Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-23 19:09 UTC

Ivan-Pasco / clean-node-server

Clean Language Framework (Frame) for Node.js Server

TypeScriptSin licencia detectada★ 0 estrellas⑂ 0 forksdesde ene 2026Ver en GitHub ↗

Ivan-Pasco/clean-node-server tiene un índice de salud de 49 sobre 100, lo que lo sitúa en la banda En riesgo. Su puntuación más alta es Vitality (81/100) y la más baja, Community & Adoption (24/100). Se actualizó por última vez hace 5 días. Una sola persona concentra la mayor parte del trabajo reciente.

49
global / 100
En riesgo

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

49
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Ivan-PascoCuenta personal
1 seguidor10 repositorios públicosdesde jun 2023

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npm@ivan-pasco/clean-node-server0.1.97437693hace 5 díasclean-languagewasmwebassemblyserverruntime

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

81Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 5 días
13.2/36Cadencia de commits — 19/52 semanas con commits
18/18Volumen de commits — 118 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year118
human_commit_share1
days_since_last_push5
active_weeks_last_year19
Cómo se puntúa
16.2/27Publica versiones — 98 etiquetas de versión (sin releases de GitHub)
36/36Recencia de las versiones — última versión hace 5 días
27/27Cadencia de publicación — una versión cada ~0,7 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count98
latest_release_tagv0.1.97
releases_from_tags
days_since_latest_release5
mean_days_between_releases0,7
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

24Crítico · 18% del índice global
Cómo se puntúa
0/60Estrellas — 0 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
0/22.5Licencia — no se detectó ningún archivo de licencia
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
48.5/80Descargas mensuales — 4376 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@ivan-pasco/clean-node-server
dependents
ecosystemsnpm
total_downloads
monthly_downloads4376
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

31En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — 0% de issues cerradas
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
2.2/25Alcance del propietario — 1 seguidores de Ivan-Pasco
13.8/25Trayectoria — 10 repos públicos, cuenta de ~3 años
Datos de entrada utilizados
followers1
owner_typeUser
is_verified
owner_loginIvan-Pasco
public_repos10
account_age_days1127
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 93 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@ivan-pasco/clean-node-server
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

66Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 3 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

37En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Licencia — license file not detected
7.5/7.5Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
2/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 4
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3/7.5Vulnerabilities — 6 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,7
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

62Moderado · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 100 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes5920
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — tsconfig.json
10/10Entorno reproducible — lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
4/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 4
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
55/55Tamaños de archivo manejables — 0/122 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes31.875
source_files_sampled122
oversized_source_files0
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
0/40Ejemplos ejecutables
Datos de entrada utilizados
example_dirs
has_mcp_signal
api_schema_files

Datos clave

0estrellas de GitHub
1contribuidores
118commits en los últimos 12 meses
5días desde el último push
98versiones publicadas
1factor bus
1issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@ivan-pasco/clean-node-server@0.1.97; advisories assessed against the repository dependency graph instead

Más detalle

OpenSSF Scorecard 3.7 / 10
3.7agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-23 19:09 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
4Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 4
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
4Vulnerabilities6 existing vulnerabilities detected
Dependencias directas 16
RegistroPaqueteRestricción de versiónManifiesto
npmbcryptjs^2.4.3package.json
npmbetter-sqlite3^11.0.0package.json
npmcommander^12.0.0package.json
npmcompression^1.8.1package.json
npmcookie-parser^1.4.6package.json
npmcors^2.8.6package.json
npmexpress^4.18.2package.json
npmexpress-rate-limit^8.4.1package.json
npmioredis^5.10.1package.json
npmjsonwebtoken^9.0.2package.json
npmmysql2^3.9.0package.json
npmnodemailer^8.0.10package.json
npmpg^8.11.3package.json
npmpino^10.3.1package.json
npmpino-http^11.0.0package.json
npmprom-client^15.1.3package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 597,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 1668,
        "JavaScript": 47421,
        "TypeScript": 984795
      },
      "pushed_at": "2026-07-18T11:44:39Z",
      "created_at": "2026-01-25T01:01:30Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T11:44:30Z",
      "description": "Clean Language Framework (Frame) for Node.js Server",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "Ivan-Pasco",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/137369164?v=4",
      "created_at": "2023-06-22T03:23:49Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 1127
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.97",
          "kind": "patch",
          "published_at": "2026-07-18T11:44:03Z"
        },
        {
          "tag": "v0.1.96",
          "kind": "patch",
          "published_at": "2026-07-17T12:35:05Z"
        },
        {
          "tag": "v0.1.95",
          "kind": "patch",
          "published_at": "2026-07-14T22:31:56Z"
        },
        {
          "tag": "v0.1.94",
          "kind": "patch",
          "published_at": "2026-07-14T06:19:05Z"
        },
        {
          "tag": "v0.1.93",
          "kind": "patch",
          "published_at": "2026-07-13T20:07:34Z"
        },
        {
          "tag": "v0.1.92",
          "kind": "patch",
          "published_at": "2026-07-12T15:01:04Z"
        },
        {
          "tag": "v0.1.91",
          "kind": "patch",
          "published_at": "2026-07-12T14:58:38Z"
        },
        {
          "tag": "v0.1.90",
          "kind": "patch",
          "published_at": "2026-07-12T14:17:45Z"
        },
        {
          "tag": "v0.1.89",
          "kind": "patch",
          "published_at": "2026-07-12T05:43:30Z"
        },
        {
          "tag": "v0.1.88",
          "kind": "patch",
          "published_at": "2026-07-12T05:23:54Z"
        },
        {
          "tag": "v0.1.87",
          "kind": "patch",
          "published_at": "2026-07-11T16:16:43Z"
        },
        {
          "tag": "v0.1.86",
          "kind": "patch",
          "published_at": "2026-07-11T15:45:29Z"
        },
        {
          "tag": "v0.1.85",
          "kind": "patch",
          "published_at": "2026-07-09T00:26:34Z"
        },
        {
          "tag": "v0.1.84",
          "kind": "patch",
          "published_at": "2026-07-09T00:10:39Z"
        },
        {
          "tag": "v0.1.83",
          "kind": "patch",
          "published_at": "2026-07-08T20:44:52Z"
        },
        {
          "tag": "v0.1.82",
          "kind": "patch",
          "published_at": "2026-07-08T18:13:42Z"
        },
        {
          "tag": "v0.1.81",
          "kind": "patch",
          "published_at": "2026-07-08T15:34:21Z"
        },
        {
          "tag": "v0.1.80",
          "kind": "patch",
          "published_at": "2026-07-07T02:07:36Z"
        },
        {
          "tag": "v0.1.79",
          "kind": "patch",
          "published_at": "2026-07-06T14:56:23Z"
        },
        {
          "tag": "v0.1.78",
          "kind": "patch",
          "published_at": "2026-07-06T14:53:14Z"
        },
        {
          "tag": "v0.1.77",
          "kind": "patch",
          "published_at": "2026-07-06T14:41:57Z"
        },
        {
          "tag": "v0.1.76",
          "kind": "patch",
          "published_at": "2026-06-29T20:50:53Z"
        },
        {
          "tag": "v0.1.75",
          "kind": "patch",
          "published_at": "2026-06-29T20:46:41Z"
        },
        {
          "tag": "v0.1.74",
          "kind": "patch",
          "published_at": "2026-06-29T20:43:25Z"
        },
        {
          "tag": "v0.1.73",
          "kind": "patch",
          "published_at": "2026-06-26T14:46:07Z"
        },
        {
          "tag": "v0.1.72",
          "kind": "patch",
          "published_at": "2026-06-23T13:53:34Z"
        },
        {
          "tag": "v0.1.71",
          "kind": "patch",
          "published_at": "2026-06-23T06:07:01Z"
        },
        {
          "tag": "v0.1.70",
          "kind": "patch",
          "published_at": "2026-06-23T05:45:48Z"
        },
        {
          "tag": "v0.1.69",
          "kind": "patch",
          "published_at": "2026-06-22T06:11:59Z"
        },
        {
          "tag": "v0.1.68",
          "kind": "patch",
          "published_at": "2026-06-21T00:31:09Z"
        },
        {
          "tag": "v0.1.67",
          "kind": "patch",
          "published_at": "2026-06-20T14:31:35Z"
        },
        {
          "tag": "v0.1.66",
          "kind": "patch",
          "published_at": "2026-06-20T13:53:59Z"
        },
        {
          "tag": "v0.1.65",
          "kind": "patch",
          "published_at": "2026-06-20T03:23:38Z"
        },
        {
          "tag": "v0.1.64",
          "kind": "patch",
          "published_at": "2026-06-19T23:51:05Z"
        },
        {
          "tag": "v0.1.63",
          "kind": "patch",
          "published_at": "2026-06-19T19:58:29Z"
        },
        {
          "tag": "v0.1.62",
          "kind": "patch",
          "published_at": "2026-06-19T17:33:45Z"
        },
        {
          "tag": "v0.1.61",
          "kind": "patch",
          "published_at": "2026-06-19T16:08:00Z"
        },
        {
          "tag": "v0.1.60",
          "kind": "patch",
          "published_at": "2026-06-19T13:50:11Z"
        },
        {
          "tag": "v0.1.59",
          "kind": "patch",
          "published_at": "2026-06-19T12:56:24Z"
        },
        {
          "tag": "v0.1.58",
          "kind": "patch",
          "published_at": "2026-06-19T06:01:39Z"
        },
        {
          "tag": "v0.1.57",
          "kind": "patch",
          "published_at": "2026-06-19T01:57:48Z"
        },
        {
          "tag": "v0.1.56",
          "kind": "patch",
          "published_at": "2026-06-18T16:53:56Z"
        },
        {
          "tag": "v0.1.55",
          "kind": "patch",
          "published_at": "2026-06-18T03:35:59Z"
        },
        {
          "tag": "v0.1.54",
          "kind": "patch",
          "published_at": "2026-06-18T02:28:23Z"
        },
        {
          "tag": "v0.1.53",
          "kind": "patch",
          "published_at": "2026-06-18T00:49:02Z"
        },
        {
          "tag": "v0.1.52",
          "kind": "patch",
          "published_at": "2026-06-16T15:28:33Z"
        },
        {
          "tag": "v0.1.51",
          "kind": "patch",
          "published_at": "2026-06-16T15:09:51Z"
        },
        {
          "tag": "v0.1.50",
          "kind": "patch",
          "published_at": "2026-06-16T05:40:17Z"
        },
        {
          "tag": "v0.1.49",
          "kind": "patch",
          "published_at": "2026-06-16T04:24:30Z"
        },
        {
          "tag": "v0.1.48",
          "kind": "patch",
          "published_at": "2026-06-16T04:14:32Z"
        },
        {
          "tag": "v0.1.47",
          "kind": "patch",
          "published_at": "2026-06-16T02:16:28Z"
        },
        {
          "tag": "v0.1.46",
          "kind": "patch",
          "published_at": "2026-06-16T00:30:38Z"
        },
        {
          "tag": "v0.1.45",
          "kind": "patch",
          "published_at": "2026-06-13T04:00:35Z"
        },
        {
          "tag": "v0.1.44",
          "kind": "patch",
          "published_at": "2026-06-10T19:41:07Z"
        },
        {
          "tag": "v0.1.43",
          "kind": "patch",
          "published_at": "2026-06-05T13:05:19Z"
        },
        {
          "tag": "v0.1.42",
          "kind": "patch",
          "published_at": "2026-06-04T06:40:31Z"
        },
        {
          "tag": "v0.1.41",
          "kind": "patch",
          "published_at": "2026-06-03T05:13:31Z"
        },
        {
          "tag": "v0.1.40",
          "kind": "patch",
          "published_at": "2026-06-02T15:37:53Z"
        },
        {
          "tag": "v0.1.39",
          "kind": "patch",
          "published_at": "2026-06-02T04:36:46Z"
        },
        {
          "tag": "v0.1.38",
          "kind": "patch",
          "published_at": "2026-06-01T01:10:31Z"
        },
        {
          "tag": "v0.1.37",
          "kind": "patch",
          "published_at": "2026-06-01T01:08:38Z"
        },
        {
          "tag": "v0.1.36",
          "kind": "patch",
          "published_at": "2026-05-28T03:59:09Z"
        },
        {
          "tag": "v0.1.35",
          "kind": "patch",
          "published_at": "2026-05-24T02:08:07Z"
        },
        {
          "tag": "v0.1.34",
          "kind": "patch",
          "published_at": "2026-05-23T20:24:28Z"
        },
        {
          "tag": "v0.1.33",
          "kind": "patch",
          "published_at": "2026-05-22T02:00:47Z"
        },
        {
          "tag": "v0.1.32",
          "kind": "patch",
          "published_at": "2026-05-21T15:05:57Z"
        },
        {
          "tag": "v0.1.31",
          "kind": "patch",
          "published_at": "2026-05-20T21:33:14Z"
        },
        {
          "tag": "v0.1.30",
          "kind": "patch",
          "published_at": "2026-05-20T03:45:37Z"
        },
        {
          "tag": "v0.1.29",
          "kind": "patch",
          "published_at": "2026-05-19T06:05:41Z"
        },
        {
          "tag": "v0.1.28",
          "kind": "patch",
          "published_at": "2026-05-18T16:13:06Z"
        },
        {
          "tag": "v0.1.27",
          "kind": "patch",
          "published_at": "2026-05-18T16:11:29Z"
        },
        {
          "tag": "v0.1.26",
          "kind": "patch",
          "published_at": "2026-05-18T05:11:27Z"
        },
        {
          "tag": "v0.1.25",
          "kind": "patch",
          "published_at": "2026-05-18T04:32:03Z"
        },
        {
          "tag": "v0.1.24",
          "kind": "patch",
          "published_at": "2026-05-18T01:58:50Z"
        },
        {
          "tag": "v0.1.23",
          "kind": "patch",
          "published_at": "2026-05-18T01:54:39Z"
        },
        {
          "tag": "v0.1.22",
          "kind": "patch",
          "published_at": "2026-05-18T01:31:01Z"
        },
        {
          "tag": "v0.1.21",
          "kind": "patch",
          "published_at": "2026-05-18T01:08:36Z"
        },
        {
          "tag": "v0.1.20",
          "kind": "patch",
          "published_at": "2026-05-18T00:43:58Z"
        },
        {
          "tag": "v0.1.19",
          "kind": "patch",
          "published_at": "2026-05-17T23:43:38Z"
        },
        {
          "tag": "v0.1.18",
          "kind": "patch",
          "published_at": "2026-05-16T22:07:08Z"
        },
        {
          "tag": "v0.1.17",
          "kind": "patch",
          "published_at": "2026-05-16T19:58:01Z"
        },
        {
          "tag": "v0.1.16",
          "kind": "patch",
          "published_at": "2026-05-16T17:47:12Z"
        },
        {
          "tag": "v0.1.15",
          "kind": "patch",
          "published_at": "2026-05-16T15:27:11Z"
        },
        {
          "tag": "v0.1.14",
          "kind": "patch",
          "published_at": "2026-05-16T15:02:06Z"
        },
        {
          "tag": "v0.1.13",
          "kind": "patch",
          "published_at": "2026-05-16T14:56:46Z"
        },
        {
          "tag": "v0.1.12",
          "kind": "patch",
          "published_at": "2026-05-16T14:51:31Z"
        },
        {
          "tag": "v0.1.11",
          "kind": "patch",
          "published_at": "2026-05-16T14:38:54Z"
        },
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-05-12T02:10:09Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-05-03T04:25:29Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-04-17T01:26:02Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-04-01T06:30:32Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-03-23T17:03:16Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-02-14T15:05:56Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-01-26T16:59:00Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-01-26T14:56:08Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-01-25T01:42:05Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-01-25T01:16:18Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-01-25T01:00:01Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a4a5d694ff85b427b8dfa34d671e78ac6cbf45dd",
          "body": "…t body\n\nAdds the Option B convenience bridge requested by prompt 752c552c\n(tarball-upload integrity check). Returns lowercase-hex SHA-256 of the\npre-parse request body as an LP-string, so a handler can compare against\na client-supplied X-Tarball-SHA256 without materializing the body in\nlinear memor\n[…]\n.\n\nContract tests: 7 cases covering binary payloads (null bytes, 0xFF,\ntar.gz-shaped), the empty-body baseline, UTF-8 text fallback (including\nmulti-byte / emoji), and additivity with _req_body_bytes.",
          "is_bot": false,
          "headline": "feat(bridge): _req_body_sha256_hex — one-shot SHA-256 over raw reques…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-18T11:44:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0553773a2ee4e6c2dd193b328bab7ed57237913",
          "body": "…utation detection\n\nInstruments repro_http_request.mjs with a heap-forensics probe requested by\nthe compiler team for bug #eed00ffee567 (STATE A truncation V2) attribution.\nTwo flags: --probe-heap enables the probe; --probe-fn <name> adds any custom\nexport (e.g. build_rows) to the wrap set.\n\nWhat it\n[…]\nring_builder_finalize get overwritten by any subsequent import\n    (bridge) call, attributing the mutation to the specific bridge.\n\nBaseline unchanged — no flag, no wrapping. Resolves prompt 41e44fdf.",
          "is_bot": false,
          "headline": "tools(repro): --probe-heap for __heap_ptr rewind + finalize-content m…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-18T11:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88064cc93d8273e59ae8d617a14de75df52fcf08",
          "body": "- Move docs/functions-reference.md → spec/ (formal function reference table)\n- Delete system-documents/test-strategy.md (session debris)\n\ndocs/ retains 6 human-readable guides (getting-started, authentication,\ndatabase, files, http-client, http-server). No principal\nNode Server Specification.md yet — README.md serves as introduction.\n\nPart of monorepo-wide docs restructuring.",
          "is_bot": false,
          "headline": "docs: adopt docs/ + spec/ two-folder structure",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-18T05:28:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5480fe5dfae20dfda6c2e781d5a923bcfb21d6e6",
          "body": "Adds Layer 3 dev-mode capture bridge (`_dev_snapshot`) plus request/log\nring buffers scoped to each request worker. Gated on CLEAN_DEV=1; returns\nan empty LP string in production. Log interceptor is idempotent and no-op\nwhen the gate is closed. Full test parity with the Rust host at 36 tests\n(tests/\n[…]\n Acceptable under the\ndev-mode-is-single-user assumption; cross-worker fidelity via main-thread\nRPC is a follow-up if that assumption changes.\n\nHost-parity check (`--host node-server --strict`) clean.",
          "is_bot": false,
          "headline": "feat(bridge): _dev_snapshot — worker-local dev-mode capture ring buffers",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-17T12:35:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da4361f2c807f5cf1544984ac3981c05995c7145",
          "body": "Implements the middle of the binary-safe triad\n  _req_body_bytes → _crypto_sha256_bytes → _fs_write_bytes\nso uploads (tarballs, images, arbitrary octets) can be hashed on the\nNode runtime without a UTF-8 decode detour.\n\n- New src/bridge/crypto-sha256-bytes.ts. Handle layout is identical to\n  _req_bo\n[…]\n)\n  payloads, gzip-like binary payloads, and output format\n  (64 lowercase hex chars).\n- Matches function-registry.toml entry _crypto_sha256_bytes shipped in\n  the compiler release preceding this one.",
          "is_bot": false,
          "headline": "feat(bridge): _crypto_sha256_bytes — binary-safe SHA-256 over LP handle",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-14T22:31:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4eea40e70cda66b6e3e7f835c3beb6413f30ea5e",
          "body": "Adds two additive bridges to un-stub the errors dashboard's tarball-upload\nendpoint on the Node runtime.\n\n_req_body_bytes: raw request body as an opaque byte sequence. Registers\nexpress.raw for application/octet-stream so binary payloads arrive as a\nBuffer instead of a UTF-8-decoded string. Returns \n[…]\ngic), the 0/1/3/4\nreturn-code taxonomy, allowlist enforcement, atomic-rename with no .tmp\nresidue, overwrite semantics, and Content-Length parity. Host parity check\nnow exits 0 for --host node-server.",
          "is_bot": false,
          "headline": "feat(bridge): binary-safe request body and atomic byte writes",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-14T06:19:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dac0372b86eadec45489638acd3d85aef939f4ac",
          "body": "…nner\n\nSingle-process runner that instantiates a compiled WASM against the real\ncompiled bridge (dist/), sets a fake RequestContext, invokes a named\nroute handler export, and prints response bytes to stdout with forensic\ncontext (result_ptr, LP-prefix length, byte/char counts) on stderr.\n\nPurpose: g\n[…]\nspatch path. Supports\n--dump-memory <off>[:<len>], --dump-hex-output, --wat-out, --json-output\nfor aliasing / truncation forensics.\n\nFirst consumer: compiler bug #eed00ffee567 (STATE A truncation V2).",
          "is_bot": false,
          "headline": "tools(repro): add repro_http_request.mjs — standalone HTTP handler ru…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T20:07:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d3f2a2366182c875ad930c82817a32c6aea5776",
          "body": "…ot cause is compiler-side (CODEGEN-UNBOX-TO-I32-MISSING-STRING-TAG-CASE)\n\nPins 4 invariants at the node-server bridge boundary against the\n+320-stride pointer-shaped-integer symptom the reporter of\n#61ef80a34ec6 (BRIDGE-JSON-GET-INTEGER-RETURNS-POINTER-AGGREGATE-QUERY)\nattributed to a 'stale box sl\n[…]\nEN-UNBOX-TO-I32-MISSING-STRING-TAG-CASE (#0ccc47714523,\ncomponent=compiler). This test guards the bridge invariants so that a\nfuture regression at THIS layer surfaces separately from the compiler bug.",
          "is_bot": false,
          "headline": "test(bridge): regression pin for aggregate json.get + .toInteger — ro…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T04:56:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a115f34aabfa24f57aa256d57b99bffc1ac76fac",
          "body": "Adds push tag 'v*' as a trigger now that the workflow_dispatch dry run\nis green. Every tagged release must pass all open reporter-artifact\nreplays before shipping.",
          "is_bot": false,
          "headline": "ci(reporter-artifacts): enable release-tag trigger",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T01:36:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "259679b5a1410453e694866d3baedfd2cb8d2de3",
          "body": "Runs every open reporter-artifact issue's replay tarball against this\ncheckout's built node-server. Manual-dispatch only for initial rollout;\nrelease-tag trigger will be added after first green run.\n\nInstalls cln + this checkout's clean-node-server build globally so\ntarballs invoke the local build via PATH.",
          "is_bot": false,
          "headline": "ci: add reporter-artifacts replay workflow (closed-loop bug workflow)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T01:34:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eeca6ddc09739bd1a8f46ceb145879ca56b6fb50",
          "body": "Adds .nvmrc → 20. Contributors with nvm auto-switch to Node 20 on `cd`\ninto the repo (or `nvm use`), matching CI (Node 20 in publish.yml) and\nthe >=18 requirement declared in package.json engines. Also unblocks\nthe pre-push hook on machines whose system Node predates vitest 2's\nminimum.\n\nRegenerates\n[…]\nson — the previous lockfile was written by an\nold npm and still claimed version 0.1.53. Re-locked under npm 10 on Node\n20 so `npm ci` in CI stays consistent with what a fresh install produces\nlocally.",
          "is_bot": false,
          "headline": "build: pin Node 20 via .nvmrc; refresh lockfile",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T15:55:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d23e65577583b5c8511ecf9a0ee63df57259020",
          "body": "The previous injectArray helper walked the store to find the next handle\nabove the highest injected key, but that did not advance the module's\ninternal nextHandle counter. As a result, after\n  resetArrayStore()  // nextHandle = 1\n  injectArray([...])  // store[1] set, nextHandle still 1\n  bridge.arr\n[…]\nnextHandle keeps counting from 1 for\nstoreArray-minted handles, and never collides with the injected range in\nany realistic test.\n\nNo source changes — the bridge is correct; the test helper was wrong.",
          "is_bot": false,
          "headline": "test(bridge): array-bridge injectArray helper uses high handle range",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T15:01:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce1ac734772cbc3e9abcc9718d1dd95037e57c4d",
          "body": "…w bridge tests\n\nAdds a comprehensive test strategy with five tiers (policy, unit, contract,\nintegration, canary) enforced by git hooks and CI:\n\n  - scripts/check-test-policy.mjs (Tier 0): blocks skipped tests without\n    a `// policy-allow-skip: <reason>` justification, placeholder markers,\n    emp\n[…]\ncomment.\n\nThe --no-verify used here is bootstrap-only: the pre-commit hook it\ninstalls cannot run against itself before it exists, and vitest 2 cannot\nboot on this machine's Node 16 (CI runs Node 20).",
          "is_bot": false,
          "headline": "test(strategy): tiered test suite with policy guard, hooks, and 12 ne…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T14:58:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68743811f74659b7a40c5fb6759e91f354e6557e",
          "body": "…alues — resolves RUNTIME-INT-VALUES-ARE-POINTERS-STATS-STRIP\n\nAdds an end-to-end regression pinning the reporter's flow: repeated\ndb.query→_json_get→numeric-string leaf must yield the exact digits, not\n+320-stride pointer-shaped values. Complements the existing hand-rolled\nJSON case in tests/json-g\n[…]\npath a compiler-emitted handler takes.\n\nThe underlying fix (BRIDGE-JSON-GET-INTEGER-RETURNS-POINTER, commit\nb14f101 in v0.1.88) already addresses the root cause — this test\nprevents silent regression.",
          "is_bot": false,
          "headline": "test(bridge): pin db.query→json.get→numeric leaf against ptr-shaped v…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T14:17:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f61d33def7afe06340a2fa3ad2264b74297913c",
          "body": "… resolves NODE-SERVER-UI-RENDER-PAGE-NO-SUBSTITUTION\n\nAlign _ui_render_page with HOST_BRIDGE.md line 419 spec and frame.ui plugin\nconvention (v3.2.7). Templates use { key } single-brace substitution with\nwhitespace tolerance and dotted paths; {{ and }} emit literal { and }.\n\nPrevious implementation\n[…]\n { item.field } placeholders per-iteration before the\nglobal pass. Key validity is restricted to identifier / dotted-path form,\nso CSS bodies and JSON literals containing { } are left as literal text.",
          "is_bot": false,
          "headline": "fix(bridge): _ui_render_page uses single-brace { key } substitution —…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T05:43:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b14f1018dc4e4d5de4cc7123e8cc0ff88df1b4ee",
          "body": "…GE-JSON-GET-INTEGER-RETURNS-POINTER\n\nCompiler 0.33.55 + frame.server 2.8.4 declared _json_get with\nparams=['any','string'], returns='any', expand_strings=false. The bridge\nkept the old 4-arg (jsonPtr,jsonLen,pathPtr,pathLen) shape and returned\na raw LP-string pointer, so the compiler's emit_unbox_a\n[…]\n Migrated the\nthree existing test files that were exercising the old 4-arg ABI to\nthe new signature — they now box the JSON input and unbox the result\nthe same way the compiler does at each call site.",
          "is_bot": false,
          "headline": "fix(bridge): _json_get switches to any-in/any-out ABI — resolves BRID…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T05:23:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eaef219ad135be395e68afc724b48722b87daca7",
          "body": "…-SERVER-BRIDGE-OOB-TASKS-FILTER\n\nfoundation/platform-architecture/function-registry.toml declares mem_scope_push\nand mem_scope_pop as \"no-op currently\" for every host, and clean-server's Rust\nbridge treats them that way. This bridge previously called the WASM-side\nscope_pop export on every internal\n[…]\nrn from\nthe bug survives an internal pop. All 383 vitest tests pass; 14/15 canaries\npass (http_client canary DIFF is a separate compiler-side canary bug).\n\nFix commit for fingerprint 654ef241296a631e.",
          "is_bot": false,
          "headline": "fix(bridge): make mem_scope_pop a no-op for WASM heap — resolves NODE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-11T16:16:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6cb315f90d1bff73ea55e3029947d370fee5289",
          "body": "Pins the db.query + json.get + string.concat pattern reported as trapping\n\"memory access out of bounds\" on node-server 0.1.85. Cannot reproduce\nend-to-end against clean-errors/dist/errors.wasm today (20x sequential +\n10x concurrent /tasks?origin=error return HTTP 200) — likely already\nfixed by compi\n[…]\nesses:\n- Sequential _db_query responses don't overlap\n- Driver errors surface as parsable {ok:false} envelopes (not raw bytes)\n- _json_get chain preserves LP-string integrity under a healthy allocator",
          "is_bot": false,
          "headline": "test(bridge): regression harness for NODE-SERVER-BRIDGE-OOB-TASKS-FILTER",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-11T15:45:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81bb3345ebcf752e205575403ac38a661b500916",
          "body": "_time_now now returns BigInt(unixSeconds) per foundation/platform-architecture\n/function-registry.toml — the registry declares it as `returns = \"i64\"` and\nNode's WebAssembly bindings require host functions bound to i64 result to\nreturn a BigInt. Previously node-server returned a heap pointer to a JS\n[…]\nal host runs with\n`--sandbox /tmp` for a file-heavy workload. Fixes the file canary DIFF\nwhere writes to /tmp/clean_canary_file.txt were rejected as\noutside-sandbox and the round-trip silently failed.",
          "is_bot": false,
          "headline": "fix(bridge): correct _time_now signature + canary driver sandbox root",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-09T00:26:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2224fba849fd124e0147e7d051df98b7815ec2e0",
          "body": "Implements the node-server child of the Cross-Component Contract\nCanaries umbrella (prompt 6ace888b-7a8d-11f1-9586-da25a95a496b,\numbrella 7fb425cb-79ba-11f1-9586-da25a95a496b).\n\nscripts/run_canaries.mjs discovers the compiler's canary corpus,\nfilters out browser-only namespaces, compiles each canary\n[…]\ns (env/file/http_client diffs, time trap). The time trap\n(_time_* i64/BigInt signature drift) is filed as\nNODE-SERVER-TIME-I64-BIGINT. The other three DIFFs need follow-up\ninvestigation before filing.",
          "is_bot": false,
          "headline": "feat(canaries): add Layer-2 nightly canary runner",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-09T00:10:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "680d2b32b3f55d0f4550faba5b4de80f9203091f",
          "body": "…SERVER-CGROUP-THROTTLE-WEDGE)\n\nWorker rotation was gated only on `readHeapPtr() - initialHeapPtr > 50MB`.\nscope_pop rewinds `__heap_ptr` but WASM `memory.grow()` is permanent — a\nsingle request that momentarily needed 60MB permanently extended\n`memory.buffer.byteLength`, but the rotation check saw \n[…]\n recycling.\n\nComplements the --memory-soft-limit mitigation shipped in 0.1.81: that\nprevents an unrecoverable wedge if the leak still happens, this stops the\nleak from accumulating in the first place.",
          "is_bot": false,
          "headline": "fix(pool): rotate on memory.buffer growth, not just __heap_ptr (NODE-…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T20:44:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01f6ba6a544f4b23ac9ac3d925c4d705359e7861",
          "body": "Adds Cross-component prompts section to CLAUDE.md (mirrors the wording\nalready in the project-root CLAUDE.md) and allows a few read-only bash\npatterns previously prompted for.",
          "is_bot": false,
          "headline": "chore: document team-prompt skills and expand bash allowlist",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T18:13:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ff058b9b5572e983a996a72cea6881291d2a28",
          "body": "Implements FRAME-AUTH-REFRESH-TOKEN-NO-ROTATION and\nFRAME-AUTH-RESET-TOKEN-BRIDGES-MISSING per function-registry.toml:\n\n- _jwt_refresh_and_rotate: verify + atomically consume a refresh token's\n  jti and return a freshly-signed token (AUTH-J007 / AUTH-J009 single-use\n  rotation). Rejects replays, tok\n[…]\n-present in one\n  event-loop tick). Expired entries return 0 and are swept lazily.\n\nBoth stores expose reset* test helpers; 9 unit tests cover round-trip,\nreplay rejection, expiry, and invalid inputs.",
          "is_bot": false,
          "headline": "feat(bridge): add _jwt_refresh_and_rotate + _auth_reset_token bridges",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T18:13:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e2a68507706c085c9bd651f59e2c9649c0a7911",
          "body": "… cgroup wedge\n\nUnder a systemd unit with MemoryMax, once RSS hits the ceiling the process gets\npinned in kernel mem_cgroup_handle_over_high (uninterruptible sleep) on the\nnext allocation. The listening socket stops responding and only SIGKILL clears\nit — Restart=always cannot rescue a D-state task \n[…]\nrprint\nf65b346bb0c4efcf02c43d4668f6f17031e7610cdb5b1e3b7c498aa70c7446f1). This is\na mitigation, not a leak fix — the underlying host-bridge scope tracking\n(part 2 of the suggested fix) is a follow-up.",
          "is_bot": false,
          "headline": "feat(cli): add --memory-soft-limit for graceful drain-and-exit before…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T15:34:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d9321fe14eca537abf5897d0f7e20fa4571cfc9",
          "body": "The ws module was in devDependencies but imported at runtime, so production\ninstalls threw ERR_MODULE_NOT_FOUND from attachWebsocketServer(). Pino's err\nserializer expanded that into a multi-line requireStack trace on every process\nstart, and the rejected import promise held the request-scope closur\n[…]\nered no WS routes — avoids\n  loading ws (~1MB heap) for API-only deployments.\n\nPart of NODE-SERVER-CGROUP-THROTTLE-WEDGE (fingerprint\nf65b346bb0c4efcf02c43d4668f6f17031e7610cdb5b1e3b7c498aa70c7446f1).",
          "is_bot": false,
          "headline": "fix(bridge): make ws an optional dependency and skip attach when unused",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T15:33:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3e74175b73ec723bae727a614dcc9034ca1d82e",
          "body": "…ING-READ-OOB-INTERMITTENT)\n\nreadRawString and readLengthPrefixedString now emit console.error with\nptr, len, bufferSize, a hex dump of bytes at ptr, the length reinterpreted\nas 4 little-endian ASCII chars, and a stack trace before throwing.\n\nThe intermittent case observed in production (len=1684632\n[…]\nbleed remain in place\n(scope_push/scope_pop rewind, per-request JS accumulator reset, worker\nrotation on error). This commit closes the diagnostic gap so future\noccurrences are not silent server-side.",
          "is_bot": false,
          "headline": "fix(bridge): log forensic context on OOB string read (NODE-SERVER-STR…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-07T02:07:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b8e36c18175eca602bcc135ebf2a6a8fe9d6d77",
          "body": "The 0.1.78 workflow failed because clean-language-spec has foundation/\nas a subfolder at its root, not the root itself. Full checkout put the\nscript at $WORKSPACE/foundation/foundation/management/scripts/... but\nCLEAN_LANGUAGE_ROOT was set to $WORKSPACE, so the script wasn't found.\n\nFix: sparse-chec\n[…]\ne foundation/ subtree into a staging dir\n(_spec/), then move _spec/foundation to $WORKSPACE/foundation. This\ngives the layout the parity script expects (<root>/foundation/,\n<root>/clean-node-server/).",
          "is_bot": false,
          "headline": "ci(parity): sparse-checkout foundation subtree from clean-language-spec",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-06T14:56:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cd2413dd46ba08df9b82441e86fbdeb0698e98c4",
          "body": "Adds a 'parity' job to the publish workflow that runs\ncheck_host_parity.py --host node-server --strict on every pull request\nand tag push. The job checks out clean-language-spec as a sibling of\nthis repo and points CLEAN_LANGUAGE_ROOT at the workspace so the script\nresolves foundation/ and clean-nod\n[…]\nng no-op stubs; this closes the systemic gap).\n\nVerified locally:\n- baseline parity check: missing 0, exit 0\n- with _arena_scope_push/_pop removed: missing 2, exit 1\n- full test suite: 359/359 passing",
          "is_bot": false,
          "headline": "ci(parity): enforce host bridge parity against function-registry.toml",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-06T14:53:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a9b9224b9645259bc45b8a65dfded0c0b6b89e7f",
          "body": "…E-E001)\n\nCompiler 0.31.5+ (confirmed on 0.33.2) emits env._arena_scope_push\n(() -> i32) and env._arena_scope_pop (i32 -> void) as WASM imports on\nevery module. clean-node-server 0.1.72-0.1.76 shipped without handlers,\ncausing every fresh WASM to fail WebAssembly.instantiate with\n\"function import re\n[…]\n33.2-produced errors.wasm and\nvia a direct WebAssembly.instantiate smoke test — module now loads\nwithout LinkError. Regression test added in\ntests/arena-scope-bridges.test.ts.\n\nBumps 0.1.76 -> 0.1.77.",
          "is_bot": false,
          "headline": "fix(bridge): add _arena_scope_push/_arena_scope_pop stubs (HOST-BRIDG…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-06T14:41:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3bf77aa0ca21a378255b80a8d713e272d9cc1403",
          "body": "Port clean-server/src/locale.rs to TypeScript. Closes the host-parity gap\nfor the 8 _i18n_* bridge functions previously stubbed to throw at runtime.\n\nThe TypeScript LocaleState mirrors the Rust observable behavior:\n  - JSON translation maps flattened to dot-separated keys.\n  - BCP-47 fallback chain:\n[…]\n for some locales than the\nRust host. Inline matches Rust output exactly.\n\nCloses the i18n entry on Step 4 of the host-bridge-parity-enforcement\nprompt (was throw-error stub; now real implementation).",
          "is_bot": false,
          "headline": "feat(bridge): implement frame.locale (i18n) — replace throw-error stubs",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-29T20:50:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b890e7973a00983972428fd1fe0786e15f58b32",
          "body": "Port clean-server's build-manifest reader (Plugin Contracts v2 §5/§8) to\nTypeScript. At startup the server looks for build-manifest.json next to\nthe main WASM. When present, it is the authoritative source for artifact\npaths: the client_hydration artifact (frontend.wasm) is served from the\ndeclared p\n[…]\nrser + path resolver (TS port of build_manifest.rs)\n- src/server.ts: manifest-first frontend.wasm + auto-registered artifact routes\n- tests/build-manifest.test.ts: 11 tests mirroring the Rust test set",
          "is_bot": false,
          "headline": "feat(server): read build-manifest.json for artifact resolution (SRV004)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-29T20:46:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "657359ac56473033b00941291313537bab1e87f7",
          "body": "The frame.ui plugin removed _ui_inject_head_css entirely (theme values now\nlive in public/css/theme.css and ship via _ui_inject_head_link). Drop the\nhost implementation, the registration, and the state.injectedCss accumulator\n(types, pool, worker, test). See the\nall-remove-ui-inject-head-css-bridge \n[…]\nno longer\nlisted as MISSING (was never MISSING here — the implementation existed; the\nregistry no longer requires it). Remaining MISSING/UNKNOWN counts are\npre-existing drift unrelated to this change.",
          "is_bot": false,
          "headline": "chore(bridge): remove orphaned _ui_inject_head_css",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-29T20:43:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e37f1658efc1869cd40943fe520d3b76b37ce10f",
          "body": "… config bridges (BRIDGE_REG_002)\n\nCompiler 0.30.362+ lowers integer:64 .toString() to an env.int64_to_string\nWASM import. Without this bridge function the Node host fails to\ninstantiate any module that uses 64-bit integer toString. Bridge receives\na JS BigInt (Node's surfacing of WASM i64) and uses\n[…]\net_global_error_handler)\npaired with upstream FRAME-SERVER-CONFIG-FIELDS-UNIMPLEMENTED — signatures\nfollow that report's suggested fix and may need adjustment if the\nframework PR picks different ones.",
          "is_bot": false,
          "headline": "fix(bridge): add int64_to_string + _mcp_http_respond, scaffold server…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-26T14:46:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52b0ce4ed998a75de1c86cc5ed5e7b8740981d07",
          "body": "…-WRAP-INCOMPLETE)\n\nscope_push/scope_pop correctly rewind the WASM bump heap per request, but\nthree bridges keep module-level Maps that grow with every allocation and\nare never reclaimed:\n\n  - bridge/list.ts: listStore (handle -> JS array)\n  - bridge/array.ts: arrayStore (handle -> JS array)\n  - bri\n[…]\nope_pop on both the success and\nerror paths. Safe because scope_pop has already reclaimed the WASM heap\nthe handles pointed into — any caller holding a stale handle is already\nholding a stale pointer.",
          "is_bot": false,
          "headline": "fix(bridge): release JS-side accumulators per request (NSR-HTTP-SCOPE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-23T13:53:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6d9509e968e3659e0a44e3c6d03838b6009c913",
          "body": "…ry coverage test\n\nThe compiler stopped emitting dot-notation bridge aliases in v0.30.123\n(see node-server CLAUDE.md \"Bridge Function Naming — Canonical Names Only\").\nThe ui.ts client-stub map kept 58 'ui.X': noop entries from that era,\nshadowed by their canonical _ui_* siblings two sections above. \n[…]\nng=0 unchanged; unknown dropped 209 → 159 (the\nremaining residual is real registry gaps tracked in\nfoundation/management/cross-component-prompts/all-registry-backfill-server-and-builtin-functions.md).",
          "is_bot": false,
          "headline": "chore(bridge): drop dead ui.X dot-notation registrations + fix regist…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-23T06:07:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53c8a64b9baead0491d0e58d6883cd52975fdd1a",
          "body": "…-REQUEST-MEMORY-RELEASE)\n\nThe HTTP request path already wraps its handler in scope_push/scope_pop\n(commit efc7cc0), but three other handler-dispatch sites that share the\nsame long-lived init WASM instance kept advancing __heap_ptr forever:\n\n  - src/workers/sse-worker.ts: each SSE connection's emitt\n[…]\ntation, and add it to the three new\nsites. The wrapper is a no-op against modules compiled with\npre-0.30.330 compilers (no scope_push/scope_pop exports), matching\nthe existing request-worker fallback.",
          "is_bot": false,
          "headline": "fix(bridge): wrap SSE/cron/job handlers in per-call scope (NSR-NO-PER…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-23T05:45:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93f995781b7c9edeca1148cd80e99a7cf2439350",
          "body": "…VER-UI-RENDER-PAGE-INTERP-STRICT-WHITESPACE)\n\nReplace the regex `/\\{([\\w.]+)\\}/g`, which only matched single-brace\n`{key}` with no internal whitespace, with a single-pass `{{ … }}`\nscanner. Matches HOST_BRIDGE.md / function-registry.toml (`{{ key }}`\nwith whitespace tolerated, missing keys → empty string) and the\nclean-server v1.9.57 sibling implementation. Single-brace `{key}` is\nintentionally no longer consumed so it stays available for the\ncl-iterate directive's item placeholders.",
          "is_bot": false,
          "headline": "fix(bridge): _ui_render_page substitutes {{ key }} per spec (NODE-SER…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-22T06:11:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efc7cc0ae0c296a513211e4b1fecfdc870c81d7a",
          "body": "…p per request (CNS-MEM-SCOPE-POP)\n\nmem_scope_push now snapshots state.exports.scope_push(); mem_scope_pop\nhands the snapshot to state.exports.scope_pop(), rewinding __heap_ptr.\nThe request worker brackets each handler invocation (including the\nerror path) with the same primitives so __malloc alloca\n[…]\n concatLengthPrefixed — which never go\nthrough mem_alloc and so can't be reclaimed by the per-allocation refcount\npath — are released at request boundaries instead of leaking until the\nworker rotates.",
          "is_bot": false,
          "headline": "fix(bridge): consume compiler scope_push/scope_pop to rewind WASM hea…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-21T00:31:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a9c2531c7168da3dba57a409e503d7de7af1f56",
          "body": "The 7679a9e fix (0.1.65) and b50d2e0 (0.1.66) added the defensive\n__heap_ptr bump to concatLengthPrefixed, string_split,\nwriteLengthPrefixedString, and writeRawBytes, but mem_alloc was\noverlooked. The compiler emits mem_alloc for every non-string object\n(records, list element slots, struct/class ins\n[…]\nogy used by nsr002-heap-ptr-overlap, covering\nconsecutive non-overlap, sentinel survival across interleaved string\nwrites, the 30-card prod render pattern, alignment, and the zero/negative\nsize no-op.",
          "is_bot": false,
          "headline": "fix(bridge): mem_alloc bumps __heap_ptr after every allocation (NSR002)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-20T14:31:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b50d2e084e4bc76697da9b46e121f1a730520957",
          "body": "The compiler's __malloc uses the __heap_ptr exported global as a bump\npointer, but doesn't reliably advance it when re-entered from a host\nbridge call. By the time control returns to JS, the global is still at\nits pre-call value — so the next bridge malloc hands out an overlapping\npointer, the next \n[…]\nvery malloc (the\nexact prod pathology) and asserts that consecutive writeString,\nstring.concat, _json_get + concat (30-card render loop), and\nstring_split all survive without length-prefix corruption.",
          "is_bot": false,
          "headline": "fix(bridge): defensively bump __heap_ptr after every malloc (NSR002)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-20T13:53:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7679a9e893a7741e386b73ae8a8820555e86edfd",
          "body": "…sion)\n\nThe 0.1.63 byte-level rewrite added an empty-input short-circuit that\nreturned one of the input pointers verbatim when the other was empty,\nas a malloc-saving optimization for the 30-card render loop. The\noptimization aliased the input into the result, which broke the\nownership invariant the\n[…]\nmutating an input buffer after concat must not change the result.\n- Updated the two short-circuit-aliasing pins that captured the 0.1.63\n  optimization to expect fresh buffers with equivalent content.",
          "is_bot": false,
          "headline": "fix(bridge): string.concat always returns fresh buffer (NSR002 regres…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-20T03:23:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0e159d969bb7efb25d38fcba52d7b8419503b80",
          "body": "…E_STRING_SPLIT)\n\nThe compiler's `iterate part in parts` reads list size from offset 0 of\nthe returned pointer and element pointers at offset 16 + i*4. Returning a\nJSON-encoded length-prefixed string meant offset 0 held the JSON byte\nlength (e.g. 17 for `[\"a\",\"b\",\"c\",\"d\"]`), so the loop ran 17× past\n[…]\nclean-server's write_string_list_to_caller and the\nwasmtime_runner reference.\n\nUpdated bridge-abi tests to assert the list layout, including the exact\n\"a```b```c```d\" / \"```\" repro from the dashboard.",
          "is_bot": false,
          "headline": "fix(bridge): string.split returns Clean list, not LP-JSON (HOST_BRIDG…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T23:51:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5e0911925ed66e4fa84a18845656aded9ecd2f8",
          "body": "The compiler emits byte-position substring inline, so iterating a string in\na `while i < s.length(): i += 1` loop over multibyte UTF-8 (em-dash E2 80 94,\narrow E2 86 92, CJK, emoji) yields a sequence of length-prefixed fragments\neach holding a single continuation byte. The previous string_concat dec\n[…]\n prod-symptom reproducer (prod WASM md5 14b8276e..., prod\nDB via SSH tunnel): /tutorials goes from 38 U+FFFD / 0 em-dashes preserved\nto 0 U+FFFD / 12 em-dashes preserved across 5 consecutive requests.",
          "is_bot": false,
          "headline": "fix(bridge): string.concat joins at byte level (NSR002)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T19:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45aff4ec840f396f36a0167e809b916e8a60116d",
          "body": "…NSR002)\n\nAdds two more guards on top of utf8-roundtrip:\n\n- http-utf8-wire.test.ts: stands up the real Express middleware stack\n  (compression, json, urlencoded, cookieParser, express.text) and verifies\n  res.type + res.send preserve multibyte UTF-8 on the wire across text/plain,\n  text/html, applic\n[…]\n round-trip, IPC, and Express's response pipeline. The\nproduction U+FFFD symptom isolated to none of them in unit/integration\ntesting — a regression introduced in any layer will now break loudly here.",
          "is_bot": false,
          "headline": "test(bridge): pin HTTP wire + SharedArrayBuffer IPC UTF-8 contracts (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T17:33:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49737ebcc4ce0923f238c772f7a649439315b241",
          "body": "NSR002 claimed clean-node-server corrupts multibyte UTF-8 in HTTP response\nbodies (em-dash bytes surfacing as U+FFFD chars). Investigation showed the\nhost bridge actually preserves UTF-8 across the full request flow when given\nvalid input: writeLengthPrefixedString / readLengthPrefixedString use\n`by\n[…]\nhows up in\nproduction traffic, WASM memory contained invalid UTF-8 before the bridge\nread it, so the corruption is upstream (compiler-emitted string-length\nhandling or framework http.respond wrapper).",
          "is_bot": false,
          "headline": "test(bridge): pin multibyte UTF-8 round-trip contract (NSR002 triage)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T16:08:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec1bb6f132275a1544245d1f92a68cccce2d7aab",
          "body": "RouteRegistry.match() did a strict method check, so HEAD requests against\nGET-registered routes (including /health, /metrics, and every WASM route)\nreturned 404. Load balancers and uptime probes using HEAD got false negatives.\n\nRFC 9110 §9.3.2: HEAD must be served identically to GET with the body\nsu\n[…]\nD', so the fix is localised to the registry — try the\nrequested method first, and for HEAD fall back to the GET route. Explicit\nHEAD handlers still win because the first pass runs before the fallback.",
          "is_bot": false,
          "headline": "fix(router): HEAD falls back to GET handler (HTTP-HEAD-RETURNS-404)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T13:50:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af0d898a49497948486574e978e59ca1fdede9b4",
          "body": "… failure\n\nCompiler 0.30.321 ships MALLOC-IGNORES-MEMORY-GROW-FAILURE — __malloc now\nreturns 0 (null) when memory.grow refuses to grow instead of returning a\ncorrupted pointer. The old bridge guard treated null-pointer and\nout-of-bounds-pointer as the same misleading \"WASM heap exhausted (see\nNSR002\n[…]\non message users have been seeing was\nthe symptom of the upstream allocator bug; with the compiler fix shipped\nand this bridge message updated, the user-visible failure now describes\nthe actual cause.",
          "is_bot": false,
          "headline": "fix(bridge): report null malloc clearly now that compiler honors grow…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T12:56:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6141f5a60235d240eaeb7453d08a6b535c37f71",
          "body": "…lookup\n\nThe dot-path walker used `(current as Record<string, unknown>)[part]` for\nevery step, so `items.length` returned the array length, `items.push`\nreturned the function, and `items.constructor` returned `Array` — none of\nwhich should be reachable via a JSON path. Mirrors clean-server's\nhost-br\n[…]\nGNORES-MEMORY-GROW-FAILURE, #d8fba3f01151) — this commit closes a\nseparate correctness divergence from clean-server in the same bridge\nfunction. Adds tests/json-get-bridge.test.ts; 163/163 tests pass.",
          "is_bot": false,
          "headline": "fix(bridge): _json_get rejects Array.prototype keys and uses own-key …",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T06:01:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b1f6e8b558edbe62564c0e34d33b9323703c86a",
          "body": "Adds a regression test that proves _http_respond writes state.response.status\nunconditionally regardless of any prior _http_set_cache / _http_no_cache call.\nThe two reports (5ac075ee, 70f95ccc) misclassified against node-server were\ncaused by frame.server's auto-wrap emitting a second _http_respond(200, ...)\nafter the helper had already set 4xx. Reclassified to framework; new bug\n276d424935c8 (FRAME-SERVER-AUTO-WRAP-CLOBBERS-STATUS) tracks the real fix.",
          "is_bot": false,
          "headline": "test(bridge): pin _http_respond status contract (RUN001/RUN002 triage)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T04:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78422a0ddccd3d133b3dbcccee44996a1048e61",
          "body": "…NTIME-DB-POOL-WEDGE)\n\nTransaction begin/commit/rollback used release() in finally blocks even when\nthe underlying op threw. mysql2 connections that error mid-stream still have\nunconsumed response bytes; releasing them back into the pool causes the next\nconsumer to trip PROTOCOL_PACKETS_OUT_OF_ORDER\n[…]\nequest-seq to the worker SAB so a timed-out sendAndWait no longer\n  leaves the worker free to clobber the next request's payload buffer.\n- 12 tests covering destroy-vs-release across every error path.",
          "is_bot": false,
          "headline": "fix(db): destroy mysql pool connections on error to prevent wedge (RU…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T01:57:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ffadb3bfd848865aabdccc2684b83650718f082",
          "body": "…T-INSERT-ID-ZERO)\n\nThe db bridge dispatches each call against a fresh pooled MySQL connection,\nso LAST_INSERT_ID() — session-local — saw a different connection than the\nprior INSERT and returned 0. SQLite (single-connection) was not affected;\nPostgreSQL uses RETURNING and has no equivalent function\n[…]\nb_execute (sync + async paths)\n- tests: 14 new cases covering alias parsing, response shape, INSERT\n  detection, and the round-trip cache (INSERT -> SELECT -> cached id,\n  no driver hit on the SELECT)",
          "is_bot": false,
          "headline": "fix(db): cache last_insert_id across pool connections (FRAME-DATA-LAS…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T16:53:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1976bf26ad05ed0207dedfd70a46f909518c1c6",
          "body": "…R-PAGE-MUSTACHE-SYNTAX-MISMATCH)\n\nThe substitution regex previously matched {{key}} (double-brace mustache),\nbut the canonical syntax — emitted by the frame.ui plugin's process_html\nexample and implemented by Rust clean-server — is {key} (single-brace).\nCompanion-page templates serving through clean-node-server were returned\nwith placeholders intact.\n\nAligns the node-server implementation with substitute_template in\nclean-server/src/bridge.rs.",
          "is_bot": false,
          "headline": "fix(bridge): _ui_render_page uses {key} single-brace syntax (UI-RENDE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T03:35:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5e1bfe422509c74773f2cb35160ef5137269471",
          "body": "…SPOND-RETURNS-ZERO-CLEARS-BODY)\n\nThe compiler-emitted route wrapper takes the _http_respond return value and\npasses it as the body pointer to a second _http_respond call. Returning 0 caused\nthe response body to be cleared. Matches Rust clean-server's\nwrite_string_to_caller(body) pattern and the registry's `returns = \"ptr\"`.",
          "is_bot": false,
          "headline": "fix(bridge): _http_respond returns body pointer instead of 0 (HTTP-RE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T02:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e68c9b343ab4b7fd534fdf16c25c35cf99322da",
          "body": "…n (NODE-MEM-ALLOC-SIGNATURE-MISMATCH)\n\nThe compiler emits memory_runtime.mem_alloc with signature (type_id: i32, size: i32) -> i32, but the JS bridge declared a single `size` parameter. JS silently dropped the second argument, so every WASM allocation called mem_alloc(0, N) and was read as size=0, \n[…]\nurned 0, and json.encode of any string produced the literal \"null\".\n\nBrings the Node host into line with function-registry.toml and the Rust host in clean-server/host-bridge/src/wasm_linker/memory.rs.",
          "is_bot": false,
          "headline": "fix(bridge): mem_alloc accepts (type_id, size) per compiler conventio…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T00:49:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc2ca5e17ccfec28f1a1c495c82814f841d9116d",
          "body": "…pe (DB-BUILD-WHERE-IGNORES-DUNDER-WHERE)\n\nbuild_where_clause treated every JSON key as a column name, producing\n`WHERE __where = ?` with the SQL fragment bound as a parameter whenever\nthe framework's frame.data plugin emitted `{\"__where\":\"<fragment>\"}` for\nModel.paginate: / Model.cursor: where: blo\n[…]\nh\nno parameter binding; `__order` is validated against a strict charset\nand surfaced via WhereResult.orderBy so _db_paginate can splice it into\nORDER BY. Matches the protocol shared with clean-server.",
          "is_bot": false,
          "headline": "fix(bridge): honor __where/__order reserved keys in where_json envelo…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T15:28:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "163aa8e95667fbfc78b5afff5d7a22e7a0328521",
          "body": "…VER_MEM_LEAK)\n\nTwo leaks identified from production telemetry on a node-server process\nthat hit its cgroup MemoryHigh limit after days of uptime:\n\n1. request-worker.ts: the error path hardcoded `needsRestart: false`\n   and never incremented `requestCount`. WASM has no GC, so a partially\n   advanced\n[…]\nhestration, which is beyond unit test reach without significant\nmocking scaffolding. Existing 121-test suite still passes; production\nverification is the cgroup-limited reproduction in the bug report.",
          "is_bot": false,
          "headline": "fix(worker): rotate on error path + sequence terminate→spawn (NODESER…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T15:09:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3619c4a46fb3dcf3b7b22daea88a411c4c7d3bf",
          "body": "…or stubs\n\nReplaces the throw-error stubs in three bridge modules with full\nimplementations matching clean-server (Rust) behaviour, closing the\nparity gap tracked in node-server-stub-implementations-triage.md.\n\n- schedule.ts: ported 5-field cron parser + setTimeout timer wheel.\n  startScheduler(stat\n[…]\nss-component bug\nDBWHERE_RAW_FRAGMENT against frame.data so both hosts can be fixed\ntogether rather than diverging node-server alone.\n\nFull vitest: 121/121 (84 prior + 37 new).\nHost parity: missing=0.",
          "is_bot": false,
          "headline": "feat(bridge): implement schedule/jobs/websocket — burn down throw-err…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T05:40:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a7dfc82d1bd23814a16dd8fad75f8c824814a9a",
          "body": "…-drift fix\n\nFrame.server plugin.toml originally declared _server_sleep params as\n[\"i32\"], so the WASM import wired up as (i32) -> void. Node-server's\nhandler matched that with `ms: number`. Clean-framework now corrects\nplugin.toml to [\"integer\"] (committed in clean-framework as\n0e5547b@main), align\n[…]\nloop. Millisecond\nsleep durations fit safely in a JS number.\n\nCloses the PLUGIN-REGISTRY-DRIFT diagnostic fingerprint\nf952554dd54431f7 (cln dev-queue), the last drift the validator was\nstill flagging.",
          "is_bot": false,
          "headline": "fix(bridge): _server_sleep accepts bigint (i64) per registry/registry…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T04:24:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "489c8321d13f2067a95e2d586f0b69ac21adc52f",
          "body": "Replaces three throw-error stubs with real SQL builders that hit the\nexisting state.database.querySync path. The clean-server implementations\ndelegate to a `db_bridge.call(\"paginate\" | \"cursor_page\" | \"valid_field\")`\nabstraction that doesn't exist in node-server; these versions inline the\nSQL direct\n[…]\nng, cursor\npredicate, and has_more detection).\n\nCloses Step 8 items 1-3 in\nfoundation/management/cross-component-prompts/\n  all-host-bridge-parity-enforcement.md. Remaining: schedule, jobs,\nwebsocket.",
          "is_bot": false,
          "headline": "feat(bridge): implement _db_paginate, _db_cursor_page, _db_valid_field",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T04:14:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05185ef8f1098cd4df5a39856ad6230d96e0a611",
          "body": "…RTE002)\n\nThe _http_route and _http_route_protected bridges previously took a numeric\nhandler index and node-server reconstructed __route_handler_${index} at\ndispatch time. The framework actually passes the WASM export name as a\nstring (e.g. __route_handler_get__ping) per the function-registry.toml\n\n[…]\nts callHandler,\n  bridge/test.ts) look up exports[handlerName] directly.\n- New test guards against regressing the naming reconstruction.\n\nCloses RTE002, RTE002-FRAMEWORK (×2). 73/73 vitest tests pass.",
          "is_bot": false,
          "headline": "fix(router): dispatch handlers by export name, not sequential index (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T02:16:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "446286717ec35c56135906bed44197d20786f427",
          "body": "… gaps\n\nThree independent fixes uncovered while running tests:\n\n1. _test_http_request signature corrected to 10 raw (ptr, len) pairs.\n   Was using 5 length-prefixed pointers (readPrefixedString); the\n   compiler (wasmtime_runner.rs) and clean-server (bridge.rs:3347)\n   both emit/expect the 10-i32 fo\n[…]\nalidate which compiler v0.30.123+ no longer\n   emits. Required by tests/registry-coverage.test.ts (auto-alias\n   regression guard).\n\nTest suite: 72/72 passing (was 70/72 with 2 pre-existing failures).",
          "is_bot": false,
          "headline": "fix(bridge): correct _test_http_request ABI + close registry-coverage…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T00:30:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b98fad9a0ffb4043bf3d244053a5420f0b85265",
          "body": "…gination\n\nCloses the remaining 26 entries in the host bridge parity check; clean\nparity now reports 0 missing on node-server.\n\nNew files (throw-error stubs — apps using these features fail with a\nclear message instead of crashing during WASM linking):\n- bridge/jobs.ts        — 12 _job_* stubs\n- bri\n[…]\n\ndb field/paginate → cursor_page → schedule → jobs → websocket.\n\nStub bodies reference clean-server/src/{jobs,websocket,locale}.rs and\nhost-bridge/src/wasm_linker/database.rs as the porting reference.",
          "is_bot": false,
          "headline": "feat(bridge): add throw-error stubs for jobs/websocket/schedule/db-pa…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T00:17:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26e8f9a67f9fd715a9ae2c9337a5d23cb5dfe715",
          "body": "Closes 31 entries in the host bridge parity check against\nfoundation/platform-architecture/function-registry.toml:\n\n- storage (8): _storage_local_*, _storage_session_* — no-op stubs\n- UI helpers (12): _ui_focus, _ui_blur, _ui_get_focus, _ui_get_selection,\n  _ui_insert_at_cursor, _ui_text_diff, _ui_s\n[…]\noss-component-prompts/\n  all-host-bridge-parity-enforcement.md.\n\nRemaining 26 missing functions (jobs, websocket, db pagination,\nschedule) need real implementations and are tracked in the same prompt.",
          "is_bot": false,
          "headline": "feat(bridge): backfill missing storage/UI/build_state/i18n imports",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-15T23:27:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46eea56e1d43bf1f1e805fa0480a044c584f8dfd",
          "body": "…g (SRV005)\n\nSame fix as clean-server: loader.js reads data-wasm from its own script element\nto locate frontend.wasm. Without it the fallback is a relative path that 404s on\nroutes deeper than /. Injecting data-wasm=\"/frontend.wasm\" (absolute) fixes hydration\non all routes.",
          "is_bot": false,
          "headline": "fix(bridge): add data-wasm absolute path to injected loader script ta…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-13T04:00:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "221b665a4179b8f9fb0d7ab509bc3ee5fd2464cb",
          "body": "Closes 6 cross-server parity bugs against clean-server (commits bb37270,\na6dc693, 88565eb, 2d19719, efb38cd, 2c43399):\n\n- NSRV-ENV-ERROR: register env.error host import with LP-format signature\n  so compiled modules that propagate runtime errors instantiate cleanly\n- NSRV-HTTP-HEADERS: add http_put/\n[…]\nV002: serve /loader.js (from ~/.cleen/plugins/frame.ui/runtime\n  with embedded stub fallback) and /frontend.wasm (sibling-of-main-WASM\n  first, then CWD / public / dist) ahead of the Express catch-all",
          "is_bot": false,
          "headline": "fix(bridge): port clean-server fixes to close NSRV-* error reports",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-10T19:41:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae7c6cccb71fa166e10a44d44aa0217d3288c922",
          "body": "…ectives\n\nAdds _http_redirect_route bridge function (layer 3) that registers static\nredirect routes during WASM start() without generating a WASM handler function.\nMatches the signature in function-registry.toml:\n  (method_ptr, method_len, from_ptr, from_len, to_ptr, to_len, status) -> i32\n\nRouteReg\n[…]\nute\nentry. Server.handleRequest short-circuits on redirectTo routes, issuing the\nLocation header and status code directly without dispatching to the worker pool.\n\nResolves NODE-REDIRECT-ROUTE-MISSING.",
          "is_bot": false,
          "headline": "feat(bridge): implement _http_redirect_route for static redirect: dir…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-05T13:05:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dec28818611029e1dfa7441a48bc2446c3c8c92c",
          "body": "…e_body\n\nResolves SYNC-CANVAS-STUBS-MISSING: WASM modules with canvasScene: blocks\nemit imports for all 238 frame.canvas bridge functions even when running\nserver-side. Without host stubs, WebAssembly.instantiate fails with a\nLinkError. Added src/bridge/canvas-stubs.ts with no-op stubs whose\nsignatu\n[…]\n Mirrors the\nclean-server/src/bridge_canvas_stubs.rs pattern.\n\nAlso adds http_get_response_body (Layer 2 http_client), fixing the\npre-existing registry-coverage test failure.\n\nBumps version to 0.1.42.",
          "is_bot": false,
          "headline": "feat(bridge): add frame.canvas client-side stubs and http_get_respons…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-04T06:40:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7191f288c14f2140fb63bce2bd8237f03f8fd1b0",
          "body": "… _email_last_error\n\nFixes BRIDGE001, SRV-MISSING-BRIDGE, BRIDGE002 on the node server runtime.\nAll frame.server apps were failing at WASM instantiation because these four\nbridge functions declared in frame.server plugin.toml [bridge] were missing.\n\n- _res_download: sets Content-Disposition: attachm\n[…]\nfires async with\n  error captured in lastEmailError for _email_last_error to report\n- _email_last_error: returns error string from last failed send\n\nAlso removes unused camelToSnake helper from ui.ts.",
          "is_bot": false,
          "headline": "feat(bridge): implement _res_download, _email_configure, _email_send,…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-03T05:13:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d80a5069663d40a4ef526fc430debc1ca2da75f",
          "body": "Part A (§FEXT-4): Full SSE wire-protocol implementation.\n- _http_sse_route registers STREAM routes by exported handler name\n- _sse_emit, _sse_emit_event, _sse_close, _sse_retry, _sse_is_connected\n  backed by a dedicated per-connection SSE worker thread\n- Worker posts events via parentPort; main thre\n[…]\n,3,5): Browser-only no-op stubs for server-side WASM\ninstantiation — DOM query, DOM patching, iframe communication, drag data.\nAll stubs return 0 or satisfy the linker; never called at server runtime.",
          "is_bot": false,
          "headline": "feat(bridge): implement SSE bridge and browser-only UI stubs",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-02T15:37:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8891684693f4d095b0057543adfc73fc1adba38b",
          "body": "BRIDGE001: replace 4-param string_matches with 3-param version using\ncompile-time pattern IDs (0=email, 1=url, 2=uuid, 3=phone, 4=date,\n5=integer, 6=number, 7=alphanumeric); old signature read pattern as a\nruntime WASM string causing always-false results.\n\nBRIDGE002: add src/bridge/test.ts implementing _test_http_request,\n_test_response_status, and _test_response_body — in-process endpoint\ntest dispatch using the route registry and handle-map pattern.",
          "is_bot": false,
          "headline": "fix(bridge): implement BRIDGE001 and BRIDGE002 fixes",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-02T04:36:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8b87080203ce02deca30e76864908ddccb0fce7",
          "body": null,
          "is_bot": false,
          "headline": "feat(bridge): add mcp bridge source files missing from previous commit",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-01T01:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "702634c3c0c4a98728c9a3cbd50fb1bf9e476c6b",
          "body": "…_head_link\n\n_db_register_migration: update from 2-param (name only) to 6-param form\n(name, up_sql, down_sql as ptr+len pairs) to match frame.data plugin output.\nStore SQL strings alongside migration name; _db_run_migrations and\n_db_rollback_migration now execute stored SQL with WASM export fallback\n[…]\nmissing bridge function (was in function-registry\nbut not implemented in node server). Injects <link rel=stylesheet href=...>\ninto response head, deduplicated by href. Adds injectedLinks to WasmState.",
          "is_bot": false,
          "headline": "feat(bridge): fix _db_register_migration signature and add _ui_inject…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-01T01:08:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4f5637c88d2e403fdf76ae11fa3fd8822a26cdd",
          "body": "…BRIDGE001)\n\nRemoved JSON.parse() branch that was re-serializing valid JSON objects\nwithout outer quotes, causing parameterized SQL queries to receive an\nembedded object instead of a string literal.",
          "is_bot": false,
          "headline": "fix(bridge): json.encode() always serializes as JSON string literal (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-28T03:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa2258d2da7efeeb6bffe3aeff1a36f426200d45",
          "body": "… (NSR001)\n\nCompiler 0.30.155+ emits these as WASM imports in every module. Both are\nno-ops for the bump-allocator runtime but must be registered to allow\nWASM instantiation to succeed.\n\n[dev-queue-skipped: SRV001, SRV002 are clean-server issues, not node-server]",
          "is_bot": false,
          "headline": "fix(bridge): add _state_reset_all and _state_reset_named host imports…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-24T02:08:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ccac1a636dece5f7997047615b8bd1e086a8b2d",
          "body": "_ui_load_layout, _ui_load_page, and _ui_render_page previously constructed\npaths internally (app/pages/, app/layouts/), encoding frame.ui plugin\nconventions in the server layer. The first argument is now treated as a full\nrelative path from project root — path construction is the caller's\nresponsibility. Mirrors the same fix in clean-server.",
          "is_bot": false,
          "headline": "fix(bridge): UI template functions accept full relative paths (SRV001)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-23T20:24:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bebec5b7261b45973c5bccb3cb8b9f74f3c1a25",
          "body": "…UI_RENDER_PAGE_MISSING)\n\nframe.server plugin declares _ui_render_page as a bridge function for\nrender() and renderWith() DSL calls, but neither function was registered\nin the WASM imports object. WASM instantiation failed immediately with\n\"unknown import: env::_ui_render_page\".\n\nImplements _ui_rend\n[…]\ndata string.\nMissing keys produce an empty string. Includes path traversal protection.\n\nAlso registers _ui_load_page which was implemented in ui.ts since\nc5cd2ea but never wired into the bridge index.",
          "is_bot": false,
          "headline": "fix(bridge): add _ui_render_page and _ui_load_page host imports (SRV_…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-22T02:00:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "120cce4d46284f719e0e3a0e595b71a1e597fbde",
          "body": "Chrome 95+ and Firefox 103+ require 'wasm-unsafe-eval' in script-src to\nallow WebAssembly.compile() and WebAssembly.instantiate(). The previous\ndefault-src 'self' policy blocked all WASM loading in modern browsers.",
          "is_bot": false,
          "headline": "fix(security): add wasm-unsafe-eval to CSP script-src (CSP_BLOCKS_WASM)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-21T15:05:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50ea5099224d3fb3c5cbdd37155fbd669d64b75f",
          "body": "Compiler v0.30.134+ emits string_matches as a WASM import in all compiled\nmodules. Adds the implementation (sig: i32,i32,i32,i32 -> i32) to the string\nbridge and registers it in the env import object, preventing LinkError on\nWASM instantiation.",
          "is_bot": false,
          "headline": "fix(bridge): add string_matches host import (BRIDGE_MISSING_STDLIB)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-20T21:33:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ea369f74c2783c63a99817c7aee0041ab9bad25",
          "body": "…s (ASYNC001)\n\nResolves ASYNC001 — three async bridge functions were absent from the env\nimport object, causing WASM instantiation failures for modules that use\nbackground tasks or server sleep. Implements the same busy-wait pattern\nused by _time_sleep; _async_fire and _async_await are fire-and-forget stubs\nmatching the clean-server v1.9.11 fix.",
          "is_bot": false,
          "headline": "fix(bridge): add _async_fire, _async_await, _server_sleep host import…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-20T03:45:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dc30aa431da766343ac05ae370a439b460a5317",
          "body": "…FEAT001)\n\nAdds _ui_load_page to createUiBridge() in src/bridge/ui.ts, resolving\napp/pages/{name}.html with the same path-traversal guard used by\n_ui_load_layout. Closes the render() parity gap between clean-server\nand clean-node-server reported as FEAT001.",
          "is_bot": false,
          "headline": "feat(bridge): add _ui_load_page bridge function for render() parity (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-19T06:05:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5cd2eaf404c86005c9678460240639f2f5e1b68",
          "body": "Tests encoded the old broken convention (1=equal, 0=different).\nCompiler codegen emits i32.eqz after string_compare, requiring 0=equal,\nnon-zero=different. Updated to match the corrected bridge implementation.",
          "is_bot": false,
          "headline": "test(bridge-abi): update string_compare expectations to match spec",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T16:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1160e95be43ba0c7d51ea914998fad962b730211",
          "body": "…turn convention\n\nNSR002: _http_redirect signature was (urlPtr, urlLen, permanent) but compiler\nemits (status, urlPtr, urlLen) per function-registry.toml spec. Status is now\npassed directly instead of being derived from a boolean permanent flag.\nAdded separate _res_redirect(urlPtr, urlLen, status) i\n[…]\n: string_compare was returning 1 for equal, 0 for different. Compiler\ncodegen emits i32.eqz after calling string_compare, so it expects 0=equal,\nnon-zero=different. Inverted the return value to match.",
          "is_bot": false,
          "headline": "fix(bridge): correct _http_redirect param order and string_compare re…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T16:11:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a3b54da20e5ff511844bbe9648a4563efcf12b6",
          "body": "… bounds check, ui snake_case rename\n\nNSR001: sanitizeHeaderValue now strips all chars outside RFC 7230 obs-text range\n(tab, 0x20–0x7E, 0x80–0xFF), preventing U+FFFD and other Unicode chars that\nNode.js v22 rejects in HTTP headers.\n\nNSR002: writeLengthPrefixedString now validates ptr+totalSize <= bu\n[…]\nctHeadCss to _ui_load_layout/_ui_inject_head_css\nin ui.ts and index.ts to match plugin.toml [bridge] declarations — the compiler\nemits snake_case WASM imports matching the canonical plugin.toml names.",
          "is_bot": false,
          "headline": "fix(bridge): resolve NSR001/NSR002/NSR003 — header sanitization, heap…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T05:11:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ead96808127c2f82bbe58202db81000da2e4a878",
          "body": "…al names only\n\nThe compiler (v0.30.123) was fixed to emit only canonical _namespace_fn import\nnames. Dot-notation aliases (db.query, req.param, etc.) are no longer emitted as\nseparate WASM imports, so the auto-alias derivation loop in createBridgeImports()\nis dead code.\n\nRemove the loop. Update the\n[…]\n method imports that the compiler always emitted as dot-notation primaries\n(string.concat, math.sin, integer.toString, list.*, etc.) remain explicitly\nregistered — those are unaffected by this change.",
          "is_bot": false,
          "headline": "refactor(bridge): remove auto-alias loop — compiler now emits canonic…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T04:32:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d514c1c29930e16ede1a1478863634bf0c7620a",
          "body": "_auth_hash_password and _auth_verify_password were never canonical names.\nThe registry defines _crypto_hash_password and _crypto_verify_password.\nNo backward compatibility needed in a development project with a single spec.",
          "is_bot": false,
          "headline": "refactor(bridge): remove backward-compat crypto aliases",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:58:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d2537bc70bde52ce9ef26fc4af9806438818eec",
          "body": "…issing functions\n\nAdds a registry coverage test that reads function-registry.toml and verifies\nthe env object covers every canonical name and alias. Fixed all 43 gaps it found:\n\ncrypto.ts: renamed _auth_hash_password/_auth_verify_password to canonical\n_crypto_hash_password/_crypto_verify_password; \n[…]\nrd and\n_auth_verify_password pointing to renamed canonical functions.\n\ntests/registry-coverage.test.ts: parses module field to skip memory_runtime\nentries; checks every env-module canonical and alias.",
          "is_bot": false,
          "headline": "fix(bridge): full registry coverage — canonical names, aliases, and m…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:54:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f75809490b8a9747d9acc04717c0fae14115d6a9",
          "body": "…nent prompt format\n\nAdds a \"Bridge Function Naming\" section to CLAUDE.md explaining the dual\n_namespace_fn / namespace.fn registration requirement and pointing to\nHOST_BRIDGE.md for the full spec. Updates the cross-component prompt\nformat reference to point at the README instead of embedding a stale\ninline template.",
          "is_bot": false,
          "headline": "docs(bridge): document dual-naming requirement and update cross-compo…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:31:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b67de00959a697cdb496771234fedce3f48c750",
          "body": "…efixed bridge functions\n\nThe compiler emits WASM imports in both _namespace_fn and namespace.fn\nstyles for all bridge namespaces. The env object only registered underscore\nnames, causing LinkError on db.query, req.param, http.respond, etc.\n\nRefactors createBridgeImports() to build env as a named va\n[…]\nnt. Keys starting with __ (e.g. __stack_pointer) are skipped.\n\nCovers all namespaces: db, req, http, json, html, ui, session, auth,\ncrypto, file, and any future additions automatically.\n\nFixes NSR004.",
          "is_bot": false,
          "headline": "fix(bridge): auto-generate dot-notation aliases for all underscore-pr…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:08:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2da585eae44180331fa671d59cf934d5f65b0cb",
          "body": "The compiler generates both camelCase and snake_case dot-notation imports\nfor every frame.ui bridge function. The previous partial fix added camelCase\nstubs but left 29 snake_case variants uncovered, causing a LinkError on\nui.set_state (and others) at WASM instantiation.\n\nAdds camelToSnake() and a p\n[…]\n-build loop in createUiClientStubs() that\nderives snake_case aliases from all camelCase ui.* entries automatically.\nFuture bridge function additions stay in sync without manual listing.\n\nFixes NSR003.",
          "is_bot": false,
          "headline": "fix(bridge): auto-generate snake_case aliases for all ui.* client stubs",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T00:43:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8908755e96fa8dba0499246da21e9b075b496450",
          "body": "…ry pre-grow, ui client stubs\n\nNSR003: frame.ui 2.6.9 registers client-side bridge functions as WASM imports in\nserver builds. Add no-op stubs for all ui.* functions in createUiClientStubs()\nand spread them into the linker env — satisfies the linker without runtime overhead.\n\nNSR001: http.redirect()\n[…]\nffset is outside the\nbounds of the DataView\". Add preGrowMemory() (16 MB default) called at startup in\nboth server.ts and request-worker.ts so memory.grow() is never triggered during\nrequest handling.",
          "is_bot": false,
          "headline": "fix(bridge): resolve NSR001/NSR002/NSR003 — header sanitization, memo…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-17T23:43:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "290f9ffb80976996590a1a1dbdd6ef509854df07",
          "body": "…ring_split to LP-pointer ABI\n\nWASM calls these functions with one i32 LP-pointer per string argument\n(pointing to [4-byte LE length][UTF-8 content]). The previous (ptr, len,\nptr, len) signature misread the second LP-pointer as a length value, causing\nexponential memory growth and offset-out-of-boun\n[…]\nted call site expectation.\n\nAdds bridge-abi.test.ts with 12 ABI contract tests covering LP-pointer and\nraw ptr+len conventions across all four affected functions.\n\nFixes: NODE-STRING-BRIDGE-CONVENTION",
          "is_bot": false,
          "headline": "fix(bridge): switch string.concat, string_compare, string_replace, st…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T22:07:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "62c2349a6d0abe2646706f92bae323de4a4eb704",
          "body": "…mer into shutdown\n\nNODE-DB-BRIDGE-OOB: writeLengthPrefixedString, readLengthPrefixedString, and\nreadRawString each called memory.buffer multiple times. When WASM malloc causes\na memory.grow(), the old ArrayBuffer is detached and replaced. All reads and\nwrites now snapshot the buffer once after mall\n[…]\nver.start(), so it fired unconditionally 35 seconds\nafter startup regardless of whether shutdown was in progress. Moved into\nthe shutdown() handler so the watchdog only runs when a signal is received.",
          "is_bot": false,
          "headline": "fix(bridge): snap memory buffer once after malloc, move force-exit ti…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T19:58:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22a2684ca2c1b3fd3f87750e98bd5ec5b8525b03",
          "body": "The compiler exports handlers as __route_handler_0, __route_handler_1, ...\nin registration order. The WASM table index passed to _http_route is an\ninternal offset unrelated to the export naming scheme.\n\nRouteRegistry now maintains a sequential counter and stores it as the\nhandlerIndex, replacing the raw WASM table offset. Dispatch uses\n__route_handler_${handlerIndex} with the counter-based index.\n\nFixes NODE-HANDLER-DISPATCH-V2.",
          "is_bot": false,
          "headline": "fix(bridge): dispatch route handlers via sequential registration counter",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T17:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ebefc8d27eec7b579279fc30f4f78d942335442",
          "body": "…ort names\n\nThe compiler emits handler indices as function table offsets, not named\nexports. Constructing __route_handler_<N> / __handler_<N> export names\nnever matched anything in the WASM module.\n\nBoth callHandler() and request-worker.ts now use\n__indirect_function_table.get(handlerIndex) — the same pattern already\nused by the array bridge for callbacks.\n\nFixes NODE-HANDLER-DISPATCH.",
          "is_bot": false,
          "headline": "fix(bridge): dispatch route handlers via WASM function table, not exp…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T15:27:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f696b4a102e1be2346e247a9437cc9de9b66eb85",
          "body": "…pected\n\nstart() resolved the port as: port || getConfiguredPort() || this.config.port\ngetConfiguredPort() always returned truthy 3000 (its module-level default),\nso this.config.port (the parsed --port value) was never reached.\n\nPassing config.port explicitly makes the CLI flag win unconditionally.\n\nFixes NODE-PORT-FLAG-IGNORED.",
          "is_bot": false,
          "headline": "fix(server): pass config.port to server.start() so --port flag is res…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T15:02:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3352fb8fd439ba8a4d75654a3e5c8e16f873a1de",
          "body": "…e.js v22\n\nObject.create alone is insufficient: JS [[Set]] walks the prototype chain\nand throws TypeError when the prototype property is non-writable, even on\nthe shadow object. Object.defineProperty creates an OWN property directly,\nbypassing the prototype chain check entirely.\n\nFixes NODE-WASM-MALLOC-READONLY (complete fix, supersedes v0.1.12).",
          "is_bot": false,
          "headline": "fix(wasm): use Object.defineProperty to install malloc wrapper on Nod…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:56:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a89695e9c12d639be722d1b6446d1fa4d432375",
          "body": "Node.js v22 (V8) enforces that WebAssembly.Instance.exports properties\nare non-writable per spec. wrapMalloc() was assigning directly to\nexports.malloc, throwing TypeError on v22+.\n\nFixes NODE-WASM-MALLOC-READONLY by using Object.create(instance.exports)\nto create a shadow object — the wrapper becomes an own property while\nall other WASM exports remain accessible via the prototype chain.",
          "is_bot": false,
          "headline": "fix(wasm): shadow WASM exports to allow malloc wrapping on Node.js v22",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:51:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2eee5bf7c6bc5be1d59eee48bd5949a146500faa",
          "body": null,
          "is_bot": false,
          "headline": "chore(settings): update allowed commands",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:39:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859f850340226d98e0746a3d01b5e9ff6afa51f6",
          "body": "Implements SyncMysqlDriver using the same SharedArrayBuffer + Atomics\npattern as SyncPostgresDriver, with a mysql-worker thread handling async\nmysql2 operations. Adds mysql/mysql2 protocol cases to createDatabaseDriver.\n\nFixes FEATURE-NODE-MYSQL reported against 0.30.110.",
          "is_bot": false,
          "headline": "feat(database): add MySQL driver via worker-thread sync bridge",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:38:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7cdc68081e67671d497762fad26d4f9727ad62d",
          "body": "Register _html_escape, _html_raw, print_string, console_input, and\nall 29 math dot-notation aliases (math.sin, math.cos, etc.) that\nwere in the HOST_BRIDGE spec but not wired into the env import object.",
          "is_bot": false,
          "headline": "feat(bridge): add missing HOST_BRIDGE functions per spec",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-12T02:10:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 98,
      "commits_last_year": 118,
      "latest_release_at": "2026-07-18T11:44:03Z",
      "latest_release_tag": "v0.1.97",
      "releases_from_tags": true,
      "days_since_last_push": 5,
      "active_weeks_last_year": 19,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@ivan-pasco/clean-node-server",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "clean-language",
            "wasm",
            "webassembly",
            "server",
            "runtime"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@ivan-pasco/clean-node-server",
          "is_deprecated": false,
          "latest_version": "0.1.97",
          "repository_url": "https://github.com/Ivan-Pasco/clean-node-server",
          "versions_count": 93,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 4376,
          "first_published_at": "2026-01-25T02:57:33.837000Z",
          "latest_published_at": "2026-07-18T11:45:36.434000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 31875,
      "source_files_sampled": 122,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 5920
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "bcryptjs",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.3"
        },
        {
          "name": "better-sqlite3",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.0.0"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.0.0"
        },
        {
          "name": "compression",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.8.1"
        },
        {
          "name": "cookie-parser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.6"
        },
        {
          "name": "cors",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.6"
        },
        {
          "name": "express",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.2"
        },
        {
          "name": "express-rate-limit",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.4.1"
        },
        {
          "name": "ioredis",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.10.1"
        },
        {
          "name": "jsonwebtoken",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.2"
        },
        {
          "name": "mysql2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.9.0"
        },
        {
          "name": "nodemailer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.10"
        },
        {
          "name": "pg",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.11.3"
        },
        {
          "name": "pino",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.3.1"
        },
        {
          "name": "pino-http",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.0.0"
        },
        {
          "name": "prom-client",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Ivan-Pasco",
          "commits": 118,
          "avatar_url": "https://avatars.githubusercontent.com/u/137369164?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "nightly-canaries.yml",
        "publish.yml",
        "reporter-artifacts.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 4,
            "reason": "dependency not pinned by hash detected -- score normalized to 4",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 4,
            "reason": "6 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a4a5d694ff85b427b8dfa34d671e78ac6cbf45dd",
        "ran_at": "2026-07-23T19:09:07Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T08:46:10Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": [
        {
          "number": 1,
          "created_at": "2026-07-13T04:02:03Z",
          "last_comment_at": "2026-07-18T11:45:37Z",
          "last_comment_author": "github-actions"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Ivan-Pasco/clean-node-server",
    "host": "github.com",
    "name": "clean-node-server",
    "owner": "Ivan-Pasco"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 49,
      "inputs": {
        "security": 37,
        "vitality": 81,
        "community": 24,
        "governance": 31,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "commits_last_year": 118,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 19
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "19/52 weeks with commits",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 19
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "118 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 118
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 98,
              "latest_release_tag": "v0.1.97",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "98 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 98
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "@ivan-pasco/clean-node-server"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 4376
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,376 downloads/month across npm",
                "points": 48.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4376,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 31,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 32,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Ivan-Pasco",
              "public_repos": 10,
              "account_age_days": 1127
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of Ivan-Pasco",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "Ivan-Pasco"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~3 yr old",
                "points": 13.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@ivan-pasco/clean-node-server"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "93 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 93
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 37,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 4",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "6 existing vulnerabilities detected",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 62,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 5920
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 4",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 31875,
              "source_files_sampled": 122,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/122 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 122,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@ivan-pasco/clean-node-server@0.1.97; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T19:09:13.595025Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/Ivan-Pasco/clean-node-server.svg",
  "full_name": "Ivan-Pasco/clean-node-server",
  "license_state": "absent",
  "license_spdx": null
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.