Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-23 07:28 UTC

agent-receipts / dashboard

Centralized audit dashboard for Agent Receipts / Obsigna — collect, view, and verify receipts from any SDK or proxy

Go · HTMLApache-2.0★ 2 estrellas⑂ 0 forksdesde abr 2026Ver en GitHub ↗

agent-receipts/dashboard tiene un índice de salud de 65 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es AI Readiness (87/100) y la más baja, Community & Adoption (36/100). Se actualizó por última vez hace 3 días. Una sola persona concentra la mayor parte del trabajo reciente.

65
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

65
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Agent ReceiptsOrganización
11 seguidores9 repositorios públicosdesde abr 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/agent-receipts/dashboardv0.13.1-34hace 3 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

81Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 3 días
11.1/36Cadencia de commits — 16/52 semanas con commits
18/18Volumen de commits — 179 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year179
human_commit_share0,87
days_since_last_push3
active_weeks_last_year16
Cómo se puntúa
27/27Publica versiones — 34 versiones publicadas
36/36Recencia de las versiones — última versión hace 3 días
27/27Cadencia de publicación — una versión cada ~3,4 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count34
latest_release_tagv0.13.1
releases_from_tagsno
days_since_latest_release3
mean_days_between_releases3,4

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

36En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 2 estrellas
0/25Forks — 0 forks
0/15Observadores — 1 observadores
Datos de entrada utilizados
forks0
stars2
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conductno
has_pull_request_template

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

58Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
43.2/46.8Resolución de issues — 92% de issues cerradas
37.7/38.3Aceptación de PR — 138/140 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/22 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs138
open_issues3
closed_issues37
issue_closed_ratio0,925
closed_unmerged_prs2
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
7.8/25Alcance del propietario — 11 seguidores de agent-receipts
7.9/25Trayectoria — 9 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers11
owner_typeOrganization
is_verified
owner_loginagent-receipts
public_repos9
account_age_days112
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 3 días
20/20Historial de versiones — 34 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/agent-receipts/dashboard
ecosystemsgo
any_deprecatedno
min_days_since_publish3

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

77Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 4 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentación

90Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://obsigna.dev
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepagehttps://obsigna.dev
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

73Bueno · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/22 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate6,6
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
0/25Dependencias indirectas libres de avisos conocidos — el conjunto transitivo no es separable de las dependencias de desarrollo y prueba en este alcance
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages13
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Dependencias indirectas libres de avisos conocidos, Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejaron 13 dependencias resueltas con OSV. Este repositorio no publica ningún paquete que el índice resuelva, por lo que se evaluó en su lugar el grafo de dependencias del repositorio. Ese grafo mezcla fijaciones de desarrollo y prueba con las dependencias distribuidas, de modo que solo se puntúan las dependencias declaradas en tiempo de ejecución; los hallazgos transitivos se informan como contexto y quedan excluidos de la puntuación. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

87Excelente · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — AGENTS.md, CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 87 de 87 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes5388
Cómo se puntúa
18/18Arranque con un solo comando — Makefile
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — lockfile
8/10Práctica demostrada con agentes — 4 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 13 de los últimos 100 commits son actualizaciones automáticas de dependencias
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfileno
typed_language
bootstrap_filesMakefile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0,04
toolchain_manifestsgo.mod
dependency_bot_commit_share0,13
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
47.7/55Tamaños de archivo manejables — 2/15 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes122.868
source_files_sampled15
oversized_source_files2

Datos clave

2estrellas de GitHub
1contribuidores
179commits en los últimos 12 meses
3días desde el último push
34versiones publicadas
1factor bus
3issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

OpenSSF Scorecard 6.6 / 10
6.6agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-23 07:27 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/22 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Dependencias directas 2
RegistroPaqueteRestricción de versiónManifiesto
Gomodernc.org/sqlitev1.54.0go.mod
Goobsigna.dev/sdk/gov0.24.0go.mod
Todas las dependencias 13

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 2 paquetes directos y 11 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Gomodernc.org/sqlitev1.54.0directa
Goobsigna.dev/sdk/gov0.24.0directa
Gogithub.com/cloudflare/circlv1.6.4indirecta
Gogithub.com/dustin/go-humanizev1.0.1indirecta
Gogithub.com/google/uuidv1.6.0indirecta
Gogithub.com/mattn/go-isattyv0.0.20indirecta
Gogithub.com/ncruces/go-strftimev1.0.0indirecta
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecindirecta
Gogolang.org/x/cryptov0.52.0indirecta
Gogolang.org/x/sysv0.46.0indirecta
Gomodernc.org/libcv1.74.1indirecta
Gomodernc.org/mathutilv1.7.1indirecta
Gomodernc.org/memoryv1.11.0indirecta
Avisos de dependencias 1

Este repositorio no publica ningún paquete que el índice resuelva, así que se evaluó su propio grafo de dependencias — 13 paquetes, que incluyen también fijaciones de desarrollo y prueba que nunca se distribuyen: 1 tienen avisos conocidos, de los cuales 0 son directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
golang.org/x/cryptov0.52.0indirectadesconocida1

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1240,
      "has_wiki": true,
      "homepage": "https://obsigna.dev",
      "languages": {
        "Go": 409182,
        "HTML": 261682,
        "Shell": 3903,
        "Makefile": 207
      },
      "pushed_at": "2026-07-20T03:28:37Z",
      "created_at": "2026-04-02T09:28:46Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T03:28:38Z",
      "description": "Centralized audit dashboard for Agent Receipts / Obsigna — collect, view, and verify receipts from any SDK or proxy",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "HTML"
      ]
    },
    "owner": {
      "blog": "https://agentreceipts.ai",
      "name": "Agent Receipts",
      "type": "Organization",
      "login": "agent-receipts",
      "company": null,
      "location": null,
      "followers": 11,
      "avatar_url": "https://avatars.githubusercontent.com/u/272751690?v=4",
      "created_at": "2026-04-01T08:01:33Z",
      "is_verified": null,
      "public_repos": 9,
      "account_age_days": 112
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-07-20T03:30:10Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-17T08:40:07Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-15T09:57:45Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-15T01:09:52Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-02T09:07:40Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-06-23T04:53:42Z"
        },
        {
          "tag": "v0.9.0-alpha.5",
          "kind": "prerelease",
          "published_at": "2026-06-22T23:47:36Z"
        },
        {
          "tag": "v0.9.0-alpha.4",
          "kind": "prerelease",
          "published_at": "2026-06-20T04:38:33Z"
        },
        {
          "tag": "v0.9.0-alpha.3",
          "kind": "prerelease",
          "published_at": "2026-06-19T23:34:31Z"
        },
        {
          "tag": "v0.9.0-alpha.2",
          "kind": "prerelease",
          "published_at": "2026-06-19T04:43:00Z"
        },
        {
          "tag": "v0.9.0-alpha.1",
          "kind": "prerelease",
          "published_at": "2026-06-19T00:21:02Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-06-12T10:56:55Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-06-10T23:45:09Z"
        },
        {
          "tag": "v0.7.0-alpha.5",
          "kind": "prerelease",
          "published_at": "2026-06-10T06:26:39Z"
        },
        {
          "tag": "v0.7.0-alpha.4",
          "kind": "prerelease",
          "published_at": "2026-06-09T10:05:38Z"
        },
        {
          "tag": "v0.7.0-alpha.3",
          "kind": "prerelease",
          "published_at": "2026-06-09T02:45:26Z"
        },
        {
          "tag": "v0.7.0-alpha.2",
          "kind": "prerelease",
          "published_at": "2026-06-09T02:23:47Z"
        },
        {
          "tag": "v0.7.0-alpha.1",
          "kind": "prerelease",
          "published_at": "2026-06-09T00:13:49Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-06-08T22:27:39Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-08T06:18:47Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-06-03T02:10:12Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-06-03T01:53:43Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-06-02T23:32:31Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-05-22T05:17:58Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-05-20T06:59:47Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-05-20T05:38:18Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-05-20T05:29:22Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-05-19T10:08:10Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-05-18T08:16:35Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-05-16T00:58:37Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-05-01T04:44:02Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-04-24T10:42:43Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-04-24T05:22:53Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-04-05T09:13:57Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e1f5a50284b93bbef74da74a2b9565af4e12a565",
          "body": "Bumps the go group with 2 updates: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) and [obsigna.dev/sdk/go](https://github.com/agent-receipts/obsigna).\n\n\nUpdates `modernc.org/sqlite` from 1.53.0 to 1.54.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https\n[…]\nte-type: version-update:semver-minor\n  dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the go group with 2 updates (#177)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T03:28:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb2ba3c7199d4f019e8a55e14d5cd5d8aabbcab3",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.5.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356f\n[…]\nsion-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go in the github-actions group (#176)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T03:27:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5952245622e5416f644eccc8e185d2881d4fa7a0",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.13.1 (#180)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-20T03:27:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9996a862efef29cc0aa79a0c61742ac193f180b",
          "body": "* fix(fleet): stack receipt preview in front of the Session Graph modal\n\nSelecting a row (or a chain cell) in the Session Graph modal opened the\nreceipt/chain detail modal behind the graph: every .modal-backdrop shared\none z-index (50), and the graph modal sits later in the document, so on a\ntie it \n[…]\n the closer registry), so a new modal is\n  registered in exactly one place.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix modal stacking so receipt previews appear above Session Graph (#178)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-20T03:23:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25520b9eb5e5dbad04cd7ec9e9e177bc95e1f21c",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.13.0 (#175)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-17T08:36:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5b0a6d9b884774bc20fac63d60ef2fc56761e34",
          "body": "* feat(enrichment): add Cost column to Overview and Sessions views\n\nOverview's recent-receipts mini-table gets the same per-row running-total\nCost column as the Receipts tab (small, session-bounded list, so a\nclient-side per-session fetch is fine).\n\nThe Sessions tab gets a session-total Cost column.\n[…]\nntSessionEnrichment=8 via a\nsemaphore channel; goroutine creation itself stays unbounded (cheap) but\nonly 8 run their Enrich() call at once. New test verifies peak concurrency\nnever exceeds the bound.",
          "is_bot": false,
          "headline": "feat(enrichment): add Cost column to Overview and Sessions views (#174)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-17T08:31:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "907fd5526b61e148f517e4eb3eacfc8d2501a2a7",
          "body": "…e agent graph (#173)\n\n* fix(enrichment): surface local enrichment in the Receipts tab's inline agent graph\n\nThe Session Graph modal and Fleet view (#172) both got a tokens/cost\nenrichment line, but the third session-scoped surface — the \"Agent graph\"\npanel shown above the receipts table when filter\n[…]\nd view) fetches each visible\nsession's enrichment once and patches a Cost column in per row via\nbinary search over its CostPoints curve, right of Time. Flat\n(non-session-grouped) tables are unchanged.",
          "is_bot": false,
          "headline": "fix(enrichment): surface local enrichment in the Receipts tab's inlin…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-17T05:30:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a4ff06603cc46fb6910f37b3de3bbcedb16f7e05",
          "body": "…raph and Fleet views (#172)\n\n* feat(enrichment): surface session-level local enrichment in Session Graph and Fleet views\n\nLocal session enrichment (token usage, estimated cost) was previously only\nfetched and rendered once per receipt, inside the single-receipt detail\nmodal, even though enrich.Enri\n[…]\ns a goroutine per session when no\n  enricher is configured — the common \"no local data\" deployment skips\n  the wg.Add/Wait entirely instead of paying setup for calls that would\n  each just return nil.",
          "is_bot": false,
          "headline": "feat(enrichment): surface session-level local enrichment in Session G…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-17T04:42:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a21328fba35c0ce8a042694e3e7811617e289930",
          "body": "Corrects a misfiled CHANGELOG entry: the local session enrichment bullet\nlanded under the already-tagged [0.11.0] heading in #170 instead of\n[Unreleased], so it never shipped in a version. Moves it to its own\n[0.12.0] section.",
          "is_bot": false,
          "headline": "chore(release): bump to v0.12.0 (#171)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-15T09:55:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f866a2bf0f30c627bf5f8600f413cb9ba0af965",
          "body": "* feat(enrich): local session enrichment as unverified sidecar\n\nAdd display-only enrichment of the receipt-detail view with locally\navailable agent session data (token usage, context-window %, estimated\ncost) when the dashboard runs on the same host/user as the agent.\n\nThe enrichment is an explicit,\n[…]\no skip\nfiles above a 128 MiB cap (real transcripts are a few MiB), and wrap the\nreader in io.LimitReader as a hard bound that also covers a 0-stat-size\ndevice file or a file that grows after the stat.",
          "is_bot": false,
          "headline": "Add local session enrichment for display-only unverified data (#170)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-15T09:52:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e16bb756af60e48dd66650bc7a217d056351f57",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.11.0 (#169)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-15T01:04:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64d929511bd4fed93c0963783079ffd2a83a8a1e",
          "body": "…use limit (#157) (#167)\n\n* feat(attribution): base temporal_overlap on edge-proximity; document path-reuse limit\n\nTwo refinements to cross-session collision detection (#157), both pre-release\nso they build on the unreleased FleetAttribution feature rather than changing\nshipped behaviour.\n\n157-a — p\n[…]\nonFarApartNoTemporalOverlap asserting that a\n  single-session edge whose touches are 90 min apart reports temporal_overlap\n  =false (the deliberate change from the old \"always true within a session\").",
          "is_bot": false,
          "headline": "fix(attribution): event-proximity temporal_overlap + document path-re…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-15T00:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "318ca3af2fbb4eb6c879e5fa9813ac14df5d94e6",
          "body": "Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.45.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.45.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n  dependency-version: 0.52.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.52.0 (#168)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T04:26:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe629ea7279f2deb9aea55898a6c151759125791",
          "body": "* docs: document forensic-key endpoint security model\n\nAdd a SECURITY.md section covering POST /api/forensic-key and\nPOST /api/forensic-key/path: the guards in place (loopback-only bind,\nHost-header/DNS-rebinding validation, cross-origin rejection, the\napplication/json Content-Type CSRF guard, and t\n[…]\no, internal/store/reader.go).\n- CHANGELOG.md: clarify that the application/json CSRF guard and the\n  \"..\"/NUL path allowlist apply only to POST /api/forensic-key/path,\n  not to POST /api/forensic-key.",
          "is_bot": false,
          "headline": "docs: document forensic key endpoint security model (#166)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-09T06:57:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32cb661ccbb4fb03b69254557ca5c84530fc4c36",
          "body": "* feat(attribution): add FleetAttribution data layer and endpoint\n\nAdd FleetAttribution([]sessionID) and GET /api/fleet/attribution?limit=N,\ncomputing one combined ADR-0029 §4 attribution payload across the N most\nrecently-active sessions (default 6, capped 12). Agent keys are namespaced\n<session_id\n[…]\no main pulled in #162's seedFleetDB (returns *store.Reader,\nfleet signatures) alongside this branch's own seedFleetDB (returns *Server,\nfleet attribution). Rename the latter to seedFleetAttributionDB.",
          "is_bot": false,
          "headline": "feat(attribution): fleet attribution data layer and endpoint (#157)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-09T06:57:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "86ef2bae3ec55c6d19d8c923613fe2163f4b1ce1",
          "body": "Path-derived state-dependency edges are inferred from shared\naction.target.resource path strings. Path identity is not file\nidentity, so these edges are evidential — they suggest two agents\ntouched the same resource — not proof of causal order.\n\nReword the README session-attribution section and the \n[…]\nwith a tooltip clarifying that\nBash/MCP/spawn receipts are signed but carry no resource path.\n\nStrings, README prose, and tooltip markup only — no behaviour change and\nno internal identifiers renamed.",
          "is_bot": false,
          "headline": "docs: remove overclaiming language from session dependency graph (#165)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-09T06:45:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81e1032285d4658d2d48299ef873416ddb475b7c",
          "body": "Bumps the github-actions group with 1 update: [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `goreleaser/goreleaser-action` from 7.2.2 to 7.2.3\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/gorel\n[…]\nsion-update:semver-patch\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action (#164)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T08:29:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae0a0cfcbf36487d2af364a373001b13eff899e3",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.10.0 (#163)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-02T07:33:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0fa0678aba9d09908c19510a7d092c721590933",
          "body": "* feat(fleet): add experimental activity-signature view\n\nAdds an experimental, flag-gated Fleet tab that renders the N most recently-\nactive sessions as 'universes': orchestrator sized by receipt volume, a\ndiscretionary activity-mix ring (bash demoted to a thin inner gauge arc),\nagent-type satellite\n[…]\no `fleetFp` to avoid\n  collision with other helpers in the shared inline script.\n- Add a keyboard focus indicator for universe cards: highlight the cell\n  boundary via `.fleet-universe:focus-visible`.",
          "is_bot": false,
          "headline": "feat(fleet): experimental activity-signature view (#162)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-07-02T06:50:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a745ed7e62c6119981e3e7e142105611a9b02bd",
          "body": "* feat(fleet): add --experimental flag and activity-signature data layer\n\n- Add `-experimental` bool CLI flag (default false) wired into Config.Experimental\n- Expose experimental field in GET /api/config JSON response\n- Add SessionSignature type and activityCategory() helper in internal/store\n- Add \n[…]\nkeyword precedence (mcp/bash first, edit before read), not 'file.modify'\n  falling through to read (it never matches read).\n- CHANGELOG: use single-dash -experimental consistently (matches -db/-port).",
          "is_bot": false,
          "headline": "feat(fleet): --experimental flag + activity-signature data layer (#161)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-30T10:35:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e3ec0217d6b49277bf15aa6f14b7ca0f4731159",
          "body": "Bumps the go group with 1 update: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `modernc.org/sqlite` from 1.52.0 to 1.53.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.52.0...v1.53.0)\n\n---\nupdated-de\n[…]\nte-type: version-update:semver-minor\n  dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump modernc.org/sqlite in the go group (#160)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T08:06:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8ce9b34f0dceb1e4963d9617899182ff734a922b",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.4.0 to 6.5.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e3721\n[…]\nsion-update:semver-minor\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go in the github-actions group (#159)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T08:06:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6473835bdff88ba16c88ae27cede09c124d3bac0",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.9.0 (#155)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-23T04:51:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1732fc3ad1b93e93cb85d2b2b3eb13b2157b6060",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): migrate Obsigna SDK to obsigna.dev/sdk/go v0.23.0 (#154)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-23T04:40:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0af2613a1f3f68fd27501493717ad0b97f352033",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.9.0-alpha.5 (#153)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-22T23:29:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd5285a80e4c7ca733a404c685a13a9302f8631e",
          "body": "Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).\n\n\nUpdates `actions/checkout` from 6.0.3 to 7.0.0\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits\n[…]\nsion-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout in the github-actions group (#150)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T23:19:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4f991cc4955b282db7343dce5661fed5e4fc62a",
          "body": "… (#151)\n\nBumps the go group with 1 update: [github.com/agent-receipts/ar/sdk/go](https://github.com/agent-receipts/ar).\n\n\nUpdates `github.com/agent-receipts/ar/sdk/go` from 0.21.0-alpha.1 to 0.22.0-alpha.1\n- [Release notes](https://github.com/agent-receipts/ar/releases)\n- [Commits](https://github.c\n[…]\nte-type: version-update:semver-minor\n  dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github.com/agent-receipts/ar/sdk/go in the go group…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T23:18:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6535f1dfa4e9cd47a8b202432f2df78b0899ce7d",
          "body": "Update the page title, header brand, action-type reference description,\nand the empty-database CLI hint to read \"Obsigna\". GitHub URLs, Go\nimport paths, and on-disk agent-receipts paths are left unchanged.",
          "is_bot": false,
          "headline": "feat: rebrand dashboard UI from Agent Receipts to Obsigna (#152)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-22T23:15:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91019088467ba3f64b14c75bd3d18c1b062645f6",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): add v0.9.0-alpha.4 SDK bump entry (#149)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-20T04:58:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffad8cc9507249fe0d459ce9c6a32f2ca9aadcf6",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.9.0-alpha.4 (#148)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-20T04:36:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "627fbbe601d81bbe58ee536893e9789b4aa77a9e",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): bump obsigna SDK to v0.21.0-alpha.1 (#147)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-20T03:58:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "301620224ef270227f603e92d9cb2de4196169bd",
          "body": "* docs: refresh README screenshots to reflect current dashboard\n\nReplace the stale 8-receipt overview screenshot with three current\nscreenshots captured from a live store with 29k+ receipts:\n\n- docs/screenshot.png — Overview tab: activity timeline, risk/status/\n  action distribution panels, Receipts\n[…]\nt texts to match the new screenshots and move the detail\nscreenshot to the Forensic decryption section where it belongs.\n\n* docs: rename session-attribution-detail.png → forensic-decryption-detail.png",
          "is_bot": false,
          "headline": "docs: refresh README screenshots to reflect current dashboard (#146)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-20T00:27:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "996c4e20fac17d94e64e2249013ba8bc81b56b20",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.9.0-alpha.3 (#145)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T23:31:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3ea7a1ce157908cbc9db50268838eb598db7cb7",
          "body": "…144)\n\nPOST /api/forensic-key and DELETE /api/forensic-key had no CSRF\nprotection: a cross-origin page could issue a CORS-simple text/plain\nPOST to replace the operator's loaded forensic key, or a DELETE to\nclear it, without triggering a preflight. Add an Origin allowlist\nguard (rejectCrossOrigin) mirroring the existing Host-header DNS-rebind\nguard, and apply it to all three forensic write endpoints. Requests\nwithout an Origin header (curl, SDK clients) are unaffected.\n\nCloses #79",
          "is_bot": false,
          "headline": "fix(forensic): reject cross-origin requests to key write endpoints (#…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T23:23:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a9c0e9847bef3a4d370843c46dc514e2012368e",
          "body": "… oversize buffer, return 413 (#143)\n\n* fix(forensic): harden key file reads against non-regular files and oversize\n\nReject non-regular files (symlinks, FIFOs, devices, directories) in\nreadFileLimited via Lstat before opening, so a FIFO at ForensicKeyPath\ncannot hang startup and a device cannot be r\n[…]\no operator-\nsupplied input can no longer reach an arbitrary file, resolving the\nCodeQL go/path-injection alert. The startup auto-load (operator-set\nconfig, not an HTTP source) is unaffected.\n\nRefs #78",
          "is_bot": false,
          "headline": "fix(forensic): harden key file reads — reject non-regular files, zero…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T23:16:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b32d635351ac3611ed03611a973e2e61aef8188",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.9.0-alpha.2 (#142)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T04:38:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e12e3ca7754f07efa92510d3379d2d34d9eace6",
          "body": "VerifyChainLinks checked each Ed25519 signature with receipt.Verify on the\nparsed Go struct, which re-marshals and canonicalizes a struct that drops any\nfield a newer SDK signed over but nested inside the payload (e.g. under\ncredentialSubject). The signature then verifies over different bytes than w\n[…]\nT /api/chains/{id}/verify?public_key=...\n\nSwap to receipt.VerifyRaw(cr.Raw, ...), the signature-side twin of\nHashRawReceipt, so both paths verify the verbatim wire bytes. Requires SDK\nv0.20.0-alpha.2.",
          "is_bot": false,
          "headline": "fix(verify): verify chain signatures from raw wire bytes (#73) (#141)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T04:35:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "641bef3e95f2feb5d5df3791b2992c8f07dafe4d",
          "body": "The project layout described internal/store as \"multi-DB\", but it was\nnever implemented — OpenReadOnly opens exactly one database. Describe\nwhat the package actually does.",
          "is_bot": false,
          "headline": "docs: correct internal/store description (not multi-DB) (#140)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T02:29:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3586e5bb75da5162b1e4a27bac96ac8349c51247",
          "body": "* feat(ui): render structured issuer and principal details\n\nSurface the issuer's type, top-level model, and operator (name + id), and\nthe principal's type as a badge in the receipt detail view. Previously these\nfields were only visible in the raw JSON blob. All new fields render\nconditionally and de\n[…]\n not omitempty, so a present-but-empty\noperator could render a stray 'operator' label. Render the row only when at\nleast one of name/id is non-empty, and emit each span only when its value is\npresent.",
          "is_bot": false,
          "headline": "feat(ui): render structured issuer and principal details (#139)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T02:15:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "442ce30c14ff3c1eca43ecada77a10fe9738923e",
          "body": "* feat(taxonomy): surface action-type taxonomy in the dashboard\n\nAdd GET /api/taxonomy serving the SDK's built-in action-type registry\n(every known type with its description and default risk level, grouped\nby category). The frontend uses it to:\n\n- render a collapsible \"Action type reference\" card in\n[…]\ncard for\n  the whole page lifetime after a transient boot-time error.\n- Fail TestTaxonomyEndpoint if an action type appears in more than one\n  category, rather than silently overwriting the map entry.",
          "is_bot": false,
          "headline": "feat(taxonomy): surface action-type taxonomy in the dashboard (#138)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T01:17:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8539cacefe3c5b16834e52f1a25197e32f8cfa39",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.9.0-alpha.1 (#137)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T00:13:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b9634d7548b127147318ae487ae6a03b9714e75",
          "body": "* feat(graph): highlight connected component on node click\n\nClicking an agent-graph node now highlights its entire state-dependency\nconnected component (all agents reachable via shared-resource contention\nedges), dims everything outside it, and emphasizes the in-component\nstate-dep edges. Delegation\n[…]\nible on\nhighlighted nodes. Use --text instead of --accent for the rings so the\nclicked node reads clearly on the blue root node as well as green\nsub-agents.\n\nAddresses Copilot review feedback on #136.",
          "is_bot": false,
          "headline": "feat(graph): highlight connected component on node click (#136)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-19T00:07:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36326f9aec23a9de25246786b0b28546e46bb333",
          "body": "… (#134)\n\nBumps the go group with 1 update: [github.com/agent-receipts/ar/sdk/go](https://github.com/agent-receipts/ar).\n\n\nUpdates `github.com/agent-receipts/ar/sdk/go` from 0.17.0-alpha.1 to 0.20.0-alpha.1\n- [Release notes](https://github.com/agent-receipts/ar/releases)\n- [Commits](https://github.c\n[…]\nte-type: version-update:semver-minor\n  dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github.com/agent-receipts/ar/sdk/go in the go group…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T07:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fb46a018e16fe79c4637f24808a9fdc08fd8d2b",
          "body": null,
          "is_bot": false,
          "headline": "docs: add agentreceipts.ai and obsigna.dev to the ecosystem table (#133)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-13T12:14:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80374245b8e113bbf89a9dbba9050f0fdc627170",
          "body": "… and security model (#132)\n\n* docs(readme): document forensic decryption, analytics, full HTTP API, and security model\n\nThe README lagged the shipped feature set (v0.8.0). Make it the canonical\nreference by adding what was missing:\n\n- Forensic decryption — default-path auto-load (~/.local/share/age\n[…]\ncosystem: the monorepo is now agent-receipts/obsigna (was agent-receipts/ar);\n  rename the entry, add an obsigna-daemon row, and repoint the mcp-proxy/spec\n  tree links and the intro links to obsigna.",
          "is_bot": false,
          "headline": "docs(readme): document forensic decryption, analytics, full HTTP API,…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-13T10:10:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6ef00f7f6731d50ced290dc41ee1f745dbcc4ba",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.8.0 (#131)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-12T10:54:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5d0313966920689832eb12c5c0a22aa315d4839",
          "body": "* feat: ADR-0029 §4 attribution and blast-radius view\n\nExtends the existing session graph panel with cross-agent state-dependency\nedges, a blast-radius attribution panel, risk rings on nodes, and a coverage\nfraction in the modal header.\n\nBackend:\n- New `SessionAttribution` method on store.Reader: qu\n[…]\nrom_agent/to_agent in the API response could flip\nbetween requests for identical data.\n\nISO-8601 timestamps sort lexicographically, consistent with the\nORDER BY timestamp ASC in the attribution query.",
          "is_bot": false,
          "headline": "Add session attribution analysis with state-dep edges (#130)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-12T10:51:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "713c05cab00e78cbdc8ddb589795c6704bd00ccb",
          "body": "* feat: surface transcript-derived model and token usage from issuer.runtime\n\nAdds dashboard support for the enrichment fields introduced in obsigna\nPR #779: issuer.runtime.{model,capture_method,usage}.\n\nStore layer:\n- Four new fields on ReceiptRow: RuntimeModel, RuntimeCaptureMethod,\n  RuntimeUsage\n[…]\n  RuntimeModel extraction only; notes that capture_method and usage\n  surface via the detail endpoint's raw JSON passthrough, not ReceiptRow.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Surface transcript-derived model and token usage in receipts (#129)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-11T09:04:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "836333a01e48aff7a44879dd9e6c03a06d5a68c9",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.7.0 (#128)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-10T23:43:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcabf891012202323d5d129a4b1b74d91a595ac2",
          "body": "Extract issuer.model from receipt JSON ($.issuer.model) into ReceiptRow.IssuerModel\nand expose it as issuer_model in the API response. The session graph renders\nthe model name as a third label line below each agent node, visible in both\nthe inline receipts-view graph and the session-detail modal graph.\n\nOlder receipts that predate the daemon stamping issuer.model degrade gracefully\n— the model line is simply absent from those nodes.",
          "is_bot": false,
          "headline": "feat: surface issuer.model in session graph nodes (#127)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-10T20:24:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4a162c6102bbd10dc76fe2517e92bfcccf0a3d8",
          "body": "* feat: node-link session graph view for agent delegation (#122)\n\nAdds a per-session agent delegation graph to the Sessions table. Each\nsession row gets a \"Graph\" button that opens a modal showing an SVG\nnode-link diagram: the orchestrator (root) at the top, sub-agents in a\nrow below, connected by d\n[…]\nb-agents → 1120 px wide viewBox instead of 800 px)\n- Inline graph collapse button: drop icon-btn class (fixed 28×28 box was\n  squishing ▾ to a dot); use bare button style matching session-collapse-btn",
          "is_bot": false,
          "headline": "feat: node-link session graph view for agent delegation (#122) (#126)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-10T20:22:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d60be0fd52ab711ea62a618a70fce6d19046a08a",
          "body": "bytes.TrimSpace was used to handle raw keys uploaded with a trailing\nnewline, but TrimSpace strips any whitespace byte including 0x0A and\n0x0D. X25519 keys are random bytes, so ~2% of keys end in such a byte;\nin those cases TrimSpace consumed a real key byte and the input no\nlonger matched any recognised encoding.\n\nReplace with bytes.TrimRight(raw, \"\\r\\n\") on the raw-key path so only\nactual line endings are stripped.",
          "is_bot": false,
          "headline": "fix: use TrimRight for raw forensic key line-ending stripping (#125)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-10T06:24:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ce781f698539541a2aad08dc06caa6bf8eaaddc",
          "body": "The Receipts tab only synced ?q= into the URL; session_id was set by\napplySessionFilter/filterBySession but never removed when the filter was\ncleared. A stale ?session_id= would then be re-applied by the deep-link\nboot logic on the next reload, making the session filter sticky and\nforcing users to h\n[…]\nthe URL to widen the view.\n\nloadReceipts() now owns URL sync for session_id too (set when present,\ndelete when empty), and the redundant URL writes in applySessionFilter /\nfilterBySession are removed.",
          "is_bot": false,
          "headline": "fix: clear session_id from URL when session filter is cleared (#124)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-10T06:12:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e89fb2b3e64defedaac5fdc4fd503dff3122a535",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.7.0-alpha.4 (#123)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T10:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f8e4a1a602168ad8a23c2fb7f10de43a742be4c",
          "body": "The dashboard read the sub-agent id from a flat `issuer.agent_id`, but the\ndaemon never emitted it there — and as of protocol v0.5.0 / daemon\nv0.18.0-alpha.1 it lives under the open `issuer.runtime` sub-object\n(ADR-0026). So `issuer.agent_id` always resolved to NULL and sub-agent\ngrouping never lit \n[…]\neal receipts; add an agent_type assertion.\n\nVerified against the live receipts.db: /api/sessions agent_count resolves\nsub-agents, /api/receipts surfaces agent_id + agent_type on all 33\nsub-agent rows.",
          "is_bot": false,
          "headline": "feat: read sub-agent identity from issuer.runtime (ADR-0026) (#121)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T09:58:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41158da6dfae42405dbbd48b68651515d5f4f25a",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.7.0-alpha.3 (#120)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T02:41:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbee21179a4c8cde9a7f6f821a6e84e9351a1cdd",
          "body": "issuer.agent_id is a Layer 3 extension field not yet produced by any\ncurrent daemon version, so the agent count was always 0. Falling back\nto issuer.id gives a correct count (≥ 1) for current receipts; once\nthe daemon starts emitting agent_id the correct subagent count appears\nautomatically.",
          "is_bot": false,
          "headline": "fix: fall back to issuer.id for Sessions tab agent count (#119)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T02:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24d724c35cd4c36ee5bafbee68b6bc368c73bcdd",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.7.0-alpha.2 (#118)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T02:21:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79df7624820bcdfad847f6697eb360f943bfa4fd",
          "body": "* feat: add Sessions tab with GET /api/sessions endpoint\n\nAdds a dedicated Sessions tab that lists all agent sessions extracted\nfrom stored receipts. Each row shows session ID, receipt count, distinct\nagent count, and first/last seen timestamps. Clicking a row navigates to\nthe Receipts tab pre-filte\n[…]\nagate errors in seedSessionsDB helpers\n\nMarshal/unmarshal and hash/insert errors were silently discarded,\ncausing later test failures with confusing messages instead of\na clear t.Fatalf at the source.",
          "is_bot": false,
          "headline": "feat: Sessions tab (#117)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T02:19:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1dc06e56505367b4bdc6772ab5d31b23ad1480cd",
          "body": "* feat: jump to session from Overview recent receipts (#111)\n\nAdd a small session pill to each receipt row in the Overview recent-receipts\nmini-table when the receipt carries a session_id. Clicking the pill switches\nto the Receipts tab and applies a session filter. Supports a ?session_id=\nURL deep l\n[…]\nregardless of merge order.\n\n* fix: data-session-id attribute on pill; call loadReceipts() in fallback branch\n\n* fix: single loadReceipts call; bookmarkable URL in both paths; focus-visible; aria-label",
          "is_bot": false,
          "headline": "feat: jump to session from Overview recent receipts (#111) (#115)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T01:51:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e22345926fc8071ad055b5a0e1cc31068d8a11e",
          "body": "* feat: filter receipts by session_id (#110)\n\nAdd a Session ID filter to the Receipts tab. Typing in the new input\nrestricts the list to receipts whose issuer.session_id matches exactly.\nClicking a session header in the grouped view pre-fills the input and\nreloads. Clear filters / chip-clear also re\n[…]\n no session_id is present.\n\n* fix: use data-session-id attribute on session header span (avoid JSON.stringify in onclick)\n\n* fix: trim session_id param; session header as button; fix changelog wording",
          "is_bot": false,
          "headline": "feat: filter receipts by session_id (#110) (#114)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T01:49:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4d901d2432b45077235d21c367b563b231b00eb",
          "body": "* feat: keyboard navigation between receipts in detail view (#112)\n\nWhen the receipt detail modal is open, j/↓ opens the next receipt in\nthe current list and k/↑ opens the previous one. Navigation stops at the\nends (no wrap). Session/agent header rows in grouped mode are skipped via\nthe [data-receipt-id] selector. Keyboard shortcuts help modal updated.\n\n* fix: serialize keyboard navigation; clarify shortcut help labels",
          "is_bot": false,
          "headline": "feat: keyboard navigation between receipts in detail view (#112) (#113)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T01:39:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5a4cf0eaca871e9d8b0cf370e4245e07574731a",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.7.0-alpha.1 (#109)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T00:12:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a7e1aff4661180e6e7e025cd6b139dbbabdd1b3",
          "body": "…lation pairs, delegation edges) (#108)\n\n* feat: add Layer 3 attribution rendering (session groups, swimlanes, correlation pairs, delegation edges)\n\nReceipts from daemon ≥ v0.17.0 / hook ≥ v0.14.0 carry three new JSON\nfields: issuer.agent_id, issuer.session_id, credentialSubject.correlation_id,\nand \n[…]\ner augmentation and switch to HashRawReceipt.\n\nAlso expose collapse state to assistive tech: add aria-expanded=\"true\"\nto the session collapse button on render and keep it in sync inside\ntoggleSession.",
          "is_bot": false,
          "headline": "feat: Layer 3 attribution rendering (session groups, swimlanes, corre…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-09T00:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a9e6a4e5d3a621fbd651249c7757e9539c4c281",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.6.1 (#107)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T22:25:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba9f83831e0f91ed5f6cd758592124e63d509b46",
          "body": "* fix: return [] instead of null for empty API result sets\n\nStore functions initialised their output as a nil slice which JSON-encodes\nas null. When the selected time range contains no receipts the /api/receipts\nendpoint returned null, causing the frontend to crash with\n\"Cannot read properties of nu\n[…]\n\n- Add receipts || [] guard to loadReceipts in the frontend\n- Remove dead nil-guards from handleTimeseriesStats, handleActionStats,\n  handleServerStats now that the store always returns non-nil slices",
          "is_bot": false,
          "headline": "fix: return [] instead of null for empty API result sets (#106)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T22:23:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee062932d0657ccc7a8711cd1caac8490c9e57d2",
          "body": "Adds skip_upload: auto to the stable formula (consistent with daemon/hook/\nmcp-proxy) and a new dashboard-alpha formula that publishes on every\nrelease — stable and pre-release alike.\n\nInstall the latest cut (including alphas/betas) with:\n  brew install agent-receipts/tap/dashboard-alpha\n\nconflicts_with the stable formula; livecheck regex extended to match\npre-release suffixes.",
          "is_bot": false,
          "headline": "feat(release): add alpha-track Homebrew formula for dashboard (#104)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T20:19:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bd569af8b43263d8ade8bbb5f2b5c8cdf6377e6",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.6.0 (#103)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T06:14:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dabf90c9ccf5ebedbf47708d1f9a36c9fb5d5c2",
          "body": "A GitHub icon next to the shortcuts button opens the project repo in a new tab,\nso operators can browse the source or report an issue.",
          "is_bot": false,
          "headline": "feat: add a GitHub link to the header (#102)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T05:42:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac6ebe7583b33ec470f34de955c2a9342224b17c",
          "body": "The stacked bars rendered as thin spikes because the inter-bar gap was 2x the\nbar width. The gap is now a small fraction (0.06) of the bar width, so the\ncontiguous time buckets read as a continuous histogram rather than spaced-out\nspikes. Genuine zero-activity buckets remain visible as gaps.",
          "is_bot": false,
          "headline": "fix: render activity timeline as a tight stacked bar chart (#101)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T05:34:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f25aaca88e20559629e3518eb3989c8ee9fa248",
          "body": "* feat: add error-rate sparkline and throughput stat card\n\nAdds two new panels to the Overview tab driven by the active time range:\n\n- Error-rate sparkline (data-card=\"error-rate\"): collapsible card with an\n  inline SVG polyline of failure % per timeseries bucket. Null/zero-total\n  buckets render as\n[…]\n)\n- recompute throughput from live stats.total in renderStats (no stale value\n  during polling); cache only rangeHours + prev per-hour as context\n- add aria-label/role=img to the sparkline trend arrow",
          "is_bot": false,
          "headline": "feat: add error-rate sparkline and throughput stat card (#100)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T04:31:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0922a406893facf1f8cbb2d5bc12da916f40ea0",
          "body": "* feat: add activity timeline chart to overview\n\nAdds a collapsible \"Activity timeline\" card to the Overview tab,\npositioned between the stats summary cards and the 3-column\ndistribution grid. The card renders an inline SVG stacked bar chart\nof receipt counts per timeseries bucket, with success (gre\n[…]\ntal so success+failure+other sum\n  exactly to the bar total (no per-segment 1px min); keeps the hit-rect\n  covering the full bar\n- show a distinct error state on fetch failure instead of 'No activity'",
          "is_bot": false,
          "headline": "feat: add activity timeline chart to overview (#99)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-08T04:14:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cd7d98731e320cc0f5064c77e892dceefdcc7e10",
          "body": "* feat: add time range picker and timeseries stats endpoint\n\nAdd a persistent 1h/6h/24h/7d/30d/All range picker to the Overview tab\nthat drives every panel — stat cards, distributions, top actions, server\nactivity, and recent receipts — via after= on /api/stats and /api/receipts.\nThe active preset i\n[…]\nedge)\n- render bucket_duration cleanly (\"1h\" not \"1h0m0s\") via formatBucketDuration\n- use second-resolution RFC3339 for the frontend after= watermark\n- add tests for to-alone and clean bucket_duration",
          "is_bot": false,
          "headline": "feat: add time range picker and timeseries stats endpoint (#98)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-07T20:15:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "575480f9bcb5a9b9d95a437198c7bdcd62af74a9",
          "body": "Each Overview card (distribution charts, Top actions, Server activity, Recent\nreceipts) gets a chevron that collapses it to just its header. The collapsed\nstate is persisted per card in localStorage so hidden cards stay hidden across\nreloads.",
          "is_bot": false,
          "headline": "feat: collapsible Overview cards with remembered state (#97)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-07T08:57:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ef24b867482957524d8c2d6ea0c2ab4be101025",
          "body": "Bumps the go group with 1 update: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `modernc.org/sqlite` from 1.51.0 to 1.52.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.51.0...v1.52.0)\n\n---\nupdated-de\n[…]\nte-type: version-update:semver-minor\n  dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump modernc.org/sqlite in the go group (#96)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-07T08:55:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9a87c11f342596cb02a90774e89b7e660646bd6",
          "body": "Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).\n\n\nUpdates `actions/checkout` from 6.0.2 to 6.0.3\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits\n[…]\nsion-update:semver-patch\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout in the github-actions group (#95)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-07T08:55:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b35dcffd8359a4341b86e18035d2d2c66412de62",
          "body": "* fix: overview summary cards no longer hang on skeletons\n\nBoth the Top actions and Server activity summary fetches ran after\nstartPolling(), which bumps poller.generation, so their gen guard always\nbailed and the skeletons never rendered. Move the fetches before startPolling\nwhile keeping each isol\n[…]\nng /api/stats/* delay recent-receipts polling and keyboard nav.\nStart polling + nav first, then load the cards guarded by a fresh generation\ncaptured after startPolling (which increments the counter).",
          "is_bot": false,
          "headline": "fix: overview summary cards no longer hang on skeletons (#94)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-07T08:50:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3244a5b67ea51c8689fb8f693af5bcc5d7c48f20",
          "body": "* feat: add server/tool breakdown panel and endpoint\n\nAdds GET /api/stats/servers which groups receipts by\ncredentialSubject.action.target.system and tool_name, computing\ntotals, failure counts, and failure rates at both levels. Rows with\nno server value are folded into an \"Unknown\" bucket placed af\n[…]\nzes as server:\"\" instead of\nthe literal \"Unknown\", so a real server named \"Unknown\" stays distinguishable.\nThe frontend renders \"\" as the \"Unknown\" label and keys the missing bucket off\nserver === ''.",
          "is_bot": false,
          "headline": "feat: add server/tool breakdown panel and endpoint (#93)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-07T05:44:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fac128525f05474f1b25032646b6172c16b6e3d2",
          "body": "* feat: add free-text search to receipts\n\nAdds a search box to the Receipts tab filter bar that searches across\nthe full raw receipt JSON via GET /api/receipts?q=<term>. The active\nterm is synced to the URL so searches are bookmarkable; loading the\ndashboard with ?q=<term> pre-fills the box and open\n[…]\nfix: populate header stats on ?q= deep-link boot\n\nAddresses Copilot review: the deep-link path skipped loadOverview, leaving the\nheader receipt-count/latest-timestamp blank until Overview was visited.",
          "is_bot": false,
          "headline": "feat: add free-text search to receipts (#92)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-07T05:36:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe89e6ed2549ab95db16b6270ccefbfb88d57153",
          "body": "* feat: add top actions by failure rate table and endpoint\n\nAdd GET /api/stats/actions returning per-action-type failure statistics\n(total, success, failure, failure_rate). Action types with fewer than 5\nreceipts are excluded via HAVING. An optional `range` query param\n(Go duration string) restricts\n[…]\nd the issue examples; frontend renders it as a percent\n- sortable Actions column headers are now real <button>s with aria-sort\n- Overview summary rows are keyboard-operable (role/tabindex/Enter/Space)",
          "is_bot": false,
          "headline": "feat: add top actions by failure rate table and endpoint (#91)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-07T04:37:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba0d61839e1d02faefffb2de35ab7f8679afa0ae",
          "body": "The collector architecture already solves the multi-machine problem —\nagents POST receipts to a central collector, the dashboard reads that\nstore from any browser. A native desktop wrapper is not needed and\nwould have locked the frontend into a local-only shape.\n\nCloses #38",
          "is_bot": false,
          "headline": "docs: supersede ADR 0001 (Wails desktop wrapper) (#89)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-06T00:01:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "496a337d7dc4c7465f01bf698ee63366a80593b1",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.5.1 (#82)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-03T02:07:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "222a15c0065a9ffd91ccf5b5cc708cbc9d25eb8d",
          "body": "v0.5.0 only read .input and .output from the decrypted parameters when\npopulating the row tooltip cache, so disclosures that capture other\ntop-level keys — for example MCP tool wrappers writing command /\narguments / result — looked the same as before decryption: the\nfallback \"Additional disclosure f\n[…]\n the schema\nmatches the server's preview convention.\n\nWhen the decrypt succeeded but every value is empty, the tooltip now\nsays \"🔓 Decrypted (empty parameters)\" instead of pretending nothing\nhappened.",
          "is_bot": false,
          "headline": "fix: show decrypted row preview for arbitrary disclosure schemas (#81)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-03T02:04:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3433ce4582ea370fd111f890fa5ccdd60880a2ae",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.5.0 (#80)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-03T01:50:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f360175ecfd1e2648d8220e2150dcc69f0c0d1f",
          "body": "* feat: load forensic key from path and auto-probe default location\n\nAdd a file-path input to the forensic key modal (pre-filled with the\nXDG default ~/.local/share/agent-receipts/forensic.key) so operators\ncan load their key by pasting or editing a path instead of using the\nfile picker.  A new POST\n[…]\nth.Join discarding the home\nprefix when joined with \"/file\") does not apply to Go; verified that\nfilepath.Join(\"/home/alice\", \"/file\") returns \"/home/alice/file\" — the\nbehaviour is Python's, not Go's.",
          "is_bot": false,
          "headline": "feat: load forensic key from path and auto-probe default location (#77)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-03T01:38:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acd3ed40806b15cb707642c7fcd95a512e62381b",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump to v0.4.0 (#76)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-02T23:29:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9312037de3036adb896cd35c8f56b621951f680",
          "body": "* feat: decrypt HPKE parameter disclosure envelopes in the dashboard\n\nOperators can now load their X25519 forensic private key into the\ndashboard and view decrypted parameters_disclosure envelopes inline in\nthe receipt detail view, closing the detail-view decryption follow-up\ndeferred in 0.3.0.\n\nThe\n[…]\n now re-syncs from the authoritative status on a non-OK or\n  failed DELETE instead of optimistically applying the error body, so the UI\n  can't show the key as cleared while the server still holds it.",
          "is_bot": false,
          "headline": "feat: decrypt HPKE parameter disclosure envelopes in the dashboard (#75)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-02T22:59:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce616d18a6446d4122e88280fe2bf4036b981655",
          "body": "* fix(verify): recompute chain hashes from raw wire bytes (#719)\n\nChain verification reported valid chains as broken. The hash-linkage\nrecompute round-tripped each receipt through the Go struct via\nreceipt.HashReceipt, which drops any forward-compat fields a newer SDK\nwrote before hashing. The resul\n[…]\nthe single allocation.\n\n* docs(verify,store): tidy ChainReceipt/VerifyChainLinks comments\n\nAdd the missing 'that' in two doc comments for readability, per PR\nreview. Comment-only; no behaviour change.",
          "is_bot": false,
          "headline": "Fix chain verification false negative with forward-compat fields (#74)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-06-02T07:40:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ebc75c264d56c9ac81db348002b83e58f887b11",
          "body": "Bumps the go group with 2 updates in the / directory: [github.com/agent-receipts/ar/sdk/go](https://github.com/agent-receipts/ar) and [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `github.com/agent-receipts/ar/sdk/go` from 0.11.0 to 0.13.0\n- [Release notes](https://github.com/agen\n[…]\nte-type: version-update:semver-minor\n  dependency-group: go\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the go group across 1 directory with 2 updates (#72)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-02T05:51:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66754b6f8d07d83fa16e7d4bdda6371ddcfb2ba9",
          "body": "Bumps the github-actions group with 1 update: [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `goreleaser/goreleaser-action` from 7.2.1 to 7.2.2\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/gorel\n[…]\nsion-update:semver-patch\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action (#70)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-02T05:50:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dde25a1264632ebef9e5de85b10d6d670c8c9bb1",
          "body": "CHANGELOG entry for the v0.3.0 cut: brings the dashboard onto sdk/go v0.11.0 (envelope-shape parameters_disclosure per ADR-0012) via #67/#68, and backfills the missing 0.2.x compare links.\n\nAfter merge, push tag v0.3.0 to trigger release.yml → goreleaser → binaries + GitHub Release + homebrew-tap formula update.",
          "is_bot": false,
          "headline": "chore(release): bump to v0.3.0 (#69)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-22T05:16:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e581b9f3cb852468967318d7d64a73d038420437",
          "body": "…est (#68)\n\n* test(store): remove double-close on raw sqlite handle in legacy-shape test\n\nThe previous patch (#67) used both `defer db.Close()` and an explicit\n`db.Close()` to release the writer before opening the reader. That\ndouble-closes the handle and can mask the inner-Close error. Drop the\ndef\n[…]\n; the explicit close is required (and now error-checked) so the\nreader sees a quiesced file.\n\nPer Copilot review on #67 (landed after merge).\n\n* test(store): t.Cleanup as failure-path Close safety net",
          "is_bot": false,
          "headline": "test(store): drop double-close on raw sqlite handle in legacy-shape t…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-22T04:53:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a926242e41f317d5f6c94aa828647084e591ce9",
          "body": "- Bumps github.com/agent-receipts/ar/sdk/go from v0.9.0 to v0.11.0.\n- Refactors internal/store/reader_test.go for the v0.3.0 envelope-shape parameters_disclosure (*receipt.DisclosureEnvelope).\n- Adds TestReader_ListReceipts_OutputStatusMismatch_LegacyShape to keep coverage of the SQL mismatch detect\n[…]\npre-v0.3.0 flat-map disclosures (per Copilot review on #67).\n\nPhase 6 of the v0.3.0 release in agent-receipts/ar (#280). Production code unchanged; envelope-shape UI rendering is a separate follow-up.",
          "is_bot": false,
          "headline": "chore(deps): bump sdk/go to v0.11.0 (v0.3.0 envelope migration) (#67)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-22T04:39:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93744dac74df2b79e8e6aa407986f9ebe103b5f1",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.2.2 (#66)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T06:57:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d40ee1de2358b4738d133cf52b654b8cd9cdd420",
          "body": null,
          "is_bot": false,
          "headline": "fix(ui): truncate long action type labels in distribution chart (#65)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T06:54:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20104ff31270c9f97d04a09400193619d81a4497",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.2.1 (#64)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T05:36:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2131c51e17964c5e1fb5cd87b9bc704bfc0b3d0d",
          "body": "…act (#63)",
          "is_bot": false,
          "headline": "fix(ui): cap action distribution chart to top 5 to keep overview comp…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T05:35:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c9b800a7cd9738252d1394098ebf71132058506",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.2.0 (#62)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T05:27:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45e5fe4fd5f5faf4759b61a7ad79215eccdd41d4",
          "body": "…t detail (#61)\n\n* feat(ui): render structured Intent and Authorization fields in receipt detail (#6)\n\nExpand the Intent section to show conversation_hash and reasoning_hash\nas truncated monospace with tooltip, plus a \"(truncated)\" note on the\nprompt preview when prompt_preview_truncated is true.\n\nA\n[…]\nce with NaN guard; use join('') for scopes badges\n\n* fix(ui): guard granted_at against invalid date before formatTime\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ui): render structured Intent and Authorization fields in receip…",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T05:20:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d81c92ffaadfc33065b284a00ce3998245cb0c8a",
          "body": "* fix: cap overview recent-receipts fetch to 20 rows (#58)\n\nThe overview loadOverview() call was fetching /api/receipts with no\nlimit, pulling up to 10k rows to display only a handful. Add ?limit=20\nto that specific fetch; the full receipts view is unchanged.\n\nCloses #58\n\nCo-Authored-By: Claude Sonn\n[…]\np limit param at 10000; fix CHANGELOG row count\n\n* fix: use maxLimit constant in error message; add limit param tests\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: cap overview recent-receipts fetch to 20 rows (#59)",
          "author_name": "Otto Jongerius",
          "author_login": "ojongerius",
          "committed_at": "2026-05-20T05:20:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 34,
      "commits_last_year": 179,
      "latest_release_at": "2026-07-20T03:30:10Z",
      "latest_release_tag": "v0.13.1",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 16,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 3.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/agent-receipts/dashboard",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/agent-receipts/dashboard",
          "is_deprecated": false,
          "latest_version": "v0.13.1",
          "repository_url": "https://github.com/agent-receipts/dashboard",
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T03:27:32Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 2,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 3
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 122868,
      "source_files_sampled": 15,
      "oversized_source_files": 2,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 5388
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.52.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 15
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 13,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.54.0"
        },
        {
          "name": "obsigna.dev/sdk/go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.24.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.54.0",
            "ecosystem": "go"
          },
          {
            "name": "obsigna.dev/sdk/go",
            "direct": true,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.6.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.52.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.74.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 13,
        "direct_count": 2,
        "indirect_count": 11
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 138,
        "open_issues": 3,
        "closed_ratio": 0.925,
        "closed_issues": 37,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "ojongerius",
          "commits": 159,
          "avatar_url": "https://avatars.githubusercontent.com/u/1726055?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish.yml",
        "release.yml",
        "shellcheck.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/22 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e1f5a50284b93bbef74da74a2b9565af4e12a565",
        "ran_at": "2026-07-23T07:27:42Z",
        "aggregate_score": 6.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T03:29:16Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-20T03:28:33Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 90,
          "created_at": "2026-06-06T00:02:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 156,
          "created_at": "2026-06-25T03:58:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 179,
          "created_at": "2026-07-20T02:56:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/agent-receipts/dashboard",
    "host": "github.com",
    "name": "dashboard",
    "owner": "agent-receipts"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 73,
        "vitality": 81,
        "community": 36,
        "governance": 58,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "commits_last_year": 179,
              "human_commit_share": 0.87,
              "days_since_last_push": 3,
              "active_weeks_last_year": 16
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "16/52 weeks with commits",
                "points": 11.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 16
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "179 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 179
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 34,
              "latest_release_tag": "v0.13.1",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 3.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "34 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 2,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 138,
              "open_issues": 3,
              "closed_issues": 37,
              "issue_closed_ratio": 0.925,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "92% of issues closed",
                "points": 43.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 92
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "138/140 decided PRs merged",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 138,
                      "decided": 140
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "followers": 11,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "agent-receipts",
              "public_repos": 9,
              "account_age_days": 112
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "11 followers of agent-receipts",
                "points": 7.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 11,
                      "login": "agent-receipts"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "9 public repos, account ~0 yr old",
                "points": 7.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 9
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/agent-receipts/dashboard"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://obsigna.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://obsigna.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 73,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 6.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 13 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 13
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 13,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 13,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 87,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 5388
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 87,
                      "sampled": 87
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.04,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "4 of the last 100 commits agent-authored or agent-credited",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 4,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 122868,
              "source_files_sampled": 15,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/15 source files over 60KB",
                "points": 47.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 15,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T07:28:00.720371Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/agent-receipts/dashboard.svg",
  "full_name": "agent-receipts/dashboard",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.