Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-27 00:59 UTC

askalf / deepdive

Local research agent — one command, a cited answer with its trust signals: source-authority mix, lexical citation verification, confidence, cost. CLI + MCP server. Runs on your own LLM router; nightly public report card. Zero hosted dependencies.

JavaScript · TypeScriptMIT★ 2 estrellas⑂ 2 forksdesde abr 2026Ver en GitHub ↗

askalf/deepdive tiene un índice de salud de 69 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Security (86/100) y la más baja, Community & Adoption (45/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

69
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

69
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Thomas SprayberryCuenta personal
21 seguidores23 repositorios públicosdesde feb 2026Sprayberry Labs

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npm@askalf/deepdive0.32.0331339hace 6 díasresearchagentllmlocalclianthropicopenaiclaudesearchdeep-researchperplexity-alternativecitecitationsself-hosted

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

84Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
9.7/36Cadencia de commits — 14/52 semanas con commits
18/18Volumen de commits — 170 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year170
human_commit_share0,85
days_since_last_push0
active_weeks_last_year14
Cómo se puntúa
27/27Publica versiones — 39 versiones publicadas
36/36Recencia de las versiones — última versión hace 6 días
27/27Cadencia de publicación — una versión cada ~3,5 días
8/10OpenSSF Scorecard: Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
Datos de entrada utilizados
releases_count39
latest_release_tagv0.32.0
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases3,5

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

45En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 2 estrellas
0/25Forks — 2 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks2
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_templateno
Cómo se puntúa
46.9/80Descargas mensuales — 3313 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@askalf/deepdive
dependents
ecosystemsnpm
total_downloads
monthly_downloads3313
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

55Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0.2/22.5Distribución de commits — el principal contribuyente firma el 99% de los commits
2.7/13.5Amplitud de contribuyentes — 2 contribuyentes
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Datos de entrada utilizados
bus_factor1
contributors_sampled2
top_contributor_share0,993
Cómo se puntúa
44.4/46.8Resolución de issues — 95% de issues cerradas
37.6/38.3Aceptación de PR — 163/166 PR decididos fusionados
1.5/15OpenSSF Scorecard: Code-Review — Found 4/22 approved changesets -- score normalized to 1
Datos de entrada utilizados
merged_prs163
open_issues1
closed_issues19
issue_closed_ratio0,95
closed_unmerged_prs3
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
9.7/25Alcance del propietario — 21 seguidores de askalf
10.9/25Trayectoria — 23 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers21
owner_typeUser
is_verified
owner_loginaskalf
public_repos23
account_age_days154
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 6 días
20/20Historial de versiones — 39 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@askalf/deepdive
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

77Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 9 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentación

90Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://www.npmjs.com/package/@askalf/deepdive
10/10Descripción del repositorio
10/10Topics — 13 topics
0/10Wiki
Datos de entrada utilizados
topicsai, cli, llm, research-agent, search, anthropic, citations, claude, deep-research, perplexity-alternative, self-hosted, mcp, model-context-protocol
has_wikino
homepagehttps://www.npmjs.com/package/@askalf/deepdive
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

86Excelente · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 4/22 approved changesets -- score normalized to 1
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 2 out of the last 2 releases have a total of 2 signed artifacts.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate8,5
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
13.2/25Dependencias indirectas libres de avisos conocidos — 1 afectados: @hono/node-server 1.19.15 (moderate 5.9)
40/40Sin avisos pendientes — ningún aviso lleva público más de 90 días
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages111
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Se cotejó el cierre de dependencias en tiempo de ejecución de npm:@askalf/deepdive@0.32.0 —lo que arrastra la instalación del paquete publicado—: 111 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

66Moderado · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 82 de 85 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,965
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes4940
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — tsconfig.json
10/10Entorno reproducible — Dockerfile, lockfile
2/10Práctica demostrada con agentes — 1 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 15 de los últimos 100 commits son actualizaciones automáticas de dependencias
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configstsconfig.json
agent_commit_share0,01
toolchain_manifests
dependency_bot_commit_share0,15
Cómo se puntúa
27/45Código verificable por tipos — JavaScript con configuración de verificación de tipos (tsconfig.json)
54.6/55Tamaños de archivo manejables — 1/134 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageJavaScript
largest_source_bytes75.892
source_files_sampled134
oversized_source_files1
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
0/40Ejemplos ejecutables
Datos de entrada utilizados
example_dirs
has_mcp_signal
api_schema_files

Datos clave

2estrellas de GitHub
2contribuidores
170commits en los últimos 12 meses
0días desde el último push
39versiones publicadas
1factor bus
1issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Más detalle

Historial de estrellas y forks 0 ★ / 2 ⇿
0Estrellas
2Forks

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

111222212026-042026-042026-05
OpenSSF Scorecard 8.5 / 10
8.5agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-27 00:59 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 4/22 approved changesets -- score normalized to 1
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
8Signed-Releases2 out of the last 2 releases have a total of 2 signed artifacts.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Dependencias directas 3
RegistroPaqueteRestricción de versiónManifiesto
npm@modelcontextprotocol/sdk^1.29.0package.json
npmplaywright^1.47.0package.json
npmzod^4.4.3package.json
Todas las dependencias 241

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 3 paquetes directos y 238 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
npm@modelcontextprotocol/sdk1.29.0directa
npmplaywright1.61.1directa
npmzod4.4.3directa
npm@babel/code-frame7.29.7indirecta
npm@babel/compat-data7.29.7indirecta
npm@babel/core7.29.7indirecta
npm@babel/generator7.29.7indirecta
npm@babel/helper-compilation-targets7.29.7indirecta
npm@babel/helper-globals7.29.7indirecta
npm@babel/helper-module-imports7.29.7indirecta
npm@babel/helper-module-transforms7.29.7indirecta
npm@babel/helper-string-parser7.29.7indirecta
npm@babel/helper-validator-identifier7.29.7indirecta
npm@babel/helper-validator-option7.29.7indirecta
npm@babel/helpers7.29.7indirecta
npm@babel/parser7.29.7indirecta
npm@babel/template7.29.7indirecta
npm@babel/traverse7.29.7indirecta
npm@babel/types7.29.7indirecta
npm@esbuild/aix-ppc640.28.1indirecta
npm@esbuild/android-arm0.28.1indirecta
npm@esbuild/android-arm640.28.1indirecta
npm@esbuild/android-x640.28.1indirecta
npm@esbuild/darwin-arm640.28.1indirecta
npm@esbuild/darwin-x640.28.1indirecta
npm@esbuild/freebsd-arm640.28.1indirecta
npm@esbuild/freebsd-x640.28.1indirecta
npm@esbuild/linux-arm0.28.1indirecta
npm@esbuild/linux-arm640.28.1indirecta
npm@esbuild/linux-ia320.28.1indirecta
npm@esbuild/linux-loong640.28.1indirecta
npm@esbuild/linux-mips64el0.28.1indirecta
npm@esbuild/linux-ppc640.28.1indirecta
npm@esbuild/linux-riscv640.28.1indirecta
npm@esbuild/linux-s390x0.28.1indirecta
npm@esbuild/linux-x640.28.1indirecta
npm@esbuild/netbsd-arm640.28.1indirecta
npm@esbuild/netbsd-x640.28.1indirecta
npm@esbuild/openbsd-arm640.28.1indirecta
npm@esbuild/openbsd-x640.28.1indirecta
npm@esbuild/openharmony-arm640.28.1indirecta
npm@esbuild/sunos-x640.28.1indirecta
npm@esbuild/win32-arm640.28.1indirecta
npm@esbuild/win32-ia320.28.1indirecta
npm@esbuild/win32-x640.28.1indirecta
npm@hono/node-server1.19.15indirecta
npm@isaacs/fs-minipass4.0.1indirecta
npm@istanbuljs/schema0.1.6indirecta
npm@jazzer.js/bug-detectors4.0.0indirecta
npm@jazzer.js/core4.0.0indirecta
npm@jazzer.js/fuzzer4.0.0indirecta
npm@jazzer.js/hooking4.0.0indirecta
npm@jazzer.js/instrumentor4.0.0indirecta
npm@jridgewell/gen-mapping0.3.13indirecta
npm@jridgewell/remapping2.3.5indirecta
npm@jridgewell/resolve-uri3.1.2indirecta
npm@jridgewell/sourcemap-codec1.5.5indirecta
npm@jridgewell/trace-mapping0.3.31indirecta
npm@napi-rs/canvas1.0.0indirecta
npm@napi-rs/canvas-android-arm641.0.0indirecta
npm@napi-rs/canvas-darwin-arm641.0.0indirecta
npm@napi-rs/canvas-darwin-x641.0.0indirecta
npm@napi-rs/canvas-linux-arm-gnueabihf1.0.0indirecta
npm@napi-rs/canvas-linux-arm64-gnu1.0.0indirecta
npm@napi-rs/canvas-linux-arm64-musl1.0.0indirecta
npm@napi-rs/canvas-linux-riscv64-gnu1.0.0indirecta
npm@napi-rs/canvas-linux-x64-gnu1.0.0indirecta
npm@napi-rs/canvas-linux-x64-musl1.0.0indirecta
npm@napi-rs/canvas-win32-arm64-msvc1.0.0indirecta
npm@napi-rs/canvas-win32-x64-msvc1.0.0indirecta
npm@types/node26.1.1indirecta
npmaccepts2.0.0indirecta
npmajv8.20.0indirecta
npmajv-formats3.0.1indirecta
npmansi-regex5.0.1indirecta
npmansi-styles4.3.0indirecta
npmappend-transform2.0.0indirecta
npmbaseline-browser-mapping2.10.43indirecta
npmbindings1.5.0indirecta
npmbody-parser2.3.0indirecta
npmbrowserslist4.28.6indirecta
npmbuffer-from1.1.2indirecta
npmbytes3.1.2indirecta
npmcall-bind-apply-helpers1.0.2indirecta
npmcall-bound1.0.4indirecta
npmcaniuse-lite1.0.30001805indirecta
npmchownr3.0.0indirecta
npmcliui8.0.1indirecta
npmcmake-js8.0.0indirecta
npmcolor-convert2.0.1indirecta
npmcolor-name1.1.4indirecta
npmcontent-disposition1.1.0indirecta
npmcontent-type1.0.5indirecta
npmcontent-type2.0.0indirecta
npmconvert-source-map2.0.0indirecta
npmcookie0.7.2indirecta
npmcookie-signature1.2.2indirecta
npmcors2.8.6indirecta
npmcross-spawn7.0.6indirecta
npmdebug4.4.3indirecta
npmdeep-extend0.6.0indirecta
npmdefault-require-extensions3.0.1indirecta
npmdepd2.0.0indirecta
npmdunder-proto1.0.1indirecta
npmee-first1.1.1indirecta
npmelectron-to-chromium1.5.389indirecta
npmemoji-regex8.0.0indirecta
npmencodeurl2.0.0indirecta
npmes-define-property1.0.1indirecta
npmes-errors1.3.0indirecta
npmes-object-atoms1.1.2indirecta
npmesbuild0.28.1indirecta
npmescalade3.2.0indirecta
npmescape-html1.0.3indirecta
npmetag1.8.1indirecta
npmeventsource3.0.7indirecta
npmeventsource-parser3.1.0indirecta
npmexpress5.2.1indirecta
npmexpress-rate-limit8.5.2indirecta
npmfast-deep-equal3.1.3indirecta
npmfast-uri3.1.4indirecta
npmfile-uri-to-path1.0.0indirecta
npmfinalhandler2.1.1indirecta
npmforwarded0.2.0indirecta
npmfresh2.0.0indirecta
npmfs-extra11.3.6indirecta
npmfsevents2.3.2indirecta
npmfsevents2.3.3indirecta
npmfunction-bind1.1.2indirecta
npmgensync1.0.0-beta.2indirecta
npmget-caller-file2.0.5indirecta
npmget-intrinsic1.3.0indirecta
npmget-proto1.0.1indirecta
npmgopd1.2.0indirecta
npmgraceful-fs4.2.11indirecta
npmhas-flag4.0.0indirecta
npmhas-symbols1.1.0indirecta
npmhasown2.0.4indirecta
npmhono4.12.29indirecta
npmhtml-escaper2.0.2indirecta
npmhttp-errors2.0.1indirecta
npmiconv-lite0.7.3indirecta
npminherits2.0.4indirecta
npmini1.3.8indirecta
npmip-address10.2.0indirecta
npmipaddr.js1.9.1indirecta
npmis-fullwidth-code-point3.0.0indirecta
npmis-promise4.0.0indirecta
npmisexe2.0.0indirecta
npmisexe4.0.0indirecta
npmistanbul-lib-coverage3.2.2indirecta
npmistanbul-lib-hook3.0.0indirecta
npmistanbul-lib-instrument6.0.3indirecta
npmistanbul-lib-report3.0.1indirecta
npmistanbul-reports3.2.0indirecta
npmjose6.2.3indirecta
npmjs-tokens4.0.0indirecta
npmjsesc3.1.0indirecta
npmjson-schema-traverse1.0.0indirecta
npmjson-schema-typed8.0.2indirecta
npmjson52.2.3indirecta
npmjsonfile6.2.1indirecta
npmlru-cache5.1.1indirecta
npmmake-dir4.0.0indirecta
npmmath-intrinsics1.1.0indirecta
npmmedia-typer1.1.0indirecta
npmmerge-descriptors2.0.0indirecta
npmmime-db1.54.0indirecta
npmmime-types3.0.2indirecta
npmminimist1.2.8indirecta
npmminipass7.1.3indirecta
npmminizlib3.1.0indirecta
npmms2.1.3indirecta
npmnegotiator1.0.0indirecta
npmnode-addon-api8.9.0indirecta
npmnode-api-headers1.9.0indirecta
npmnode-releases2.0.51indirecta
npmobject-assign4.1.1indirecta
npmobject-inspect1.13.4indirecta
npmon-finished2.4.1indirecta
npmonce1.4.0indirecta
npmparseurl1.3.3indirecta
npmpath-key3.1.1indirecta
npmpath-to-regexp8.4.2indirecta
npmpdfjs-dist6.1.200indirecta
npmpicocolors1.1.1indirecta
npmpkce-challenge5.0.1indirecta
npmplaywright-core1.61.1indirecta
npmproper-lockfile4.1.2indirecta
npmproxy-addr2.0.7indirecta
npmqs6.15.3indirecta
npmrange-parser1.3.0indirecta
npmraw-body3.0.2indirecta
npmrc1.2.8indirecta
npmrequire-directory2.1.1indirecta
npmrequire-from-string2.0.2indirecta
npmretry0.12.0indirecta
npmrouter2.2.0indirecta
npmsafer-buffer2.1.2indirecta
npmsemver6.3.1indirecta
npmsemver7.8.5indirecta
npmsend1.2.1indirecta
npmserve-static2.2.1indirecta
npmsetprototypeof1.2.0indirecta
npmshebang-command2.0.0indirecta
npmshebang-regex3.0.0indirecta
npmside-channel1.1.1indirecta
npmside-channel-list1.0.1indirecta
npmside-channel-map1.0.1indirecta
npmside-channel-weakmap1.0.2indirecta
npmsignal-exit3.0.7indirecta
npmsource-map0.6.1indirecta
npmsource-map-support0.5.21indirecta
npmstatuses2.0.2indirecta
npmstring-width4.2.3indirecta
npmstrip-ansi6.0.1indirecta
npmstrip-bom4.0.0indirecta
npmstrip-json-comments2.0.1indirecta
npmsupports-color7.2.0indirecta
npmtar7.5.22indirecta
npmtmp0.2.7indirecta
npmtoidentifier1.0.1indirecta
npmtsx4.23.1indirecta
npmtype-is2.1.0indirecta
npmtypescript5.9.3indirecta
npmundici-types8.3.0indirecta
npmuniversalify2.0.1indirecta
npmunpipe1.0.0indirecta
npmupdate-browserslist-db1.2.3indirecta
npmurl-join4.0.1indirecta
npmvary1.1.2indirecta
npmwhich2.0.2indirecta
npmwhich6.0.1indirecta
npmwrap-ansi7.0.0indirecta
npmwrappy1.0.2indirecta
npmy18n5.0.8indirecta
npmyallist3.1.1indirecta
npmyallist5.0.0indirecta
npmyargs17.7.3indirecta
npmyargs-parser21.1.1indirecta
npmzod-to-json-schema3.25.2indirecta
Avisos de dependencias 1

Instalar npm:@askalf/deepdive@0.32.0 arrastra 111 paquetes, directos y transitivos: 1 tienen avisos conocidos, de los cuales 0 son dependencias directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
@hono/node-server1.19.15indirectamoderada12.0.5

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "ai",
        "cli",
        "llm",
        "research-agent",
        "search",
        "anthropic",
        "citations",
        "claude",
        "deep-research",
        "perplexity-alternative",
        "self-hosted",
        "mcp",
        "model-context-protocol"
      ],
      "is_fork": false,
      "size_kb": 1006,
      "has_wiki": false,
      "homepage": "https://www.npmjs.com/package/@askalf/deepdive",
      "languages": {
        "Shell": 964,
        "Dockerfile": 572,
        "JavaScript": 530455,
        "TypeScript": 370258
      },
      "pushed_at": "2026-07-26T17:47:46Z",
      "created_at": "2026-04-22T00:13:43Z",
      "owner_type": "User",
      "updated_at": "2026-07-26T17:03:53Z",
      "description": "Local research agent — one command, a cited answer with its trust signals: source-authority mix, lexical citation verification, confidence, cost. CLI + MCP server. Runs on your own LLM router; nightly public report card. Zero hosted dependencies.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://sprayberrylabs.com",
      "name": "Thomas Sprayberry",
      "type": "User",
      "login": "askalf",
      "company": "Sprayberry Labs",
      "location": null,
      "followers": 21,
      "avatar_url": "https://avatars.githubusercontent.com/u/263217947?v=4",
      "created_at": "2026-02-22T19:05:23Z",
      "is_verified": null,
      "public_repos": 23,
      "account_age_days": 154
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-07-20T14:48:57Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2026-07-12T14:03:08Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-07-11T15:07:06Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-07-11T13:37:56Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-07-11T12:53:01Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-07-02T23:44:05Z"
        },
        {
          "tag": "v0.27.1",
          "kind": "patch",
          "published_at": "2026-07-02T22:50:17Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-07-02T01:30:47Z"
        },
        {
          "tag": "v0.26.1",
          "kind": "patch",
          "published_at": "2026-06-27T02:02:06Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-06-18T21:56:49Z"
        },
        {
          "tag": "v0.25.3",
          "kind": "patch",
          "published_at": "2026-06-15T19:10:23Z"
        },
        {
          "tag": "v0.25.2",
          "kind": "patch",
          "published_at": "2026-06-15T18:23:35Z"
        },
        {
          "tag": "v0.25.1",
          "kind": "patch",
          "published_at": "2026-06-12T21:24:38Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-06-12T18:04:31Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-06-12T15:19:16Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-06-12T10:32:44Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-06-12T01:19:15Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-06-12T01:07:12Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-06-12T00:19:07Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-06-10T01:07:13Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-06-09T21:42:58Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-09T19:58:33Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-09T18:39:37Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-09T18:23:54Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-06-09T17:48:15Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-06-04T18:23:34Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-06-04T17:23:34Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-05-28T16:13:30Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-18T14:51:28Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-05-18T14:24:32Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-05-18T14:05:22Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-05-07T18:59:58Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-05-07T18:22:47Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-05-06T20:19:32Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-05-05T21:48:08Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-05T21:08:32Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-02T00:59:46Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-04-23T23:04:01Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-04-22T16:10:59Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4a13089fe289c7adf72ad79c0fe7aa744e1731da",
          "body": "…ory (#185)\n\nClears the two vulnerabilities behind Scorecard alert #36 (Vulnerabilities\ncheck, score 8). Both are transitive and both fixes are in-range, so this is a\nlockfile-only bump with no manifest change.\n\ntar 7.5.20 -> 7.5.22 (GHSA-r292-9mhp-454m, moderate)\n  Uncontrolled recursion in mapHas/\n[…]\nk 1.24.3,\n  which is a regression rather than a fix.\n\nVerified: npm ci clean, tsc --noEmit clean, 854 tests pass (2 skipped),\nnpm audit reports tar resolved and only the stale hono advisory remaining.",
          "is_bot": false,
          "headline": "fix(deps): patch tar and @hono/node-server; document stale hono advis…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-26T17:03:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1b75d6cf9906ea46bac5e56791084d85579bb13e",
          "body": "Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.4.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n  dependency-version: 3.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump fast-uri from 3.1.3 to 3.1.4 (#184)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T16:46:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "542a106a24c462b2779edbfb563418935c3cb658",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.32.0 (#183)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-20T14:48:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7ac0c65b62aa11d53bb663a4a7310b1435e805d",
          "body": "Fresh installs resolve config to $XDG_CONFIG_HOME/deepdive/config.json,\nthe page cache to $XDG_CACHE_HOME/deepdive, and sessions to\n$XDG_STATE_HOME/deepdive/sessions. An existing legacy ~/.deepdive/\nkeeps winning for all three paths, and the DEEPDIVE_CONFIG /\nDEEPDIVE_CACHE_DIR / DEEPDIVE_SESSIONS_D\n[…]\nare ignored per the spec.\n\nResolution is centralized in src/xdg.ts with an injectable legacy-dir\ncheck; test/xdg.test.mjs pins the precedence matrix. Help text, README,\nand CHANGELOG updated to match.",
          "is_bot": false,
          "headline": "feat: XDG Base Directory layout for fresh installs (#179) (#182)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-20T14:35:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd3e05391849ce0859b7856cc437a2b8e4706cd7",
          "body": "Bumps the non-major group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).\n\n\nUpdates `github/codeql-action/init`\n[…]\n: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Thomas Sprayberry <263217947+askalf@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump the non-major group with 3 updates (#180)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T11:07:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "515086f920eb9071e30683df1dbe16813da44087",
          "body": "Bumps oss-fuzz-base/base-builder-javascript from `0d2d180` to `61d74ab`.\n\n---\nupdated-dependencies:\n- dependency-name: oss-fuzz-base/base-builder-javascript\n  dependency-version: 61d74ab736764e98c8e7017dafd8bdd1129f004177dc38eec08bdbb3dd3ea7d8\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump oss-fuzz-base/base-builder-javascript (#181)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T09:52:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ecc59ca8647fc612de44aaea8458d9def71c9f8",
          "body": null,
          "is_bot": false,
          "headline": "docs: point OpenSSF Scorecard badge at api.scorecard.dev (#178)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-19T13:18:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58aa0d1e54eed7eb9e8d9ddc2606a8307f91859f",
          "body": "…p (#176)\n\nBumps the non-major group with 1 update: [tsx](https://github.com/privatenumber/tsx).\n\n\nUpdates `tsx` from 4.23.0 to 4.23.1\n- [Release notes](https://github.com/privatenumber/tsx/releases)\n- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)\n- [Commits](https\n[…]\n: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Thomas Sprayberry <263217947+askalf@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tsx from 4.23.0 to 4.23.1 in the non-major grou…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T22:27:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "10379fe981b4e52a96e9b17eb1683656428242fd",
          "body": "Bumps oss-fuzz-base/base-builder-javascript from `5d38358` to `0d2d180`.\n\n---\nupdated-dependencies:\n- dependency-name: oss-fuzz-base/base-builder-javascript\n  dependency-version: 0d2d18019500c5b4b00c3edb37a5a3b8291fd9b43a19932a3dabb75e3f66f64d\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump oss-fuzz-base/base-builder-javascript (#177)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T22:24:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "751aae3525211176dce74e104b2f84a484958c46",
          "body": "Bumps [zod](https://github.com/colinhacks/zod) from 3.25.76 to 4.4.3.\n- [Release notes](https://github.com/colinhacks/zod/releases)\n- [Commits](https://github.com/colinhacks/zod/compare/v3.25.76...v4.4.3)\n\n---\nupdated-dependencies:\n- dependency-name: zod\n  dependency-version: 4.4.3\n  dependency-type\n[…]\n: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Thomas Sprayberry <263217947+askalf@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zod from 3.25.76 to 4.4.3 (#173)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-12T19:07:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8ad78577ea820e587613ef354d8a639e71d78ab1",
          "body": "Bumps the non-major group with 1 update: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).\n\n\nUpdates `@types/node` from 26.1.0 to 26.1.1\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped\n[…]\n: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Thomas Sprayberry <263217947+askalf@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @types/node in the non-major group (#172)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-12T17:37:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccad3753913c6e44c3181c839113dfbc0a782ee1",
          "body": "Bumps the non-major group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [actions/stale](https://github.com/ac\n[…]\n: version-update:semver-minor\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump the non-major group with 4 updates (#175)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-12T15:07:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69d159bfa083f7a8dad33460d15e4ba877e97ca0",
          "body": "…ild (#171)",
          "is_bot": false,
          "headline": "harden: digest-pin the ClusterFuzzLite base image + npm ci in fuzz bu…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-12T14:10:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2683728e7f6777a540cdfe7df3f7faa6aaf25ff9",
          "body": "…ns (v0.31.1) (#170)",
          "is_bot": false,
          "headline": "harden: ClusterFuzzLite fuzzing + job-scoped workflow write permissio…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-12T14:02:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd0df92f8849174268d4836a2b96603bb80b098d",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): add the OpenSSF Scorecard badge (#167)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T23:59:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15a2ce8af50c066832efe476d51775b65114cec5",
          "body": "* docs: add Contributor Covenant Code of Conduct\n\n* docs: add contributing guide",
          "is_bot": false,
          "headline": "docs: add CONTRIBUTING guide and code of conduct (#169)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T23:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e5e4173597a6ccf17d603221e69db47914b47b5",
          "body": null,
          "is_bot": false,
          "headline": "harden: scope release token out of npm test (#168)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T23:44:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a28f59a3437d57daae814bffc324f40daa996a4",
          "body": "…ublished results) (#166)",
          "is_bot": false,
          "headline": "ci(scorecard): wire the OpenSSF Scorecard action (weekly + on-push, p…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T23:02:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d5abb5a16fa065320037064a412268fb39a6fe7",
          "body": "…gned-Releases) (#165)",
          "is_bot": false,
          "headline": "ci(release): attach npm tarball + Sigstore provenance to releases (Si…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T23:02:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38541b92d3ad2a96cf378839cb401a177dc00ba2",
          "body": "… canary-data branch) (#164)",
          "is_bot": false,
          "headline": "docs(README): link the nightly public report card (canary dashboard +…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T21:47:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97f4059a54f336b003ece7cdd423d1ce2b030522",
          "body": "… paths (#163)\n\nOperator configured a trusted publisher for @askalf/deepdive on npmjs,\nbound (per fleet convention) to the publish.yml filename. This moves the\npackage to the fleet's proven tokenless pattern and fixes the three\nworkflow defects found in today's review:\n\n- publish.yml becomes THE pub\n[…]\norts on the existing tag).\n\nPost-merge: verify the OIDC path (dispatch publish.yml for v0.31.0 —\nexpect the version-conflict error AFTER a successful tokenless auth),\nthen revoke the NPM_TOKEN secret.",
          "is_bot": false,
          "headline": "ci: migrate npm publish to OIDC trusted publishing + fix the recovery…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T15:51:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be904c318d93837190d1bfadc7165683ae2723b9",
          "body": null,
          "is_bot": false,
          "headline": "release: 0.31.0 — MCP server mode (#162)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T15:06:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2778b4ecb751f19cbcfe406bc7170eac6a6ff99",
          "body": "…ed (#160) (#161)\n\n`deepdive mcp` runs a Model Context Protocol server on stdio exposing one\ntool, deepdive_research: any MCP client (Claude Code, IDEs, agent\nharnesses) gets a research tool whose every answer arrives with the trust\nsignals the CLI reports — source-trust mix, citations supported,\nco\n[…]\ncp.test.mjs: protocol-level via InMemoryTransport + injected\nrunner, flag mapping, footer, schema rejection, error rendering, and a\nreal-stdio smoke spawning `deepdive mcp`. Suite: 845/0.\n\nCloses #160",
          "is_bot": false,
          "headline": "mcp: server mode — deepdive_research over stdio, trust signals attach…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T15:00:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50049d2f4fc120ac0883a6c41a1447ccd4b96c28",
          "body": null,
          "is_bot": false,
          "headline": "release: 0.30.0 — #157 adapter-aware site: hint (#159)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T13:37:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5242d19eca7c21121af67b4c27a0fb537af45a3b",
          "body": "…irective (#157) (#158)\n\nv0.29.0's live receipt: hinted retries fired ×3 and still surfaced zero\nallowed-host results — a bare host token can't steer an aggregator's\nranking, and two of the runner fan-out's three backends can't respond to a\nhost hint at all.\n\n- New optional SearchAdapter.searchHinte\n[…]\nlpubs.nist.gov →\n  also nvlpubs) — the form the original 7/2 probe ranked #1 with.\n\n839 tests / 0 fail (11 new). Receipt protocol unchanged: NIST Q ×3 on the\nrunner, target 3/3 (was 1/3).\n\nCloses #157",
          "is_bot": false,
          "headline": "search: adapter-aware site: hint — the allow-domain retry becomes a d…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T13:25:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a168e1a343d683ba1593c681739f2f3b6276c3e",
          "body": "…k/host cap (#156)",
          "is_bot": false,
          "headline": "release: 0.29.0 — #147 allow-domain recovery + #148 relevance tiebrea…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T12:52:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6de1395517ca2f7c90cc724be1f94105ec682c6",
          "body": "…cap + bench canonical column (#148) (#155)\n\n* keep-stage: relevance tiebreak in uniform-tier pools + per-host slot cap + bench canonical column (#148)\n\nAuthority ranking orders by WHO published; once a pool is uniformly\ntrustworthy it stops discriminating exactly where it is the only axis left,\nand\n[…]\n column. Reported,\n  never gated — the measurement instrument for this change.\n\nAddresses #148\n\n* bench: #148 receipt boards — academic + niche-ops authority-compare w/ canonical column (branch build)",
          "is_bot": false,
          "headline": "keep-stage: relevance tiebreak in uniform-tier pools + per-host slot …",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T12:47:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ef4eca802be60b1d55c5da6d1007e61cd4e3253",
          "body": "…ctural-fallback skip (#147) (#154)\n\n* search: fix the --allow-domain coin flip — hinted retry + honest structural-fallback skip (#147)\n\nLive on v0.27.1, the same question with --allow-domain=nvlpubs.nist.gov ran\nthree times: one answer, two exit 3s — while a raw probe carrying the host\nname found t\n[…]\nin.test.mjs plus canServeAllowedDomain and\nservesDomains-union unit cases.\n\nCloses #147\n\n* test: match the hint host as a query token, not a substring (CodeQL js/incomplete-url-substring-sanitization)",
          "is_bot": false,
          "headline": "search: fix the --allow-domain coin flip — hinted retry + honest stru…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-11T12:39:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f5825fa3e668694f9402877af7b936ad4fedc904",
          "body": "…dpass) (#153)",
          "is_bot": false,
          "headline": "README: sweep to the renamed tools (redstamp/truecopy/strongroom/fiel…",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-10T18:46:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6260d778bdd334e5a8d5a4a32c51dcd68d8edcbd",
          "body": null,
          "is_bot": false,
          "headline": "README: align askalf framing to the operation story (#152)",
          "author_name": "Thomas Sprayberry",
          "author_login": "askalf",
          "committed_at": "2026-07-10T15:13:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de28096dedd18276e6fbfba9eb8e16f360229420",
          "body": "Bumps the non-major group with 2 updates: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [tsx](https://github.com/privatenumber/tsx).\n\n\nUpdates `@types/node` from 26.0.1 to 26.1.0\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/release\n[…]\n: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Thomas Sprayberry <263217947+askalf@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the non-major group with 2 updates (#151)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T17:54:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "113f040cddad7d125cb8f547076f823447092c3f",
          "body": "Bumps the non-major group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).\n\n\nUpdates `github/codeql-action/init`\n[…]\n: version-update:semver-patch\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump the non-major group with 3 updates (#150)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T10:07:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "deed38a7c73b391d3d0058c0a5c42c2209d4131e",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.28.0 (#149)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T23:43:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "379ba8bc9b355be7d341785caa08e07a1b81e01b",
          "body": "…nt spans, not the document head (#145) (#146)\n\nHead-first truncation reduced long formal documents to front matter:\nthe first real PDF ingest (129-page NIST SP 800-63B-4) extracted all\n18,265 words, capped to the first 2,000 — title page, authors, abstract,\nToC — and the synth correctly refused to \n[…]\nd head-first cap.\nDeterministic, LLM-free, zero new deps.\n\nPinned by test/relevance-window.test.mjs incl. a NIST-shaped fixture\nasserting head-first misses the normative text and windowing reaches it.",
          "is_bot": false,
          "headline": "feat: relevance-windowed per-source cap — budget goes to query-releva…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T23:41:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5236f58d67726935010b4b5c11af6a16c036b72f",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.27.1 (#144)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T22:49:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ead8a801543fd0eff367eeb9d4d37acdac6f43be",
          "body": "…(#142) (#143)\n\nA live v0.27.0 run grounded 16/18 citations in the official OpenSSH\nrelease notes yet badged `mixed` — openssh.org scored unknown while the\nset's one recognized primary was a marginally relevant Windows install\nguide. Same coverage class as #130: canonical project sites with no\ndocs.\n[…]\nrg — the mirror search actually surfaces — and openbsd.org,\nthe parent project), pinned by a new test case. Re-scoring the live\nrun's five kept sources: 1 primary / 4 unknown -> 3 primary / 2 unknown.",
          "is_bot": false,
          "headline": "fix: OpenSSH/OpenBSD project hosts score primary in source authority …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T22:46:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fc1f0c252a7dd89f680828b0d9a1abe8153bf14",
          "body": "…4-8) (#141)\n\nREADME + cli usage comment suggested `claude-opus-4-7` for reasoning-heavy runs;\nopus-4-7 is superseded by opus-4-8 (current). Docs/examples only — benchmark\nreceipts, CHANGELOG history, the pricing table, and the still-valid default\nclaude-sonnet-4-6 are untouched.",
          "is_bot": false,
          "headline": "docs: refresh superseded opus model-id in examples (opus-4-7 -> opus-…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T12:29:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0062b46844bc811403bde2cc226730e062694fb",
          "body": "…onal-dep accuracy (#140)",
          "is_bot": false,
          "headline": "docs(readme): v0.27.0 state — board receipts, SE keyword ladder, opti…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T12:22:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1a4b31b37597f4da84ea3e48a601cde2d01daf3",
          "body": "…shipped empty, not just since 0.20.0 (#139)",
          "is_bot": false,
          "headline": "docs(test): correct the #135 scope note — all 28 auto-release bodies …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T12:13:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27d4eeecd66797cec8546eb4bc39aea3f2348540",
          "body": "…niche-ops un-deaded (+5, trust high) (#138)",
          "is_bot": false,
          "headline": "bench: source-authority off-vs-prefer board at v0.27.0 — 23% -> 44%, …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T02:44:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a63177369adcf0723b3ab362d1e52e4c87ddefcb",
          "body": "… cell (#137)",
          "is_bot": false,
          "headline": "bench(compare): name the failure when a run renders as an empty board…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T02:26:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d76a25b195412f9a3d94cf9bbee15f646b87129",
          "body": "…emptied every release body (#135) (#136)",
          "is_bot": false,
          "headline": "fix(release): changelog extraction never worked — $ under the m flag …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T01:38:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99b49d3df5b08debdc0684314f433b7a9da0ef76",
          "body": "…Exchange keyword ladder (#131) (#134)",
          "is_bot": false,
          "headline": "chore(release): v0.27.0 — ops/infra authority coverage (#130) + Stack…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T01:30:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b6f829e1949270884073966ae999e729d586043",
          "body": "…ero-result NL queries (#131) (#133)",
          "is_bot": false,
          "headline": "feat(search): stackexchange adapter walks the #86 keyword ladder on z…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T01:26:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1959f406d16a918301e178eedd2f4d3c7b31327",
          "body": "…roject docs + the SE network's own domains (#130) (#132)",
          "is_bot": false,
          "headline": "feat(source-authority): cover the ops/infra canon — nginx.org-class p…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T01:24:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97db37c7db2826ffc2ced923a5b7fc95deed0ace",
          "body": "… 18% -> 38% primary/reputable (#129)",
          "is_bot": false,
          "headline": "bench: source-authority off-vs-prefer board at v0.26.1 (P3 of #111) —…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T00:49:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0926292dec3a8fe37f3b1855c8ed8048aea3641",
          "body": "…adge entry (#128)",
          "is_bot": false,
          "headline": "docs(changelog): cut the missing 0.26.1 section + add the #124 HTML-b…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-07-02T00:38:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8716e5f6556ede13bcb857dec5dfb97590b72a5f",
          "body": "Bumps the non-major group with 3 updates: [playwright](https://github.com/microsoft/playwright), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [pdfjs-dist](https://github.com/mozilla/pdf.js).\n\n\nUpdates `playwright` from 1.61.0 to 1.61.1\n- [Release notes](\n[…]\n: version-update:semver-minor\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the non-major group with 3 updates (#127)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T10:00:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abfc194d75ddaf18550f0a517b75265ccf210c59",
          "body": "…prefix exclusion fix (#125) (#126)",
          "is_bot": false,
          "headline": "chore(release): v0.26.1 — ship source-trust HTML badge (#124) + docs-…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-27T02:01:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7c269e7452ede742be71f196644ab21c466b3d7",
          "body": "…prefix boost (#111) (#125)\n\ndocs.google.com matched the `docs.` documentation-subdomain boost and scored\n`primary` (top authority, 1.0) — but it's the Google Docs app, where anyone can\npublish a document, not Google's product docs. An arbitrary user-published\nGoogle Doc therefore ranked as authorit\n[…]\nnot boosted). Google's real product docs at\ndevelopers.google.com / cloud.google.com are unaffected (the latter is already\na curated primary domain). Pinned by a new case in source-authority.test.mjs.",
          "is_bot": false,
          "headline": "fix(source-authority): exclude user-publishable docs. hosts from the …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-26T14:58:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac536dd89bc649a0a6a045d73164ec662c8448f9",
          "body": "…) (#124)\n\nThe HTML export now shows deepdive's source-trust label — the orthogonal axis to\ncitation support (whether the sources themselves are credible, not just whether\nclaims are cited) — on the shareable artifact, mirroring the CLI footer and the\n--json envelope. renderTrustBadge reuses the sam\n[…]\nurceTrust the other surfaces use, so every output reports one\nconsistent signal. Only shown when there's something to flag (mixed/low); a\nhigh-trust run stays clean. Tooltip is HTML-escaped. +6 tests.",
          "is_bot": false,
          "headline": "feat(export): surface the source-trust badge in the HTML report (#111…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-25T01:14:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09944ec40412be7a61bcfe7061e8d65b0110b2d6",
          "body": "claude-sync and claude-bridge are being moved back to private. Remove public references/links so nothing 404s. npm packages stay published.",
          "is_bot": false,
          "headline": "chore: remove claude-sync from stack listing (now private) (#123)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-24T20:17:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80bb3ea49087ae7379e4d4263d3f8b1063869810",
          "body": "The agent repo (@askalf/agent) is being made private and held back until the platform goes live. Remove public references/links so nothing 404s in the meantime. To be re-added at launch.",
          "is_bot": false,
          "headline": "chore: remove agent from stack listing (held back pre-launch) (#122)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-24T18:40:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2548f7ca46c6975c501b18ae3b167d6e1a124a4a",
          "body": "…g the run (#104) (#121)\n\ncallLLMStream wrapped only the initial connect in retry, so once the synthesis\nstream was flowing a mid-generation upstream stall tripped the idle-token\ndeadline and the TimeoutError killed the whole run. On a single-pass factual\nlookup synthesis is the only synthesis call,\n[…]\ny.test.mjs covers buffered-stall retry + fresh buffer,\npre-first-token retry, post-first-token no-retry, and a long-but-healthy stream\nthat outlives the connect timeout. Full suite: 760 pass / 0 fail.",
          "is_bot": false,
          "headline": "fix(synthesize): retry intermittent upstream stalls instead of failin…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-24T17:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bcec93aebf81e706e255121024b10dbd1ea1dca7",
          "body": "…letes #111 P4)\n\nCompletes P4 (stretch) of #111 — search-side bias toward primary sources.\n\nThe keep-stage authority ranking can only reorder what search already returned; a `multi:` fan-out could fill its result cap with content farms and truncate a low-ranked primary source before the keep stage s\n[…]\nL().hostname` + `endsWith`), not substring — verified safe. Test assertion changed from `url.includes(...)` to an exact-URL match to clear a CodeQL incomplete-url-substring false positive.\n\nRefs #111.",
          "is_bot": false,
          "headline": "feat(sources): bias multi-search fan-out toward primary sources (comp…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-24T16:40:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "affb2a168568d8de05868f25fec2847f0c98eb24",
          "body": "…hived)",
          "is_bot": false,
          "headline": "Remove deja from Own Your Stack list (repo shelved: now private + arc…",
          "author_name": "askalf",
          "author_login": "askalf",
          "committed_at": "2026-06-23T19:25:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d426f8ab53ceac3eb6d99a35353bf5953ecf1eba",
          "body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.3 to 26.0.0.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\ngned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: AskALF <263217947+askalf@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @types/node from 25.9.3 to 26.0.0 (#119)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T16:46:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6f0d5f5c6fb8f5069f428090cfd3e227159d68f",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#118)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T10:03:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58a59f52aedd8351036d78bb7edca6c1b330148d",
          "body": "…thority feature",
          "is_bot": false,
          "headline": "readme: add cordon + picket to footer; document the v0.26.0 source-au…",
          "author_name": "askalf",
          "author_login": "askalf",
          "committed_at": "2026-06-19T19:18:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d51b1d52f6d8b8cb30d0049784d64a574236bfb6",
          "body": "dist/ is gitignored and `npm test` ran against it without building first, so a\nfresh clone (no dist) — or a stale dist after a src change — failed: fetch-wedge\ncouldn't import FetchWedgeError, source-authority couldn't import its dist module,\nand the llm-stream streaming subtests cancelled (2 files \n[…]\nelled).\nAdd a `pretest` that runs the build. Verified: wipe dist, `npm test` auto-rebuilds\nand 731/733 pass (2 intentional skips).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: build before test so `npm test` works on a fresh checkout (#117)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-19T16:26:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7b7bfdb699f0b3037c3bffe9aa09d29dc9b35e63",
          "body": "Wires the measurable axis behind the source-authority work into the bench.\nEvery scoreboard now carries an `authority` column (the kept-source mix the CLI\nreports in --json: NP/NR/NU/NL · trust) plus an aggregate primary/reputable\nshare — reported, never gated (`unknown` is neutral; a niche topic le\n[…]\nlive LLM, like the rest of the harness. Reads the\nreal --json sourceTrust the CLI emits, so the bench stays zero-dep and measures\nthe shipped signal. No src/ changes; manual-only, never wired into CI.",
          "is_bot": false,
          "headline": "bench: source-authority distribution metric (P3 of #111) (#116)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-18T22:10:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aaf6eafd40bb5c475ad3924ffba5c26c214bd519",
          "body": "Ships the source-authority layer (#112/#113/#114): deterministic, no-LLM\ndomain scoring (scoreAuthority), keep-stage ranking that gives authoritative\nsources the limited fetch slots (--source-authority prefer|strict|off), and a\nsource-trust signal in the footer + --json — orthogonal to citation support,\nso a fully-cited answer built on content farms is flagged instead of silently\nconfident. Version bump + CHANGELOG + README doctor sample only.",
          "is_bot": false,
          "headline": "release: 0.26.0 — source authority, a second trust axis (#111) (#115)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-18T21:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6ec98a3eff83cafd8fd016043072a23f7b73dea",
          "body": "…f #111) (#114)\n\nAdds the orthogonal trust axis to deepdive's output. Citation support asks\n\"does the answer match its cited source?\"; this asks \"are those sources\nthemselves credible?\" — so a fully-cited answer built entirely on content\nfarms is no longer indistinguishable from one grounded in prim\n[…]\nhigh/mixed/low + counts; footer\n  with trust). Full suite 739 pass / 0 fail.\n\nNo LLM, deterministic, auditable — same philosophy as the lexical verifier.\nP3 (bench metric) is the remaining #111 slice.",
          "is_bot": false,
          "headline": "feat(sources): surface a source-trust signal in output + --json (P2 o…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-18T01:41:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15b645478efa31d7d16d104828fbd675a347012a",
          "body": "…(P1 of #111) (#113)\n\nWires the #112 scoreAuthority module — until now a pure, unused export —\ninto the fetch keep-stage so authoritative/primary sources win the limited\nfetch slots ahead of whatever search happened to rank first.\n\n- source-authority.ts: add rankByAuthority(items, urlOf, mode) +\n  S\n[…]\ns green (117 pass / 0 fail).\n\nDefault is \"prefer\" per the issue — a reorder-only boost that drops\nnothing, so it cannot starve a query. P2 (trust signal in output/--json)\nand P3 (bench metric) follow.",
          "is_bot": false,
          "headline": "feat(sources): rank candidates by domain authority at the keep stage …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-18T01:21:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26a267776e5f7cabbc57e70d9947dc733864680c",
          "body": null,
          "is_bot": false,
          "headline": "readme: refresh Own Your Stack footer (add hybrid + current stack)",
          "author_name": "askalf",
          "author_login": "askalf",
          "committed_at": "2026-06-16T20:51:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "953414cf7e9b98b8b381053cf091656bf719e664",
          "body": "Pure, deterministic per-URL trust scorer — the foundation for ranking which\nfetched sources to keep and for a source-trust signal distinct from citation\nsupport. Boost-led: gov/edu/standards/academia/official-docs = primary,\nwikipedia/SO/github = reputable; unknown is neutral (niche-but-legit not\npu\n[…]\n conservative seed denylist of observed content farms.\nNot yet wired into the keep loop — next commit. Validated on the 2026-06-15\ndogfood domains: content farms -> low, AWS/Fed/redis docs -> primary.",
          "is_bot": false,
          "headline": "feat(sources): source-authority scorer (P1 of #111) (#112)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-15T21:01:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31feaef5b70576063f580a7652cdb3c1edfb13a8",
          "body": "…es (#108)\n\nBumps the non-major group with 2 updates in the / directory: [playwright](https://github.com/microsoft/playwright) and [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).\n\n\nUpdates `playwright` from 1.60.0 to 1.61.0\n- [Release notes](https://github.com\n[…]\n: version-update:semver-minor\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the non-major group across 1 directory with 2 updat…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-15T20:53:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d23cdcdaeed884f171e9c7a247732173cc5d5e3",
          "body": "… (#110)\n\nThe installed `deepdive` bin (an npm symlink to dist/cli.js) was a silent\nno-op: the entry-point guard compared process.argv[1] (the symlink path) to\nimport.meta.url (the resolved module path), which never matched, so main()\nnever ran. Resolve both with realpathSync before comparing. Regression test\nspawns the CLI through a symlink. Affected every npm-global install; missed\nbecause the bench/tests invoke node dist/cli.js directly.",
          "is_bot": false,
          "headline": "fix(cli): run main() under symlink invocation + release 0.25.3 (#109)…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-15T19:09:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67967f93fbcd3e09990e4518c506b58c88bafef3",
          "body": "…107)\n\nShips the synthesis-reliability fix to npm: synthesis always streams (even\nin --json / non-TTY) bounded by an idle-token deadline, so a long generation\ncompletes in one pass and a stalled stream fails fast instead of burning 3x\nwhole-call retries.",
          "is_bot": false,
          "headline": "release: 0.25.2 — streaming synthesis + idle-token deadline (#106) (#…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-15T18:22:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92ec973ae34495052cda9aa01b2bfaccb6d3247b",
          "body": "…106)\n\nfactual-lookup's synthesis generates a large (~8k-token) answer that takes\n~110-150s. The non-streaming client waits for the whole response under a 120s\nwhole-call timeout, so it intermittently timed out mid-generation and re-ran\nthe full generation 3x (~360s) before failing. That is the #104\n[…]\nwhole-call timeout). A residual intermittent upstream SSE\nstall remains (~1 in 4) — tracked in #104; likely round-trip/tunnel aggravated,\nto be retested with deepdive running in-network next to dario.",
          "is_bot": false,
          "headline": "fix(synth): stream the synthesis call + idle-token deadline (#104) (#…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-15T16:08:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed21639f824c8c79b459d8a0959ee443ea4b75f1",
          "body": "Supersedes the DuckDuckGo-confounded 2026-06-12-v0.25.0-validation.md as the\nreference board for synth/planner prompt comparisons, now that the bench runs\non a deterministic search layer (#102). 5/6 PASS, support 0.92-1.00 on the\nfive completing questions. factual-lookup is blocked by the #104 fetch wedge\n(infra, intermittent), not a regression.",
          "is_bot": false,
          "headline": "bench: add clean SearXNG stock baseline board (2026-06-15) (#105)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-15T14:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5160ab3339883c94fc2b67802cc37330c39b691",
          "body": "DuckDuckGo HTML rate-limits the test box's IP and silently degrades to\nthe wikipedia fallback. For questions Wikipedia can't answer (e.g.\nfactual-lookup's \"Claude API rate limits\"), that turns a search failure\ninto a confident \"the sources don't contain it\" answer that reads like\nan LLM hedge — maki\n[…]\nards record the backend (URL kept to stderr, never\ncommitted).\n\nTests cover resolveBackend + questionArgs + the scoreboard line.\nValidated e2e: factual-lookup PASS via SearXNG, 32/32 citations (1.00).",
          "is_bot": false,
          "headline": "bench: run searches through SearXNG, not DuckDuckGo (#102)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-15T01:29:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9349685b8cd04930af0dbee1d9d2ef4ee6dd5f6b",
          "body": null,
          "is_bot": false,
          "headline": "npm: align description to Own Your Stack",
          "author_name": "askalf",
          "author_login": "askalf",
          "committed_at": "2026-06-14T18:29:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43546da74300427262624b7b1cbe193d64f15961",
          "body": null,
          "is_bot": false,
          "headline": "README: align to Own Your Stack",
          "author_name": "askalf",
          "author_login": "askalf",
          "committed_at": "2026-06-14T15:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4020be9d1cdc2eaa8333c5c2558d3a6ab0f99230",
          "body": "Bumps [esbuild](https://github.com/evanw/esbuild) from 0.28.0 to 0.28.1.\n- [Release notes](https://github.com/evanw/esbuild/releases)\n- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/evanw/esbuild/compare/v0.28.0...v0.28.1)\n\n---\nupdated-dependenci\n[…]\nld\n  dependency-version: 0.28.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump esbuild from 0.28.0 to 0.28.1 (#101)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-13T20:47:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d794c01da88d801a08723c3ad120be896e6e5ebc",
          "body": null,
          "is_bot": false,
          "headline": "release: 0.25.1 — hard per-fetch deadline (#87 wedge fix) (#100)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T21:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5071e8437693ee56add16b3b4f6beb9d8625fe0a",
          "body": "* fix(browser): hard per-fetch deadline closes the #87 wedge class\n\nRoot-cause audit of the 18-minute idle hang: the page work includes\nprotocol calls the per-call timeouts cannot cover. page.evaluate accepts\nno timeout at all - a renderer main thread blocked after domcontentloaded\n(dialog, window.p\n[…]\nde\ndrains the event loop before the unref'd deadline timer fires and\nnode:test cancels the still-pending test. Keep-alive in the TEST; the\nproduction unref stays (it must never hold the process open).",
          "is_bot": false,
          "headline": "fix(browser): hard per-fetch deadline closes the #87 wedge class (#99)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T21:21:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e48f100b00ac27ff43519c513721d8d64fcf8ef",
          "body": "…recency levers (4/3 @ 1.00) (#98)",
          "is_bot": false,
          "headline": "bench: v0.25.0 stock validation board — 5/6, recent PASSES with both …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T21:13:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "248177897678965f7a41a8ad7d13877eed4d573a",
          "body": null,
          "is_bot": false,
          "headline": "release: 0.25.0 — date-grounded planner and critic (#96)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T18:03:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf1b765f30ac7dfd719850dedf6a77e17120ec4f",
          "body": "* feat(plan): date-ground the planner and critic prompts\n\nThe planner had no notion of the current date, so recency-sensitive\nquestions got queries anchored to the model's training-time sense of\n\"recent\" - and with --since set, the recency filter then culled most of\nwhat those stale queries returned\n[…]\n once DDG rate-limiting on this IP\ncools - the after-run hit HTTP 202 throttling mid-bench.\n\n* bench: date-grounded planner after-board — 5/6, academic 0.68->0.92, recent 1/3->2-4/3 (bistable at gate)",
          "is_bot": false,
          "headline": "feat(plan): date-ground the planner and critic prompts (#95)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T18:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "411cda2035fc3cbf230dc894bee45e33c4143615",
          "body": "…(#94)\n\nThe promised unconfounded re-run: fresh npm ci + build in an isolated\nworktree at the release commit, only the shipped change set. The news\nadapter alone accounts for recent's recovery (1/3 sources at v0.23.0\n-> 3/3 at 1.00 support).",
          "is_bot": false,
          "headline": "bench: clean v0.24.0 board — 6/6, recent 3/3 sources at 1.00 support …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T15:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e73c377a49b96798d71aa46279d1f205c23b773a",
          "body": "…e fallback (#93)",
          "is_bot": false,
          "headline": "release: 0.24.0 — news adapter (keyless Bing News RSS) + recency-awar…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T15:18:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6074c63ac5414d1003e0829f10d2f37bd387561",
          "body": "…llback default (#92)\n\n* feat(search): news adapter (Bing News RSS, keyless) + recency-aware fallback default\n\nThe v0.23.0 bench's one failure was the `recent` question: DDG throttled,\nand the wikipedia fallback's undated/stale pages were culled by\n--since=180d, leaving 1/3 sources. Recency was the \n[…]\n in the full board). Full scoreboard 6/6 — first perfect run;\n  committed in bench/results/2026-06-12-v0.24.0-news-fallback.md.\n\n* bench: disclose the concurrent-planner-edit confound on the 6/6 board",
          "is_bot": false,
          "headline": "feat(search): news adapter (keyless Bing News RSS) + recency-aware fa…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T15:07:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19a7fb15ba5099795f1a7d6738c215052a95b59f",
          "body": "Same six questions that scored 1/6 under last night's DDG block and\n4/6 yesterday morning. With the keyword ladder (#89) and dario 4.8.66\nupstream: every run completes, citation support 0.68-1.00, cost\n$0.04-$0.16/query. The one FAIL (recent) completed with a fully-cited\nanswer but kept 1 source vs the 3-source gate — --since=180d thins\nthe pool by design; gate calibration question, not a product gap.",
          "is_bot": false,
          "headline": "bench: v0.23.0 validation — 5/6 PASS, 6/6 completed (#91)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T10:40:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af873fd3039cdd017bb428f72089a9797d7a3bef",
          "body": null,
          "is_bot": false,
          "headline": "release: 0.23.0 — Wikipedia keyword ladder (#90)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T10:32:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dfffa0674887cdc15d335c6ea9d55a3e628a33d",
          "body": "…terms (#89)\n\n* feat(wikipedia): keyword ladder — retry zero-result queries with key terms\n\nCloses #86. MediaWiki search matches article titles/text and returns\nzero for the planner's long natural-language queries (\"nginx\nfastcgi_buffer_size upstream sent too big header php-fpm fix\"), which\nhollowed\n[…]\nres are this exact gap; DDG re-throttled mid-bench and\nthe un-laddered fallback came back empty).\n\n* fix(query-keywords): linear punctuation trim — no quantified regex over input (js/polynomial-redos)",
          "is_bot": false,
          "headline": "feat(wikipedia): keyword ladder — retry zero-result queries with key …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T10:28:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "faeca9d0eda6c18793faa459f32d470824019ac6",
          "body": "… block (#88)\n\nSame live conditions as the v0.21.0 baseline (DDG rate-limiting the\nbox). Default wikipedia fallback turns three zero-source deaths into\ncompleted, fully-cited answers (factual-lookup, comparison, niche-ops\nall 1.00 citation support). Strict PASS stays 1/6 because the\nsource-count gates honestly flag thin encyclopedia-only grounding; the\ntwo remaining exit-3s are the verbatim-query/encyclopedia mismatch\ntracked in #86.",
          "is_bot": false,
          "headline": "bench: v0.22.0 after-scoreboard — completed runs 1/6 -> 4/6 under DDG…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T01:25:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3f80f15b4f94426324084e10a538bf150df26cf",
          "body": null,
          "is_bot": false,
          "headline": "release: 0.22.0 — search fallback on by default (#85)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T01:18:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e11422c8e33b3ee5695e78623d9ece5b0edfc410",
          "body": "…never die (#84)\n\nThe v0.21.0 baseline bench (bench/results/, committed here) made the\ncase: with DuckDuckGo rate-limiting the box's IP, 5/6 default-config\nquestions died with zero sources (exit 3) while the one multi-backend\nquestion passed with 12 sources and 0.86 citation support. A default\nrun d\n[…]\non\nthat exited 3 minutes earlier now completes via the fallback — 3\nsources, 9/9 citations supported, $0.044, with the stderr notice.\n\n682 tests: default resolution, none/off/blank disable, overrides.",
          "is_bot": false,
          "headline": "feat(search): default --search-fallback=wikipedia — degrade visibly, …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T01:16:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18b2398f8c1f4524192359c97ea9100ea1a7e1de",
          "body": "…on visibility, quality bench (#83)",
          "is_bot": false,
          "headline": "release: 0.21.0 — PDFs out of the box, --max-runtime, multi degradati…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T01:06:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f581bdce955a94e510bac0d63632444b292571a",
          "body": "…deadline (#82)\n\nBoth straight from the first live bench run.\n\nmulti: partial-failure tolerance was HIDING sub-adapter failures — DDG\nwas rate-limited the whole run, every query silently lost its\ngeneral-web results, and the answer synthesized from one StackExchange\nsource with no indication why. No\n[…]\nuntime=5s aborts in ~6s with the named cause;\nunitless value exits 2 with usage. 681 tests (was 672): benching,\nlastFailures reset, all-benched throw, search.degraded emission,\nconfig/flag resolution.",
          "is_bot": false,
          "headline": "feat(search): multi degradation visibility + benching; --max-runtime …",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T01:02:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "106f0d729de25d5f44f955bcecb07ca5f78709b0",
          "body": "…es (#81)\n\nThe planner/synth prompts are the project's highest-leverage knobs and\ncan't be tuned blind. bench/run.mjs runs the golden questions in\nbench/questions.json through the built CLI against a live endpoint and\nscores each run on structural gates: completed, enough sources,\ncitation-verifier \n[…]\nund can synthesize from a single source when DDG is silently\nrate-limited inside multi: (partial-failure tolerance hides it), and\ncaught a fetch-stage wedge — both queued as the next resilience round.",
          "is_bot": false,
          "headline": "feat(bench): quality bench harness — golden questions, structural gat…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T00:53:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2522dc84d14e7ada2bcf43eb56948644c4c3c047",
          "body": "…e box (#80)\n\n* feat(pdf): ship pdfjs-dist as an optional dependency — PDFs work out of the box\n\nDefault `npm install -g @askalf/deepdive` now reads PDFs with zero extra\nsteps. The academic adapters (arxiv, pubmed, semanticscholar, openalex)\nsurface PDFs constantly; silently skipping them gutted exa\n[…]\nworlds (pdfjs hidden: typecheck clean, 34\npass / 2 skipped incl. degraded-path pass; pdfjs present: 672 pass /\n1 skipped).\n\n* test(doctor): pdf check asserts ok-or-info depending on extractor presence",
          "is_bot": false,
          "headline": "feat(pdf): ship pdfjs-dist as an optional dependency — PDFs out of th…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T00:50:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17505db7de3fa049bc3046b62e0548b554288b9c",
          "body": "Rate-limit detection (DDG 202/403/429 + challenge page), request\nspacing, per-query search error tolerance with search.error events,\nzero-source abort before the synthesis call (NoSourcesError, exit 3),\nopt-in --search-fallback recovery pass, --version flag.\n\nCHANGELOG entry + README doctor sample refreshed. Merging this\npublishes 0.20.0 to npm via auto-release.yml.",
          "is_bot": false,
          "headline": "release: 0.20.0 — search resilience (#79)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T00:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b98d52762084d9f9cced65ba066eb53bf8759ce",
          "body": "--search-fallback=<adapters> (env DEEPDIVE_SEARCH_FALLBACK, config key\nsearchFallback): when a round's primary searches produce ZERO candidates\n(rate-limited, down, or genuinely empty), the round's queries re-run once\nthrough the fallback adapter before the zero-source guard fires. A comma\nlist fans\n[…]\n (was 650): fallback recovery / not-consulted-when-healthy /\nskipped-queries coverage / both-empty still aborts; parse-args, config\nresolution, normalizeAdapterList. Completion script + usage updated.",
          "is_bot": false,
          "headline": "feat(search): --search-fallback recovery pass + --version flag (#78)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T00:14:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d877bb7df46db1a77d2d8f5f4eaef3a358f4680b",
          "body": "…is (#77)\n\nDogfood finding (2026-06-10 smoke): DDG silently rate-limits a burst of\nqueries (~7 in quick succession), every search returns 0 results with no\nwarning, and the run still burns a synthesis LLM call to produce\n\"unable to answer\".\n\nThree fixes:\n\n- DuckDuckGo adapter now detects throttling \n[…]\n were\n  rate limits.\n\n650 tests (was 619): DDG throttle detection + spacing, agent error\ntolerance + short-circuit + guard, preKept still averts the abort,\nmulti classification, CLI message rendering.",
          "is_bot": false,
          "headline": "feat(search): rate-limit detection + zero-source abort before synthes…",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-12T00:11:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68e08a3ccf4b6df946e7927a1c4d37364cc466bb",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh doctor sample version, add ecosystem footer line (#76)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-11T23:27:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10dc05ccbfd4ebed0d0a12db6c3c1fd3514a44f3",
          "body": "* feat(export): heading anchors + table of contents in the HTML report (v0.19.0)\n\n- markdownToHtml gains headingIds: slug ids on headings (lowercased,\n  dashed, deduped -2/-3; derived from readable text with inline markup\n  and [N] cites stripped). Off by default; the HTML export enables it,\n  so de\n[…]\nware, slug-consistent with\n  markdownToHtml), headingPlainText, slugify.\n\n10 new tests (629 total green). Bundles the v0.19.0 release.\n\n* fix(markdown): linear slug trim to resolve js/polynomial-redos",
          "is_bot": false,
          "headline": "feat(export): heading anchors + table of contents (v0.19.0) (#75)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-10T01:06:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6456a83cfb8670d28d711bc4a9a296d9d424e61a",
          "body": "- deepdive rerun <id>: fresh re-run + automatic diff vs the parent (#72)\n- --search=multi:a,b[,c...]: concurrent fan-out across adapters (#73)\n\n607 → 619 tests. See CHANGELOG for the full 0.18.0 entry.",
          "is_bot": false,
          "headline": "release: 0.18.0 — rerun + multi-adapter fan-out (#74)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-09T21:42:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5906062baf06bc3e446bc1657a3f28801ba2f8c7",
          "body": "Queries every listed adapter concurrently, interleaves results\nround-robin in adapter order, dedupes on the normalized URL, re-ranks\ndensely. Partial failures tolerated (a throttled backend doesn't sink\nthe round); throws only when EVERY sub-adapter failed, naming each.\nSub-adapters resolve recursiv\n[…]\nain engine or two gives the planner a source pool no single\nbackend returns.\n\nNew exports MultiSearch/interleaveResults. 12 new tests (619 total\ngreen); live-verified interleaving ddg+wikipedia+arxiv.",
          "is_bot": false,
          "headline": "feat(search): multi-adapter fan-out — --search=multi:a,b[,c...] (#73)",
          "author_name": "AskALF",
          "author_login": "askalf",
          "committed_at": "2026-06-09T21:33:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 39,
      "commits_last_year": 170,
      "latest_release_at": "2026-07-20T14:48:57Z",
      "latest_release_tag": "v0.32.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 14,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 3.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 85,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@askalf/deepdive",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "research",
            "agent",
            "llm",
            "local",
            "cli",
            "anthropic",
            "openai",
            "claude",
            "search",
            "deep-research",
            "perplexity-alternative",
            "cite",
            "citations",
            "self-hosted"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@askalf/deepdive",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/askalf/deepdive",
          "versions_count": 39,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3313,
          "first_published_at": "2026-04-22T16:11:15.637000Z",
          "latest_published_at": "2026-07-20T14:49:47.192000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-04-26",
            "count": 1
          },
          {
            "date": "2026-05-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 75892,
      "source_files_sampled": 134,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 4940
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 5
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 111,
        "malicious_count": 0,
        "assessed_package": "npm:@askalf/deepdive@0.32.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "playwright",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.47.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "playwright",
            "direct": true,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/fs-minipass",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@jazzer.js/bug-detectors",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jazzer.js/core",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jazzer.js/fuzzer",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jazzer.js/hooking",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jazzer.js/instrumentor",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-android-arm64",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-darwin-arm64",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-darwin-x64",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-arm64-gnu",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-arm64-musl",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-riscv64-gnu",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-x64-gnu",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-x64-musl",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-win32-arm64-msvc",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-win32-x64-msvc",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv-formats",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "append-transform",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.10.43",
            "ecosystem": "npm"
          },
          {
            "name": "bindings",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-from",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001805",
            "ecosystem": "npm"
          },
          {
            "name": "chownr",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cmake-js",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "cors",
            "direct": false,
            "version": "2.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-extend",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "default-require-extensions",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.389",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": false,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "file-uri-to-path",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fs-extra",
            "direct": false,
            "version": "11.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.29",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ip-address",
            "direct": false,
            "version": "10.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-promise",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-hook",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-typed",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jsonfile",
            "direct": false,
            "version": "6.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.54.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "minizlib",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-addon-api",
            "direct": false,
            "version": "8.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-api-headers",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.51",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "pdfjs-dist",
            "direct": false,
            "version": "6.1.200",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "pkce-challenge",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "playwright-core",
            "direct": false,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "proper-lockfile",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.3",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rc",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "retry",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "router",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-support",
            "direct": false,
            "version": "0.5.21",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tar",
            "direct": false,
            "version": "7.5.22",
            "ecosystem": "npm"
          },
          {
            "name": "tmp",
            "direct": false,
            "version": "0.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "universalify",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "url-join",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": false,
            "version": "3.25.2",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 241,
        "direct_count": 3,
        "indirect_count": 238
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 163,
        "open_issues": 1,
        "closed_ratio": 0.95,
        "closed_issues": 19,
        "closed_unmerged_prs": 3
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "askalf",
          "commits": 139,
          "avatar_url": "https://avatars.githubusercontent.com/u/263217947?v=4"
        },
        {
          "type": "User",
          "login": "tgonzalezc5",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/102870299?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.993
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "actionlint.yml",
        "auto-release.yml",
        "cflite.yml",
        "ci.yml",
        "codeql.yml",
        "npm-drift-watch.yml",
        "publish.yml",
        "scorecard.yml",
        "stale.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 4/22 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "2 out of the last 2 releases have a total of 2 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4a13089fe289c7adf72ad79c0fe7aa744e1731da",
        "ran_at": "2026-07-27T00:59:18Z",
        "aggregate_score": 8.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T17:04:46Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T17:03:50Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": [
        {
          "number": 186,
          "created_at": "2026-07-26T18:08:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/askalf/deepdive",
    "host": "github.com",
    "name": "deepdive",
    "owner": "askalf"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 69,
      "inputs": {
        "security": 86,
        "vitality": 84,
        "community": 45,
        "governance": 55,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 170,
              "human_commit_share": 0.85,
              "days_since_last_push": 0,
              "active_weeks_last_year": 14
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "14/52 weeks with commits",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 14
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "170 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 170
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 39,
              "latest_release_tag": "v0.32.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 3.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "39 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 39
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 45,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 2,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "@askalf/deepdive"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3313
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,313 downloads/month across npm",
                "points": 46.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3313,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.993
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 163,
              "open_issues": 1,
              "closed_issues": 19,
              "issue_closed_ratio": 0.95,
              "closed_unmerged_prs": 3
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "95% of issues closed",
                "points": 44.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 95
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "163/166 decided PRs merged",
                "points": 37.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 163,
                      "decided": 166
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 4/22 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "followers": 21,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "askalf",
              "public_repos": 23,
              "account_age_days": 154
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "21 followers of askalf",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 21,
                      "login": "askalf"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "23 public repos, account ~0 yr old",
                "points": 10.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 23
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@askalf/deepdive"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "39 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 39
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai",
                "cli",
                "llm",
                "research-agent",
                "search",
                "anthropic",
                "citations",
                "claude",
                "deep-research",
                "perplexity-alternative",
                "self-hosted",
                "mcp",
                "model-context-protocol"
              ],
              "has_wiki": false,
              "homepage": "https://www.npmjs.com/package/@askalf/deepdive",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@askalf/deepdive",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "13 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "excellent",
        "name": "Security",
        "value": 86,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "excellent",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 8.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 4/22 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "2 out of the last 2 releases have a total of 2 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@askalf/deepdive@0.32.0 runtime dependency closure — what installing the published package pulls in — 111 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@askalf/deepdive@0.32.0",
                  "assessed": 111
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 111,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 111,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 66,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.965,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 4940
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "82 of 85 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 82,
                      "sampled": 85
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.15
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "15 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 15,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 75892,
              "source_files_sampled": 134,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/134 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 134,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T00:59:34.262877Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/askalf/deepdive.svg",
  "full_name": "askalf/deepdive",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.