Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 6673,
"has_wiki": false,
"homepage": null,
"languages": {
"CSS": 377163,
"HTML": 48520,
"Rust": 2787894,
"Shell": 2180,
"Python": 40870,
"JavaScript": 1798662
},
"pushed_at": "2026-07-21T16:05:49Z",
"created_at": "2026-04-12T06:33:57Z",
"owner_type": "User",
"updated_at": "2026-07-19T17:00:22Z",
"description": null,
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Rust",
"significant_languages": [
"Rust",
"JavaScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "User",
"login": "Ramenm",
"company": null,
"location": null,
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/43914741?v=4",
"created_at": "2018-10-06T18:22:27Z",
"is_verified": null,
"public_repos": 4,
"account_age_days": 2848
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.8.2",
"kind": "patch",
"published_at": "2026-07-19T17:00:05Z"
},
{
"tag": "v0.7.7",
"kind": "patch",
"published_at": "2026-06-25T18:44:19Z"
},
{
"tag": "v0.7.6",
"kind": "patch",
"published_at": "2026-06-25T18:25:28Z"
},
{
"tag": "v0.7.5",
"kind": "patch",
"published_at": "2026-06-25T17:55:52Z"
}
],
"recent_commits": [
{
"oid": "f7dafcc2909deb8398e3365df948c9800abd17a4",
"body": "Release MCPace 0.8.2",
"is_bot": false,
"headline": "Merge pull request #15 from Ramenm/release/0.8.2",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-19T17:00:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3bb4069887c66437c48a13daa77d5857f52c7d14",
"body": null,
"is_bot": false,
"headline": "Fix release URL assertion",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T10:28:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e34b0766fc0e6d4aa2e933bdb051d55d9c46628",
"body": null,
"is_bot": false,
"headline": "Fix non-Windows HTTP probe lint",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T10:01:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "43b3afb9723e8047f0d261db793d548f05d564c1",
"body": null,
"is_bot": false,
"headline": "Fix native installer placement and TCP test flakes",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T09:47:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "824a054daea9e081655d56e8a13469a9fb9d1d6d",
"body": null,
"is_bot": false,
"headline": "Fix Windows release verification",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T06:32:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "06364acd818ff7e73b975f2e3b4ab2871aa4b983",
"body": null,
"is_bot": false,
"headline": "Fix cross-platform release artifact proofs",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T06:00:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3a74b9228e32eb4b8405ea934788e0d87a519bc7",
"body": null,
"is_bot": false,
"headline": "Retry transient Windows lease lock contention",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T04:43:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d127c8cf9969334bd2baf1c0f6bb70add2d815d",
"body": null,
"is_bot": false,
"headline": "Harden Windows timeout proof diagnostics",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T04:00:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c28e390571a35c645eb30886616c37a026398dcb",
"body": null,
"is_bot": false,
"headline": "Fix release platform smoke and Rust timeout flake",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T03:30:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "000c633d5ade629500a0a7714b3bbda44a63a7a9",
"body": null,
"is_bot": false,
"headline": "Make assurance proof validation checkout independent",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T02:23:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6032a0abae0e2f730c2fc4880c33667e5d625478",
"body": null,
"is_bot": false,
"headline": "Fix cross-platform release CI proofs",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-18T01:02:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4b98043384ae98721669f54369400c95d4e1a8a",
"body": "Simplify the public command surface while preserving generated compatibility entrypoints, add ownership-safe status/uninstall and supervisor recovery proofs, and harden installer, report freshness, source archive, and publication gates.\\n\\nVerified locally with npm test/check, Rust fmt/clippy/302+4 \n[…]\nllel Rust runs, installed-binary/native-npm smoke, live MCP and source-bound release proofs, Gitleaks, Trivy, and npm audit. Unsigned OS installers remain draft-only; npm is the supported public lane.",
"is_bot": false,
"headline": "Release MCPace 0.8.2 CLI and lifecycle hardening",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-17T23:52:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "577f01ffd4075ea0f837eccc0953b103de16ec88",
"body": null,
"is_bot": false,
"headline": "Fix direct Linux stop without user bus",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-17T12:07:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba69ad89b937d04c7548c8ed8a960e567d76a046",
"body": null,
"is_bot": false,
"headline": "Harden supervised runtime lifecycle ownership",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-17T09:58:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d344f472bdad8dab0781bd99ac58a0cb70a38919",
"body": null,
"is_bot": false,
"headline": "fix: avoid Darwin probe timeout errors",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-16T20:33:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f8a15d8a0430145101b541ba2e406fb5c4bb6bf",
"body": null,
"is_bot": false,
"headline": "fix: preserve serve startup failure details",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-16T19:34:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d5cc0edb460627fd5e4b7d450483ddd1c89920ab",
"body": null,
"is_bot": false,
"headline": "fix: start packaged runtime on macOS",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-16T18:08:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5311669dd22b1535cc38958fbde4c66e66a9b585",
"body": null,
"is_bot": false,
"headline": "fix: unblock native release matrix",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-16T16:35:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "00081b65f598c6b0d6a01e6a6dcdca2fa3424dda",
"body": null,
"is_bot": false,
"headline": "test: make assurance portable to clean CI",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-16T15:31:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5cc55bcb1c6d81b19411cc64ca2a0605b5d92d20",
"body": null,
"is_bot": false,
"headline": "fix: make user autostart supervision reliable",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-16T15:13:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24458e75641b4eb54ecf3e7e7375f02c23719898",
"body": null,
"is_bot": false,
"headline": "release: prepare MCPace 0.8.0",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-15T07:18:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8d164c4eae8864a43a11a3173c10fa20e233d288",
"body": "The Windows autostart fix reached GitHub at 0.7.8, but npm cannot republish an existing latest version. Bump the workspace, Cargo crate, npm launcher, native optional dependency pins, lockfiles, and project config to 0.7.9 so the main publish workflow can produce a real latest package containing the\n[…]\n autostart verify --json --root .\nTested: MCP initialize POST returned HTTP 200 and serverInfo.version 0.7.9\nNot-tested: npm latest publication before push; requires GitHub trusted publishing workflow",
"is_bot": false,
"headline": "Release the autostart repair as a new npm latest version",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-06T05:39:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "845ca44672fe59cec26895c5c2c3deebaee5281c",
"body": "Windows Run entries could be configured correctly while the current MCP endpoint was still down, and launching the foreground agent path from login could leave a console-hosted process model. The autostart target now uses an agent start path on Windows, which delegates to the existing hidden serve s\n[…]\nTested: MCP initialize POST to http://127.0.0.1:39022/mcp returned HTTP 200\nNot-tested: Actual Windows logoff/login cycle; current-user Run entry was verified in registry and by current-session repair",
"is_bot": false,
"headline": "Keep Windows MCPace autostart hidden and live",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-06T05:25:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb79f06baea22aa79786479b4080cf111850bf4c",
"body": "The release hygiene tests exercised a local cleanzip helper that was excluded from Git, so clean GitHub checkouts failed while the local workspace passed. Track the helper and narrow persistent environment helpers to Windows so Linux clippy sees no dead platform-only code.\n\nConstraint: CI runs from \n[…]\nsts/node/source-archive-hygiene.test.mjs tests/node/source-archive-policy.test.mjs\n\nTested: npm run check:rust\n\nTested: npm run check:ci\n\nNot-tested: GitHub Actions rerun before this commit is pushed.",
"is_bot": false,
"headline": "Keep CI release hygiene self-contained",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-05T17:59:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3b1034c59ec23a59d32dff8559fe83182adc3ca4",
"body": "The project had moved to the new direct MCPace Agent login model, but the local\nWindows startup state still had the old wscript/VBS entry and the release gates\nwere catching stale generated/compat artifacts. This hardens autostart install\nand verify around the real login item, removes obsolete compa\n[…]\nrun check:ci\nTested: npm run check:rust\nTested: npm run build\nTested: target/release/mcpace.exe autostart verify --json --root .\nNot-tested: Full OS reboot/login cycle after the Run entry was enabled.",
"is_bot": false,
"headline": "Make login startup dependable across release checks",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-05T17:49:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8048339a04902771e782dbb7213a963ebce67eda",
"body": "After the stable native packages became visible in the npm registry, npm ci started validating omitted optional workspace lockfile entries more strictly. The lockfile stubs now carry the release version while still avoiding hoisted native packages in source installs, and the source-bundle test mirro\n[…]\npm@11.16.0 -- npm ci --ignore-scripts --no-audit --no-fund --omit=optional\n\nTested: npm run check:rust\n\nTested: node --test tests/node/supply-chain-policy.test.mjs tests/node/docs-and-package.test.mjs",
"is_bot": false,
"headline": "Keep post-publish source installs valid",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T09:59:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "97bcabe490d56e27fe394ff07053997637013a1f",
"body": "The 0.7.8 source bump made workspace optional native package ranges point at a version that has to be built by the publish workflow before it exists in npm. Source CI should install only locked dev tooling, while the publish job builds and contract-checks native tarballs separately.\n\nConstraint: Nat\n[…]\nTested: npm run check:security-policy\nTested: npm run check:package\nNot-tested: Local check:publish-contract pass without GitHub-built native tarballs; local run correctly blocked on missing tarballs.",
"is_bot": false,
"headline": "Keep release installs independent of unpublished native packages",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T09:31:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78f5a1f8bae99b51a85dda5a770d5b8492996901",
"body": "The dev lane proved the release workflow, trusted publishing, npm install, version reporting, diagnostics, and Windows autostart against the npm binary. Bumping source metadata lets the main branch publish the same code as stable latest automatically instead of skipping the already-published 0.7.7 v\n[…]\nted: npm run check; npm run check:package; npm run pack:npm:dry-run; npm run check:rust; npm view @mcpace/cli@0.7.8 returned E404 before bump.\nNot-tested: main-branch stable publish before merge/push.",
"is_bot": false,
"headline": "Prepare a stable 0.7.8 npm release",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T09:18:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ffb88bc7da3ed97375590bbaf4bd6c5d2dcb7595",
"body": "Node 24 warns when a child process uses shell:true together with an argument array. MCPace terminal diagnostics only need fixed npm probes, so Windows now routes them through cmd.exe explicitly without enabling Node's shell option.\n\nConstraint: Windows npm is exposed as npm.cmd, but diagnostics must\n[…]\ne.js --mcpace-npm-diagnostics --json; npm run check:workflow-policy; npm run check:security-policy; npm run check:publish-trust\nNot-tested: Fresh npm registry install of this exact commit before push.",
"is_bot": false,
"headline": "Keep npm diagnostics warning-free on current Node",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T09:06:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3917cf3603e2cb65ce7fd96180445cc989e41e7d",
"body": "Windows autostart can resolve a local MCPace root even when a user invokes the npm-installed binary from elsewhere. Using mcpace.config.json for --version therefore made a freshly published dev binary look stale. The version command now reports the compiled package version while doctor remains the p\n[…]\nrun check:publish-trust; target/release/mcpace.exe --version with MCPACE_ROOT pointing at config version 999.999.999\nNot-tested: CI rebuild/publish of the new dev package before this commit is pushed.",
"is_bot": false,
"headline": "Make npm-installed MCPace report its actual binary version",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T08:58:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "610cf36b708efaafdf4846873d3e1d356d2800d6",
"body": "The npm registry requires package-side trust relationships for every published package, including native optional packages. Add a bulk helper around npm trust github so a maintainer can authenticate once and configure all MCPace packages without repeated UI clicks.\n\nConstraint: npm trust requires np\n[…]\nm run check; npm run check:workflow-policy; npm run check:security-policy\nNot-tested: npm run npm:trust:configure against npm because this session is not logged in to npm and cannot satisfy owner 2FA.",
"is_bot": false,
"headline": "Automate npm trusted publisher bootstrap",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T08:41:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "70f1d8dde567ede720eb019773c7d01eaf55c0c9",
"body": "OpenSSF Scorecard only supports the default branch outside pull requests, so manual proof runs from dev must not turn that third-party limitation into a repository failure. CodeQL still runs on dev dispatches while Scorecard remains active for pull requests and the default branch.\n\nConstraint: ossf/\n[…]\ncheck:security-policy; npm run check:publish-trust; node scripts/run-node-tests.mjs --quiet tests/node/project-hygiene.test.mjs\nNot-tested: GitHub security workflow rerun after this commit before push",
"is_bot": false,
"headline": "Keep dev security dispatch from false failing",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T07:41:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5f5d4767ab462c4727a285833b9c5feee0510834",
"body": "The publish workflow previously exported NODE_AUTH_TOKEN from a missing repository secret, which left an empty token in the publish environment. npm then attempted token auth and failed before OIDC trusted publishing could authenticate the GitHub-hosted workflow. Remove the token fallback and tighte\n[…]\neck:publish-trust; npm run check:workflow-policy; npm run check:security-policy; node scripts/run-node-tests.mjs --quiet; npm run check:ci\n\nNot-tested: Real npm OIDC publish after this workflow change",
"is_bot": false,
"headline": "Let npm trusted publishing own release authentication",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T07:24:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "97837d2d9b2dcfbae2f509a0dfe0ea5e13cb51c3",
"body": "The npm publish workflow now runs full Rust checks inside the Ubuntu glibc baseline image before native tarballs are published. That image previously lacked node, so dashboard upstream tests failed for an environmental reason rather than a product regression. Install the distro nodejs package in tha\n[…]\nn check:rust; MCPACE_GLIBC_BASELINE_CHECKS=full bash scripts/build-linux-glibc-baseline.sh for x86_64-unknown-linux-gnu\n\nNot-tested: GitHub-hosted linux-arm64 baseline rerun before pushing this commit",
"is_bot": false,
"headline": "Keep Linux release baseline tests faithful",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T07:14:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bdf9375991b154c8034c90eafed86ff205cdd593",
"body": "The published npm package did not update after main merged because publish-npm only supported manual dry-runs and tag-shaped gates, while the 0.7.7 registry package predated the Windows autostart fix. Add an explicit publish planner so dev branch pushes produce unique prerelease versions on the dev \n[…]\nll run blocks.\nTested: npm run check:ci; npm run check:rust; npm run build; npm run platform:binary-smoke\nNot-tested: Live npm publish from GitHub Actions will be verified after merging this workflow.",
"is_bot": false,
"headline": "Automate npm release channels without stale package reuse",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T07:03:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72c0425829aa69217b5a5d2977cd2d224c7d04e9",
"body": "Windows Startup folder shortcuts show up as command scripts, which made MCPace look like an accidental .cmd autostart entry. Store the launch command in the per-user Run registry key instead and clean up the legacy Startup-folder file on enable/disable.\n\nConstraint: Windows users should see a named \n[…]\nat/auto-launch/Cargo.toml\n\nTested: cargo test --manifest-path crates/compat/auto-launch/Cargo.toml --locked\n\nTested: cargo check --locked\n\nNot-tested: rebuilt release binary and reboot autostart smoke",
"is_bot": false,
"headline": "Make Windows autostart register as MCPace",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-07-03T06:18:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "13722af758bd149f26afa489e56458f01e700ed0",
"body": "GitHub-hosted Windows jobs check out the repository on D: while temporary directories can live on C:. The release completion tests were joining report paths against the repo root unconditionally, which corrupted absolute paths emitted from cross-drive temporary output directories.\n\nConstraint: Relea\n[…]\nreport paths as absolute when they are absolute; only join repoRoot for relative report paths.\nTested: node --test tests/node/release-completion.test.mjs\nTested: npm run check\nTested: git diff --check",
"is_bot": false,
"headline": "Keep release tests portable across Windows runner drives",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-26T08:56:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "204b7486f4ff3390b48ecf292c37ee2ddbef580c",
"body": "The release flow needed to stop treating archives as the main user-download artifact while still avoiding a risky custom self-updater. This makes npm the recommended install/update path, builds installable GitHub assets for every enabled native target, lowers the Linux glibc floor with an Ubuntu 22.\n[…]\n packed native npm tarball proof\nNot-tested: Live GitHub-hosted Windows MSI signing, macOS notarization, and non-dry-run npm/GitHub publication require external credentials and protected environments.",
"is_bot": false,
"headline": "Make installable releases the safe public path",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-26T08:47:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3870ac5e90d92078ab1aa1ab919b6c35e57ba26",
"body": "After the native packages were published, npm could fully resolve optional platform packages during npm ci. The lockfile now records those real package entries, and negative resolver tests explicitly ignore installed optional packages so they keep testing missing-binary behavior instead of depending\n[…]\n explicitly rather than relying on absent node_modules entries\nTested: npm ci --ignore-scripts --no-audit --no-fund; npm run check; npm run check:package; npm run check:install-smoke; git diff --check",
"is_bot": false,
"headline": "Keep CI installs compatible with published native packages",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T19:10:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92636fa1f2130352479a220b917ecd78c05212b7",
"body": "The regression builds native package tarballs into the OS temp directory. GitHub Windows runners can place that temp directory on a different drive than the checkout, so path.relative returns a drive-qualified path that must not be joined back under the repository root.\n\nConstraint: Windows CI temp \n[…]\nry | would increase cleanup risk and couple the test to workspace write state\nConfidence: high\nScope-risk: narrow\nTested: node tests/node/npm-publish-contract.test.mjs; npm run check; git diff --check",
"is_bot": false,
"headline": "Keep native tarball regression portable across Windows runners",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T19:03:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd4cae09b8ed7bc6057f3efd4d3029f430b3a978",
"body": "The first published native packages also claimed a mcpace bin entry, which caused npm to skip creating the launcher shim during a normal install. Native packages now only provide platform binaries while @mcpace/cli remains the sole user-facing command owner, and the release is bumped because 0.7.6 i\n[…]\nun check:publish-trust; npm run check:workflow-policy; npm run check:security-policy; cargo check --locked; focused native tarball regression\nNot-tested: Fresh registry install of 0.7.7 before publish",
"is_bot": false,
"headline": "Ensure npm installs create the mcpace command",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T18:44:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8c6d0809d1fd97a6fa8b98b29974b9333ebe025",
"body": "The first npm publication showed that the launcher package metadata was correct but the packed bin shim lacked executable mode, so fresh installs on Windows did not create the mcpace command until npm rebuild. Keep the bin shim executable in git, add a regression check for that release property, and\n[…]\nrust; npm run check:workflow-policy; npm run check:security-policy; npm run check; cargo check --locked; git diff --check\n\nNot-tested: Fresh install of 0.7.6 from npm until tag-gated publish completes",
"is_bot": false,
"headline": "Restore npm launcher command creation",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T18:25:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a60e7f9e30b5bb6e6c544dc49b9fbde74de9f818",
"body": "The first scoped npm publish cannot rely only on trusted publishing because npm package settings exist only after package creation. Add repository/provenance metadata to the launcher and generated native packages, then permit a narrowly scoped protected-environment token fallback for this bootstrap \n[…]\n; npm run check:publish-trust; npm run check:workflow-policy; npm run check:security-policy; npm run check; git diff --check\n\nNot-tested: Real npm publish until the tag-gated GitHub workflow completes",
"is_bot": false,
"headline": "Prepare npm packages for first trusted-release bootstrap",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T17:55:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f990262fd792886d566a7cf72a540270149aa2ca",
"body": "The manual npm dry-run proved that the publish job downloaded generated\nnative tarballs before running the clean source test suite. That polluted the\nworkspace state expected by the publish-contract regression test and would\nbreak the release lane before the actual contract enforcement step.\n\nConstr\n[…]\nr artifact download\nTested: npm run check; npm run check:workflow-policy; npm run check:security-policy; npm run check:publish-trust; git diff --check\nNot-tested: GitHub publish-npm dry-run after push",
"is_bot": false,
"headline": "Keep publish validation independent of staged native tarballs",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T17:31:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a13303226639a89c20eef869bbd83f770e41bb7",
"body": "The publish workflow previously skipped every job when manually dispatched\nfrom main, which made the safest pre-release package proof impossible without\nfirst creating a release tag. Keep real publication tag-gated, but allow the\nmanual dry-run path to build native packages and exercise npm publish\n\n[…]\nted: npm run check; npm run check:workflow-policy; npm run check:security-policy; npm run check:publish-trust; npm run check:package; git diff --check\nNot-tested: GitHub publish-npm dry-run after push",
"is_bot": false,
"headline": "Allow npm publish dry-runs before cutting release tags",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T17:24:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52fe15cfab7ccea4a5279de7978fc1a8145e8d84",
"body": "The manual platform proof workflow now pins macOS to explicit release runner images and adds an Intel macOS Rust smoke lane, matching the release target split more closely than a single moving macos-latest label.\n\nConstraint: GitHub warned that macos-latest is migrating to macOS 26, which can silent\n[…]\ncheck; manual platform-proof run 28186596161 passed before this pinning change on Linux/macOS/Windows.\nNot-tested: New macos-15-intel lane after this commit until GitHub Actions reruns platform-proof.",
"is_bot": false,
"headline": "Stabilize macOS platform proof coverage",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T17:00:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d4c9a3e6cea557fc7c2d66ee0b0809050d40588",
"body": "The release path now treats MCPace as one generic local Streamable HTTP broker for Codex, Cursor, Claude-family, and other supported local MCP clients while hardening the surrounding install, restart, package, dashboard, and proof surfaces.\n\nThis keeps compatibility generic instead of pinning behavi\n[…]\nrowser; isolated temp HOME client install for 10 local targets; git diff --cached --check.\nNot-tested: Native macOS LaunchAgent execution; real cloud public relay; GitHub branch protection after push.",
"is_bot": false,
"headline": "Make MCPace reliable across local client installs and managed restarts",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-25T16:43:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "283a9e8e94ed7d925b432789d0f16f240f6415f1",
"body": "The Rust adapter tests use tiny Node-based stdio MCP mocks for upstream tools/list coverage. Hosted Windows rust jobs did not install Node, so those mocks produced an empty catalog and made the main CI fail even though product code and local checks passed. The rust matrix now installs the repo Node \n[…]\nl assumptions explicit in both CI setup and test guards\n\nTested: cargo fmt --check; cargo test -- --test-threads=1; npm run check; git diff --check\n\nNot-tested: GitHub hosted Windows rerun before push",
"is_bot": false,
"headline": "Keep Windows Rust CI running upstream mock tests",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-14T14:30:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9b2d5f4dd58c816e6016dcc940eb7fbda2c76237",
"body": "Windows autostart can launch from WScript or Explorer without the current shell environment, which left MCPACE_MCP_SETTINGS invisible after login and made rootless serve commands fail outside the repo. The change teaches the autostart launcher to hydrate persistent MCPace env vars from the registry \n[…]\nuser-specific paths or settings defaults\n\nTested: cargo fmt --check; cargo test; git diff --check; rootless serve status from home with source-built binary\n\nNot-tested: Full Windows reboot/login cycle",
"is_bot": false,
"headline": "Make Windows MCPace restart survive user environment drift",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-14T14:13:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab31356be8750560e6b0aa06a5d9710978eb74ac",
"body": "The Windows hosted Rust runner exposed that the parallel projection test\nassumed the auto upstream worker count would be at least two. On constrained\nrunners available_parallelism can be one, so the peer-gated fake upstreams\nrun sequentially and both return no tools.\n\nThe test now scopes MCPACE_UPST\n[…]\nts that require upstream fan-out must force their worker budget instead of relying on available_parallelism.\nTested: npm run check:rust\nNot-tested: GitHub-hosted Windows Rust after this follow-up push",
"is_bot": false,
"headline": "Make parallel-probe Rust test independent of runner CPU count",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-06T20:34:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b4e8be991b578bc36d1be6d5046a5bd9d29b69e3",
"body": "The hosted Rust job uncovered that several Rust tests exercise local HTTP listeners and short-lived stdio upstream processes. Running the lib suite with the default parallel harness can race those live probes on constrained runners, producing unrelated catalog misses even when the implementation is \n[…]\nect-hygiene.test.mjs tests/node/platform-proof.test.mjs\nTested: npm run check\nTested: npm run check:package\nTested: npm run pack:npm:dry-run\nNot-tested: GitHub-hosted Rust CI after this follow-up push",
"is_bot": false,
"headline": "Stabilize Rust CI around live runtime tests",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-06T20:27:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "016ff28f98ccdfa0cddd6471882305981724fa88",
"body": "The Windows node matrix was checking out Cargo.lock with CRLF because the repository only pinned common source extensions to LF. The docs/package metadata test intentionally compares Cargo.lock content with LF-sensitive Rust metadata, so lockfiles need to be covered by the same repository text polic\n[…]\ne/docs-and-package.test.mjs tests/node/project-hygiene.test.mjs\nTested: npm run check\nTested: npm run check:package\nTested: npm run pack:npm:dry-run\nNot-tested: GitHub-hosted Windows runner after push",
"is_bot": false,
"headline": "Make hosted Windows CI honor lockfile LF policy",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-06T20:14:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2eb60e83766ca7a61bc8e68e0b71eeb02069e48c",
"body": "After adding LF rules for .mjs and HTML, switching branches on Windows still materialized .gitattributes itself with CRLF because the named control files were only covered by text=auto. The hygiene gate checks those names directly, so they need explicit LF attributes as well.\n\nConstraint: core.autoc\n[…]\nfile type/name to the LF hygiene gate, add a matching .gitattributes rule in the same change.\n\nTested: node --test tests/node/project-hygiene.test.mjs\n\nNot-tested: Fresh clone on another Windows host.",
"is_bot": false,
"headline": "Keep repository control text files LF on Windows",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-06T20:05:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9cac4effd250b3cf89a05179ebcfbd4b6a7f1194",
"body": "Fast-forwarding main on a Windows checkout exposed that .mjs scripts and the dashboard HTML were not covered by the repository LF attributes. With core.autocrlf enabled, Git can materialize those files with CRLF and make the project hygiene gate fail before push.\n\nConstraint: The repository enforces\n[…]\nt-hygiene's line-ending gate covered by .gitattributes.\n\nTested: node --test tests/node/project-hygiene.test.mjs\n\nNot-tested: Hosted GitHub runners; this is a local Windows checkout normalization fix.",
"is_bot": false,
"headline": "Keep generated JavaScript and dashboard sources LF on Windows",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-06T20:03:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5e4a811687f665e2830527de8cb63994e4255492",
"body": "Node 24 on Windows can reject direct spawnSync of npm.cmd with EINVAL, which made the full release proof fail even though the underlying npm commands worked from the shell. Route npm script invocations through the current npm CLI entrypoint when available, and keep a cmd.exe fallback only for Window\n[…]\n: npm run proof:local -- --full\n\nTested: npm run check:rust\n\nTested: npm run check:ci\n\nTested: npm run build:release-artifacts\n\nNot-tested: npm publish blocked pending platform binary package tarballs",
"is_bot": false,
"headline": "Keep Windows local proof from spawning npm shims directly",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-06T19:59:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ef0e56c57e25f2df7104c308ef34226a8ab7478",
"body": "Windows verification exposed a release-build borrow issue, Rust 1.95\nclippy/rustfmt drift, and stale guardrail expectations. The runtime smoke\nalso showed that upstream server definitions such as browser and playwright\nmust remain in user MCP settings while the repository config stays focused on\nMCP\n[…]\nindows MCP runtime smoke with sequential-thinking upstream_search/upstream_call and tools/list cache hit checks\nNot-tested: External/browser-desktop upstream tool execution and publish/release dry-run",
"is_bot": false,
"headline": "Keep MCPace Windows runtime usable without bundling personal upstreams",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-06-05T13:29:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5ca29ee3214b853da44ae25c4e324a6c797be2f",
"body": "…ntation and scripts.",
"is_bot": false,
"headline": "Remove stale report files and update release manifest with new docume…",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-29T19:44:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee5d07d5e3222a0c211f14b0a03b9503f0cec1fe",
"body": "The server cards now expose the useful per-server actions without making\nusers reason through worker internals, and the dashboard backend now handles\nthose actions through the existing dynamic mcpace server commands instead of\nstatic or per-server shortcuts.\n\nConstraint: UI actions must work for arb\n[…]\n cargo check --package mcpace\nTested: node scripts/cargo-task.mjs fmt --check; git diff --check\nTested: live 39022 healthz refresh ok, server-autotune empty POST 200, ABP process count 0 after restart",
"is_bot": false,
"headline": "Make dashboard server controls act on real MCPace state",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-26T21:09:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b1953265271c4bbbc3768304f5e74c69d97a7c47",
"body": "The dashboard was guessing server purpose and the upstream pool only cleaned idle child processes lazily. This change makes server rows derive capability text from backend/source/tools-list evidence and exposes generic pool eviction in runtime status so process cleanup applies across pooled stdio MC\n[…]\ns test\n\nTested: node scripts/cargo-task.mjs test dashboard\n\nTested: node scripts/cargo-task.mjs fmt --check\n\nTested: live 39022 health shows upstreamSessionPool evictedIdleCount and zero ABP processes",
"is_bot": false,
"headline": "Make MCP server controls evidence-driven",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-26T20:26:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d95b86b8eb206ee4721cf7872f471376e22e718f",
"body": "This pass turns the local hub toward the scheduler niche: discover likely MCP\nservers, infer conservative runtime/effect classes, expose policy/instance\nsurfaces, and ship a lab corpus that keeps auto mode auditable. It also fixes\nrelease-only Windows load stability found during final validation by \n[…]\npm run pack:npm:dry-run; npm publish --workspace @mcpace/cli --dry-run --json; npm run build:release-artifacts; npm run check\nNot-tested: Real npm publish, because npm authentication is not configured",
"is_bot": false,
"headline": "Make MCPace prove safe automatic runtime scheduling",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-26T12:45:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f44b73610097cc739602795b70360a4f05ab5f4",
"body": null,
"is_bot": false,
"headline": "Remove manager.settings.json and centralize helper functions",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-25T17:12:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ad5ee0d551b433e3d2ab0d110571763b5d71d1f",
"body": "…tracking",
"is_bot": false,
"headline": "Add strict MCP JSON-RPC validation, lifecycle gating, and request ID …",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-23T13:19:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1a3bfbee254ec499a8ce477f331d357dc30d49a",
"body": "The source tree is trimmed to the public MCPace runtime and npm launcher surface while preserving the local Windows restart path through a stable cargo-installed native binary. The bundled checks now validate manifest-declared source paths instead of treating a normal git checkout as a release archi\n[…]\ntion; /healthz readiness probe.\n\nNot-tested: Full Windows logout/login reboot cycle; GitHub-hosted CI because repository intentionally avoids paid hosted CI.\n\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
"is_bot": false,
"headline": "Ship a lean verified source surface",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-20T06:26:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7f3533342a831267a363d9f73e6a26ac05d46d5f",
"body": "Promotes the final automation quiet-state cleanup into main through PR flow.\n\nConstraint: User wants no stale PRs, no automatic paid GitHub Actions, and no hanging repository state.\nRejected: Leave security/codeql schedules active | they still create skipped check noise on a private repo without ena\n[…]\nling or a self-hosted runner is intentionally configured.\nTested: npm run ci:local:quick\nNot-tested: Manual GitHub workflow dispatch after future runner setup\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
"is_bot": false,
"headline": "Promote quiet automation cleanup to main",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-19T14:36:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1fc5a72c9e4c45742589336c4c3637c31e8c91ad",
"body": "Makes the remaining hosted workflows manual-only and pauses Dependabot version PR creation. This removes automatic skipped/failing check noise while preserving explicit workflow dispatch for later GitHub Actions setup.\n\nConstraint: User wants no hanging GitHub noise and does not want paid hosted Act\n[…]\nor a trusted self-hosted runner.\nTested: npm run ci:local:quick\nTested: git diff --check\nNot-tested: Manual GitHub workflow dispatch after future runner setup\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
"is_bot": false,
"headline": "Keep GitHub automation quiet until runners are intentional",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-19T14:35:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45768872e7bc41deaa450c0ebf633c48bad1729f",
"body": "Brings the locally verified dev branch into main through the normal pull-request path while preserving the dev branch for continued work.\n\nConstraint: User asked to avoid paid GitHub-hosted Actions and run CI locally instead.\nConstraint: Branch protection/status-check enforcement is not available on\n[…]\npromotion into main after local CI passes.\nTested: npm run ci:local\nNot-tested: GitHub-hosted Actions, intentionally manual-only to avoid paid runner minutes.\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
"is_bot": false,
"headline": "Promote locally verified dev to main",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-19T14:29:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c7670d14b5ec738f7b73f898401fc1a27f44e5d4",
"body": "Moves the default repository quality gate to local commands and keeps GitHub-hosted Actions as explicit manual proof lanes. This prevents private-repo pushes and pull requests from starting paid GitHub runners while preserving a cloud validation path when billing is intentionally enabled.\n\nThe local\n[…]\ns.\nTested: npm run hooks:install\nTested: npm run ci:local\nTested: git diff --cached --check\nNot-tested: Manual GitHub workflow dispatch after billing recovery\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
"is_bot": false,
"headline": "Avoid paid hosted CI for normal repository sync",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-19T14:20:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "71096d349e1a5b753862e22dd0549bfb0ba4b1d0",
"body": "Reworks the public source snapshot around evidence-backed MCP install, overhead, and runtime-validation lanes. The change removes stale preset-era artifacts, refreshes reports and docs, adds targeted MCP overhead and race coverage, and keeps local/public publication decisions separated.\n\nThe adapter\n[…]\nce upstream_search and browser dashboard smoke against localhost:39022\nNot-tested: npm/native package publication and optional cargo audit/deny advisory lanes\nCo-authored-by: OmX <omx@oh-my-codex.dev>",
"is_bot": false,
"headline": "Prepare MCPace for evidence-first public source sync",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-19T14:04:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb1c2b678a6b6a72268afcca65b9c0ddf7d2b7d8",
"body": "…dynamic source policies\n\nThis commit refactors upstream tool validation to work with session pools by moving validation after lease acquisition and passing the pool to validation functions. It introduces dynamic source policy inference based on server characteristics (name, command, URL) to replace\n[…]\nd script updates in package.json\n\nThe core refactor enables safer, more flexible upstream server handling by decoupling tool validation from lease acquisition and making source policies context-aware.",
"is_bot": false,
"headline": "refactor: implement session pooling for upstream tool validation and …",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-17T19:04:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "12d9c229b66e65b6769548aefae0d08a05ea4881",
"body": null,
"is_bot": false,
"headline": "Add Playwright E2E test script for dashboard",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-16T19:48:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3e3d0fc45e15411ea8f919981d8a68ba24207f4f",
"body": "…exposure guards, message-integrity hardening, and upstream resilience improvements",
"is_bot": false,
"headline": "chore: bump version to 0.6.0 and implement lifecycle hardening, tool …",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-15T18:36:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e8ebc6ec80e91470d3dbf52d19a71cc1f092ccb3",
"body": "The adapter now keeps the default auto tools/list path cache-only and\nfalls back to broker tools when the upstream catalog is cold or stale,\nwhile serve warms a persistent tools/list cache in the background. The\nraw catalog path still supports native/hybrid/refresh modes, but probes\ncallable upstre\n[…]\n; cargo check; cargo clippy --all-targets -- -D warnings; cargo test; live mcpace serve MCP smoke with tools/list in 60ms\nNot-tested: Long-running multi-day cache aging beyond schema/fingerprint tests",
"is_bot": false,
"headline": "Prevent DA clients from timing out on large upstream MCP catalogs",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-14T10:16:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c162d52c632d47e6c397ba44fd7a0ec6e9a1414",
"body": "MCPace was treating every upstream as a short-lived direct child, which left Windows launcher descendants alive for npx-based servers and made Docker/Bun launchers sensitive to absolute shim paths. This keeps upstream registration config-driven while hardening stdio process-tree cleanup, adding a se\n[…]\n docker mcp gateway server test (8 tools); serve restart/status warnings empty; leak check 0.\n\nNot-tested: Direct HTTPS upstream without stdio/TLS adapter; heavyweight docker image-specific run smoke.",
"is_bot": false,
"headline": "Stabilize dynamic MCP upstream launch paths",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-13T17:00:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "94085d7b488ff4546ed09941637985d1b8b5c212",
"body": "Defaulting top-level tool exposure to broker keeps initial tools/list small and avoids probing every configured upstream MCP server during client startup. Native projected tools remain available through explicit MCPACE_TOOL_EXPOSURE=auto|hybrid|native for clients that need them.\n\nThe doctor now trea\n[…]\ne-syntax.mjs --json; node scripts/mcpace-full-doctor.mjs --json\nNot-tested: Non-Codex clients that deliberately rely on implicit top-level projected upstream tools without setting MCPACE_TOOL_EXPOSURE",
"is_bot": false,
"headline": "Prevent MCPace startup fan-out from stalling clients",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-11T13:31:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "941040cd246dec0682247dd5b1a86ac6e5ac3244",
"body": "Merged with local verification because GitHub-hosted checks did not start due to the account billing/spending-limit blocker.\n\nLocal evidence for head 23673f5002653cb28accc9cf7d662500bbe37f84:\n- npm run test:repo: pass (39/39)\n- npm run test:rust:ci: pass\n- npm run doctor:full: exit 0 with warnings o\n[…]\nargo check -p mcpace: pass\n- code/security review blockers resolved\n\nHosted CI blocker annotation: jobs were not started because recent account payments failed or spending limit needs to be increased.",
"is_bot": false,
"headline": "Merge verified MCPace dev proof lane",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-11T12:26:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23673f5002653cb28accc9cf7d662500bbe37f84",
"body": "The local tree had accumulated machine-state artifacts and Linux verification work that needed to be made safe before updating the dev branch. This commit keeps private client/runtime state out of the source snapshot, adds a Linux auto-check/doctor surface with durable evidence, and preserves Window\n[…]\n run verify:secrets; npm run verify:npm-pack; npm test; cargo check -p mcpace; targeted linux-auto contract test\nNot-tested: Linux Docker full auto-check on a real Linux host from this Windows session",
"is_bot": false,
"headline": "Harden local readiness before syncing the public proof lane",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-11T12:16:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f90d27b2e7d6d1221f849c597e1a974690e1e58e",
"body": "The local readiness sweep found two integration-contract drifts: adapter_profile advertised token reducers that strict pluginPolicy could not accept, and disabled source-only MCP servers made health/readiness look failed even though they were intentionally disabled.\n\nThis checkpoint keeps the fix, r\n[…]\nlive smoke; healthz readyForRuntimeOps true; git diff --check\n\nNot-tested: npm/native public publication and GitHub release were not run; optional third-party supply-chain scanners are still warnings.",
"is_bot": false,
"headline": "Stabilize MCPace plugin and readiness gates",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-04T13:25:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eb1b705b984cdf2ad73b649ac11b579326de7461",
"body": "The repo was technically ready for a source-preview opening, but one client-surface test used a literal private-key marker as fake redaction input. That could create confusing GitHub secret-scanning noise after making the repository public. Replace it with a non-secret test redaction block while kee\n[…]\nracked-file secret pattern scan returned 0 provider/private-key matches\\nTested: git diff --check\\nNot-tested: full npm test, full Cargo suite, GitHub secret scanning UI after public visibility change",
"is_bot": false,
"headline": "Reduce public-readiness friction before opening the repo",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T18:16:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6e62afaf33643bc82568adda2271ec7062354ec1",
"body": "The product-practice gate had a compiled binary and tiny upstream fixture available, but runtime-trace still stopped at a manual checklist. The harness now runs a bounded local proof by spawning a temporary MCPace serve process, calling initialize and tools/list over HTTP MCP, then calling upstream_\n[…]\ntract.test.js tests/node/product-truth-contract.test.js\\nTested: git diff --check\\nNot-tested: full npm test, full Cargo test/build, multi-host runtime proof, real external client compatibility traces",
"is_bot": false,
"headline": "Prove the local MCP broker loop before adding more surface",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T17:32:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d22a7e3321b38dfbc471b34605b644e6e65dc3d6",
"body": "The second full_ci run proved Docker cleanup was fixed, but left two\ncorrectness gaps: Windows archive listings still needed platform-neutral\nentry handling, and the full Docker proof was asserting a stdio-owned plan\neven though the default distribution intentionally has no upstream servers.\nThe pro\n[…]\ncontract.test.js tests/node/archive-contract.test.js\nTested: npm test\nTested: node scripts/verify-ubuntu-docker-full.mjs --json\nNot-tested: Re-dispatched full GitHub CI after this proof alignment fix.",
"is_bot": false,
"headline": "Make full CI proofs match portable default artifacts",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T16:40:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7139c645535a543f3a2e95399d487cc4d6ff8415",
"body": "The real full_ci GitHub run proved the cheap path was not enough: Windows\nhosted source tests found zip entries created with platform separators, and\nUbuntu Docker lanes passed their checks but left root-owned bind-mount files\nthat the host runner could not remove. The Docker proof scripts now resto\n[…]\nive-contract.test.js\nTested: node scripts/verify-ubuntu-docker-fast.mjs --json\nTested: node scripts/verify-ubuntu-docker-e2e.mjs --json\nNot-tested: Re-dispatched full GitHub CI after this cleanup fix.",
"is_bot": false,
"headline": "Make full GitHub CI lanes clean up after themselves",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T16:03:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7a383f251c585cc8d8e7ac2264962030463044ae",
"body": "The GitHub run reached Linux rust-tests and exposed a Windows-specific\nplaceholder assertion. A Rust-only Docker proof also showed that the\ndashboard upstream smoke should not fail before test intent when node is not\ninstalled. This keeps the CI path platform-neutral while preserving the real\nupstre\n[…]\n -- -D warnings\nTested: npm test\nTested: docker run --rm -v ${PWD}:/work -w /work rust:1.95-bookworm bash -c 'cargo test --locked --lib'\nNot-tested: Re-dispatched GitHub CI after this portability fix.",
"is_bot": false,
"headline": "Keep Rust tests portable in CI and Rust-only containers",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T15:37:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "113dce32ab1a83b9d4c1f53f82ac7f3185a515f3",
"body": "The GitHub run reached the real Rust quality gate after the setup-node cache fix\nand then exposed two Linux-only clippy failures: the Unix-only upstream test did\nnot import the stdio spawn helper, and the POSIX detach closure nested an\nunnecessary unsafe block. Windows local clippy could not see the\n[…]\nm test\nTested: docker run --rm -v ${PWD}:/work -w /work rust:1.95-bookworm bash -c 'cargo clippy --all-targets --locked -- -D warnings'\nNot-tested: Re-dispatched GitHub CI after this Linux clippy fix.",
"is_bot": false,
"headline": "Make Linux clippy prove the pushed CI branch",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T15:07:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "07097aa6dcd852a37fecf42aed87c924365e5b4c",
"body": "The first dispatched CI run proved the budget split worked because all expensive\nfull-ci lanes were skipped, but setup-node failed immediately on jobs that had no\nnpm lockfile to cache. MCPace currently has no package-lock.json, so automatic\npackage-manager caching must stay disabled anywhere setup-\n[…]\nts/node/stack-contract.test.js tests/node/rust-test-runner-contract.test.js\nTested: git diff --check\nNot-tested: Re-dispatched GitHub CI after this fix; previous run failed at setup-node before tests.",
"is_bot": false,
"headline": "Prevent GitHub setup-node from failing before tests",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T14:56:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bf3af5f0492cac8a0ce5033ee8e56fcdd0a546ba",
"body": "The default workflow was proving too much on every pull request: full Windows,\nmacOS, Rust, Docker, and release dry-run lanes all competed for hosted minutes\nbefore a change was release-shaped. This keeps fast confidence on normal pushes\nand pull requests while preserving explicit full-proof paths f\n[…]\nff --check\nTested: git ls-remote confirmed actions/checkout@v6 and actions/setup-node@v6 tags exist upstream\nNot-tested: Actual GitHub-hosted workflow execution; requires pushing the branch to GitHub.",
"is_bot": false,
"headline": "Keep GitHub CI useful without burning hosted minutes",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T14:50:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b79f8c272867c34795fefcf279d31b3e5713f291",
"body": "This change completes the client-first runtime lane: MCPace can install one\nlocalhost Streamable HTTP entry into supported local clients, onboard useful\nBYO MCP servers through preset/starter fragments, expose live upstream tools\nthrough broker and projected MCP tools, and keep source/release eviden\n[…]\ne-final-20260502T141338Z.json\nNot-tested: Actual macOS host execution; verified macOS contracts/matrix only.\nNot-tested: Published native npm install from registry; package mode remains thin-launcher.",
"is_bot": false,
"headline": "Make MCPace client-first runtime usable across local clients",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-02T14:37:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04e5d7814684c184eca697cc76041e567942fb8b",
"body": "A live CLI sweep found that `mcpace --version` failed even though the binary\nsupports `mcpace version`. The npm launcher forwards user flags directly, so\ncommon package-manager and smoke-test probes should not trip over this alias.\n\nConstraint: Keep the Rust command surface minimal while supporting \n[…]\noot version_flag_aliases_version_command -- --exact\nTested: cargo run --quiet -- --version\nTested: cargo run --quiet -- -V\nTested: npm run verify:rust-quality\nTested: npm test\nTested: git diff --check",
"is_bot": false,
"headline": "Support standard version flags for CLI smoke checks",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-01T13:42:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5a4c2f7beb4bc73034cd44a0b813757f15ec7892",
"body": "MCPace now commits to one local adapter endpoint with generic upstream\nbrokering, source-only MCP server discovery from user mcp_settings.json,\nand no bundled upstream server recommendations by default.\n\nThis also tightens the proof boundary around runtime hardening: explicit\nenvironment allowlistin\n[…]\ndiff --check\nNot-tested: Published npm provenance proof.\nNot-tested: GitHub Release publication.\nNot-tested: macOS/Linux real-host runtime from this Windows host.\nNot-tested: HTTP upstream forwarding.",
"is_bot": false,
"headline": "Make MCPace a verifiable BYO local MCP runtime",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-05-01T13:33:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72d64b061d746c1f379c75b2dd1996beb139a3be",
"body": "MCPace now keeps the Codex-visible tool surface small without hiding what is\nactually proxied. The runtime exposes explicit upstream discovery, policy audit,\npolicy suggestions, guarded upstream calls, batch/session routing, and a\nsurface manifest that distinguishes native MCPace tools from configur\n[…]\nanifest, upstream_policy_audit, upstream_policy_suggest, browser guard/batch smoke, windows-mcp guarded PowerShell smoke\nNot-tested: Linux/macOS real-host runtime lanes and public/cloud relay surfaces",
"is_bot": false,
"headline": "Make MCPace honest and safe as the local MCP gateway",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-28T21:52:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6d0a1faebf5a874db00bb975f433e599a90db255",
"body": "This change closes the practical local gaps around client install,\nrestore, runtime lease forwarding, and proof truth. It adds previewable\ninstalls and rollback backups, gates upstream wrapper calls with\nscheduler leases, heartbeat-renews short-TTL calls, refuses stale\nresponses after lease loss, co\n[…]\nm run prove:local; npm run prove:report; git diff --check\nNot-tested: real-host runtime proof across Windows/macOS/Linux; GitHub/npm publish provenance proof; durable pooled-session takeover semantics",
"is_bot": false,
"headline": "Make MCPace safer to run without manual recovery",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-28T09:42:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c3654215254cee5a6bd75e24a02d50972e310b6",
"body": "Snapshot the verified local MCPace working tree onto a GitHub-backed branch.\nThis keeps client startup behind stable MCPace management tools while adding\nruntime/client hardening, npm release lanes, evidence reports, and the latest\nupstream bridge improvements: explicit upstream catalog/call/batch t\n[…]\n npm run test:repo; npm run lint:npm; cargo +stable build --release; live HTTP MCP upstream_catalog and upstream_probe cache smoke at http://127.0.0.1:39022/mcp\nNot-tested: GitHub-hosted CI after push",
"is_bot": false,
"headline": "Make MCPace native runtime and upstream bridge releasable",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-27T18:49:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "756a6259debc41d47eac34ff4534c7ef0304c209",
"body": "The GitHub repository had an unrelated older history, so this merge keeps that\nhistory reachable while making the current Rust-first one-server MCPace tree the\npublished mainline. Conflicting legacy files were resolved in favor of the\ncurrent local implementation so the remote ends up with the verif\n[…]\nble cargo test -q\nTested: npm test\nTested: rustup run stable cargo build --release\nNot-tested: Manual inspection of every historical remote-only file beyond the ones excluded by current repo contracts",
"is_bot": false,
"headline": "Preserve GitHub history while publishing the new one-server MCPace",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-21T20:36:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cdbee04e7efde0fcf6ef7fc932968ec4a554c070",
"body": "This change finishes the local one-server direction: MCPace now centers on a\nsingle localhost MCP URL, a managed serve lifecycle, and HTTP-first client\ninstall/export/plan flows instead of per-client launcher drift. The client\nsurfaces, docs, dashboard/help text, and verification now line up around \n[…]\nclient plan --json --root . --client-id hermes-agent\nNot-tested: Fresh interactive session validation in every supported client UI\nNot-tested: Cloud/public relay surfaces and blocked connector classes",
"is_bot": false,
"headline": "Make MCPace the one local HTTP server for supported clients",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-21T20:29:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "87d1d585a2143ded0557d1f49c97b185972ebb88",
"body": "The workspace arrived without git metadata, so this commit snapshots the\ncurrent Rust-only repo locally and removes ambiguity about the exact\nchecked state. While verifying the snapshot, Windows hub launch tests\nexposed a background-start path that left `hub up` hanging under\ncaptured stdio; the lau\n[…]\n\nNot-tested: bare `cargo test` under this machine's `rust-toolchain.toml` override, because the local 1.95.0 rustup override is misconfigured even though `+stable` resolves to Rust 1.95.0 successfully",
"is_bot": false,
"headline": "Capture a verified local baseline for mcpace",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-21T13:24:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "49269071e74873ba3fd86064d4b19517cc691da4",
"body": "The top-level verification entrypoints were already present, but the reusable\nscenario catalog should live in its own module so both the scripts and the\nreporting surface can share one definition of what the repo claims to verify.\n\nConstraint: Verification scripts and reports should derive their sce\n[…]\nd of copying them into scripts or docs\nTested: Module restored into the reconstructed tree before final verification rerun\nNot-tested: Scenario-by-scenario behavioral review beyond the full test suite",
"is_bot": false,
"headline": "Extract reusable verification scenarios once the CI lane is in place",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-12T20:54:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2b31568d563ae8f621f6e85e1fe5a9c0afa1bbc4",
"body": "Finish the timeline with the public-facing README, contributor guidance, and summary reports once the runtime, verification, and audit surfaces have settled into the shape that should be presented to other people.\n\nConstraint: Public-facing repo narrative should trail the implementation and verifica\n[…]\nas a distilled view of the verified repository surface\nTested: Final narrative files reviewed against the current repository contents\nNot-tested: External contributor onboarding against the final docs",
"is_bot": false,
"headline": "Refresh the public MCPace narrative after the baseline stabilizes",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-12T14:27:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c31e649c3d7d5b2ef460d62b9150d893c8e482f",
"body": "Integrate the separate report stream without flattening it so the main line shows that the baseline, artifacts, and explanatory reports arrived as a parallel documentation effort.\n\nConstraint: Audit work should read as a distinct lane rather than generic follow-up edits\nRejected: Re-commit reports l\n[…]\nnce: medium\nScope-risk: narrow\nDirective: Keep evidence-oriented reporting distinguishable from stable product documentation\nTested: Merge completed cleanly\nNot-tested: Re-rendered reports after merge",
"is_bot": false,
"headline": "Merge the audit lane after the reporting baseline is coherent",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-11T20:41:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63c200c859f52b484f3bb8ec5e8fb0204ca918d2",
"body": "Extend the reporting lane with the latest generated verification artifacts so the repository keeps an evidence snapshot of what the launcher actually produced at this stage.\n\nConstraint: Verification artifacts are evidence snapshots and should travel with the audit narrative that produced them\nRejec\n[…]\nerated audit artifacts as time-bound evidence, not evergreen documentation\nTested: Artifacts reviewed for consistency with the recorded baseline\nNot-tested: Fresh regeneration after later code changes",
"is_bot": false,
"headline": "Publish verification artifacts alongside the verified baseline",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-11T12:18:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a06d8345744aaa5b6439c3c8eff629569209f04d",
"body": "…able\n\nStart a separate reporting lane for the reproducible baseline so the narrative of audit work remains visible instead of being flattened into general documentation updates.\n\nConstraint: Audit-style reports should preserve their own cadence and context\nRejected: Fold audit results into generic \n[…]\nports dated and evidence-oriented instead of rewriting them into timeless docs\nTested: Reports reviewed against the current launcher and verification behavior\nNot-tested: Independent third-party audit",
"is_bot": false,
"headline": "Record the security and stability baseline once behavior looks repeat…",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-10T18:49:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d3290d5004ffbcf90c1d37f5693ba292415cc820",
"body": "Add CODEOWNERS once the collaboration and verification surfaces are present so future changes route to a clear owner instead of relying on implicit knowledge.\n\nConstraint: Ownership metadata is useful only after the repo has enough surface to review meaningfully\nRejected: Add ownership in the first \n[…]\nw\nDirective: Keep ownership mappings aligned with the reviewable surface of the repository\nTested: Ownership file reviewed for repo scope coverage\nNot-tested: Live code-owner review requests on GitHub",
"is_bot": false,
"headline": "Make repository ownership explicit before wider sharing begins",
"author_name": "Ramenm",
"author_login": "Ramenm",
"committed_at": "2026-04-10T11:27:00Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 4,
"commits_last_year": 116,
"latest_release_at": "2026-07-19T17:00:05Z",
"latest_release_tag": "v0.8.2",
"releases_from_tags": true,
"days_since_last_push": 3,
"active_weeks_last_year": 17,
"days_since_latest_release": 5,
"mean_days_between_releases": 8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": false,
"has_contributing": false,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 10
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"Cargo.toml"
],
"largest_source_bytes": 429592,
"source_files_sampled": 353,
"oversized_source_files": 11,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"Cargo.toml",
"package.json"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 146,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"crates",
"npm"
],
"dependencies": [
{
"name": "auto-launch",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.6"
},
{
"name": "getrandom",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.3"
},
{
"name": "serde",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "serde_json",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1"
},
{
"name": "which",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "8"
},
{
"name": "clap",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "4"
},
{
"name": "ureq",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "3.3.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "auto-launch",
"direct": true,
"version": "0.6.0",
"ecosystem": "crates"
},
{
"name": "clap",
"direct": true,
"version": "4.6.1",
"ecosystem": "crates"
},
{
"name": "getrandom",
"direct": true,
"version": "0.2.17",
"ecosystem": "crates"
},
{
"name": "getrandom",
"direct": true,
"version": "0.3.4",
"ecosystem": "crates"
},
{
"name": "serde",
"direct": true,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_json",
"direct": true,
"version": "1.0.150",
"ecosystem": "crates"
},
{
"name": "ureq",
"direct": true,
"version": "3.3.0",
"ecosystem": "crates"
},
{
"name": "which",
"direct": true,
"version": "8.0.4",
"ecosystem": "crates"
},
{
"name": "android_system_properties",
"direct": false,
"version": "0.1.5",
"ecosystem": "crates"
},
{
"name": "anstream",
"direct": false,
"version": "1.0.0",
"ecosystem": "crates"
},
{
"name": "anstyle",
"direct": false,
"version": "1.0.14",
"ecosystem": "crates"
},
{
"name": "anstyle-parse",
"direct": false,
"version": "1.0.0",
"ecosystem": "crates"
},
{
"name": "anstyle-query",
"direct": false,
"version": "1.1.5",
"ecosystem": "crates"
},
{
"name": "anstyle-wincon",
"direct": false,
"version": "3.0.11",
"ecosystem": "crates"
},
{
"name": "base64",
"direct": false,
"version": "0.22.1",
"ecosystem": "crates"
},
{
"name": "bitflags",
"direct": false,
"version": "2.13.0",
"ecosystem": "crates"
},
{
"name": "block2",
"direct": false,
"version": "0.6.2",
"ecosystem": "crates"
},
{
"name": "bytes",
"direct": false,
"version": "1.12.1",
"ecosystem": "crates"
},
{
"name": "cc",
"direct": false,
"version": "1.2.66",
"ecosystem": "crates"
},
{
"name": "cesu8",
"direct": false,
"version": "1.1.0",
"ecosystem": "crates"
},
{
"name": "cfg-if",
"direct": false,
"version": "1.0.4",
"ecosystem": "crates"
},
{
"name": "cfg_aliases",
"direct": false,
"version": "0.2.1",
"ecosystem": "crates"
},
{
"name": "clap_builder",
"direct": false,
"version": "4.6.0",
"ecosystem": "crates"
},
{
"name": "clap_derive",
"direct": false,
"version": "4.6.1",
"ecosystem": "crates"
},
{
"name": "clap_lex",
"direct": false,
"version": "1.1.0",
"ecosystem": "crates"
},
{
"name": "colorchoice",
"direct": false,
"version": "1.0.5",
"ecosystem": "crates"
},
{
"name": "combine",
"direct": false,
"version": "4.6.7",
"ecosystem": "crates"
},
{
"name": "core-foundation",
"direct": false,
"version": "0.10.1",
"ecosystem": "crates"
},
{
"name": "core-foundation-sys",
"direct": false,
"version": "0.8.7",
"ecosystem": "crates"
},
{
"name": "dirs",
"direct": false,
"version": "6.0.0",
"ecosystem": "crates"
},
{
"name": "dirs-sys",
"direct": false,
"version": "0.5.0",
"ecosystem": "crates"
},
{
"name": "dispatch2",
"direct": false,
"version": "0.3.1",
"ecosystem": "crates"
},
{
"name": "find-msvc-tools",
"direct": false,
"version": "0.1.9",
"ecosystem": "crates"
},
{
"name": "heck",
"direct": false,
"version": "0.5.0",
"ecosystem": "crates"
},
{
"name": "http",
"direct": false,
"version": "1.4.2",
"ecosystem": "crates"
},
{
"name": "httparse",
"direct": false,
"version": "1.10.1",
"ecosystem": "crates"
},
{
"name": "is_terminal_polyfill",
"direct": false,
"version": "1.70.2",
"ecosystem": "crates"
},
{
"name": "itoa",
"direct": false,
"version": "1.0.18",
"ecosystem": "crates"
},
{
"name": "jni",
"direct": false,
"version": "0.21.1",
"ecosystem": "crates"
},
{
"name": "jni-sys",
"direct": false,
"version": "0.3.1",
"ecosystem": "crates"
},
{
"name": "jni-sys",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "jni-sys-macros",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "libc",
"direct": false,
"version": "0.2.186",
"ecosystem": "crates"
},
{
"name": "libredox",
"direct": false,
"version": "0.1.18",
"ecosystem": "crates"
},
{
"name": "log",
"direct": false,
"version": "0.4.33",
"ecosystem": "crates"
},
{
"name": "memchr",
"direct": false,
"version": "2.8.2",
"ecosystem": "crates"
},
{
"name": "nix",
"direct": false,
"version": "0.31.3",
"ecosystem": "crates"
},
{
"name": "objc2",
"direct": false,
"version": "0.6.4",
"ecosystem": "crates"
},
{
"name": "objc2-cloud-kit",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-core-data",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-core-foundation",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-core-graphics",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-core-image",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-core-location",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-core-text",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-encode",
"direct": false,
"version": "4.1.0",
"ecosystem": "crates"
},
{
"name": "objc2-foundation",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-io-surface",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-quartz-core",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-security",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-service-management",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-ui-kit",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "objc2-user-notifications",
"direct": false,
"version": "0.3.2",
"ecosystem": "crates"
},
{
"name": "once_cell",
"direct": false,
"version": "1.21.4",
"ecosystem": "crates"
},
{
"name": "once_cell_polyfill",
"direct": false,
"version": "1.70.2",
"ecosystem": "crates"
},
{
"name": "openssl-probe",
"direct": false,
"version": "0.2.1",
"ecosystem": "crates"
},
{
"name": "option-ext",
"direct": false,
"version": "0.2.0",
"ecosystem": "crates"
},
{
"name": "os_info",
"direct": false,
"version": "3.15.0",
"ecosystem": "crates"
},
{
"name": "percent-encoding",
"direct": false,
"version": "2.3.2",
"ecosystem": "crates"
},
{
"name": "proc-macro2",
"direct": false,
"version": "1.0.106",
"ecosystem": "crates"
},
{
"name": "quote",
"direct": false,
"version": "1.0.46",
"ecosystem": "crates"
},
{
"name": "r-efi",
"direct": false,
"version": "5.3.0",
"ecosystem": "crates"
},
{
"name": "redox_users",
"direct": false,
"version": "0.5.2",
"ecosystem": "crates"
},
{
"name": "ring",
"direct": false,
"version": "0.17.14",
"ecosystem": "crates"
},
{
"name": "rustls",
"direct": false,
"version": "0.23.41",
"ecosystem": "crates"
},
{
"name": "rustls-native-certs",
"direct": false,
"version": "0.8.4",
"ecosystem": "crates"
},
{
"name": "rustls-pki-types",
"direct": false,
"version": "1.15.0",
"ecosystem": "crates"
},
{
"name": "rustls-platform-verifier",
"direct": false,
"version": "0.6.2",
"ecosystem": "crates"
},
{
"name": "rustls-platform-verifier-android",
"direct": false,
"version": "0.1.1",
"ecosystem": "crates"
},
{
"name": "rustls-webpki",
"direct": false,
"version": "0.103.13",
"ecosystem": "crates"
},
{
"name": "same-file",
"direct": false,
"version": "1.0.6",
"ecosystem": "crates"
},
{
"name": "schannel",
"direct": false,
"version": "0.1.29",
"ecosystem": "crates"
},
{
"name": "security-framework",
"direct": false,
"version": "3.7.0",
"ecosystem": "crates"
},
{
"name": "security-framework-sys",
"direct": false,
"version": "2.17.0",
"ecosystem": "crates"
},
{
"name": "serde_core",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_derive",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "shlex",
"direct": false,
"version": "2.0.1",
"ecosystem": "crates"
},
{
"name": "smappservice-rs",
"direct": false,
"version": "0.1.3",
"ecosystem": "crates"
},
{
"name": "strsim",
"direct": false,
"version": "0.11.1",
"ecosystem": "crates"
},
{
"name": "subtle",
"direct": false,
"version": "2.6.1",
"ecosystem": "crates"
},
{
"name": "syn",
"direct": false,
"version": "2.0.118",
"ecosystem": "crates"
},
{
"name": "thiserror",
"direct": false,
"version": "1.0.69",
"ecosystem": "crates"
},
{
"name": "thiserror",
"direct": false,
"version": "2.0.18",
"ecosystem": "crates"
},
{
"name": "thiserror-impl",
"direct": false,
"version": "1.0.69",
"ecosystem": "crates"
},
{
"name": "thiserror-impl",
"direct": false,
"version": "2.0.18",
"ecosystem": "crates"
},
{
"name": "unicode-ident",
"direct": false,
"version": "1.0.24",
"ecosystem": "crates"
},
{
"name": "untrusted",
"direct": false,
"version": "0.9.0",
"ecosystem": "crates"
},
{
"name": "ureq-proto",
"direct": false,
"version": "0.6.0",
"ecosystem": "crates"
},
{
"name": "utf8-zero",
"direct": false,
"version": "0.8.1",
"ecosystem": "crates"
},
{
"name": "utf8parse",
"direct": false,
"version": "0.2.2",
"ecosystem": "crates"
},
{
"name": "walkdir",
"direct": false,
"version": "2.5.0",
"ecosystem": "crates"
},
{
"name": "wasi",
"direct": false,
"version": "0.11.1+wasi-snapshot-preview1",
"ecosystem": "crates"
},
{
"name": "wasip2",
"direct": false,
"version": "1.0.4+wasi-0.2.12",
"ecosystem": "crates"
},
{
"name": "webpki-root-certs",
"direct": false,
"version": "1.0.8",
"ecosystem": "crates"
},
{
"name": "webpki-roots",
"direct": false,
"version": "1.0.8",
"ecosystem": "crates"
},
{
"name": "winapi-util",
"direct": false,
"version": "0.1.11",
"ecosystem": "crates"
},
{
"name": "windows-link",
"direct": false,
"version": "0.2.1",
"ecosystem": "crates"
},
{
"name": "windows-registry",
"direct": false,
"version": "0.6.1",
"ecosystem": "crates"
},
{
"name": "windows-result",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "windows-strings",
"direct": false,
"version": "0.5.1",
"ecosystem": "crates"
},
{
"name": "windows-sys",
"direct": false,
"version": "0.45.0",
"ecosystem": "crates"
},
{
"name": "windows-sys",
"direct": false,
"version": "0.52.0",
"ecosystem": "crates"
},
{
"name": "windows-sys",
"direct": false,
"version": "0.61.2",
"ecosystem": "crates"
},
{
"name": "windows-targets",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows-targets",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_aarch64_gnullvm",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_aarch64_gnullvm",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_aarch64_msvc",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_aarch64_msvc",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_i686_gnu",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_i686_gnu",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_i686_gnullvm",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_i686_msvc",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_i686_msvc",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_x86_64_gnu",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_x86_64_gnu",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_x86_64_gnullvm",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_x86_64_gnullvm",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "windows_x86_64_msvc",
"direct": false,
"version": "0.42.2",
"ecosystem": "crates"
},
{
"name": "windows_x86_64_msvc",
"direct": false,
"version": "0.52.6",
"ecosystem": "crates"
},
{
"name": "wit-bindgen",
"direct": false,
"version": "0.57.1",
"ecosystem": "crates"
},
{
"name": "zeroize",
"direct": false,
"version": "1.9.0",
"ecosystem": "crates"
},
{
"name": "zmij",
"direct": false,
"version": "1.0.21",
"ecosystem": "crates"
},
{
"name": "@mcpace/cli",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@mcpace/cli-darwin-arm64",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@mcpace/cli-darwin-x64",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@mcpace/cli-linux-arm64-gnu",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@mcpace/cli-linux-x64-gnu",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@mcpace/cli-win32-arm64-msvc",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@mcpace/cli-win32-x64-msvc",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@publint/pack",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "mri",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "package-manager-detector",
"direct": false,
"version": "1.6.0",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "publint",
"direct": false,
"version": "0.3.21",
"ecosystem": "npm"
},
{
"name": "sade",
"direct": false,
"version": "1.8.1",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 146,
"direct_count": 8,
"indirect_count": 138
}
},
"maintainership": {
"issues": {
"open_prs": 10,
"merged_prs": 6,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 5
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "Ramenm",
"commits": 116,
"avatar_url": "https://avatars.githubusercontent.com/u/43914741?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"codeql.yml",
"linux-auto.yml",
"performance.yml",
"platform-proof.yml",
"publish-npm.yml",
"release-dry-run.yml",
"release.yml",
"security.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Cargo.lock",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/19 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "f7dafcc2909deb8398e3365df948c9800abd17a4",
"ran_at": "2026-07-25T15:52:03Z",
"aggregate_score": 6.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T16:05:08Z",
"oldest_open_prs": [
{
"number": 10,
"created_at": "2026-07-16T15:17:05Z",
"last_comment_at": "2026-07-16T15:17:06Z",
"last_comment_author": "dependabot"
},
{
"number": 11,
"created_at": "2026-07-16T15:17:05Z",
"last_comment_at": "2026-07-16T15:17:06Z",
"last_comment_author": "dependabot"
},
{
"number": 12,
"created_at": "2026-07-16T15:17:09Z",
"last_comment_at": "2026-07-16T15:17:10Z",
"last_comment_author": "dependabot"
},
{
"number": 13,
"created_at": "2026-07-16T15:17:10Z",
"last_comment_at": "2026-07-16T15:17:11Z",
"last_comment_author": "dependabot"
},
{
"number": 16,
"created_at": "2026-07-21T16:05:02Z",
"last_comment_at": "2026-07-21T16:05:03Z",
"last_comment_author": "dependabot"
},
{
"number": 17,
"created_at": "2026-07-21T16:05:06Z",
"last_comment_at": "2026-07-21T16:05:07Z",
"last_comment_author": "dependabot"
},
{
"number": 18,
"created_at": "2026-07-21T16:05:13Z",
"last_comment_at": "2026-07-21T16:05:14Z",
"last_comment_author": "dependabot"
},
{
"number": 19,
"created_at": "2026-07-21T16:05:14Z",
"last_comment_at": "2026-07-21T16:05:14Z",
"last_comment_author": "dependabot"
},
{
"number": 20,
"created_at": "2026-07-21T16:05:21Z",
"last_comment_at": "2026-07-21T16:05:22Z",
"last_comment_author": "dependabot"
},
{
"number": 21,
"created_at": "2026-07-21T16:05:44Z",
"last_comment_at": "2026-07-21T16:05:45Z",
"last_comment_author": "dependabot"
}
],
"last_merged_pr_at": "2026-07-19T17:00:06Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/Ramenm/MCPace",
"host": "github.com",
"name": "MCPace",
"owner": "Ramenm"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"security": 75,
"vitality": 81,
"community": 24,
"governance": 27,
"engineering": 66
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 81,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 76,
"inputs": {
"commits_last_year": 116,
"human_commit_share": 1,
"days_since_last_push": 3,
"active_weeks_last_year": 17
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "17/52 weeks with commits",
"points": 11.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 17
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "116 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 116
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 4,
"latest_release_tag": "v0.8.2",
"releases_from_tags": true,
"days_since_latest_release": 5,
"mean_days_between_releases": 8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "4 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 4
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 24,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 51,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "critical",
"name": "Sustainability & Governance",
"value": 27,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "at_risk",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 39,
"inputs": {
"merged_prs": 6,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 5
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "6/11 decided PRs merged",
"points": 20.9,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 6,
"decided": 11
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/19 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 34,
"inputs": {
"followers": 0,
"owner_type": "User",
"is_verified": null,
"owner_login": "Ramenm",
"public_repos": 4,
"account_age_days": 2848
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of Ramenm",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "Ramenm"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "4 public repos, account ~7 yr old",
"points": 17.1,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 4
}
},
{
"code": "account_age_years",
"params": {
"years": 7
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 66,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "9 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 9
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 75,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 69,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 6.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/19 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 146 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 146
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 146,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 146,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 64,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.84,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "84 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 84,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Cargo.lock",
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"Cargo.toml"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Cargo.toml (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "Cargo.toml"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Rust (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "dependency automation configured, none observed in the sampled commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "dependency_bot_config_only",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"primary_language": "Rust",
"largest_source_bytes": 429592,
"source_files_sampled": 353,
"oversized_source_files": 11
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Rust (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "11/353 source files over 60KB",
"points": 53.3,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 353,
"oversized": 11
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Could not fetch crates package 'mcpace' from its registry"
],
"report_type": "repository",
"generated_at": "2026-07-25T15:52:10.569432Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/Ramenm/MCPace.svg",
"full_name": "Ramenm/MCPace",
"license_state": "custom",
"license_spdx": null
}