Registro público
Informe de salud del softwareesquema 0.26.0 · métricas 1.13.0 · 2026-07-22 19:42 UTC

Utilities-Studio / infra

TypeScriptSin licencia detectada★ 0 estrellas⑂ 0 forksdesde abr 2026Ver en GitHub ↗

Utilities-Studio/infra tiene un índice de salud de 40 sobre 100, lo que lo sitúa en la banda En riesgo. Su puntuación más alta es Engineering Quality (58/100) y la más baja, Community & Adoption (25/100). Se actualizó por última vez hace 5 días. Una sola persona concentra la mayor parte del trabajo reciente.

40
global / 100
En riesgo

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

40
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Utilities StudioOrganización
0 seguidores3 repositorios públicosdesde abr 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
npm@utilities-studio/sync-env1.1.13234316hace 5 días
npm@utilities-studio/vite-env1.0.83118hace 18 días
npm@utilities-studio/env-local1.0.93319hace 18 días
npm@utilities-studio/github-env1.0.115262hace 15 días
npm@utilities-studio/env-encrypt1.0.83138hace 18 días
npm@utilities-studio/stripe-sync1.0.93329hace 18 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

44En riesgo · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 5 días
8.3/36Cadencia de commits — 12/52 semanas con commits
17.3/18Volumen de commits — 84 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year84
human_commit_share0,94
days_since_last_push5
active_weeks_last_year12
Cómo se puntúa
0/27Publica versiones — sin versiones publicadas
0/36Recencia de las versiones — sin versiones
0/27Cadencia de publicación — sin versiones
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count0
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

25Crítico · 18% del índice global
Cómo se puntúa
0/60Estrellas — 0 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
0/22.5Licencia — no se detectó ningún archivo de licencia
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
49.5/80Descargas mensuales — 5156 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@utilities-studio/sync-env, @utilities-studio/vite-env, @utilities-studio/env-local, @utilities-studio/github-env, @utilities-studio/env-encrypt, @utilities-studio/stripe-sync
dependents
ecosystemsnpm
total_downloads
monthly_downloads5156
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

32En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
0/25Alcance del propietario — 0 seguidores de Utilities-Studio
4.9/25Trayectoria — 3 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers0
owner_typeOrganization
is_verified
owner_loginUtilities-Studio
public_repos3
account_age_days96
Cómo se puntúa
25/25Publicado y resoluble — 6 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 16 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@utilities-studio/sync-env, @utilities-studio/vite-env, @utilities-studio/env-local, @utilities-studio/github-env, @utilities-studio/env-encrypt, @utilities-studio/stripe-sync
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

58Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 6 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

55Moderado
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
0/10Descripción del repositorio
0/10Topics
0/10Wiki
Datos de entrada utilizados
topics
has_wikino
homepage
has_readme
has_docs_dir
has_descriptionno

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

41En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — sin datos
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Licencia — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate4,1
Excluidos de la puntuación (sin datos o no aplicable): branch_protection, ci_tests, signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

47En riesgo · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 79 de 79 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — packages/env-encrypt/tsconfig.json, packages/env-local/tsconfig.json, packages/github-env/tsconfig.json, packages/stripe-sync/tsconfig.json, packages/sync-env/tsconfig.json, packages/vite-env/tsconfig.json
0/10Entorno reproducible
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 84
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfiles
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configspackages/env-encrypt/tsconfig.json, packages/env-local/tsconfig.json, packages/github-env/tsconfig.json, packages/stripe-sync/tsconfig.json, packages/sync-env/tsconfig.json, packages/vite-env/tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
55/55Tamaños de archivo manejables — 0/26 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes17.694
source_files_sampled26
oversized_source_files0

Datos clave

0estrellas de GitHub
1contribuidores
84commits en los últimos 12 meses
5días desde el último push
0versiones publicadas
1factor bus
0issues abiertas
ecosistemas de paquetes

Advertencias de recopilación de datos

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@utilities-studio/sync-env@1.1.13; advisories assessed against the repository dependency graph instead

Más detalle

OpenSSF Scorecard 4.1 / 10
4.1agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-22 19:42 UTC

10Binary-Artifactsno binaries found in the repo
n/dBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Dependencias directas 20
RegistroPaqueteRestricción de versiónManifiesto
npm@dotenvx/dotenvx^2.1.4packages/env-encrypt/package.json
npmcac^7.0.0packages/env-encrypt/package.json
npmpicocolors^1.1.1packages/env-encrypt/package.json
npmcac^7.0.0packages/env-local/package.json
npmpicocolors^1.1.1packages/env-local/package.json
npm@dotenvx/dotenvx^2.1.4packages/github-env/package.json
npmcac^7.0.0packages/github-env/package.json
npmpicocolors^1.1.1packages/github-env/package.json
npm@clack/prompts^1.7.0packages/stripe-sync/package.json
npm@supabase/stripe-sync-engine^0.48.5packages/stripe-sync/package.json
npmcac^7.0.0packages/stripe-sync/package.json
npmpicocolors^1.1.1packages/stripe-sync/package.json
npmstripe^22.3.0packages/stripe-sync/package.json
npm@clack/prompts^1.7.0packages/sync-env/package.json
npmcac^7.0.0packages/sync-env/package.json
npmdotenv^17.4.2packages/sync-env/package.json
npmjsonc-parser^3.3.1packages/sync-env/package.json
npmpicocolors^1.1.1packages/sync-env/package.json
npmcac^7.0.0packages/vite-env/package.json
npmpicocolors^1.1.1packages/vite-env/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 288,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "TypeScript": 123683
      },
      "pushed_at": "2026-07-17T14:55:41Z",
      "created_at": "2026-04-19T21:17:12Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T14:56:54Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Utilities Studio",
      "type": "Organization",
      "login": "Utilities-Studio",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/277069873?v=4",
      "created_at": "2026-04-17T17:19:34Z",
      "is_verified": null,
      "public_repos": 3,
      "account_age_days": 96
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "90d0347e943ddd803beab25f1518b73d40434257",
          "body": null,
          "is_bot": false,
          "headline": "fix(sync-env): report redacted command failures",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-17T14:55:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "837a6bea337603be3587c50597554e75409f632f",
          "body": "• add Bun dependency caching and `bun ci` installs\n• support trusted post-deploy commands for Workers and Supabase\n• improve workflow naming, permissions, and preview cleanup\n• update action versions and document workflow changes",
          "is_bot": false,
          "headline": "feat(workflows): enhance reusable deployment workflows",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-16T13:31:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee285e36e1f02ede67deb35424aba7b35705f5ee",
          "body": "- remove default empty string for environment input\n- fix empty string evaluation in reusable workflow template\n- update sync-env and db push commands to handle optional environment inputs\n- add test to ensure no empty string literals in workflow template",
          "is_bot": false,
          "headline": "fix(workflows): resolve empty string handling in supabase-deploy",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-08T10:37:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15e7841d58f1df863a27a2f69832aa2ab7b3ffc5",
          "body": null,
          "is_bot": false,
          "headline": "fix(github-env): correct version rollback to 1.0.1",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-07T17:22:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf335bfd010dbfc730641dd77109b536921311f8",
          "body": "- prepare for major release with updated package version",
          "is_bot": false,
          "headline": "feat(github-env): bump version to 2.0.0",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-07T17:21:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4694cebb7799a84eb23436be9a5b52dce831465",
          "body": null,
          "is_bot": false,
          "headline": "fix(github-env): bump version to 1.0.1",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-07T17:20:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03ff09c97444bc11fa0399f4c1c8b8f880262c0c",
          "body": "- implement `--skip-reserved` option to bypass GitHub-reserved env keys during export\n- update workflows to include `--skip-reserved` in env loading steps\n- enhance README with documentation for the new CLI option\n- add tests to validate `--skip-reserved` behavior in various scenarios",
          "is_bot": false,
          "headline": "feat(github-env): add support for skipping GitHub-reserved keys",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-07T17:16:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfdad19f9d98708f2ff7bf1b9122732894b6fd24",
          "body": "- add reusable steps for resolving and loading dotenv files in GitHub Actions workflows\n- integrate `github-env` CLI for loading env vars into Cloudflare, Supabase, and Pages workflows\n- update tests for `supabase-deploy.yml` and add new test for env resolution in multiple workflows\n- ensure consistent use of quotes in workflow YAML files\n- refactor pre-deploy command placement in Cloudflare Pages workflow",
          "is_bot": false,
          "headline": "feat(workflows): enhance env loading and testing across workflows",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-07T17:09:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01118aef9f8d8e0df7e8d4a8b9387262f37697e4",
          "body": "- implement test suite to validate `secret-keys` subpath exports for Node (ESM and CommonJS)\n- ensure build scripts, package dist output, and release workflows align with expected contracts\n- update `.gitignore` to verify dist directory is ignored\n- adjust `tsconfig.json` to suppress deprecation warnings for TypeScript 6.0\n- enhance README with usage examples for `secret-keys` subpath",
          "is_bot": false,
          "headline": "feat(sync-env): add tests for package contract and secret-keys subpath",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-04T19:56:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30555d043a453548c3db0901ee03b8206ecb2f90",
          "body": "- implement classification logic for public, secret, and non-classified keys\n- refactor key detection logic to use the standalone `secret-keys` module\n- update `README` with the new classifier and usage examples\n- export `classifyEnvKey`, `isSecretKey`, and `hasPublicEnvMarker` utilities\n- enhance tests with comprehensive coverage for key classification scenarios",
          "is_bot": false,
          "headline": "feat(sync-env): add reusable env key classifier for secrets detection",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-04T14:16:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1781ee1d6e10a77f7528024e1adeea9e0eee47",
          "body": "…ions\n\n- introduce `github-env` CLI tool to load dotenv files into GitHub Actions environments and step outputs\n- support `--environment`, `--env-dir`, and `--env-file` options for flexible env file resolution\n- implement env key masking for sensitive values and GitHub-specific output formatting\n- add robust tests for env file resolution, parsing, and GitHub Actions export logic\n- publish package with initial version `v1.0.0`",
          "is_bot": false,
          "headline": "feat(github-env): add CLI for dotenv file integration with GitHub Act…",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-07-04T12:22:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d0a2da7cda6545bb28cdeb63e360d24568ee9bb",
          "body": "- introduce `skip_project_config_push` input to conditionally skip `supabase config push --yes`\n- update workflow logic with `if` condition for skipping project config push\n- document new option in README with usage example\n- add tests to validate the behavior of the new input",
          "is_bot": false,
          "headline": "feat(workflows): add skip_project_config_push option to supabase deploy",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-06-29T17:19:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b16b2a5a41775f8a76d9d93d1bb43acb37d6f99a",
          "body": "- introduce `--env-dir` and `--env-file` options for env file configuration\n- update validation to prioritize `--output` and maintain backward compatibility for `--out`\n- enhance env variable extraction with file-based key filtering\n- refactor and optimize `.env` file detection logic\n- bump package version to v1.0.3",
          "is_bot": false,
          "headline": "feat(vite-env): add env file and directory support to CLI",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-06-20T04:29:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c9acab4a8233cc7fe65628ae9921a83c01d635d",
          "body": "- add `banner`, `info`, `step`, and `fail` methods to improve CLI output\n- centralize version, interactivity, and color configuration logic\n- integrate `cli-kit` across `vite-env`, `sync-env`, `stripe-sync`, `env-encrypt`, and `env-local` utilities\n- update tests and enhance default options handling for `env-encrypt`",
          "is_bot": false,
          "headline": "feat(cli-kit): extract shared helpers for CLI utilities",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-06-20T03:42:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d07d4524532dafca209db3b4f454f6e5aa45b97a",
          "body": "- enhance `envGetPattern` regex for better matching\n- bump package version to v1.1.4",
          "is_bot": false,
          "headline": "fix(sync-env): improve regex for env variable extraction",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-06-18T00:07:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03d2e65e90d3e317499b19c9409797135b9aa118",
          "body": null,
          "is_bot": false,
          "headline": "fix(sync-env): include `PASSWORD` in sensitive key filtering",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-06-06T23:55:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6713ec38af4d89e43f2e889230610fa3413aebf5",
          "body": "- bump `sync-env` to v1.1.2 and `env-encrypt` to v1.0.5 in README\n- update `github-script` action to v9 across multiple workflows",
          "is_bot": false,
          "headline": "chore(workflows): upgrade `github-script` to v9 and update versions",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-30T03:18:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac553d494c80cd7fc17766355c7b7eb58a4fe933",
          "body": "- bump `actions/github-script` to v8 across workflows\n- upgrade `cloudflare/wrangler-action` to v4 for deployment\n- update `supabase/setup-cli` to v2 for Supabase deployment\n- enforce Node.js 24 runtime with `FORCE_JAVASCRIPT_ACTIONS_TO_NODE24` environment variable",
          "is_bot": false,
          "headline": "feat(workflows): upgrade actions and enforce Node.js 24",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-30T02:53:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "102a4fe3f3b3ab9d6fd773e169649c7892b7e36e",
          "body": "- introduce `deploy_seeds` input for Supabase workflow\n- update README to document seed deployment capability\n- extend deployment script to support `--include-seed` flag",
          "is_bot": false,
          "headline": "feat(workflows): add optional seed deployment to supabase deploy",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-30T02:44:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68924dafce9a07661a436e42e20e9242d394b8ab",
          "body": "- add warning message for failed tag push due to permissions",
          "is_bot": false,
          "headline": "fix(workflows): handle tag push failure in supabase deploy script",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-22T14:11:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07a7c908ee82fd7a4a923ea3fa523fa454adcd3b",
          "body": null,
          "is_bot": false,
          "headline": "fix(packages): add npm provenance metadata",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-22T01:27:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44fb5ad70c0a1f01027c669e99a1be4a746337db",
          "body": "- enhance version comparison to prevent incorrect bumps\n- modify permissions to allow `contents: write`",
          "is_bot": false,
          "headline": "fix(workflows): improve release versioning logic",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-22T01:17:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7eec3a466f3ecc35260ecf6e8aa96d0d04e80350",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): replace bun publish with npm publish",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-22T01:00:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6f2f1ed13429c29b332b007517707777fc6cafb",
          "body": null,
          "is_bot": false,
          "headline": "chore(workflows): remove anthropic Claude workflows",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-22T00:54:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f4ccdab1d89c55c7832fb698bb6065ec1edc5ef",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): adjust permissions and disable caching in release",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-22T00:53:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "749b852bcf026c2bce859f44fbb1c945b4239179",
          "body": "- implement comprehensive unit tests for env-local functionality\n- enhance local env generation to ensure proper key filtering and merging\n- update README with new behavior and examples",
          "is_bot": false,
          "headline": "feat(env-local): add unit tests and improved env generation logic",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-08T00:43:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccdac1f6ef026abc3f456d5e3f6bf4ac31a2a967",
          "body": "- add `--env-file` and `--output` flags for flexibility in file generation\n- enhance detection of base env files to support `.env` and `.env.development`\n- update README and usage instructions\n- clarify behavior for single-tier and multi-tier projects\n- bump package version to 1.0.2 in `package.json` and README",
          "is_bot": false,
          "headline": "feat(env-local): support custom base env and output files",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-07T22:46:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1ea58b099e36e99eaa9f2a6d786994b722a9e7f",
          "body": "- introduce `--target` flag for `pull` command with auto-detection, public, and stripe-sync-engine options\n- integrate `@supabase/stripe-sync-engine` dependency\n- update README with pull target usage and related environment variables\n- enhance logic to support direct Postgres connections for Supabase stripe-sync-engine\n- bump package version to 1.0.3 in `package.json` and README",
          "is_bot": false,
          "headline": "feat(stripe-sync): add pull target support for stripe-sync-engine",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-06T22:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f36543f8111e73552155c397a72120c653f6688e",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): correct version bump syntax in release script",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-04T03:15:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a333e7d733f338b67c0514ca2297b45c84c37af",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): correct version bump syntax in release script",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-04T03:13:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8da211bac121a4549c3ce4c59684cccb9f031d30",
          "body": "- add tests for `parseEnv` and `diffEnv` to validate env file comparison\n- export `DiffKind`, `Diff`, `parseEnv`, and `diffEnv` for external usage\n- update `parseEnv` to reset `processEnv`, ensuring predictable behavior\n- make `main` function conditional with `import.meta.main`\n- bump package version to 1.0.4 in `package.json` and README",
          "is_bot": false,
          "headline": "feat(env-encrypt): add unit tests and improve exports",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-04T03:08:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c8f58a740368e5d7ce3362abc7cadcb2ab6315d",
          "body": "- add `isCiEnvironment` check for `CI` and `GITHUB_ACTIONS` flags\n- update CLI behavior to exit successfully without processing `--stage` in CI\n- revise README to document the new behavior",
          "is_bot": false,
          "headline": "feat(env-encrypt): skip --stage in CI environments",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-04T02:54:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d85e521ffdd32e1d6644ba8c8ced8d3388da2fe7",
          "body": "- check for existing tags before creating new ones\n- update version bump logic for custom patch increments",
          "is_bot": false,
          "headline": "fix(workflows): prevent duplicate tags in release workflow",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-03T23:31:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22757d2b3adf60e1689e6f0e287498bfba75fd10",
          "body": null,
          "is_bot": false,
          "headline": "chore(env-encrypt): bump version to 1.0.2",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-03T23:28:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bca76e09da573fa4b0aa5ae481efab488cd59a5c",
          "body": "- move rebase step earlier in release workflow\n- prevent redundant rebase command after version bump",
          "is_bot": false,
          "headline": "fix(workflows): rebase before version bump in release step",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-03T23:13:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2989ebd41400c14bba1b1062cae327a8f41d7632",
          "body": "- implement CLI to check, compare, and encrypt .env files\n- support flags for --stage, --check, and --env-dir\n- update workflows, package.json, and README for env-encrypt integration",
          "is_bot": false,
          "headline": "feat(env-encrypt): add CLI for dotenvx comparison and encryption",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-03T22:43:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "849bb73827882ca507c652d08c324004d44e8672",
          "body": null,
          "is_bot": false,
          "headline": "chore(workflows): set consistent timeout for all actions",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-05-03T17:07:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a92e835bf7870ec17c564171296c5fad04bd2f2",
          "body": "- add GITHUB_TOKEN to checkout step for authentication\n- commit version bump to main before tagging release\n- push tags along with main branch updates",
          "is_bot": false,
          "headline": "fix(workflows): update release workflow for version bump and tagging",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T23:46:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "264eb428f8422646409a305ce993169f5727cf88",
          "body": null,
          "is_bot": false,
          "headline": "chore(sync-env): bump version to 1.1.2",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T17:42:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "066f3f713305386e189cb00bbecde5144d146cb8",
          "body": "- implement expandVars function for `${VAR}` substitution\n- integrate variable expansion into env file loading logic",
          "is_bot": false,
          "headline": "feat(sync-env): add env variable expansion support",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T17:41:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6653869c50e7b1992a329cba8cad78985c33b114",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): add missing Cloudflare API token to deploy secrets",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T00:55:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "535151066944917461556ae5ec5baddfa61403bc",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump package versions for stripe-sync and sync-env",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T00:47:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4959112a87b503b191155704fcca46a782ae733",
          "body": "path.join concatenates paths even when the second arg is absolute,\nproducing invalid paths like /apps/api/home/runner/work. path.resolve\ncorrectly returns the absolute path when given one.",
          "is_bot": false,
          "headline": "fix: use path.resolve instead of path.join for --env-dir",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T00:28:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a853341357d2c6cf35eb2ebfbb10ff87672368b",
          "body": "When install_directory differs from working_directory, sync-env\nwas resolving --env-dir relative to the working directory instead\nof the repo root. Now uses GITHUB_WORKSPACE for absolute path.",
          "is_bot": false,
          "headline": "fix: resolve --env-dir as absolute path for monorepo support",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-25T00:18:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b315f9e583504b3f4796d90af4b2098099ffd330",
          "body": null,
          "is_bot": false,
          "headline": "docs: add comprehensive README for infra setup and usage",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-24T21:49:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1591891243ad6075720279963f22ea8aa85e6585",
          "body": "Add WEBHOOK_URL env var and webhookUrl config field so the webhook\ncommand works with Cloudflare Workers and other non-Supabase backends.\nFalls back to Supabase URL construction for backwards compatibility.",
          "is_bot": false,
          "headline": "feat(stripe-sync): support custom webhook URL for non-Supabase projects",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-24T21:40:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aeb283df4e576ce320a16e289db514d1d4409a8",
          "body": null,
          "is_bot": false,
          "headline": "feat: add build_mode and deploy_branch inputs for preview deployments",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-24T21:37:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b33adf83d2f14be63ed3ccda754dcec333ccc7e",
          "body": "sync-env v1.1.0:\n- Auto-discovers apps/*/wrangler.jsonc when no root config exists\n- --env-dir flag for specifying env file location\n- Runs wrangler commands from each app's directory\n\ncloudflare-deploy.yml:\n- install_directory input for monorepo root installs\n- Per-worker concurrency groups and PR comment markers\n- Passes --env-dir to sync-env when dirs differ",
          "is_bot": false,
          "headline": "feat: monorepo support for sync-env and cloudflare-deploy",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-24T06:23:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df2cc1e53b3edd2e7195fbb596126b07efd7b8c7",
          "body": "…ploy",
          "is_bot": false,
          "headline": "feat(workflows): add required account_id input to Cloudflare Pages de…",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-24T06:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17929d3ef7d431e91b4048b7959fd7359ab9499d",
          "body": null,
          "is_bot": false,
          "headline": "feat(workflows): add Node.js 24 and latest Bun setup to workflows",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-22T02:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b9080b20d7d311172fe5930ffdd0cd270e41979",
          "body": "…files)\n\nEncrypted env files (.env.development.encrypted) are decrypted to\n.env.development by a postinstall hook during bun install. The detect\nstep was running before install, so the decrypted files didn't exist\nyet and tier detection failed.\n\nFix: move detect step after install, pass DOTENV private keys to\ninstall step so postinstall can decrypt.",
          "is_bot": false,
          "headline": "fix: move env tier detection after install (postinstall decrypts env …",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-22T01:16:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36a18c48ae2b494c7422a08c3227dbe271f4b3d7",
          "body": "- Pages: output mode=production for none/single tiers (not empty)\n- Pages: guard DOTENV keys with tier check (only set for correct tier)\n- sync-env: add DOTENV_PUBLIC_KEY (no suffix) to CF skip list",
          "is_bot": false,
          "headline": "fix: address code review findings for multi-tier env support",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:25:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d1094e4545c463b193fac297f71825decd474f9",
          "body": "…-env",
          "is_bot": false,
          "headline": "feat(workflows): make supabase-deploy environment optional for single…",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:19:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "164338c87a87d59801b752c24da7cd5fc78fbe12",
          "body": "…-deploy",
          "is_bot": false,
          "headline": "feat(workflows): support multi-tier env detection in cloudflare-pages…",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:16:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dea1ba90517fbe4856aeed22e05a89c3039ee88",
          "body": null,
          "is_bot": false,
          "headline": "feat(workflows): support multi-tier env detection in cloudflare-deploy",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:14:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "726099d055dc47ec50629e24e91298b95cf0c1b9",
          "body": null,
          "is_bot": false,
          "headline": "feat(vite-env): fallback to .env when .env.development missing",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:10:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36aa61aec4cc7d9a11984243d2b7269deabe9dfa",
          "body": null,
          "is_bot": false,
          "headline": "feat(sync-env): support root-level wrangler vars for single-env tier",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:09:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8a173cbd777be30b976b3a3ff9af48c3e93ce8c",
          "body": null,
          "is_bot": false,
          "headline": "feat(sync-env): add tier detection and env file loading",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T21:03:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72305b8de17dc0fcb0ac56b185ce61484d4c4cd1",
          "body": "7 tasks covering sync-env tier detection, root-level wrangler vars,\nvite-env fallback, and all three deploy workflow adaptations.",
          "is_bot": false,
          "headline": "docs: add multi-tier env implementation plan",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T17:52:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f44b7d7101b5aa5714f2b67d8a62b5b1208132d9",
          "body": "Three tiers -- none (static), single (.env), multi (.env.development +\n.env.production) -- with auto-detection across sync-env, vite-env, and\nall deploy workflows. Zero breaking changes to existing callers.",
          "is_bot": false,
          "headline": "docs: add multi-tier env support design spec",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-21T16:45:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "828254c7a1f9c9ef2d981a7feb2b6ba93c003fd2",
          "body": "WRANGLER_OUTPUT_FILE_DIRECTORY JSON parsing was silently failing,\nresulting in empty preview URLs in PR comments. Now uses\nwrangler-action's built-in command-output and deployment-url outputs.",
          "is_bot": false,
          "headline": "fix(workflows): use wrangler-action outputs for preview URL extraction",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T13:08:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32692e6101d9f6a58829c1353e44892d5d03a58d",
          "body": "- add step to extract preview URL from wrangler output\n- update deployment comment logic to use extracted preview URL",
          "is_bot": false,
          "headline": "feat(workflows): improve preview URL extraction for deploy comments",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T12:27:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e79c88e349468118cffbaa6da8f086e3d0b0906",
          "body": "…ssions\n\n- replace event-based triggers with `workflow_call` for modularity\n- enhance concurrency handling for better run management\n- update permissions to align with new workflow requirements",
          "is_bot": false,
          "headline": "feat(workflows): migrate triggers to `workflow_call` and update permi…",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T11:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e5cf4254535c875be1d855e4ec26b1090615e49",
          "body": "- refactor to use `env` for deployment and alias URLs in PR comments",
          "is_bot": false,
          "headline": "feat(workflows): improve env variable handling for deploy comments",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T03:43:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10ddc5f662b274d93d7f956b8ceaa6dde30566a2",
          "body": "- replace `<h3>` tags with markdown headers (`###`)\n- improve URL matching regex for Cloudflare Workers preview URLs\n- enhance readability of branch and status formatting with backticks",
          "is_bot": false,
          "headline": "style(workflows): update deployment messages for markdown consistency",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T02:30:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a7123c984c0cc14a1f2afbeb8dd60145b5b53ef",
          "body": "- update condition for closed PRs in cleanup workflow\n- enhance deployment comments with dynamic branch, status, and links\n- unify marker naming to `<!-- cf-workers-preview -->` across workflows\n- improve HTML formatting and table structure for clarity",
          "is_bot": false,
          "headline": "feat(workflows): improve PR handling and deployment messaging",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T02:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f49ccd3467d59ff013c8a739d8cba2dc6cde358",
          "body": "- refactor environment and concurrency handling for clarity\n- add flags for improved build and deploy step customization\n- update input descriptions for better readability and usability\n- revise pull request handling logic and conditions",
          "is_bot": false,
          "headline": "feat(workflows): enhance cloudflare deploy workflow for flexibility",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T02:19:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8490292746809e4b31b9437902935157880cddd5",
          "body": "- refactor environment and concurrency handling for clarity\n- add flags for improved build and deploy step customization\n- update input descriptions for better readability and usability\n- revise pull request handling logic and conditions",
          "is_bot": false,
          "headline": "feat(workflows): enhance cloudflare deploy workflow for flexibility",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T02:08:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4a7ee4bbd490dc44658b0e47647f428ab9ed433",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): add missing Cloudflare API token to deploy env",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T02:03:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d8a86a24d8176dc92fa2120b6ccbeee52dd75ae",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): add missing Cloudflare API token to env",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T02:01:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6fe88856d66e33c905c8a5958b677c539535f27",
          "body": "- modify environment key to fix conditional handling for pull requests\n- ensure proper defaults for non-PR deployments",
          "is_bot": false,
          "headline": "fix(workflows): update env handling in Cloudflare deploy workflow",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T01:58:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81320fbcaae0b08e1f8fd5b3c93caab7d90e241b",
          "body": "- make `environment` input optional with default value\n- update concurrency and environment handling for clearer defaults\n- simplify preview URL extraction and build commands\n- enhance table formatting by removing redundant columns",
          "is_bot": false,
          "headline": "feat(workflows): improve Cloudflare deploy workflow flexibility",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T01:55:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e34c6454baa189ed7d2e79a12ace59bbbc237008",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): correct release workflow push command",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T01:48:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "385c41e81832a2fe992493283440c65754e3853d",
          "body": null,
          "is_bot": true,
          "headline": "release: @utilities-studio/sync-env v1.0.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-20T01:29:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "060ad5d5125aadb45717b4d18b3b1194b7d18317",
          "body": "- add checks for missing env files and skip sync if none found\n- introduce `skip_sync_env` and `skip_build` inputs in Cloudflare deploy workflow\n- conditionally execute build and sync steps based on workflow inputs",
          "is_bot": false,
          "headline": "feat(sync-env): improve env file handling and CI workflow flexibility",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T01:29:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "046291045754035522ff9e012c91484836c0df94",
          "body": null,
          "is_bot": false,
          "headline": "fix(workflows): update package input description and Node.js version",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T01:01:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6820dcf34c3ec474873bba58c84fb024a7d3ea97",
          "body": null,
          "is_bot": true,
          "headline": "release: @utilities-studio/stripe-sync v1.0.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-20T00:48:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c14bb04b7d797da4f05449bd3ed95781ba984ee3",
          "body": null,
          "is_bot": true,
          "headline": "release: @utilities-studio/vite-env v1.0.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-20T00:47:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b72b85b66cd9094cf8205e0ad6ade96b269b0aa5",
          "body": null,
          "is_bot": true,
          "headline": "release: @utilities-studio/env-local v1.0.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-20T00:47:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a1d88a366b94797be16aca1018e64927eed34a0",
          "body": null,
          "is_bot": true,
          "headline": "release: @utilities-studio/sync-env v1.0.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-20T00:47:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "326d957986260f12ee4d62ef3151d7b50ecffa6c",
          "body": "- update `package` input to support choices and default to \"all\"\n- improve usability with predefined options for package selection",
          "is_bot": false,
          "headline": "feat(workflows): enhance release workflow inputs",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T00:33:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e923f4272606e9c2321ad32a0e0f852dad955e75",
          "body": "- update npm publish step to include .npmrc token authentication\n- simplify supabase deploy workflows by removing complex deploy logic\n- replace `deploy_functions` string toggle with boolean input",
          "is_bot": false,
          "headline": "refactor(workflows): simplify npm and supabase deploy workflows",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T00:30:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb712a387cc9edf3c5d3e302ece045232593bcde",
          "body": "- update `ProductConfig` and `PriceConfig` types to make fields optional\n- simplify config parsing by merging credit packs and subscriptions\n- update push logic to handle flexible product/price configurations\n- add detailed README for stripe-sync package usage and config\n\nrefactor(workflows): enhance release workflow\n\n- add `package` input for manual package selection\n- improve diff detection logic for changed packages",
          "is_bot": false,
          "headline": "feat(stripe-sync): improve product config flexibility and add usage docs",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-20T00:14:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cc72d3e2b8495fc87b74c6b90284f5c43f2224f",
          "body": "- introduce Claude automation workflows for code reviews\n- add Cloudflare Workers deploy and cleanup support\n- configure Cloudflare Pages deploy with workflow_call",
          "is_bot": false,
          "headline": "feat(workflows): add GitHub Actions for Claude, Cloudflare deploys",
          "author_name": "Hariom Sharma",
          "author_login": "harryy2510",
          "committed_at": "2026-04-19T23:54:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 84,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 12,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 12,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@utilities-studio/sync-env",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@utilities-studio/sync-env",
          "is_deprecated": false,
          "latest_version": "1.1.13",
          "repository_url": "https://github.com/Utilities-Studio/infra",
          "versions_count": 16,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2343,
          "first_published_at": "2026-04-20T00:47:16.354000Z",
          "latest_published_at": "2026-07-17T14:55:39.848000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@utilities-studio/vite-env",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@utilities-studio/vite-env",
          "is_deprecated": false,
          "latest_version": "1.0.8",
          "repository_url": "https://github.com/Utilities-Studio/infra",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 311,
          "first_published_at": "2026-04-20T00:47:48.629000Z",
          "latest_published_at": "2026-07-04T12:24:32.763000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 18
        },
        {
          "name": "@utilities-studio/env-local",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@utilities-studio/env-local",
          "is_deprecated": false,
          "latest_version": "1.0.9",
          "repository_url": "https://github.com/Utilities-Studio/infra",
          "versions_count": 9,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 331,
          "first_published_at": "2026-04-20T00:47:33.201000Z",
          "latest_published_at": "2026-07-04T12:23:09.107000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 18
        },
        {
          "name": "@utilities-studio/github-env",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@utilities-studio/github-env",
          "is_deprecated": false,
          "latest_version": "1.0.1",
          "repository_url": "https://github.com/Utilities-Studio/infra",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1526,
          "first_published_at": "2026-07-05T04:05:43.703000Z",
          "latest_published_at": "2026-07-07T17:23:25.053000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 15
        },
        {
          "name": "@utilities-studio/env-encrypt",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@utilities-studio/env-encrypt",
          "is_deprecated": false,
          "latest_version": "1.0.8",
          "repository_url": "https://github.com/Utilities-Studio/infra",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 313,
          "first_published_at": "2026-05-03T22:43:42.088000Z",
          "latest_published_at": "2026-07-04T12:22:47.564000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 18
        },
        {
          "name": "@utilities-studio/stripe-sync",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@utilities-studio/stripe-sync",
          "is_deprecated": false,
          "latest_version": "1.0.9",
          "repository_url": "https://github.com/Utilities-Studio/infra",
          "versions_count": 9,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 332,
          "first_published_at": "2026-04-20T00:48:04.164000Z",
          "latest_published_at": "2026-07-04T12:23:42.426000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 18
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/env-encrypt/tsconfig.json",
        "packages/env-local/tsconfig.json",
        "packages/github-env/tsconfig.json",
        "packages/stripe-sync/tsconfig.json",
        "packages/sync-env/tsconfig.json",
        "packages/vite-env/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 17694,
      "source_files_sampled": 26,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [
        {
          "name": "@dotenvx/dotenvx",
          "manifest": "packages/env-encrypt/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.4"
        },
        {
          "name": "cac",
          "manifest": "packages/env-encrypt/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "picocolors",
          "manifest": "packages/env-encrypt/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "cac",
          "manifest": "packages/env-local/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "picocolors",
          "manifest": "packages/env-local/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@dotenvx/dotenvx",
          "manifest": "packages/github-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.4"
        },
        {
          "name": "cac",
          "manifest": "packages/github-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "picocolors",
          "manifest": "packages/github-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@clack/prompts",
          "manifest": "packages/stripe-sync/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.0"
        },
        {
          "name": "@supabase/stripe-sync-engine",
          "manifest": "packages/stripe-sync/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.48.5"
        },
        {
          "name": "cac",
          "manifest": "packages/stripe-sync/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "picocolors",
          "manifest": "packages/stripe-sync/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "stripe",
          "manifest": "packages/stripe-sync/package.json",
          "ecosystem": "npm",
          "version_constraint": "^22.3.0"
        },
        {
          "name": "@clack/prompts",
          "manifest": "packages/sync-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.0"
        },
        {
          "name": "cac",
          "manifest": "packages/sync-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "dotenv",
          "manifest": "packages/sync-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "jsonc-parser",
          "manifest": "packages/sync-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.1"
        },
        {
          "name": "picocolors",
          "manifest": "packages/sync-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "cac",
          "manifest": "packages/vite-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "picocolors",
          "manifest": "packages/vite-env/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "harryy2510",
          "commits": 79,
          "avatar_url": "https://avatars.githubusercontent.com/u/7416971?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "cloudflare-deploy.yml",
        "cloudflare-pages-cleanup.yml",
        "cloudflare-pages-deploy.yml",
        "cloudflare-workers-cleanup.yml",
        "release-package.yml",
        "supabase-deploy.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "90d0347e943ddd803beab25f1518b73d40434257",
        "ran_at": "2026-07-22T19:42:43Z",
        "aggregate_score": 4.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T14:55:46Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Utilities-Studio/infra",
    "host": "github.com",
    "name": "infra",
    "owner": "Utilities-Studio"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 40,
      "inputs": {
        "security": 41,
        "vitality": 44,
        "community": 25,
        "governance": 32,
        "engineering": 58
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 44,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 84,
              "human_commit_share": 0.94,
              "days_since_last_push": 5,
              "active_weeks_last_year": 12
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "12/52 weeks with commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "84 commits in the last year",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 84
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 25,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "@utilities-studio/sync-env",
                "@utilities-studio/vite-env",
                "@utilities-studio/env-local",
                "@utilities-studio/github-env",
                "@utilities-studio/env-encrypt",
                "@utilities-studio/stripe-sync"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 5156
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,156 downloads/month across npm",
                "points": 49.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5156,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 32,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "Utilities-Studio",
              "public_repos": 3,
              "account_age_days": 96
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of Utilities-Studio",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "Utilities-Studio"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "3 public repos, account ~0 yr old",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 3
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@utilities-studio/sync-env",
                "@utilities-studio/vite-env",
                "@utilities-studio/env-local",
                "@utilities-studio/github-env",
                "@utilities-studio/env-encrypt",
                "@utilities-studio/stripe-sync"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "16 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 58,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 41,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 4.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 47,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "79 of 79 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 79,
                      "sampled": 79
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/env-encrypt/tsconfig.json",
                "packages/env-local/tsconfig.json",
                "packages/github-env/tsconfig.json",
                "packages/stripe-sync/tsconfig.json",
                "packages/sync-env/tsconfig.json",
                "packages/vite-env/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/env-encrypt/tsconfig.json, packages/env-local/tsconfig.json, packages/github-env/tsconfig.json, packages/stripe-sync/tsconfig.json, packages/sync-env/tsconfig.json, packages/vite-env/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/env-encrypt/tsconfig.json, packages/env-local/tsconfig.json, packages/github-env/tsconfig.json, packages/stripe-sync/tsconfig.json, packages/sync-env/tsconfig.json, packages/vite-env/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 84",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 84
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 17694,
              "source_files_sampled": 26,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/26 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 26,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@utilities-studio/sync-env@1.1.13; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T19:42:48.670071Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/u/Utilities-Studio/infra.svg",
  "full_name": "Utilities-Studio/infra",
  "license_state": "absent",
  "license_spdx": null
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.26.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.