Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"ai-agent",
"claude-desktop",
"document-automation",
"hancom",
"hwpx",
"local-first",
"mcp",
"model-context-protocol",
"python",
"vscode"
],
"is_fork": false,
"size_kb": 7491,
"has_wiki": true,
"homepage": "https://pypi.org/project/hwpx-mcp-server/",
"languages": {
"Python": 4369480,
"Dockerfile": 812,
"PowerShell": 29277,
"AppleScript": 13491
},
"pushed_at": "2026-07-28T05:50:14Z",
"created_at": "2025-09-19T10:39:17Z",
"owner_type": "User",
"updated_at": "2026-07-28T04:31:45Z",
"description": "MCP server for AI agents to read, edit, inspect, and validate local HWPX documents.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": null,
"name": "Kyuhyun Ko",
"type": "User",
"login": "airmang",
"company": "경기도교육청",
"location": null,
"followers": 15,
"avatar_url": "https://avatars.githubusercontent.com/u/38392618?v=4",
"created_at": "2018-04-15T05:34:35Z",
"is_verified": null,
"public_repos": 14,
"account_age_days": 3026
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v6.0.4",
"kind": "patch",
"published_at": "2026-07-28T06:01:09Z"
},
{
"tag": "v5.1.1",
"kind": "patch",
"published_at": "2026-07-27T12:14:06Z"
},
{
"tag": "v5.1.0",
"kind": "minor",
"published_at": "2026-07-22T08:01:25Z"
},
{
"tag": "v5.0.0",
"kind": "major",
"published_at": "2026-07-21T03:06:17Z"
},
{
"tag": "v4.4.1",
"kind": "patch",
"published_at": "2026-07-20T23:46:17Z"
},
{
"tag": "v4.3.2",
"kind": "patch",
"published_at": "2026-07-20T15:51:01Z"
},
{
"tag": "v4.3.0",
"kind": "minor",
"published_at": "2026-07-18T16:00:20Z"
},
{
"tag": "v4.2.1",
"kind": "patch",
"published_at": "2026-07-18T01:04:11Z"
},
{
"tag": "v4.1.0",
"kind": "minor",
"published_at": "2026-07-17T12:24:01Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2026-07-16T15:43:40Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2026-07-15T23:21:11Z"
},
{
"tag": "v2.23.1",
"kind": "patch",
"published_at": "2026-07-15T14:34:37Z"
},
{
"tag": "v2.23.0",
"kind": "minor",
"published_at": "2026-07-15T01:54:41Z"
},
{
"tag": "v2.18.3",
"kind": "patch",
"published_at": "2026-07-14T05:54:51Z"
},
{
"tag": "v2.18.2",
"kind": "patch",
"published_at": "2026-07-13T10:00:39Z"
},
{
"tag": "v2.18.1",
"kind": "patch",
"published_at": "2026-07-10T12:38:39Z"
},
{
"tag": "v2.18.0",
"kind": "minor",
"published_at": "2026-07-08T05:56:58Z"
},
{
"tag": "v2.17.0",
"kind": "minor",
"published_at": "2026-07-08T02:32:56Z"
},
{
"tag": "v2.16.0",
"kind": "minor",
"published_at": "2026-07-06T11:09:05Z"
},
{
"tag": "v2.15.0",
"kind": "minor",
"published_at": "2026-07-03T13:27:30Z"
},
{
"tag": "v2.14.0",
"kind": "minor",
"published_at": "2026-07-03T12:59:19Z"
},
{
"tag": "v2.13.0",
"kind": "minor",
"published_at": "2026-07-03T11:57:21Z"
},
{
"tag": "v2.12.0",
"kind": "minor",
"published_at": "2026-07-02T03:31:30Z"
},
{
"tag": "v2.11.0",
"kind": "minor",
"published_at": "2026-07-02T01:26:51Z"
},
{
"tag": "v2.10.0",
"kind": "minor",
"published_at": "2026-06-30T23:50:35Z"
},
{
"tag": "v2.9.0",
"kind": "minor",
"published_at": "2026-06-30T15:04:01Z"
},
{
"tag": "v2.8.0",
"kind": "minor",
"published_at": "2026-06-29T02:31:54Z"
},
{
"tag": "v2.7.0",
"kind": "minor",
"published_at": "2026-06-27T05:06:57Z"
},
{
"tag": "v2.5.0",
"kind": "minor",
"published_at": "2026-06-24T23:34:57Z"
},
{
"tag": "v2.4.1",
"kind": "patch",
"published_at": "2026-06-12T03:30:22Z"
},
{
"tag": "v2.4.0",
"kind": "minor",
"published_at": "2026-06-11T15:36:01Z"
},
{
"tag": "v2.3.5",
"kind": "patch",
"published_at": "2026-06-09T22:10:09Z"
},
{
"tag": "v2.3.4",
"kind": "patch",
"published_at": "2026-06-06T14:17:53Z"
},
{
"tag": "v2.3.3",
"kind": "patch",
"published_at": "2026-06-04T06:43:58Z"
},
{
"tag": "v2.3.2",
"kind": "patch",
"published_at": "2026-06-03T23:51:34Z"
},
{
"tag": "v2.3.1",
"kind": "patch",
"published_at": "2026-06-03T15:30:55Z"
},
{
"tag": "v2.3.0",
"kind": "minor",
"published_at": "2026-06-02T11:59:16Z"
},
{
"tag": "v2.2.6",
"kind": "patch",
"published_at": "2026-04-27T14:02:56Z"
},
{
"tag": "v2.2.5",
"kind": "patch",
"published_at": "2026-04-02T07:53:48Z"
},
{
"tag": "v2.2.4",
"kind": "patch",
"published_at": "2026-03-08T14:42:20Z"
},
{
"tag": "v2.2.3",
"kind": "patch",
"published_at": "2026-03-08T13:19:39Z"
},
{
"tag": "v2.2.2",
"kind": "patch",
"published_at": "2026-03-08T12:43:40Z"
},
{
"tag": "v2.2.1",
"kind": "patch",
"published_at": "2026-03-08T09:13:51Z"
}
],
"recent_commits": [
{
"oid": "87e5657bd10f20b727a6195e6a474693455f979c",
"body": "v6.0.1 is a preserved failed tag: the compatibility install matrix's nine\nembedded assertions still named 6.0.0 and prepublish failed closed with\nnothing published. Every embedded coordinate is now audited repo-wide\n(floors and history deliberately kept), and this time the entire\nprepublish chain — \n[…]\n 3.10 platform smoke, and both ToolSpec checks — was\nexecuted locally end to end and passed before tagging. Never delete,\nmove, or reuse v6.0.1.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: recover as 6.0.2 with a full local prepublish dry-run behind it",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T04:22:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9ad93f2151b06416b524a56a1bcdb9f7e746c1c0",
"body": "Last stale 6.0.0 literal in the embedded smoke assertion; the core line\nnext to it was already bumped.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: the platform smoke asserts the automation version that ships",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T03:45:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "33206b4135595577e36079fdc4daf0a9208d1130",
"body": "v6.0.0's release run stopped in prepublish and published nothing: the\nparity suites read fixtures from a python-hwpx repository checkout the\nworkflow never made, and the clean installed-wheel gates fail closed\nwithout uv. Prepublish now checks out the released core at v5.0.1 next to\nthe repository a\n[…]\ncompat extra mirrors, docs, and test expectations — while\nboth floors and the contract hash stay unchanged. Never delete, move, or\nreuse v6.0.0.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: recover as 6.0.1 after the preserved v6.0.0 tag",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T03:36:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cf005a16c721f4e8ba8b742dfdc88bdef5760985",
"body": "The compat-matrix and minimum-Python gates pip-download the public core\nat release time; 5.0.0 will never exist on PyPI. The platform smoke's\nversion assert and wheel patterns move with them. MIN_PYTHON_HWPX and\nboth floor asserts stay 5.0.0 — the contract floor is unchanged and so is\nthe contract hash. Touched prepublish digests refrozen deliberately.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: the release-time core downloads name 5.0.1, floors stay 5.0.0",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T03:02:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3b51049982c4336646135a10be1f770fd92f2882",
"body": "…ed pin\n\ncheck_transition_identity equated candidate.pythonHwpx with the contract\nfloor; the plugin validator equates it with the actual core version. The\ntwo only coincided while 5.0.0 was both. The candidate now must equal the\nrelease workflow's remote-truth observation pin (5.0.1) and that pin mu\n[…]\nsatisfy the contract floor — so the floor stays a floor and the candidate\nstays the train. Mutation-checked: a floor-valued candidate now fails.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: the candidate names the exact train, derived from the observ…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T02:48:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c3a1aad66fc3a4d7c7e30c6554a61f1cb696702b",
"body": "…igests\n\nCore recovered as 5.0.1 after the preserved v5.0.0 tag (its run never\npublished). The remote-truth observation now pins 5.0.1; the identity\ncandidate keeps the contract floor 5.0.0 — the gate proved the two are\ndifferent things. The provenance freeze flags exactly the two run blocks\nthe pin edit touched; their digests are refrozen deliberately.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: observe core 5.0.1 and refreeze the two touched prepublish d…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T02:46:00Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6c13f256f02a5e8f6578e3aa3ea13485ffdea946",
"body": "…es on\n\nThe fixture-QA parity golden froze a PNG sha256, but the page was encoded\nat test time — Pillow's PNG output differs across builds/platforms for\nidentical pixels, so the candidate CI failed on ubuntu while the same\npixels passed where the golden was frozen. The page is now a checked-in\nfixtu\n[…]\nThe clean installed-wheel gate fails closed without uv; the test job never\ninstalled it. It now does, next to the other bootstrapped gate tools.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: freeze the parity page as a fixture file, give CI the uv it gat…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T02:21:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e46bf8a3763e52533774cae92cd76cbebc8db91d",
"body": "The identity gate requires the approved state to be visible wherever a\nreader could mistake the train for published truth: README banner, the\nuse-cases guide, the hardening guide, and the skill-first workflow guide\nnow all say release-approved with remote truth still pending.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: carry the release-approved state into every release-facing doc",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T02:08:03Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2d973c6de538d1ee0dd98180961f6b9d99ab7146",
"body": "Separate owner approval was given on 2026-07-28 after the Fable 5 release\nreview, the verdict remediation train, and the early public closure of the\npython-hwpx#68 observation window (recorded there). currentPublic still\nnames the 4.2.0/5.1.0/0.8.0 stack per the promotion gate; it changes only\nin a follow-up commit after full remote truth is observed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "release: promote the candidate to release-approved",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T02:06:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "134fb94a56f9b31769d26cc892ab3d1419e7eef8",
"body": "The 5.1.1 safety patch shipped from the maintenance branch (tag v5.1.1).\nThis -s ours merge records that lineage so main can fast-forward to the\n6.0 train without losing v5.1.1 reachability; the 6.0 tree supersedes the\n5.x layout wholesale and takes no content from the maintenance side.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "merge: connect the 5.1.1 maintenance line into the 6.0 candidate",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-28T02:06:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "09db92cc6937fd323673fb7fa8855a0d76318fcc",
"body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: freeze release provenance",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-27T13:21:34Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0158557d5625c7dbd9271ab1463f493384975f19",
"body": "The intro explained the package by what it sits on and what MCP adds, and\nnever said where it can run. That omission matters more here than in core:\npeople assume a workflow layer needs a desktop office suite behind it.\nIt does not — the Hancom render oracle is the `[oracle]` extra, and\neverything e\n[…]\ninstall\nwith no MCP SDK present, so \"the authoring and form-fill workflows run\nthere\" is not an extrapolation from core's behaviour.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: this layer runs wherever Python runs, not only next to Hancom",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-27T12:08:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5fe0bfbc55d1b1d6da23adbdefbac948574ff67b",
"body": null,
"is_bot": false,
"headline": "fix: freeze maintenance release step chain",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T14:10:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec50822c95addcd11f79c2ee41a47faed60340b7",
"body": null,
"is_bot": false,
"headline": "test: reject release shell bypasses",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T14:04:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "163d42023e1e136ad8a9e39a2b544212a2a166b6",
"body": null,
"is_bot": false,
"headline": "fix: provision phase zero metadata parser",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:47:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9b2edc0572a9ec8cdd1ab366f75b90b3e418d4d4",
"body": null,
"is_bot": false,
"headline": "fix: harden remote artifact readback",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:47:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4c82fcc63043f52bf61c25428813ade665aae93",
"body": null,
"is_bot": false,
"headline": "test: reject release verification bypasses",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:34:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45abd84c359d570995ca5629c621cd624e6ea4eb",
"body": null,
"is_bot": false,
"headline": "docs: distinguish coherent public train",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:27:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a0108b7d12f2e6b3907dcb20d7c7c579584f1d2",
"body": null,
"is_bot": false,
"headline": "fix: verify published artifact hashes",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:24:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20a1a674db1a2a6c6a663362ad02b9cadebb6c8d",
"body": null,
"is_bot": false,
"headline": "fix: require exact legacy core cap",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:24:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad7842b194dc43d4450dfc85def13c437ff3dfbf",
"body": null,
"is_bot": false,
"headline": "test: enforce release provenance ordering",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:16:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc5db75b9ac18f8d279f661a2a53a00c7a4f1065",
"body": null,
"is_bot": false,
"headline": "build: bind release artifacts to one manifest",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T13:13:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "60ee8a9e68af6569085202fa7d0697fc34853ac2",
"body": null,
"is_bot": false,
"headline": "fix: cap legacy core dependency before 5.1.1",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T12:56:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d313886fbc9c63ee8278bd34d4ee8f160f991ce",
"body": null,
"is_bot": false,
"headline": "fix: close pre-release automation gates",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T12:55:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a004fb4a957d181049dca2a0cc541a0d580ecd21",
"body": null,
"is_bot": false,
"headline": "fix: make minimum-version gates self-contained",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T03:08:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "533b9ffa264d1a820856f496c10333a92428e962",
"body": null,
"is_bot": false,
"headline": "fix: reject symlinked release inputs",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T02:56:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f5f350eee19cbe4488285bbfeeb5dde6880e8d9",
"body": null,
"is_bot": false,
"headline": "test: execute README from clean base install",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T02:55:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c8d9463d3cd91406c7f8708adc25a96a921c043",
"body": null,
"is_bot": false,
"headline": "fix: harden release inputs and facade typing",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T02:45:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70dec6db9ea83b56f6879fea9751e30fad01fb20",
"body": null,
"is_bot": false,
"headline": "test: verify tracked replacement semantics",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T02:07:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c94723284d59441e3f706d925e8e0fb1d3f9195f",
"body": null,
"is_bot": false,
"headline": "test: guard neutral table anchors after headings",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T01:56:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bdb606b827b1ebd58b3d81b59c228f6e9a395e72",
"body": null,
"is_bot": false,
"headline": "feat!: establish python-hwpx-automation 6.0",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-26T01:43:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad71cca45a3ce49b0836862831e038a4c95837bb",
"body": "An adversarial pass found all of these. Two of them mean I had been reporting\ngreen on gates that were inspecting nothing.\n\n**The hygiene gate classified this repository as core.** It identified the\nproject by the literal `name = \"hwpx-mcp-server\"`, so the rename silently moved\nit into the branch wh\n[…]\nalls nothing.\n Measured, then fixed by mirroring all six extras.\n\nSuite 1321 passed, 2 failed (the test_visual_oracle pair that conflicts with\nHWPX_ORACLE_STRUCTURAL_ONLY=1). Static gates all exit 0.",
"is_bot": false,
"headline": "fix: six things the rename broke that nothing was checking",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T22:37:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3189c58b189efc54239ef00906cb90ab3e16c7c8",
"body": "Adversarial review planted build/lib/hwpx_mcp_server — the exact state that\nshipped a polluted wheel three times — and the whole file passed. Both checks\nwere complicit: the first deletes build/ before building, and the second treats\nthe leak as its success condition. Neither could see an already-di\n[…]\nthe wrong function. Collection caught it immediately.\n\nAll three mutations re-run and fail. Suite 1321 passed, 2 failed (the\ntest_visual_oracle pair that conflicts with HWPX_ORACLE_STRUCTURAL_ONLY=1).",
"is_bot": false,
"headline": "test: detect the dirty build tree instead of only describing it",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T15:56:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27c6fd0100272237fff971601df12e71d7666113",
"body": "The name described 4% of the package. About 50,000 of its 66,000 lines are the\napplication layer — authoring, form-fill, exam, eval-plan, compliance,\nrendering — and not one file under office/, workflow/, ops_services/ or core/\nimports mcp. After 5.0 moved another 24,000 lines here, a Python user wh\n[…]\nly\ndefeated it would be worse than the drift.\n\nSuite 1320 passed, 2 failed (the test_visual_oracle pair that conflicts with\nHWPX_ORACLE_STRUCTURAL_ONLY=1; 16 pass without it). Static gates all exit 0.",
"is_bot": false,
"headline": "feat!: become python-hwpx-automation, with MCP as an extra",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T15:28:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "765b3fc516831b9b2de4883032892a822ced9caa",
"body": "This owner had been importing hwpx.visual.detectors, .diff, .block_splits and\n.qa_contracts from core while claiming to be the canonical rendering owner. They\nare here now, with the tests, QA drivers and fixtures that exercise them —\nthirteen test files and eleven scripts, moved rather than deleted \n[…]\ne test_visual_oracle pair that conflicts with\nHWPX_ORACLE_STRUCTURAL_ONLY=1, unchanged since P3 and green without it (16\npassed). Product-boundary, public-hygiene and architecture ratchets all exit 0.",
"is_bot": false,
"headline": "feat!: take the rendering runtime core was still holding",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T14:27:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a00d127c2ca1ec0f80ae8bc59679e3d89c4401e2",
"body": "…d 6.0.0\n\n`compose_exam` and `verify_question_splits` carried an internal stage codename\nin the Korean summary an agent reads to decide whether to call them — the most\nuser-facing place such a name can hide.\n\nRemoving them moves the contract hash, which is not obvious: `_tool_payload`\nadds each boun\n[…]\ns superseded, stating\nthat publishing early shortens public notice rather than satisfying it.\n\nSuite 1093 passed, 3 skipped. Product-boundary, public-hygiene and\narchitecture-ratchet gates all exit 0.",
"is_bot": false,
"headline": "chore!: drop internal codenames from two tool descriptions, and recor…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T12:11:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a1a64fcf3db132abebb541b765aa1aa5a99ce8d",
"body": "The floor bump and report_parser's arrival shifted numbers that several tests\npin, and none of it was visible until the parity freeze cleared the collection\nerrors — a run that aborts at collection never reaches the ratchets.\n\nThe contract hash moved from 429cb6706323e762 to 9bfc7ec7b0c3c62b because\n[…]\nNPATH\nfixed four immediately. Worth recording because the failure looked exactly like\na real defect.\n\nSuite: 1086 passed, 4 skipped.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: re-derive the ratchets the 5.0 train moved",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T11:12:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d2a90405cb3708861e49a549f71c1cf2c350c2fe",
"body": "BREAKING CHANGE: requires python-hwpx>=5.0.0, and declares the `hwpx` console\ncommand that core used to own.\n\nThe floor is the mechanism, not a preference. Core stops declaring `hwpx` at\nexactly 5.0, so pinning >=5.0.0 here is what makes \"no valid install has two\npackages claiming that name\" a fact \n[…]\nn. Found\nby sweeping surviving modules for imports of departing ones.\n\nNo module under src/ imports a removed core surface any more.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat!: take the hwpx console name and require core 5.0",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T08:07:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1b3a72eebfcd85c46a6cb36246271f5957f8adbc",
"body": "…eted\n\nFive tests asserted \"the MCP copy matches the core copy\". The next phase deletes\nthe core side, which leaves those assertions with no subject. Deleting the tests\nwould have dropped the only mechanical evidence that the move preserved the API,\nso the core side is recorded now, while it still e\n[…]\n; mypy\nclean over 114 files; the CI ruff gates (--select E9,F and the scoped\nE4,E7,E9,F) pass. Suite 1096 passed, 3 skipped, exit 0.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: freeze what the parity tests compared against, before it is del…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T05:21:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "01e7ca0c9ffc84ff784c569eed6ccaff4ec3c721",
"body": "The redline degrade fixture patched both core's oracle and the canonical owner's.\nThat was correct while both copies were live — patching only core left the tool\non a live backend, which is how the flake came back. Core's verify_redline no\nlonger resolves a renderer at all now, so the core patch rea\n[…]\ny alias for it.\n\nVerified deterministic: three consecutive runs at 20 passed, 1 skipped, 1.64s\neach — no live render in any of them.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: patch one oracle module, because there is only one left to reach",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T04:29:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8844da0ec421005f583d9e5e5c96f9fa99f8e0bc",
"body": "Five tests reached into core modules that the next phase deletes. Four of them\nonly needed the canonical owner instead:\n\n test_toc_mcp hwpx.authoring._outline_style_refs -> office.authoring\n test_quality_contract hwpx.visual.oracle.resolve_oracle -> office.rendering\n \n[…]\nsingle value in the frozen JSON fails the corresponding form and only that form.\nA golden file nobody has seen fail is not evidence.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: point the functional suites at the owners that will still exist",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T04:28:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "21c4cef98be804e2be8e9c1cc434529bdd621070",
"body": "policy, measure, engine, report and apply existed twice. Comparing normalised\nsyntax trees showed the two versions were behaviourally identical: measure,\nengine and apply matched exactly, and policy and report differed only in whether\na forward-reference annotation was quoted. 1,408 lines against 1,\n[…]\nctor argument, and layout_style supplies it alongside\nthe oracle — core no longer reads PDFs, and this layer owns the imaging stack.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: import core's fit contract instead of keeping a second copy",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T04:00:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "29aea604b6967f0f6e63a12387a96e76ab61f0f6",
"body": "office/document_ops/redline.py held a line-for-line copy of core's\nverify_redline. The two were identical apart from a docstring, which is exactly\nthe arrangement that produced this session's other defect: a fixture patched one\ncopy while the runtime used the other. It now calls core and supplies a \n[…]\nCP surface asked for a Hancom-backed verdict, and\ncore's honest degrade is the right answer for a library but the wrong answer\nhere.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: delegate redline verification to core instead of copying it",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-25T02:35:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "addb8f9860c41a6e1122d7d564faa743000b6015",
"body": "The redline receipt test forces both oracle backends unavailable so the\nstructural degrade path is deterministic. It patched only hwpx.visual.oracle,\nbut since the visual runtime split the MCP tool resolves\nhwpx_mcp_server.office.rendering.oracle, which is a distinct class. On a\nmacOS+Hancom box the\n[…]\nit guards a test that drives the MCP\nsurface, so it must read the canonical owner's availability, not the core\ncompatibility copy's.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: point oracle degrade fixture at the canonical rendering owner",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T23:08:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "85884fd6ca677ca53118301cd7fa819dbbbc90c8",
"body": null,
"is_bot": false,
"headline": "docs: publish compatibility observation guidance",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T14:19:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32a02e9f6b9a0575b727b1671617eddd430fd638",
"body": null,
"is_bot": false,
"headline": "feat: canonicalize document operation workflows",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T13:29:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "10fbda6d5a98a04df4e0e357858573f15c92849a",
"body": null,
"is_bot": false,
"headline": "Make office rendering canonical",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T12:22:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae60cec57162fc942d9ba82941ff42912a5801e1",
"body": null,
"is_bot": false,
"headline": "Make MCP exam runtime canonical",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T08:58:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0bb52c7b9e3bb01ff3381d381a3f91b5180596e",
"body": null,
"is_bot": false,
"headline": "feat: make office evalplan runtime canonical",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T07:37:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f15e4579252ec9e15e5d43926a22f8c1b55ae22c",
"body": null,
"is_bot": false,
"headline": "refactor: canonicalize form-fill runtime",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-24T01:24:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea0237fc5685ea8877dcde95752b4fcac6558024",
"body": null,
"is_bot": false,
"headline": "refactor: own compliance quality utilities in MCP",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-23T23:28:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0d16bf57dc99f40082d5ec64fca08f4fc031bcc",
"body": null,
"is_bot": false,
"headline": "feat: make office authoring runtime canonical",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-23T15:31:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f49b7c5d85c059b7eba0b608557c50469dda1ed5",
"body": null,
"is_bot": false,
"headline": "feat: make office agent runtime canonical",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-23T13:42:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5e0835df92b5d4b38576d1df05196685b71b64d",
"body": null,
"is_bot": false,
"headline": "refactor: own office rendering and house style",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-23T12:45:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0cb5bb347fdb2e76333d7145845efd3d62d069a",
"body": "…se (additive)\n\nContract c2cd81fdb3089bae -> 429cb6706323e762 (floors bumped to core 4.2.0 /\nmcp 5.1.0 / skill 0.8.0), PENDING collapsed to RELEASED, delta receipt\nfinalized, hermetic core pin f6b79f0. 5.0.0 boundary receipt validated against\nits own frozen hash. 752 passed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): hwpx-mcp-server 5.1.0 — apply_evalplan_fill clean pha…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-22T07:52:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7381fc126ab65b3e2cf4df9fa219a1003ab9fc1e",
"body": "…ll (additive)\n\nAdds phase=\"structural\"|\"all\"(default, prior behaviour)|\"clean\" to\napply_evalplan_fill; \"clean\" = all + core's finalize_evalplan cleanup, so the\nMCP surface fills a real eval-plan form residue-free in one call. Additive:\ndefault unchanged, existing callers unaffected. Contract surface change recorded\nunder PENDING_CONTRACT_HASH (release train collapses it). 747 passed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(evalplan): expose fill_evalplan clean phase on apply_evalplan_fi…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-22T07:37:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2164f48378f1748d512b086d3a2e5f10916f808b",
"body": null,
"is_bot": false,
"headline": "fix: preserve quoted path whitespace",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-22T00:42:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ef22a8e25e33c8f905478ca6e68c0c99960a4d2",
"body": "Preserve ordinary path names byte-for-byte by only unwrapping quotes and\nfile: URIs, so surrounding whitespace is no longer stripped and a spaced\nfilename is not redirected to an unspaced one. Resolve empty and localhost\nfile-URI authorities to the local path, and reject non-local authorities and\nmalformed file URIs with the typed WorkspacePathError contract instead of\nmangling them or leaking an untyped urlsplit ValueError. Add regression tests\nfor each case.",
"is_bot": false,
"headline": "fix: preserve ordinary paths and harden file-URI normalization",
"author_name": "Sanjay Santhanam",
"author_login": null,
"committed_at": "2026-07-22T00:42:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1bc17fcb51595b54f742876dc51840ce3611c1c1",
"body": "Accept quoted paths, file URIs, and mixed Windows separators before applying the existing workspace authorization checks.",
"is_bot": false,
"headline": "fix: normalize workspace path inputs",
"author_name": "Sanjay Santhanam",
"author_login": null,
"committed_at": "2026-07-22T00:42:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c86e8ef4d147b6daf226eb7a0db5ab413efd69c7",
"body": "…ts (#82)\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: serve the downloads badge from pepy to avoid upstream rate limi…",
"author_name": "Kyuhyun Ko",
"author_login": "airmang",
"committed_at": "2026-07-21T07:35:58Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "da6a92e650758e21409e68e4c75f3780a3a52d32",
"body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add PyPI monthly-downloads badge (#81)",
"author_name": "Kyuhyun Ko",
"author_login": "airmang",
"committed_at": "2026-07-21T07:12:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "37b129e7d87e0fa326d49e45e0433fa5dae78bbb",
"body": "…eceipt\n\nRelease the major-boundary surface: contract c2cd81fdb3089bae (floors\npython-hwpx 4.0.0 / mcp 5.0.0 / skill 0.7.0), delta receipt finalized,\nhermetic core pin 62ba2563.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): hwpx-mcp-server 5.0.0 — collapse the 5.0.0 boundary r…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-21T02:54:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fd0f98ac822bc8dd64efa4c3e59a4a6f00e8482c",
"body": "Update the hardening guide and use-cases to describe the 5.0.0 surface (default\n119 / advanced 127, hash c9a451a7c003752a) and to state that the five transition\nstubs are removed and the quality-generation replacement path is\ncreate_document_from_plan + inspect_document_quality; fold the prior 4.3.0\n[…]\ne checklist counts. Add the\nCHANGELOG [Unreleased] entry for the breaking removal, the demotion, and the\nform_fill submodule-import hygiene fix.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: sweep guides and changelog for the 5.0.0 major boundary",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-21T02:41:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "48867b9f36a6b52912a4150608135eb9f19d9e6d",
"body": "…(5.0.0)\n\nExecute the docs/deprecation-5.0.0.md removal contract at the 5.0.0 major\nboundary. Remove the five one-transition stubs plan_edit, preview_edit,\napply_edit, analyze_quality_generation, and apply_quality_generation from the\ncanonical ToolSpec registry, the explicit tool bindings, the FastM\n[…]\neprecated-stub list and installed count against the\nnow-diverged live registry and cross-checks the 5.0.0 receipt. Ratchet\nserver.py 272 -> 267.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat!: remove five transition stubs and demote three formfit facades …",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-21T02:40:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5a3a24fe28873bc102fb3a5bd94df6d5aead5466",
"body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: align README with the python-hwpx style (#80)",
"author_name": "Kyuhyun Ko",
"author_login": "airmang",
"committed_at": "2026-07-21T00:07:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "58bd79875d2814d4c268c1126f2e01f7dd0642a6",
"body": "…4.4.0 preserved\n\nThe 4.4.0 prepublish installed the hermetic core without the [preview]\nextra, so the MathML success-path test honestly failed; the tag is\npreserved per house policy. Workflows now install\npython-hwpx[visual,preview] so release gates exercise the advertised path.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 4.4.1 — install the preview extra in release gates; v…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T23:39:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "deddfea43aeae5a27b1964de5b02c776d4562ead",
"body": "…hash flips\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 4.4.0 — viewer surface + seam typing merge, contract …",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T23:30:38Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cd3b04866d020ae0b12eff3205a4afff48b0c6c0",
"body": "Author docs/tool-contract-delta-4.4.0.json proving the render_preview viewer\nchange is additive-only: holding versions, classification, counts, domains, and\nevery other tool fixed, the canonical payload delta is confined to\nrender_preview's input schema (one optional boolean `viewer`) and output sch\n[…]\ne pre-release hash move\nf82caecbcfc742e9 -> c89cbc5f98eb5367 and the fail-closed core dependency. Add\nthe matching CHANGELOG [Unreleased] entry.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add the additive-only contract delta proof for the viewer param",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T23:07:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d0cca34886a8a42c54f5e4d51d26c5e463e83866",
"body": "Add an additive optional `viewer` parameter (default false) to render_preview.\nWhen true, the manifest carries a self-contained scrollable document viewer\nunder `structuredContent.viewer` — built via core `render_document_viewer`,\nwith equations as native MathML when `python-hwpx[preview]` is presen\n[…]\n PENDING_CONTRACT_HASH. Architecture ratchets\nupdated honestly (preview_export.py 453->583, hwpx_ops.py 1422->1434,\nrender_preview C901 15->16).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: expose the document viewer through render_preview (S-092 P3)",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T23:07:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "af114fc4edc994aab307024e90272bdd9e32cf97",
"body": "…8 P2)\n\nResolve the 29 measured pyright errors across ops_services/{form_fields,\nsave_policy,tables,transactions}.py and workflow/service.py, typing-first,\nand remove their permanent [dynamic-seam] excludes from pyproject.\n\n- DocumentStorage.save_document gains the universal `quality` kwarg (both\n \n[…]\n contract hash unchanged (f82caecbcfc742e9); no tool/schema/error-code\nchanges. mypy 36/36, pyright 0, ruff E9/F, ratchets, hygiene, 742 passed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "type: bring the five [dynamic-seam] files into the pyright gate (S-08…",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T19:04:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a9a5ec3d20f78943e38e1f24285b19e9f24e8a82",
"body": "The 4.3.1 tag failed prepublish (version-lock test not bumped, plus a\nCI-only snapshot-cleanup test failure under investigation); per house\npolicy the tag is preserved and never reused. This bumps the project\nversion, the release-coordinates lock, and the changelog.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 4.3.2 coordinates — v4.3.1 preserved as a failed tag",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T15:09:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8092762f09adeb613692db21a1c2420a8d30fdf1",
"body": "Patch release carrying #77 (Fixes #73): GUI MCP clients launching the\nserver from a degenerate cwd no longer get every path rejected (Windows)\nor the whole filesystem as workspace (macOS); a typed\nWORKSPACE_ROOT_INVALID error with exact HWPX_MCP_WORKSPACE_ROOTS examples\nis returned and the server stays up for mcp_server_health. Contract hash\nf82caecbcfc742e9 unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): 4.3.1 — degenerate cwd workspace fallback fix ships",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-20T14:38:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "019a44fa92e43df7d407a55c6ee93a8d30956922",
"body": "Unconfigured GUI MCP clients launch the server from the filesystem root\n(/ on macOS) or the Windows system directory (C:\\Windows\\System32), so the\nimplicit cwd workspace fallback either rejected every real document path\n(\"outside the authorized workspace roots\") or, at the root, opened the whole\nfil\n[…]\nor;\nexplicit configuration behaviour is unchanged and still fails fast.\n\nThe README quickstart now sets HWPX_MCP_WORKSPACE_ROOTS from the start.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: reject degenerate cwd workspace fallback (#73) (#77)",
"author_name": "Kyuhyun Ko",
"author_login": "airmang",
"committed_at": "2026-07-20T14:13:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a3272194e15a8ed9fe8fabee7d8acf5956f91061",
"body": "* chore: add issue and PR templates\n\nAdds GitHub issue forms (bug report, feature request), issue-template\nconfig with Discussions/use-cases contact links, and a PR template.\nSECURITY.md already exists and is left untouched.\n\n* chore: align hancom-verified dropdown wording with the version note field",
"is_bot": false,
"headline": "chore: add issue and PR templates (#76)",
"author_name": "Kyuhyun Ko",
"author_login": "airmang",
"committed_at": "2026-07-20T13:44:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20a93d0318386c5787862f75d2cc003a798dc4fd",
"body": "…updates (#72)\n\nBumps the github-actions group with 4 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/setup-python](https://github.com/actions/setup-python), [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) and [softprops/act\n[…]\n-type: direct:production\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the github-actions group across 1 directory with 4 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T11:59:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8320d50ef79a08e786f7c90f5674bb92ff03114f",
"body": "S-084 re-measured all five deferred files against the decomposed core:\n32 errors total (form_fields 4, save_policy 8, tables 2, transactions 11,\nworkflow/service.py 7 — Optional subscripts and Path/str seams). The facade\ndecomposition alone does not type the seam, so the itemized defer stands;\nadmis\n[…]\naive line-removal scripts drop the include entry\nfirst and fake a zero — lift the exclusion (the '# dynamic-seam' suffixed\nline) when measuring.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: refresh the dynamic-seam pyright defer with measured error counts",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-19T02:20:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0d9d3b1486c6c118e398c8bcf5240c3950177dc2",
"body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: repoint hermetic core pins at the python-hwpx 3.3.1 release commit",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-18T15:45:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1838a22b7bcea7bcb9c7b5a3eb301d3b646a77c0",
"body": "The 4.0.0 contract-delta renderer derived its facade list from the live\nregistry, so the 4.3.0 promotion would have rewritten the historical\nreceipt. The eleven 4.0.0 facades become a frozen literal (checked against\nthe live set staying a subset), and the version-coordinate literals in the\nproduct-boundary tests move to 4.3.0/3.3.1.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: freeze the 4.0.0 delta receipt and align coordinate literals",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-18T15:40:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c1e7c0d4461f58fb2a0d6f28201419d72b58daf8",
"body": "Removes the two tools from _COMPATIBILITY_REPLACEMENTS: both are directly\nconsumed as core primitives of the universal form-fill workflow, so the\npublic classification states the truth. Baseline classification moves to\n110 public / 9 compatibility; the installed surface stays exactly\n121 default / 1\n[…]\nn classification-only by payload\nsubstitution (docs/tool-contract-delta-4.3.0.json).\n\nRelease coordinates: 4.3.0, core floor python-hwpx>=3.3.1.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: promote apply_table_ops/apply_body_ops to public",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-18T15:35:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2676da6d85c5a516dfc95f072b16de4b8f739475",
"body": "pyright coverage rises from 8 to 22 of the 36 mypy-gated files; the 14\nremaining files carry itemized reasons (schema-frozen implicit-Optional tool\nsignatures, dynamic core-object seams) instead of a blanket exclusion. The\nramp surfaced and fixed a real latent crash: get_tables_by_handle used\ntable.\n[…]\nm their defining modules through the\nupstream seam, and the 5.0.0 deprecated-stub migration contract is documented\nin docs/deprecation-5.0.0.md.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: extend pyright to the mypy surface with itemized exclusions",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-18T08:48:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cd48fa83738b9f270635413513a4a9b482b1495e",
"body": "_ensure_table_border_fill (C901 57), matches (29), and\napply_style_to_text_ranges (48) now delegate to small annotated helpers, all\n<=10 except the pre-existing _split_run (12). The border-fill helpers live in\nthe new private leaf module ops_services/_border_fill.py — the repo's blessed\nsplit pattern — keeping tables.py under the <750 service cap (526 lines).\nExact ratchet baselines updated; behavior byte-identical.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: decompose the worst-complexity MCP service functions",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-18T08:48:42Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e07490f85c95c387145ebcdfde92f038b866c546",
"body": "The v4.2.0 tag failed prepublish on the hermetic CI core checkout still\npinned to the 3.2.0 release commit; no artifact was published and the tag is\npreserved as failure history. Repoint the release/tests core pins to the\nexact python-hwpx 3.3.0 commit, bump to 4.2.1, and regenerate the contract at\nfff2c9093ca4677b (MIN_MCP_VERSION is part of the canonical payload; the tool\nsurface stays 121/132/28).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: recover the 4.2.0 prepublish failure as 4.2.1",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-18T00:58:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e7df7a41bb62a42fe96b393c1d9f4214d94cbdf5",
"body": "Raise the coordinate floor to core 3.3.0 / skill 0.5.0, regenerate the\ncontract docs at hash f909a00fe4590c64 (verified: substituting only the three\nversion coordinates in the payload reproduces the 4.1.0 hash c127914cc3f4480e,\nso the delta is version-coordinates-only; names, order, schemas, and the\n121/132/28 counts are unchanged), and update the locked boundary tests.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: prepare hwpx-mcp-server 4.2.0 release",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-17T22:36:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f768570f835f7561b8f76264db07f04d3cae59e2",
"body": "- Pin mcp==1.28.1 so the resolver admits exactly the audited runtime set;\n document the patch re-audit procedure (docs/mcp-sdk-reaudit.md) and lock\n the invariant with a test.\n- Extract the shared v2 render contracts into the leaf module\n workflow/render_contracts.py; rendering and render_queue r\n[…]\nt.\n- Document the core oracle controls (HWPX_ORACLE_STRUCTURAL_ONLY,\n HWPX_ORACLE_BUDGET_SECONDS) that bound optional real-Hancom verification.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: align SDK admission, remove the render cycle, bound oracle waits",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-17T22:20:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a2fb903246cffa3e200afc5d78a078dc461b8e45",
"body": null,
"is_bot": false,
"headline": "refactor: decompose the MCP runtime services",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-17T12:12:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff1b88ec377e3118950af9344d77b0451129e4f7",
"body": null,
"is_bot": false,
"headline": "docs: mark hwpx-mcp-server 4.0.0 released",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T14:57:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a6a4c9341e4245157350e71329209921a61e3b3",
"body": null,
"is_bot": false,
"headline": "fix: preserve agent contract error codes",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T11:55:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "701b456427d8ee613a7239cebbc56f67140b5536",
"body": null,
"is_bot": false,
"headline": "fix: validate CallToolResult structured output",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T11:10:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ddf496ff61ae1f010ccb38900131172273d168c",
"body": null,
"is_bot": false,
"headline": "docs: align S079 contract identity",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T10:28:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04c7337d5646c9713e7fa4fbf53a69731a4d951a",
"body": null,
"is_bot": false,
"headline": "docs: refresh MCP-compliant tool contract",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T10:23:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f77a2ff109be4d2e77d9ead77f0d8eb70ae27d89",
"body": null,
"is_bot": false,
"headline": "fix: publish MCP-compliant output schema roots",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T10:23:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a3bb63476d35bd6e21cd9e89807b54d64efa1f1",
"body": "This reverts commit b5542a9d39dd307725b065bbf51312d69e800810.",
"is_bot": false,
"headline": "Reapply \"fix: tolerate unavailable optional Hancom oracle\"",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T10:02:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a839b1612c210df05c3b9161d7078b33584ce8a5",
"body": "This reverts commit 323952f1bbcf52c337bd5b27ccb26444a8e872ed.",
"is_bot": false,
"headline": "Revert \"Reapply \"fix: close post-return recovery claim races\"\"",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T10:02:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "221d4bfdc803eea9f7ba24649e2e927c15926348",
"body": null,
"is_bot": false,
"headline": "test: handle missing retired parent packages",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T09:40:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b5542a9d39dd307725b065bbf51312d69e800810",
"body": "This reverts commit d10c3e4bd03c04853bcaa2d7ee31bc64163827cf.",
"is_bot": false,
"headline": "Revert \"fix: tolerate unavailable optional Hancom oracle\"",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T09:35:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "323952f1bbcf52c337bd5b27ccb26444a8e872ed",
"body": "This reverts commit b37f4a7a28ba1359d248e3dcad57c544ed3f5312.",
"is_bot": false,
"headline": "Reapply \"fix: close post-return recovery claim races\"",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T09:35:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d10c3e4bd03c04853bcaa2d7ee31bc64163827cf",
"body": null,
"is_bot": false,
"headline": "fix: tolerate unavailable optional Hancom oracle",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T09:28:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b37f4a7a28ba1359d248e3dcad57c544ed3f5312",
"body": "This reverts commit 4468aab51c591c01297e68bd03387bec062f4f6b.",
"is_bot": false,
"headline": "Revert \"fix: close post-return recovery claim races\"",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T09:28:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4468aab51c591c01297e68bd03387bec062f4f6b",
"body": null,
"is_bot": false,
"headline": "fix: close post-return recovery claim races",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T09:22:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f83d43493fcba902daafadb29266b8ac59ab1680",
"body": null,
"is_bot": false,
"headline": "fix: harden consolidated form transactions",
"author_name": "kokyuhyun",
"author_login": "airmang",
"committed_at": "2026-07-16T08:36:22Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 43,
"commits_last_year": 382,
"latest_release_at": "2026-07-28T06:01:09Z",
"latest_release_tag": "v6.0.4",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 20,
"days_since_latest_release": 0,
"mean_days_between_releases": 1.3
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 85,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "python-hwpx-automation",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"hwpx",
"hancom",
"document-automation",
"workflow",
"mcp",
"ai-agent",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/python-hwpx-automation/",
"is_deprecated": false,
"latest_version": "6.0.4",
"repository_url": "https://github.com/airmang/python-hwpx-automation",
"versions_count": 2,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": "2026-07-28T05:05:20.971757Z",
"latest_published_at": "2026-07-28T05:59:49.769903Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 22,
"stars": 65,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2025-09-27",
"count": 1
},
{
"date": "2026-02-04",
"count": 1
},
{
"date": "2026-02-22",
"count": 1
},
{
"date": "2026-02-23",
"count": 1
},
{
"date": "2026-02-24",
"count": 2
},
{
"date": "2026-02-26",
"count": 1
},
{
"date": "2026-03-04",
"count": 1
},
{
"date": "2026-03-10",
"count": 1
},
{
"date": "2026-03-13",
"count": 1
},
{
"date": "2026-03-14",
"count": 1
},
{
"date": "2026-03-19",
"count": 1
},
{
"date": "2026-03-23",
"count": 1
},
{
"date": "2026-03-26",
"count": 1
},
{
"date": "2026-04-16",
"count": 1
},
{
"date": "2026-04-25",
"count": 1
},
{
"date": "2026-05-08",
"count": 1
},
{
"date": "2026-05-27",
"count": 1
},
{
"date": "2026-07-08",
"count": 1
},
{
"date": "2026-07-23",
"count": 1
},
{
"date": "2026-07-27",
"count": 1
}
],
"complete": true,
"collected": 21,
"total_forks": 22
},
"star_history": null,
"open_issues_and_prs": 10
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"src/hwpx_automation/py.typed"
],
"toolchain_manifests": [],
"largest_source_bytes": 131521,
"source_files_sampled": 372,
"oversized_source_files": 6,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"pyproject.toml"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 2,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 20,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "python-hwpx",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.0.0,<6"
},
{
"name": "pydantic",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.11,<3"
},
{
"name": "cryptography",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=42.0"
},
{
"name": "anyio",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.0"
},
{
"name": "tomli",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "anyio",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "cryptography",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pydantic",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "python-hwpx",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "build",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "jsonschema",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "markitdown",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mcp",
"direct": false,
"version": "1.28.1",
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "numpy",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "olefile",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "packaging",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pillow",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pymupdf",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pyright",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-cov",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "python-hwpx-automation",
"direct": false,
"version": "6.0.2",
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "ruff",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "setuptools",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "uvicorn",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 22,
"direct_count": 4,
"indirect_count": 18
}
},
"maintainership": {
"issues": {
"open_prs": 2,
"merged_prs": 69,
"open_issues": 8,
"closed_ratio": 0.429,
"closed_issues": 6,
"closed_unmerged_prs": 5
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "airmang",
"commits": 384,
"avatar_url": "https://avatars.githubusercontent.com/u/38392618?v=4"
},
{
"type": "User",
"login": "seonghoony",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/18564028?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.997
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"codeql.yml",
"dependency-review.yml",
"release.yml",
"tests.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 2,
"reason": "dependency not pinned by hash detected -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool detected: CodeQL",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "87e5657bd10f20b727a6195e6a474693455f979c",
"ran_at": "2026-07-28T06:06:26Z",
"aggregate_score": 6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-28T04:32:08Z",
"oldest_open_prs": [
{
"number": 84,
"created_at": "2026-07-23T14:48:01Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 90,
"created_at": "2026-07-27T03:42:33Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-21T07:35:59Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 75,
"created_at": "2026-07-20T13:28:39Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 78,
"created_at": "2026-07-20T15:45:37Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 83,
"created_at": "2026-07-23T12:26:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 85,
"created_at": "2026-07-23T14:58:49Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 86,
"created_at": "2026-07-23T22:38:12Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 87,
"created_at": "2026-07-24T00:36:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 88,
"created_at": "2026-07-24T13:52:03Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 89,
"created_at": "2026-07-25T23:17:39Z",
"last_comment_at": "2026-07-28T02:05:59Z",
"last_comment_author": "airmang"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/airmang/python-hwpx-automation",
"host": "github.com",
"name": "python-hwpx-automation",
"owner": "airmang"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"security": 68,
"vitality": 83,
"community": 57,
"governance": 49,
"engineering": 76
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"commits_last_year": 382,
"human_commit_share": 0.99,
"days_since_last_push": 0,
"active_weeks_last_year": 20
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "20/52 weeks with commits",
"points": 13.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 20
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "382 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 382
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 43,
"latest_release_tag": "v6.0.4",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 1.3
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "43 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 43
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.3 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.3
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 57,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"forks": 22,
"stars": 65,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "65 stars",
"points": 29.3,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 65
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "22 forks",
"points": 11,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 22
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 49,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 15,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.997
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 56,
"inputs": {
"merged_prs": 69,
"open_issues": 8,
"closed_issues": 6,
"issue_closed_ratio": 0.429,
"closed_unmerged_prs": 5
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "43% of issues closed",
"points": 20.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 43
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "69/74 decided PRs merged",
"points": 35.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 69,
"decided": 74
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 49,
"inputs": {
"followers": 15,
"owner_type": "User",
"is_verified": null,
"owner_login": "airmang",
"public_repos": 14,
"account_age_days": 3026
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "15 followers of airmang",
"points": 8.7,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 15,
"login": "airmang"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "14 public repos, account ~8 yr old",
"points": 20.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 14
}
},
{
"code": "account_age_years",
"params": {
"years": 8
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"packages": [
"python-hwpx-automation"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "2 published versions",
"points": 12,
"status": "partial",
"details": [
{
"code": "published_versions",
"params": {
"count": 2
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 76,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"ai-agent",
"claude-desktop",
"document-automation",
"hancom",
"hwpx",
"local-first",
"mcp",
"model-context-protocol",
"python",
"vscode"
],
"has_wiki": true,
"homepage": "https://pypi.org/project/hwpx-mcp-server/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://pypi.org/project/hwpx-mcp-server/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "10 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 10
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 68,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 2",
"points": 1,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool detected: CodeQL",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 2 resolved dependencies against OSV; 20 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 2
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 20
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 2,
"unassessed_packages": 20,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 2,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 1
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 55,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.929,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "92 of 99 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 92,
"sampled": 99
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"src/hwpx_automation/py.typed"
],
"agent_commit_share": 0.45,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.01
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "src/hwpx_automation/py.typed",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "src/hwpx_automation/py.typed"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "45 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 45,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "1 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 2",
"points": 2,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "good",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 131521,
"source_files_sampled": 372,
"oversized_source_files": 6
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python with type-check config (src/hwpx_automation/py.typed)",
"points": 27,
"status": "partial",
"details": [
{
"code": "typecheck_config_language",
"params": {
"files": "src/hwpx_automation/py.typed",
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "6/372 source files over 60KB",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 372,
"oversized": 6
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"deps.dev does not index pypi:python-hwpx-automation@6.0.4; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-28T06:06:32.977195Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/airmang/python-hwpx-automation.svg",
"full_name": "airmang/python-hwpx-automation",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}