates `serde` from 1.0.228 to 1.0.229\n- [Release notes\n[…]\nncy-version: 1.1.3+spec-1.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: patch-updates\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump the patch-updates group across 1 directory with 4 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T08:23:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1832bc3992190340d338971765ec61bdb9c94ae",
          "body": "Avoid compiling the shared support module in the tool_output integration test crate, which triggered clippy dead-code failures under -D warnings.",
          "is_bot": false,
          "headline": "test: inline cargo_allow_command helper in tool_output",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T08:14:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2279331382d7e67839fd33a64cfb50a73660d00",
          "body": "The `tool` subcommand had zero binary-level integration coverage despite\nhaving 10 unit tests. Its identity, digest, and capability-generation\noutput is security-relevant (used by pre-commit verification).\n\nAdd crates/cargo-allow/tests/tool_output.rs with two integration tests:\n- tool_identity_json_\n[…]\ns\n  cargo-allow and the schema_id\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2659 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "test: add tool command integration test (#2795)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T07:57:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63829a7e77a666d7cc5723146c53c695bdb96799",
          "body": "…-0.11.0\n\ndeps: bump sha2 from 0.10.9 to 0.11.0",
          "is_bot": false,
          "headline": "Merge pull request #2771 from EffortlessMetrics/dependabot/cargo/sha2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T07:48:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f003984049f4e2e876de045edae1f4c35f5d2e4",
          "body": "…h-updates-2b5d80e5f5\n\ndeps: bump the patch-updates group across 1 directory with 4 updates",
          "is_bot": false,
          "headline": "Merge pull request #2768 from EffortlessMetrics/dependabot/cargo/patc…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T07:30:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80ead5a1beb02a6f7671233e924018eea49441d7",
          "body": "… output (#2785) (#2793)\n\ncargo-allow prints a 600+ char claim boundary on every human-format run\nwith no way to suppress it short of --format json. CI logs are polluted.\n\nAdd a global --quiet/-q flag that:\n- Suppresses CLAIM_BOUNDARY_TEXT in check/audit human output\n- Suppresses CLAIM_BOUNDARY_TEXT\n[…]\n through every command signature.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2657 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "feat(ux): add --quiet/-q flag to suppress claim boundary and advisory…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T05:28:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad86d12c72a36bd03c1b474aca56aebeb79c65d2",
          "body": "Bumps the patch-updates group with 4 updates in the / directory: [serde](https://github.com/serde-rs/serde), [serde_json](https://github.com/serde-rs/json), [toml](https://github.com/toml-rs/toml) and [clap](https://github.com/clap-rs/clap).\n\n\nUpdates `serde` from 1.0.228 to 1.0.229\n- [Release notes\n[…]\nncy-version: 1.1.3+spec-1.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: patch-updates\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump the patch-updates group across 1 directory with 4 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T05:24:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "104c0e850300230239dd4345ebeff1a756994d1d",
          "body": "…(#2792)\n\ncargo-allow shipped with Cargo default release profile (no LTO, no strip,\nopt-level=3, full debug paths). For a CPU-bound CLI tool this left\nmeasurable binary size and runtime performance on the floor.\n\nAdd:\n- lto = 'thin' — cross-crate inlining without fat-LTO build cost\n- strip = true — \n[…]\nry\n- codegen-units = 1 — better optimization at cost of slower compile\n\nThese settings apply to all workspace binaries (cargo-allow, cargo-intent,\ncargo-proof).\n\nBuild-only change; no production code.",
          "is_bot": false,
          "headline": "perf: add [profile.release] with LTO, strip, codegen-units=1 (#2789) …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T05:21:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ab820bed5c4cd55324f709a847ae88f3f59cc17",
          "body": "…rectly (#2777, #2778) (#2783)\n\nTwo init.rs bugs:\n\n#2777: The non-force path used exists() + AtomicReplace, leaving a TOCTOU\nwindow between the existence check and the unconditional rename. An external\nprocess that creates the file in the window would be silently overwritten\nwithout --force. Fixed b\n[…]\nnd using the correct action word.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2656 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(init): use CreateNewOnly for non-force path; report overwrite cor…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T04:31:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5280a9a7bf8bf11860de65ea78071f249841a11d",
          "body": "…ctions (#2776) (#2782)\n\nThe wildcard branch of source_tree_path_matches_filter checked\nsource_tree_scope_has_wildcard(&item_path) — the file being filtered.\nReal file paths never contain wildcards, so the branch was dead code.\nA glob pattern in the filter_path (e.g. --path 'src/**/*.rs') never\nmatc\n[…]\no fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (616 pass + 1 pre-existing flaky Windows\ntemp-dir doctor test); cargo-allow check --mode no-new (status: passed).",
          "is_bot": false,
          "headline": "fix(core): source_tree_path_matches_filter supports glob in both dire…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T04:24:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c54ab10ac31463199ca0476d818666458e327524",
          "body": "* docs: add SECURITY.md for vulnerability reporting (#1884)\n\ncargo-allow is a supply-chain governance tool with no SECURITY.md —\nexternal users and security researchers had no private reporting path.\n\nAdd SECURITY.md with:\n- Private reporting via email and GitHub Security Advisories\n- Response timel\n[…]\nitives, upstream dependency CVEs)\n- Hardening measures inventory (cargo-deny, Dependabot, SHA-pinned\n  actions, OIDC Trusted Publishing, keyless attestation, Windows CI)\n\n* policy: receipt SECURITY.md",
          "is_bot": false,
          "headline": "docs: add SECURITY.md for vulnerability reporting (#1884) (#2775)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T03:17:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1634f535d3a2c82adf3c713a2ca2a9de7ce199fd",
          "body": "…1949) (#2774)\n\nThe issue reported that evidence references to directory targets were\ntreated as valid. Investigation found the bug was already fixed: the\nevidence_reference_diagnostic function catches directories at the\nmetadata level (Ok(_) => InvalidLocalPath 'exists but is not a file')\nbefore th\n[…]\nactor\ncannot silently regress it.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2656 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "test(evidence): pin directory-target rejection as InvalidLocalPath (#…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T02:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92c5c71f4098d3b2ce2bfe428dd1c73c65f24f83",
          "body": "…773)\n\nThe legacy unsafe-allowlist parser captured scope, justification, and\naudit_url fields but the converter silently dropped them because the\nLegacyUnsafeRule type had no fields for them and the converter had no\npreservation path. Compliance reviews lost provenance on migration.\n\nAdd scope, just\n[…]\non: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (615 pass + 1 pre-existing flaky init\ntest on Windows); cargo-allow check --mode no-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): preserve unsafe provenance fields via links (#1865) (#2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T00:17:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53cb843b6ddf7629824ccc503d38ac52e41f2bcd",
          "body": "…1870) (#2772)\n\nnormalize_legacy_expires only mapped 'permanent' → 'never'. Legacy\nledgers using RFC3339 timestamps with timezones (2025-12-01T00:00:00Z vs\n2025-12-01T00:00:00-05:00) produced non-deterministic, non-comparable\nLifecycle values — breaking reproducible-migration guarantees.\n\nAdd canoni\n[…]\n plus the plain-date passthrough.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2654 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): canonicalize legacy expires timestamps to YYYY-MM-DD (#…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T00:10:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cff1f439aafb0fb817c381526396181c68169e2",
          "body": "Remove RTK from the live agent contract and reusable PR and plan templates. Keep historical evidence and runtime compatibility behavior unchanged.",
          "is_bot": false,
          "headline": "chore: remove RTK command wrapper guidance (#2761)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T23:27:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9bc1d519eb6ae5be164b6139fe19e6cfdce2cd3",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T23:00:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2dc7c28d60351cec88e2a02097753ad2f091a8ff",
          "body": "* ci: add Dependabot for Rust deps and GitHub Actions (#1898)\n\ncargo-allow had no automated dependency update path. Combined with the\ncargo-deny supply-chain audit (#1897), Dependabot ensures advisories are\nboth caught (deny) and patched (Dependabot PRs).\n\nConfiguration:\n- cargo ecosystem: weekly, M\n[…]\nen PRs max, patch updates grouped\n- github-actions ecosystem: weekly, Monday, 5 open PRs max\n\nCI-only; no production code changes.\n\n* policy: receipt .github/dependabot.yml\n\n* chore: trigger CI re-run",
          "is_bot": false,
          "headline": "ci: add Dependabot for Rust deps and GitHub Actions (#1898) (#2758)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T22:58:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66ebd703a631a84292815e8da934c895d710a409",
          "body": "cargo-allow had no test coverage reporting and no automated way to track\ncoverage regressions. As a governance tool, coverage visibility matters.\n\nAdd a coverage job to ci.yml that runs cargo-tarpaulin on the full\nworkspace and uploads the Cobertura XML to Codecov. The job is separate\nfrom the main test job so tarpaulin's instrumentation overhead doesn't\nslow down PR feedback. fail_ci_if_error: false so coverage upload\nfailures don't block merges.\n\nCI-only; no production code changes.",
          "is_bot": false,
          "headline": "ci: add cargo-tarpaulin coverage reporting to Codecov (#1902) (#2760)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T22:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70abd9d51f34222152ae7af26426f18ae74e75d5",
          "body": "The release install-smoke job ran on ubuntu-latest only, so the published\nbinary was never tested on Windows — the repo's primary dev OS. A Windows\nbinary could ship broken without any CI signal.\n\nMatrix the install-smoke job across ubuntu-latest and windows-latest with\nfail-fast: false. Added expli\n[…]\nds the OS.\n\nThe smoke script (scripts/release-install-smoke.sh) already uses bash and\ncargo install, which work on Windows via Git Bash. No script changes needed.\n\nCI-only; no production code changes.",
          "is_bot": false,
          "headline": "ci: matrix release install-smoke across ubuntu+windows (#1904) (#2759)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T22:26:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfb47b5f1247680dfec0ee9e8ee5b47b1859d6f6",
          "body": "Enable repo-wide delegate_spec_system cutover, replace CI embedded audit with cutover receipt, and document honest fail-closed posture until cargo-intent audit vertical ships.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2568): retire embedded spec-system CI audit path (#2757)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T20:50:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dac02808a09a61e80b76aa8a15db7f286d4a0445",
          "body": "Wave 6 closeout: validate packaging, boundaries, support postures, forbidden production deps, dogfood/simplification prerequisites, and rollback documentation without authorizing physical repository extraction.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2559): add extraction readiness checklist receipt (#2756)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T20:32:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b287fabba89946dbda97319d2d2e6392e7589776",
          "body": "* feat(#2208): add simplification inventory and remove io shim\n\nClassify extraction abstractions with mandatory labels, fold cargo-allow io helpers into command_support, and add audit script plus closeout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2208): update move ledger after io sh\n[…]\n: Cursor <cursoragent@cursor.com>\n\n* fix(#2208): move re-exports before io_tests for clippy\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2208): add simplification inventory and remove io shim (#2755)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T20:22:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65df48a2c6080eb34ea4a1b8090e959597ade616",
          "body": "* feat(#2558): add three-product dogfood pipeline smoke\n\nRun one real source change through cargo-intent, bridged proof planning, stubbed RIPR/Hawk evidence, gates, and reconciliation with honest claim boundary; wire CI and closeout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2558): re\n[…]\nCursor <cursoragent@cursor.com>\n\n* fix(#2558): align stub fixture needles with parity files\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2558): add three-product dogfood pipeline smoke (#2754)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T19:55:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "505502bdd0b1c13bfc40bb107a6d3dcd6749079f",
          "body": "* feat(#2605): add exact-candidate interop smoke A-E\n\nRun packaged three-product interop journeys outside the monorepo with installed candidate binaries, negative scenario controls, CI wiring, and offline receipt characterization.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2605): corre\n[…]\ncursoragent@cursor.com>\n\n* fix(#2605): accept findings exit from cargo-intent change status\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2605): add exact-candidate interop smoke A-E (#2753)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T18:59:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c49efeaed59d6812eec55d11e59191be475c3ee",
          "body": "Introduce proof.hawk.v1 provider with analysis receipt validation, finding mapping, source-anchor resolution, and receipt currentness so Hawk liveness stays provider-owned while cargo-proof consumes snapshots.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2555): add proof-adapter-hawk analysis adapter (#2752)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T17:59:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3fd7fb3b2b9ecdf619ad7bed3726adf7092ebc91",
          "body": "Land RiprGripReceiptV1 validation, receipt currentness, requirement-grip comparison, and ProofProviderV1 wiring without RIPR or intent crate imports. Authored evidence purpose remains cargo-intent owned.",
          "is_bot": false,
          "headline": "feat(#2556): add proof-adapter-ripr grip adapter (#2751)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T17:42:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d28ac4b28515d4f60a9aaafd5ebbb6a3e0e37cd1",
          "body": "* feat(#2567/#2554): add proof-adapter-cargo-allow provider\n\nLand snapshot-bound read-only cargo-allow provider contract, public process discovery, dry-run argv compilation via proof-adapter-command, and ProofProviderV1 wiring without cargo-allow private imports.\n\n* fix(#2567): satisfy source-tree c\n[…]\nllow from package smoke\n\nUnpublished adapter depends on proof-adapter-command; keep it out of workspace package verification until #2604 publish posture.\n\n* fix(#2567): satisfy clippy on adapter crate",
          "is_bot": false,
          "headline": "feat(#2567/#2554): add proof-adapter-cargo-allow provider (#2750)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T17:21:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d5537123d98fc7908c12d05ebf9752a7686c51d",
          "body": "* feat(#2589-B): add thin cargo-proof CLI\n\nIntroduce cargo-proof product shell with identity, render, exit mapping, plan and dry-run commands wired to proof-engine, plus six-crate proof-candidate install smoke.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2589-B): allow-dirty package in proof-candidate-smoke\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2589-B): add thin cargo-proof CLI (#2749)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T16:02:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bf7ec4e014662e04b4b234ca1bd1236dc74517d5",
          "body": "* feat(#2589-A): scaffold proof-engine crate\n\nIntroduce provider registry, captured receipts, obligation planning, currentness, dry-run, explicit execution gates, cache, contradiction detection, and phase-gate evaluation.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2589-A): align proof-\n[…]\ning\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* chore: cargo fmt proof-engine tests\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2589-A): scaffold proof-engine crate (#2748)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T15:34:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d446a9ca82f23f20c3f8f31b8fa2948d5df16e9",
          "body": "Introduce reviewed command registry, structured argv compilation, dry-run reports, and receipt interpretation with prose-to-shell rejection.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2603-B): scaffold proof-adapter-command crate (#2747)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T15:07:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f95ce9a06e7d600ad5f6c1e8bb64582cbbb080f0",
          "body": "* feat(#2603-A): scaffold proof-provider-api crate\n\nAdd provider API trait, fake provider, conformance harness, and parity/ledger registration.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2603-A): satisfy package smoke and crate doc boundary\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2603-A): allow proof-provider-api manifest and fixture README\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2603-A): scaffold proof-provider-api crate (#2746)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T14:43:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "edcf65627ee8d2c625e02b81e485031b781343ab",
          "body": "* feat(#2588-B): add proof-protocol plan and receipt DTOs\n\nLand provider-neutral plan, capability, receipt, contradiction, and phase-gate transport with parity fixtures, ledger entries, and shims.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* chore(#2588-B): refresh lockfile for proof-protocol deps\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2588-B): add proof-protocol plan and receipt DTOs (#2745)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T14:20:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "549149ae17df7ff2989cf0d6d599fdc40585df36",
          "body": "Combine translation and recompile contract into a settlement plan with await-apply, await-recompile-proof, and await-currentness-refresh residual obligations.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-F): add intent-edit settlement plan (#2744)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T14:02:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4fe64f6733dc3574ae02255255fd81e2dd5c8cd0",
          "body": "* feat(#2613-E): compile recompile contract via intent-engine\n\nBind intent-edit translation output to intent-engine phase-obligation transport with parity fixture, ledger, and shim registration.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2613-E): use transport DTOs without intent-engin\n[…]\ncally and validate round-trip in dev tests. Fix parity path recursion and clippy dead-code.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-E): compile recompile contract via intent-engine (#2743)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:52:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9d0408c94d1793becf5d2e1d7c2fdce01eea473",
          "body": "…t-translation\n\nfeat(#2613-D): translate intent-edit plans to repo-edit",
          "is_bot": false,
          "headline": "Merge pull request #2742 from EffortlessMetrics/cursor/2613d-repo-edi…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:26:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "394efbcabd143366754e7c0e706974fe243cf45c",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2613-D): remove duplicate move-ledger key",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:14:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "76c888fb4507e028f6683b65c5716ba4b4c42070",
          "body": "Add repo-edit translation DTOs that map validated edit plans and approval envelopes into SingleTargetApplyMode requests without executing apply.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-D): translate intent-edit plans to repo-edit",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:02:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6fe67305273776ac77a84d056493e2a8b64d9913",
          "body": "…approval\n\nfeat(#2613-C): add dialect adapters and approval/currentness",
          "is_bot": false,
          "headline": "Merge pull request #2741 from EffortlessMetrics/cursor/2613c-dialect-…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:00:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1cf1e64f9c55857c0909b2fbaaf566a1dc4bd34",
          "body": "Land intent-edit dialect selector normalization and approval/currentness fail-closed envelopes with parity/ledger registration; repo-edit translation deferred to #2613-D.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-C): add dialect adapters and approval/currentness",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:48:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5d7217d1499f2f3d999067c917025dcc4883c30a",
          "body": "…otocol-scaffold\n\nfeat(#2588-A): scaffold proof-protocol crate and boundary",
          "is_bot": false,
          "headline": "Merge pull request #2740 from EffortlessMetrics/cursor/2588a-proof-pr…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:44:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63c597d4e52076c72be1c07ba48c89c2707c8f51",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2588-A): satisfy source-tree boundary rustdoc check",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:33:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43d8f30cdd3d8c5242c7a3cf528e46d2f1654113",
          "body": "Introduce proof-protocol with parity/ledger registration, ADR-0002 forbidden-edge tests, and policy surfaces without wiring cargo-allow to proof-protocol.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2588-A): scaffold proof-protocol crate and boundary",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:19:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9caa9d8d35933b434fe14709c29c4991c7783ad4",
          "body": "feat(#2613-B): add intent-edit plan and find-before-create",
          "is_bot": false,
          "headline": "Merge pull request #2739 from EffortlessMetrics/cursor/2613b-edit-plan",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:16:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d40197e20a92f2ea54836431e1a67c24142f0b6",
          "body": "Land edit-plan transport with stable action IDs, find-before-create validation, parity fixture, and ledger registration without repo-edit translation yet.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-B): add intent-edit plan and find-before-create",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:03:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5e356dd094bf18a1ff22cd56f1e804b8c6dd331e",
          "body": "…dit-scaffold\n\nfeat(#2613-A): scaffold intent-edit crate and boundary topology",
          "is_bot": false,
          "headline": "Merge pull request #2738 from EffortlessMetrics/cursor/2613a-intent-e…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:00:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be58541ad771687522bfe8009ed785a3181d2bfc",
          "body": "Add IntentEdit to extraction parity stages, fix allow classification for intent-edit docs, and keep scaffold deps on repo-edit only so workspace packaging stays green.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2613-A): register IntentEdit stage and package-safe deps",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:48:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "64f3659e4b930ae19960084ab15eb005148642f2",
          "body": "Introduce intent-edit with parity/ledger registration, ADR-0002 forbidden-edge tests, and policy surfaces without wiring cargo-allow to intent-edit.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-A): scaffold intent-edit crate and boundary topology",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:30:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12c80d559f6caa9be89eb14fefeabf1e9f9bc646",
          "body": "propose --write uses CreateNewOnly or ReplaceWithBackup with fail-closed repository containment.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-J): migrate propose through repo-edit apply (#2737)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:24:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "579f0e0a540369cdded6cd00c873b5443f649258",
          "body": "* feat(#2602-I): migrate migrate through repo-edit apply\n\nmigrate --update and --out forward policy writes through SingleTargetApplyMode with repository-contained --out targets.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-I): hybrid apply for in-repo migrate --out\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-I): migrate migrate through repo-edit apply (#2736)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:04:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "13beac9eb3e4b34c0998bfd36cc0c42fa4999aba",
          "body": "* feat(#2602-H): migrate add through repo-edit apply\n\nadd --update/--write and add --from-plan forward policy writes through SingleTargetApplyMode with backup semantics preserved.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-H): canonicalize portable mutation targets on Windows\n\nCo-\n[…]\nsor <cursoragent@cursor.com>\n\n* fix(#2602-H): best-effort canonical paths for apply targets\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-H): migrate add through repo-edit apply (#2735)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T10:47:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d5b4701b4b42718108b4c12e8995f34c183c76e8",
          "body": "Replace force_create_new with AtomicReplace, CreateNewOnly, and ReplaceWithBackup modes preserving --force .toml.bak behavior.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-G): add SingleTargetApplyMode backup semantics (#2734)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T10:16:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "821c243e2de10933fa4e05b781ff8cde0d572fa1",
          "body": "Prune --write rewrites policy via apply_single_target with containment and mutation-lock unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-F): migrate prune through repo-edit apply (#2733)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:57:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cbc8c7d10c910b996202c77ff087c1e729f50f84",
          "body": "Refresh --write rewrites policy via apply_single_target with containment and mutation-lock unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-E): migrate refresh through repo-edit apply (#2732)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:41:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0f2c25cd6b4a23c344de5a5cc1fb9a26f6c38919",
          "body": "* feat(#2602-D): migrate init through repo-edit apply\n\nRoute cargo-allow init policy writes through repo-edit::single_target_apply with parity fixture, shim registry, and init test alignment.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-D): align init parent error test with apply path\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-D): migrate init through repo-edit apply (#2731)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:22:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "47739d1097c56def4ae7bd5d76522c1da1a98e65",
          "body": "* feat(#2602-C): add generic single-target apply receipts\n\nIntroduce repo-edit apply receipt envelope, digest helpers, and single_target_apply with containment-checked portable receipts and parity fixtures.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-C): receipt parity allow entry and clippy\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-C): generic single-target apply receipts in repo-edit (#2730)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:04:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a6fada9edf91f72c874140581f08d4329a7c4fc",
          "body": "* feat(#2602-B): extract single-target atomic write to repo-edit\n\nMove write_file and write_file_no_overwrite into repo-edit::atomic_write with cargo-allow ModuleFacade shims, parity fixtures, and focused regression tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-B): receipt par\n[…]\nv1.toml so diff/shallow-diff characterization passes, and apply rustfmt to repo-edit tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-B): extract single-target atomic write to repo-edit (#2729)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T08:39:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b24e7cddc958e1e8eed6a320c2ae081f979ec98",
          "body": "* feat(#2602-A): scaffold repo-edit lock and containment\n\nExtract mutation_lock and assert_path_within_root into repo-edit with cargo-allow ModuleFacade shims, parity fixtures, and stage receipt. Documents #2568 residual spec-system CI audit path.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* \n[…]\n<cursoragent@cursor.com>\n\n* fix(#2602-A): document repo-edit source-tree boundary in lib.rs\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-A): scaffold repo-edit lock and containment (#2728)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T07:59:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "78780b30a50c23ede3ac05e65175ca4e105a3627",
          "body": "* refactor(#2568): remove embedded precommit evaluator\n\nStaged precommit now delegates to cargo-intent or fails with provider_unavailable; embedded spec_system_workspace evaluation path removed from spec_precommit. Updates conformance tests, stage receipts, and parity claim boundaries.\n\nCo-authored-\n[…]\nrsor.com>\n\n* fix(#2568): use NotApplicable for empty delegated precommit; repair allow.toml\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "refactor(#2568): remove embedded precommit evaluator (#2727)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T06:58:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "129dc18d001cd35793b9ca81d70b06ab2f36d02e",
          "body": "…(#2726)\n\nWhen delegate_spec_system is enabled, legacy spec-system commands and the embedded precommit evaluator reject instead of falling back; staged precommit still delegates only via delegate_staged_precommit. Adds cutover fixtures, parity/shim claim updates, and reachability receipt evidence for #2568.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2601-C): fail closed embedded spec-system authority at cutover …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T06:22:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2632bca73d66efcc69cb195136a959330ba2395b",
          "body": "…recommit-delegate\n\nfeat(#2601-B): delegate staged precommit to cargo-intent",
          "is_bot": false,
          "headline": "Merge pull request #2722 from EffortlessMetrics/cursor/2601b-staged-p…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T06:04:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd321b9518f70f63276ab51eaf6f5cb6d1f47292",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "ci(#2601-B): build cargo-intent before delegation e2e tests",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T05:47:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f1b90f250f953f42332ee7da169dabee3cd44e8b",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "style: rustfmt intent_delegate and release_prep_tests",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T05:44:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0496822b31f32d31ea667e0bd7f36cd90fbf8719",
          "body": "When intent-delegation config enables delegate_staged_precommit, cargo-allow\ninvokes cargo-intent via subprocess and validates repo.analysis-receipt.v1\nthrough repo-protocol only, without an intent-protocol dependency.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2601-B): delegate staged precommit to cargo-intent",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T05:41:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6ab43a8043d1a4d78ebfa70a7eca0ae37de4ae7f",
          "body": "…#2724)\n\n* ci: add cargo-deny supply-chain audit and CODEOWNERS (#1897, #1899)\n\ncargo-allow is a governance tool but had no cargo-deny supply-chain audit\nand no CODEOWNERS file.\n\nAdd a cargo-deny CI job running cargo deny check advisories bans licenses\nsources on ubuntu-latest with a deny.toml confi\n[…]\npping each crate/directory to its owner for automatic\nreview requests.\n\nChild of #1786. CI-only; no production code changes.\n\n* fix(ci): correct cargo-deny-action SHA; receipt deny.toml and CODEOWNERS",
          "is_bot": false,
          "headline": "ci: add cargo-deny supply-chain audit and CODEOWNERS (#1897, #1899) (…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T04:42:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "457d9303ff3d4fd280d8e9f1fac8b029d2a17548",
          "body": "…725)\n\nParse errors from legacy migration said 'missing field owner' with no\nindication of which legacy ledger file produced the error. On a repo with\nmultiple ripr ledger files, the operator had to grep by hand.\n\nWrap load_legacy_or_canonical (single-file path) and load_lane_config\n(batch path) wit\n[…]\nallowlist`): missing field owner'\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2510 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): parse errors include source legacy filename (#1868) (#2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T04:10:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea457e25acd2cd1334c82b593715df982162b310",
          "body": "…(#1861) (#2723)\n\nimport_legacy_policy_dir concatenated lane outputs without checking global\nID uniqueness before validate_policy. When two lanes produced entries with\nthe same ID (e.g. both had id = allow-1), validate_policy caught the\nduplicate and aborted the entire migration — no partial result,\n[…]\nboth survive with namespaced IDs.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2510 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): namespace cross-lane ID collisions instead of aborting …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T03:24:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d83cacdc9a55fd94eaaad1cbbc1a2aa3cc601068",
          "body": "cmd_migrate only called validate_policy, skipping the source-tree evidence\nreference validation that add and refresh enforce. A migration could write\nentries with evidence pointing at non-existent or out-of-tree files to the\nlive ledger.\n\nAdd validate_evidence_references_for_source_tree to the --upd\n[…]\nlidator has the source-tree root.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(cli): migrate --update validates evidence references (#1871) (#2717)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T02:21:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebf60ede167ae2a9172d365ae21522d48482d7f4",
          "body": "…721)\n\nimport_legacy_policy_dir iterated only known lane descriptors and silently\nskipped any .toml files in the directory that didn't match. A user\nmigrating a ripr ledger with a custom section (e.g. [vendor] or [sbom])\nsaw 'migration complete' and silently lost that section.\n\nDetect unrecognized .\n[…]\noad_repo_policy_migration_config.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): warn on unrecognized legacy directory files (#1867) (#2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T02:15:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd9006094f564edc7ca6f7f4567c1a0f66ebe833",
          "body": "…2696)\n\nlocation_drift fired on any 1-line delta, so every receipt drifted the\nmoment any code above an entry changed. This flooded the advisory channel\nand eroded reviewer trust — the exact opposite of what drift detection\nshould do.\n\nAdd DRIFT_LINE_TOLERANCE (default 3): line-only shifts within th\n[…]\nsage_fires_on_column_only_change.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(match): location_drift tolerance for small line shifts (#1808) (#…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T01:27:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be4ea6daed243f3462a5801beed91d7add169396",
          "body": "…handling (#1858) (#2695)\n\nevidence_repair_queues was conditionally omitted when empty in three\ndifferent ways across three artifacts:\n- report_json.rs: skipped the entire array when empty (early return)\n- receipt.rs: only inserted the key when queues was non-empty\n- doctor.rs: unrelated conditional\n[…]\npt_error, diff) with the new key.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2505 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(report): always emit evidence_repair_queues for consistent empty-…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T00:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9b877b47a7a5a22fd57f7d210a79b64620c0f26",
          "body": "…ds (#1877) (#2694)\n\nis_generated_path used file_name.contains(\".generated.\") and\nfile_name.ends_with(\".generated\") which matched compound words like\nreport-pre-generated.json where generated is part of a larger word, not a\nfile extension marker.\n\nReplace with has_generated_extension which splits on\n[…]\nes and three true-positive cases.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2506 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(scanner): .generated heuristic no longer misfires on compound wor…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T00:44:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a18189a0374755097fdc28267c861683c151288",
          "body": "…strings (#2659) (#2672)\n\nextract_lints tracked paren depth correctly but the final .split(',')\nwas a flat split that did not skip commas inside string literals. A\nreason like reason = \"see policy: a, b\" produced a spurious extra\nlint entry with a corrupt identity from the comma-separated fragment.\n\n[…]\nped quotes inside reason strings.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2500 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(scanner): extract_lints no longer splits on commas inside reason …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T23:13:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1c96a3a8666f575fed17e2f734f37af7704b8a92",
          "body": "…capes (#1839) (#2671)\n\nvalidate_import_roots_config only checked duplicate id and duplicate path.\nThe entry.path was later joined via root.join(&entry.path) at discover.rs\nwith no source-tree-relative validation — the same bug class the federation\nlayer calls out in its #2011 comment. An absolute p\n[…]\nccepts_source_tree_relative_path.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2502 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(policy): validate import-root paths for traversal and absolute es…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T23:06:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df3abb8fdf2e0c9ddd57bfaed98ad75b1c8366d3",
          "body": "classification is a free-form string, but baseline_debt is the only value\nwith structural lifecycle semantics (requires expires + created, caps at\n120 days, blocks in Strict/Release). A typo like baseline-debt or\nBaselineDebt silently bypassed all three enforcements.\n\nAdd looks_like_baseline_debt_ty\n[…]\ng passes, unrelated values pass).\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2501 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(policy): reject baseline_debt classification typos (#2661) (#2670)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T23:06:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c8b30b9ded33e5c1206bce90736515d34dfcdd8",
          "body": "…rovider-discovery\n\nfeat(#2601-A): cargo-intent provider discovery",
          "is_bot": false,
          "headline": "Merge pull request #2669 from EffortlessMetrics/cursor/2601a-intent-p…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T22:03:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c2e7e80606d2aa7facee01404322fa6eea9d18d",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2601-A): wire provider discovery into doctor for clippy",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:58:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3c670a0a0986bacc31e112a569495e7fd044d250",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: rustfmt intent_provider",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:51:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc4a9f106538ad2ec0d6958c8d55e78847e55c7a",
          "body": "Discover cargo-intent via explicit override, compatibility config, then PATH while rejecting workspace target and crates paths.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2601-A): cargo-intent provider discovery",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:46:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c5883f0625fa301c0ccba470d571b4897e795f3e",
          "body": "…nstall-smoke\n\nfeat(#2599-C): intent-candidate isolated install smoke",
          "is_bot": false,
          "headline": "Merge pull request #2657 from EffortlessMetrics/cursor/2599c-intent-i…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:42:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fba19d8db50feff8853eba2bc4b086deacb8cdda",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): scope install isolation to cargo-intent closure",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:33:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "605dbb0965fad7184e4402e006536880ba5c8bab",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): avoid patch writer clobbering crate loop var",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:28:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "df54785d10e56e4993b00252de541bd5cf41b152",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): read packaged crates from isolated target dir",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:24:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "616d2b0b98a4235093e70be20d223380a4363f31",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): incremental patch without --locked",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:18:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ef7b3f238ab389899a25cad30d5f109fa39834de",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): package intent deps without patch lock drift",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:11:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "048e79fd53979cbce6551db42e04c76b493a618d",
          "body": "Prove the seven-crate intent stack packages and installs outside the workspace without proof/test invocation or workspace target/debug leakage.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2599-C): intent-candidate isolated install smoke",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:00:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d839ea6d62f1470612f924ca243e0496e20a5c98",
          "body": "* feat(#2599-B): change status staged precommit vertical\n\nWire cargo intent change status --staged --phase precommit through repo-snapshot, intent-engine phase obligations, and intent-protocol transport with render/exit mapping. No cargo-allow production dependency on intent crates.\n\nCo-authored-by:\n[…]\n\n\n* fix(#2599-B): restore parity registry field and exclude cargo-intent from package smoke\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2599-B): change status staged precommit vertical (#2656)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T20:53:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 5,
      "commits_last_year": 2295,
      "latest_release_at": "2026-07-18T00:52:46Z",
      "latest_release_tag": "v0.1.11",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 7,
      "mean_days_between_releases": 8.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "allow-core",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-core",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 6064,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2021,
          "first_published_at": "2026-05-27T03:18:05.875614Z",
          "latest_published_at": "2026-07-18T00:50:11.488335Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-diff",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-diff",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5656,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1885,
          "first_published_at": "2026-05-27T03:47:57.520975Z",
          "latest_published_at": "2026-07-18T00:51:02.330957Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-rust",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-rust",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5702,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1901,
          "first_published_at": "2026-05-27T03:18:39.115606Z",
          "latest_published_at": "2026-07-18T00:50:40.210362Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-files",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-files",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5698,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1899,
          "first_published_at": "2026-05-27T03:18:34.007252Z",
          "latest_published_at": "2026-07-18T00:50:30.152040Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-match",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-match",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5669,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1890,
          "first_published_at": "2026-05-27T03:27:40.457493Z",
          "latest_published_at": "2026-07-18T00:50:43.257274Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "cargo-allow",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "command-line-utilities",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/cargo-allow",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5608,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1869,
          "first_published_at": "2026-05-27T04:07:37.858491Z",
          "latest_published_at": "2026-07-18T00:51:22.688717Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-23",
            "count": 2
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 407
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/allow-core/Cargo.toml",
        "crates/allow-diff/Cargo.toml",
        "crates/allow-files/Cargo.toml",
        "crates/allow-inventory/Cargo.toml",
        "crates/allow-match/Cargo.toml",
        "crates/allow-policy-legacy/Cargo.toml",
        "crates/allow-policy/Cargo.toml",
        "crates/allow-report/Cargo.toml",
        "crates/allow-rust/Cargo.toml",
        "crates/cargo-allow/Cargo.toml",
        "crates/cargo-intent/Cargo.toml",
        "crates/cargo-proof/Cargo.toml",
        "crates/intent-edit/Cargo.toml",
        "crates/intent-engine/Cargo.toml",
        "crates/intent-model/Cargo.toml",
        "crates/intent-protocol/Cargo.toml",
        "crates/proof-adapter-cargo-allow/Cargo.toml",
        "crates/proof-adapter-command/Cargo.toml",
        "crates/proof-adapter-hawk/Cargo.toml",
        "crates/proof-adapter-ripr/Cargo.toml",
        "crates/proof-engine/Cargo.toml",
        "crates/proof-protocol/Cargo.toml",
        "crates/proof-provider-api/Cargo.toml",
        "crates/repo-edit/Cargo.toml",
        "crates/repo-protocol/Cargo.toml",
        "crates/repo-snapshot/Cargo.toml",
        "crates/rust-source-index/Cargo.toml"
      ],
      "largest_source_bytes": 229120,
      "source_files_sampled": 1010,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 5031
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "sha2",
          "manifest": "crates/allow-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-files",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy-legacy",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-rust",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-files/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-inventory/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-match/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-policy-legacy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy",
          "manifest": "crates/allow-policy-legacy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/allow-policy-legacy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-policy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/allow-policy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/allow-policy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy-legacy",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tree-sitter",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tree-sitter-rust",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-inventory",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-files",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-rust",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-match",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-report",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-diff",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy-legacy",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-edit",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "intent-engine",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "intent-protocol",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-snapshot",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-engine",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-edit",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-engine/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/intent-engine/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-engine/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/intent-model/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-model/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-model/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/intent-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-adapter-command",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 2077,
        "open_issues": 405,
        "closed_ratio": 0.41,
        "closed_issues": 281,
        "closed_unmerged_prs": 39
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "EffortlessSteven",
          "commits": 2308,
          "avatar_url": "https://avatars.githubusercontent.com/u/15812269?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml",
        "ub-review.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/12 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3366897b078191bee344d03af2d27bf635e322fd",
        "ran_at": "2026-07-25T12:18:32Z",
        "aggregate_score": 5.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T11:45:57Z",
      "oldest_open_prs": [
        {
          "number": 2623,
          "created_at": "2026-07-22T06:25:55Z",
          "last_comment_at": "2026-07-22T06:58:24Z",
          "last_comment_author": "chatgpt-codex-connector"
        },
        {
          "number": 2802,
          "created_at": "2026-07-25T09:40:48Z",
          "last_comment_at": "2026-07-25T09:40:56Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-25T11:39:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 1466,
          "created_at": "2026-06-06T19:34:20Z",
          "last_comment_at": "2026-07-23T23:55:08Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1471,
          "created_at": "2026-06-06T20:28:23Z",
          "last_comment_at": "2026-07-23T23:55:09Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1476,
          "created_at": "2026-06-06T20:34:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1477,
          "created_at": "2026-06-06T21:39:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1776,
          "created_at": "2026-06-21T16:09:45Z",
          "last_comment_at": "2026-07-23T23:19:14Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1777,
          "created_at": "2026-06-21T16:09:46Z",
          "last_comment_at": "2026-07-23T23:39:13Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1779,
          "created_at": "2026-06-21T16:10:40Z",
          "last_comment_at": "2026-07-23T23:39:39Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1780,
          "created_at": "2026-06-21T16:11:47Z",
          "last_comment_at": "2026-07-23T23:16:58Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1781,
          "created_at": "2026-06-21T16:12:23Z",
          "last_comment_at": "2026-07-23T23:17:25Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1782,
          "created_at": "2026-06-21T16:12:25Z",
          "last_comment_at": "2026-07-23T23:16:33Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1783,
          "created_at": "2026-06-21T16:13:02Z",
          "last_comment_at": "2026-07-23T23:19:42Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1784,
          "created_at": "2026-06-21T16:13:04Z",
          "last_comment_at": "2026-07-23T23:40:58Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1785,
          "created_at": "2026-06-21T16:13:39Z",
          "last_comment_at": "2026-07-21T03:23:39Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1786,
          "created_at": "2026-06-21T16:13:41Z",
          "last_comment_at": "2026-06-21T21:20:10Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1787,
          "created_at": "2026-06-21T16:13:42Z",
          "last_comment_at": "2026-06-21T21:20:26Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1797,
          "created_at": "2026-06-21T16:15:22Z",
          "last_comment_at": "2026-07-23T23:16:03Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1808,
          "created_at": "2026-06-21T16:17:18Z",
          "last_comment_at": "2026-07-23T23:54:37Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1809,
          "created_at": "2026-06-21T16:17:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1823,
          "created_at": "2026-06-21T19:50:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1825,
          "created_at": "2026-06-21T19:51:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/EffortlessMetrics/cargo-allow",
    "host": "github.com",
    "name": "cargo-allow",
    "owner": "EffortlessMetrics"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 56,
        "vitality": 76,
        "community": 50,
        "governance": 53,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 2295,
              "human_commit_share": 0.87,
              "days_since_last_push": 0,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "2295 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 2295
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 5,
              "latest_release_tag": "v0.1.11",
              "releases_from_tags": false,
              "days_since_latest_release": 7,
              "mean_days_between_releases": 8.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "5 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 7 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 2,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "packages": [
                "allow-core",
                "allow-diff",
                "allow-rust",
                "allow-files",
                "allow-match",
                "cargo-allow"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 34397,
              "monthly_downloads": 11465
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "11,465 downloads/month across crates",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 11465,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "merged_prs": 2077,
              "open_issues": 405,
              "closed_issues": 281,
              "issue_closed_ratio": 0.41,
              "closed_unmerged_prs": 39
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "41% of issues closed",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 41
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2077/2116 decided PRs merged",
                "points": 37.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2077,
                      "decided": 2116
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/12 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 7,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "EffortlessMetrics",
              "public_repos": 75,
              "account_age_days": 852
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "7 followers of EffortlessMetrics",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 7,
                      "login": "EffortlessMetrics"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "75 public repos, account ~2 yr old",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 75
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "allow-core",
                "allow-diff",
                "allow-rust",
                "allow-files",
                "allow-match",
                "cargo-allow"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 7
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 7 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/12 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 80,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 5031
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 87,
                      "sampled": 87
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.48,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/allow-core/Cargo.toml",
                "crates/allow-diff/Cargo.toml",
                "crates/allow-files/Cargo.toml",
                "crates/allow-inventory/Cargo.toml",
                "crates/allow-match/Cargo.toml",
                "crates/allow-policy-legacy/Cargo.toml",
                "crates/allow-policy/Cargo.toml",
                "crates/allow-report/Cargo.toml",
                "crates/allow-rust/Cargo.toml",
                "crates/cargo-allow/Cargo.toml",
                "crates/cargo-intent/Cargo.toml",
                "crates/cargo-proof/Cargo.toml",
                "crates/intent-edit/Cargo.toml",
                "crates/intent-engine/Cargo.toml",
                "crates/intent-model/Cargo.toml",
                "crates/intent-protocol/Cargo.toml",
                "crates/proof-adapter-cargo-allow/Cargo.toml",
                "crates/proof-adapter-command/Cargo.toml",
                "crates/proof-adapter-hawk/Cargo.toml",
                "crates/proof-adapter-ripr/Cargo.toml",
                "crates/proof-engine/Cargo.toml",
                "crates/proof-protocol/Cargo.toml",
                "crates/proof-provider-api/Cargo.toml",
                "crates/repo-edit/Cargo.toml",
                "crates/repo-protocol/Cargo.toml",
                "crates/repo-snapshot/Cargo.toml",
                "crates/rust-source-index/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "48 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 48,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 229120,
              "source_files_sampled": 1010,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/1010 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1010,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch crates package 'cargo-proof' from its registry",
    "Could not fetch crates package 'intent-edit' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T12:18:48.202021Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/EffortlessMetrics/cargo-allow.svg",
  "full_name": "EffortlessMetrics/cargo-allow",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadascrates.io.