matches BEFORE a trailing newline in Python, so a sha256 digest\n[…]\ned / 7 skipped, ruff clean. Not a signature forgery (the receipt\nmust be authentically signed); a strictness/canonicality gap, no One-Way-Door.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(canonicality): anchor every validator with \\A..\\Z, not ^..$ (6-le…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T14:48:06Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "f8e76cd5cee86f63d4945860953c829b46ae4141", "body": "…BDOS-01, int\u003c->str cap parity)\n\nThe 6-lens gate confirmed 1 remaining P2 (and re-confirmed RT-09/RT-10/crypto/relation/packaging and\nverify_evidence_pack/verify_sample_opening/recompute all hold): verify_bundle(dict) leaked a raw\nValueError on a huge merkle.tree_size / leaf_index (e.g. 10**5000). R\n[…]\n raw ValueError; a legit small tree_size is\nunaffected.\n\nRegression test added (bidirectional). Full suite 1952 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise): bound integer magnitude in _require_int (6-lens L2-…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T14:23:18Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "74c882aaad67673fae6d1a3b16bd39d486f38f1c", "body": "…ree (release-vorlauf)\n\nAdded \"Addendum 2 — reconciled to the shipped v3.6.1 release tree\" to the pre-tag adversarial audit\nrecord. Every number carries its command source (No-Fake, vorlauf P5), and figures that changed vs the\nv3.6.0 addendum are called out so nothing contradicts the shipped state:\n\n[…]\nl branch-base snapshot, not the shipped count.\n- 0 open P0/P1 holds (signed register). Status boundary unchanged (BETA, EXPERIMENTAL relation).\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "docs(pre-tag): P5 reconcile the audit addendum to the shipped 3.6.1 t…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:49:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "8fe8b629d40c2fd1bf8dd68731156cef739e4fda", "body": "…attest-dryrun startup failure\n\nThe published-artifact-gate's reusable-attest-dryrun job called reusable-build-attest.yml whose\nbuild-attest job declares id-token:write + attestations:write, but the workflow-wide contents:read\ncannot be exceeded by a called workflow -> the run was refused at startup\n[…]\n from PR #102 per Owner-GO, so 3.6.1 carries the fix without a separate merge). The\nreusable workflow is unchanged; CI-only, no package change.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "ci(pag): integrate PR #102 permission fix into 3.6.1 (P3) — reusable-…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:46:30Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "710357a8ad9ca36a554385422f49cf51f98a3f0f", "body": "…typed errors (6-lens L2/L3)\n\nThe 6-lens gate confirmed 2 P2 fail-closed defects on SECONDARY exported surfaces (it also\nre-confirmed RT-09/RT-10/crypto/relation and every primary verify_* surface hold):\n\n- L2-BDOS-01: recompute_merkle_root_b64(dict) walked merkle.inclusion_proof_b64 with an INERT\n \n[…]\n\n\nRegression tests added (load_bundle malformed matrix; recompute 100k-proof fast fail-closed).\nFull suite 1951 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise+dos): recompute_merkle_root_b64 budget + load_bundle …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:37:57Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "5d35b6a371ef1c63561ba8c6304a3a4b270143d7", "body": "…enewal_policy (6-lens L2-01/L3-02)\n\nThe 6-lens gate confirmed 2 P2 never-raise leaks, both the recurring class \"an exported\nverify_*/evaluate_* surface missing a guard its sibling already has\". (My earlier claim that\nverify_prereg was clean was wrong — I tested with an empty claim, which short-circ\n[…]\nnd shape\nsurfaces are the three now-guarded ones plus verify_sequence.\n\nRegression tests added. Full suite 1949 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise): sibling-guard parity for verify_prereg + evaluate_r…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:04:17Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "4737356ee318af768a60b7c2b236871ef250f219", "body": "…e never-raise + bare-eval clean-skips)\n\nThe 6-lens gate confirmed 4 findings; after per-finding live re-verification against the\neditable HEAD (No-Fake), 3 were real and 1 (L2-01 verify_prereg) was a FALSE finding — the\ngate's own probe env had a stale build; verify_prereg already returns a fail-cl\n[…]\nession tests added (verify_evaluation_card bad paths; verify_sample_opening non-ASCII).\nFull in-repo suite 1947 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise+packaging): 3 real 6-lens findings (evalcard/persampl…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T12:35:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "a1d1d71d80e747ebeca6112d17b99c090c53ebf2", "body": "…widen pre_tag negation\n\nThe single-round 6-lens Berkeley gate confirmed 1 P0 (and confirmed every other RT-10\nguard HELD live: absent/empty/foreign-key/tamper/dangling/self-supersede/non-string-id/\nlist-typed severity-status/dup-id downgrade/lowercase p0/status!='closed').\n\n- L5-01 (P0, fail-open):\n[…]\nion tests added (rings -> anomaly, linear chain -> legit; the concession\nwords -> not counted). Full suite 1945 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(register): P0 supersession-cycle fail-open (6-lens gate L5-01) + …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T11:52:20Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "5bf162451046cc4dc6e5196690dfc5c70e43b357", "body": "…rify_dual_hash guard (P2 L3-02)\n\nThe single-round 6-lens Berkeley gate confirmed 2 findings (and confirmed the crypto/\ncanonicality, RT-09 direct-dict budgets incl. string_len, relation subject-pin, and RT-10\nregister/pre_tag surfaces all WITHSTOOD). Both fixed:\n\n- L6-01 (P1) from-sdist \"pip instal\n[…]\ndded (verify_dual_hash non-bytes; the 5 module-skip guards exercised by the\ncleanroom). Full in-repo suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(packaging+never-raise): from-sdist test invariant (P1 L6-01) + ve…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T11:19:34Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "bfae68b63bb4cb1ac21b2babc4990cec03fc2281", "body": "…ound gate L3-01/L3-02)\n\nThe corrected single-round 6-lens Berkeley gate (PUBLIC-contract scoped, no more\ninternal-helper over-confirmation) confirmed 2 P2 never-raise leaks on exported\nrelying-party surfaces; both fixed with zero behavioural change on valid input:\n\n- L3-01 verify_bundle(str) / reco\n[…]\nf-element; first==second None-roots) is now typed-error\nor fail-closed False, 0 raw exceptions. Full suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise): close 2 public raw-exception leaks (6-lens single-r…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T10:39:37Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "aa502badaaccd1a5cc0b8e563bcdc063f6afe7a8", "body": "…ster severity type-confusion P1)\n\nA 6-lens Berkeley re-gate (Owner-tuned agent budget) surfaced further findings; after\nrigorous per-finding verification (PUBLIC never-raise contract applies to exported\nverify_*/evaluate_* only — internal helpers may raise, their public callers wrap them) 3\nwere re\n[…]\n, and\nthe strict public sweep confirms no public caller leaks their TypeError. Not over-fixed.\n\nFull suite 1941 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(teil5): remediate 6-lens Berkeley re-gate — 3 real findings (regi…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T10:07:17Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "297a9a61818563065a4dfff9c483ba725fb6527a", "body": "…5 fixes\n\nA faithful Berkeley re-gate (10 attack classes incl. RT-09 direct-dict + RT-10\nassertion-by-absence, 3-juror refute-to-kill) found 6 real defects in this session's\nown Teil-5 work. All fixed with bidirectional regression tests:\n\n- RT10-REG-01 (P1, fail-open): findings_register.verify_and_c\n[…]\nsstehend/... The genuine 3.6.0 record\n still passes.\n\nFull suite 1938 passed / 7 skipped. ruff clean. CHANGELOG updated to the hardened state.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(teil5): remediate 6 Berkeley-gate FIX_FIRST findings on the Teil-…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T09:15:18Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "93c1dbbc2267c8e2d329f776a76aecba6dac0dcc", "body": "…toolchain\n\ncargo fmt --check disagreed with the runner's rustfmt on line breaks at\nmain.rs:1132/1496 because the toolchain was unpinned (rustfmt/clippy output is\nversion-dependent). Pin the exact toolchain in tools/pb_verify_rs/rust-toolchain.toml\n(1.95.0 + rustfmt + clippy), reformat main.rs with \n[…]\ne pinned toolchain.\n\nFindings register: PB-2026-0718-15 open -> closed (regenerated + re-signed, pinned\npubkey stable). 0 open P0/P1 unchanged.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(rust): PB-2026-0718-15 deterministic cargo fmt/clippy via pinned …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T08:22:14Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "e1bb2f37a41738b36b62f1bbdd4d4d0999801e9a", "body": "…ces stale-substring C12.2 (PB-2026-0718-14)\n\nThe audit_candidate_matrix C12.2 \"0 open P0/P1\" check derived PASS from a lexical\n\"0 open P0/P1\" substring in a version-scoped .md, with NO freshness / supersession /\nsignature / contradiction check. A STALE record that still said \"0 open\" granted PASS\nw\n[…]\n\nsubstring semantics to the register (absent -> FAIL, not PENDING; a fake .md grants nothing).\n\nFull suite 1932 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(audit-candidate): RT-10 signed structured findings register repla…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T08:17:01Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "01ab3805c0907d8ffef0e3fa27f2cb557ad766ac", "body": "…y path (PB-2026-0718-16)\n\nThe input_bytes + json_nodes + json_depth budget lives in loads_strict, which a STR\nbundle path funnels through (load_bundle -> loads_strict). A caller that hands an\nALREADY-PARSED dict to verify_bundle(dict) bypassed that chokepoint, so the structural\nbudget was INERT on \n[…]\n Shallow bundles unaffected.\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors::test_rt09_direct_dict_structural_budget\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(budget): RT-09 enforce structural budget on the direct-dict verif…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:45:41Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "805d68e1e861cc0b85d87ac08cc7411f82e6df87", "body": "…-0718 thorough-sweep closure)\n\nevaluate_public_transparency built a named-status dict verdict but a non-str\nsigned_note (123/None/list) hit an early string op → raw AttributeError before\nthe fail-closed path. Coerce a non-str note to \"\" so every checkpoint parse\nfails gracefully (all statuses FAIL)\n[…]\nrdict).\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors\n ::test_evaluate_public_transparency_non_str_note_is_verdict\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(public_transparency): never-raise on non-str signed_note (PB-2026…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:33:08Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "1f939d5d2783aa5ec0fca6841d11def185cc8a35", "body": "…athTypedErrors regression\n\nThe new CallerPathTypedErrors regression test (pinning the bc0028a caller-path fixes) exposed a second\nvkey parser: verify_cosignature routes through _parse_witness_vkey (NOT _parse_vkey), which still raised a\nraw AttributeError on a non-str vkey. Added the same isinstanc\n[…]\ney was a valid str, not None/int.)\n\nFull suite 1924 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): _parse_witness_vkey typed on non-str vkey + CallerP…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:27:14Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "bc0028a98f7d6d78a0bffb166feefc60140c9a67", "body": "… checkpoint non-str vkey (final sweep)\n\nA comprehensive gate-substitute sweep (every public verify surface x budget/malformed-JSON/type-confusion,\n74 surface-attack combinations across 50 functions) confirmed the whole surface is never-raise for untrusted\nWIRE input, and closed the last two raw-exc\n[…]\nff clean; sweep CLEAN (no raw non-typed exception on any probed input).\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): typed caller-path errors — verify_bundle bad-path +…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:23:20Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "b9b8aeb5b5e1de481b6a979f5adf37292fec07c3", "body": "…al sweep)\n\nThe comprehensive verify_* sweep found verify_sdjwt_vc raised a raw AttributeError on a non-dict policy\n(policy.get(...)) — the same type-confusion class as decision/outcome/relation_statement. Now a fail-closed\nverdict (ok=False). (bundle.verify_bundle(\u003chuge str>) -> OSError is the docu\n[…]\n wire input; left for the gate to adjudicate.) Suite green; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): verify_sdjwt_vc fail-closed on non-dict policy (fin…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T06:25:53Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "d191e844a15142e2ff63525de4c5b8f98dae2994", "body": "…rs never-raise, HF token budget-consistent\n\nTo break the round-by-round pattern (each Berkeley RE-GATE found the budget-leak class on one more verify\nsurface), a full sweep of every loads_strict call site closed the remaining ones in one batch:\n\n- intoto verify_intoto_dsse / verify_eval_result_dsse\n[…]\nFalse + duplicate named in detail). Full suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): proactive loads_strict-sweep — in-toto DSSE verifie…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T06:23:04Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "6a3dec77bfb2daa7540c09fc9ef8dcbeb1c33a0e", "body": "…get family + relstmt policy + CLI inspect)\n\nThe Berkeley gate on ee923a4 found the never-raise budget class STILL LIVE on the SD-JWT family (which I had\nonly fixed for TYPE-confusion, not budget) plus two more:\n\nBUDGET (P1 x5) verify_status_snapshot / verify_key_binding / verify_sd_jwt (header+payl\n[…]\nicyGuard, CliInspectLoneSurrogate).\nFull suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): close 9 final Berkeley RE-GATE findings (SD-JWT bud…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T06:10:35Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "ee923a48923806c0a233d90a6daa2bd83f6818ce", "body": "…part deferred to 3.6.2)\n\nThe CI fmt/clippy gate I added turned the previously-green advisory rust-parity check RED: the runner's\nrustfmt formats differently than the local toolchain (rust 1.95.0) — Diff at main.rs:1132/1496 — a classic\nrustfmt version drift. The code stays cargo-fmt + clippy-clean \n[…]\n a red advisory check (No-Fake: a red check must be a real regression).\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "ci(rust): revert version-fragile fmt/clippy gate (PB-2026-0718-15 CI …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:33:32Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "29bbbbc38db87e41caa205376fb54992609c6fd0", "body": "…gate to the rust job\n\nCatches a fmt/clippy regression in the Rust second-verifier going forward (advisory rust job, annotates).\nPlus the CHANGELOG entry for the fmt/clippy code fix.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "ci(rust): PB-2026-0718-15 add cargo fmt --check + clippy -D warnings …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:29:22Z", "body_truncated": false, "is_coding_agent": true }, { "oid": "4e9dbc7f4c20f77bbabf849811de2a1d0224dae3", "body": "…rity preserved)\n\nTeil-5 finding: the Rust second-verifier tree was not fmt-clean and clippy -D warnings failed\n(collapsible-match in the same-key fail-closed branch, a redundant closure). Applied `cargo fmt` and the\ntwo machine-applicable clippy fixes.\n\nNo behavior change: the fixes are cosmetic (f\n[…]\nn vectors and the same-key branch clippy touched). Release build\nclean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "style(rust): PB-2026-0718-15 cargo fmt + clippy -D warnings green (pa…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:28:03Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "7f6a6dc323225f329ab306c18d27bbbe3f2d09c3", "body": "…erification core (direct dict path)\n\nTeil-5 finding (Berkeley GATE-T5-02): the merkle_path budget (256) was defined but enforced NOWHERE.\nverify_inclusion / verify_consistency ran a per-step hash loop over an unbounded proof list, and the 8 MiB\ninput_bytes byte-proxy never applies when a bundle is \n[…]\nfails, legit small proof verifies).\nFull suite 1919 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(budget): PB-2026-0718-16 enforce merkle-path step budget in the v…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:25:06Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "c13159130dc6e13cd2ac1064a25b9cb4c93eb5c8", "body": "…asses vacuously on singletons\n\nTeil-4 finding: the corpus-integrity comparator grouped cases by crossFormatId and SKIPPED any group with\n\u003c 2 members. All six xfmt-* groups had exactly one member, so the \"same scenario agrees across formats\"\ncheck was vacuously true and reported ok=true while verify\n[…]\ntic contradictory pair fails; an agreeing pair passes. Full suite 1916.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(conformance): PB-2026-0718-11 cross-format comparator no longer p…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:14:45Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "cb52ca062489eb0ec158092da483b2cbcbaa3c87", "body": "…pe-confused input\n\nExtends the breadth sweep: verify_sd_jwt (dict-returning, untrusted SD-JWT compact from a holder) raised a\nraw AttributeError on a non-str compact (.split(\"~\")); verify_commitment raised a raw AttributeError on a\nnon-str PRESENTED identifier (identifier.encode() inside salted_com\n[…]\nff clean. Regression cases added to tests/test_sibling_never_raise_361.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): verify_sd_jwt + verify_commitment fail-closed on ty…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:04:43Z", "body_truncated": true, "is_coding_agent": true } ], "releases_count": 47, "commits_last_year": 560, "latest_release_at": "2026-07-23T11:34:27Z", "latest_release_tag": "v3.7.0", "releases_from_tags": false, "days_since_last_push": 0, "active_weeks_last_year": 4, "days_since_latest_release": 0, "mean_days_between_releases": 0.8 }, "community": { "has_readme": true, "has_license": true, "has_description": true, "has_contributing": true, "health_percentage": 100, "has_issue_template": false, "has_code_of_conduct": true, "has_pull_request_template": true }, "ecosystem": { "packages": [ { "name": "proofbundle", "exists": true, "license": "MIT", "keywords": [ "cryptography", "merkle", "transparency-log", "ed25519", "sd-jwt", "verifiable-credentials", "attestation", "provenance", "rfc6962", "Development Status :: 4 - Beta", "Intended Audience :: Developers", "License :: OSI Approved :: MIT License", "Programming Language :: Python :: 3", "Programming Language :: Python :: 3.10", "Programming Language :: Python :: 3.11", "Programming Language :: Python :: 3.12", "Programming Language :: Python :: 3.13", "Programming Language :: Python :: 3.14", "Topic :: Security :: Cryptography" ], "ecosystem": "pypi", "matches_repo": true, "registry_url": "https://pypi.org/project/proofbundle/", "is_deprecated": false, "latest_version": "3.7.0", "repository_url": "https://github.com/b7n0de/proofbundle", "versions_count": 41, "total_downloads": null, "dependents_count": null, "deprecation_note": null, "maintainers_count": null, "monthly_downloads": 6574, "first_published_at": "2026-07-01T15:10:44.562607Z", "latest_published_at": "2026-07-23T11:48:28.208813Z", "latest_version_yanked": null, "days_since_latest_publish": 0 } ] }, "popularity": { "forks": 2, "stars": 2, "watchers": 0, "fork_history": { "days": [ { "date": "2026-07-06", "count": 1 }, { "date": "2026-07-20", "count": 1 } ], "complete": true, "collected": 2, "total_forks": 2 }, "star_history": null, "open_issues_and_prs": 5 }, "ai_readiness": { "has_nix": false, "example_dirs": [ "examples" ], "has_llms_txt": false, "has_dockerfile": true, "has_mcp_signal": false, "bootstrap_files": [ "Makefile" ], "api_schema_files": [], "has_devcontainer": false, "typecheck_configs": [ "src/proofbundle/py.typed" ], "toolchain_manifests": [ "tools/pb_verify_rs/Cargo.toml" ], "largest_source_bytes": 171563, "source_files_sampled": 257, "oversized_source_files": 3, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "dependencies": { "manifests": [ "pyproject.toml" ], "advisories": { "error": null, "scope": "repository_graph", "source": "osv", "findings": [], "collected": true, "malicious": [], "truncated": false, "by_severity": {}, "advisory_count": 0, "affected_count": 0, "assessed_count": 46, "malicious_count": 0, "assessed_package": null, "unassessed_count": 16, "direct_affected_count": 0 }, "ecosystems": [ "pypi" ], "dependencies": [ { "name": "cryptography", "manifest": "pyproject.toml", "ecosystem": "pypi", "version_constraint": ">=42" }, { "name": "rfc8785", "manifest": "pyproject.toml", "ecosystem": "pypi", "version_constraint": ">=0.1.4" } ], "all_dependencies": { "error": null, "source": "github-sbom", "packages": [ { "name": "cryptography", "direct": true, "version": null, "ecosystem": "pypi" }, { "name": "rfc8785", "direct": true, "version": null, "ecosystem": "pypi" }, { "name": "base64", "direct": false, "version": "0.22.1", "ecosystem": "crates" }, { "name": "base64ct", "direct": false, "version": "1.8.3", "ecosystem": "crates" }, { "name": "block-buffer", "direct": false, "version": "0.10.4", "ecosystem": "crates" }, { "name": "cfg-if", "direct": false, "version": "1.0.4", "ecosystem": "crates" }, { "name": "const-oid", "direct": false, "version": "0.9.6", "ecosystem": "crates" }, { "name": "cpufeatures", "direct": false, "version": "0.2.17", "ecosystem": "crates" }, { "name": "crypto-common", "direct": false, "version": "0.1.7", "ecosystem": "crates" }, { "name": "curve25519-dalek", "direct": false, "version": "4.1.3", "ecosystem": "crates" }, { "name": "curve25519-dalek-derive", "direct": false, "version": "0.1.1", "ecosystem": "crates" }, { "name": "der", "direct": false, "version": "0.7.10", "ecosystem": "crates" }, { "name": "digest", "direct": false, "version": "0.10.7", "ecosystem": "crates" }, { "name": "ed25519", "direct": false, "version": "2.2.3", "ecosystem": "crates" }, { "name": "ed25519-dalek", "direct": false, "version": "2.2.0", "ecosystem": "crates" }, { "name": "equivalent", "direct": false, "version": "1.0.2", "ecosystem": "crates" }, { "name": "fiat-crypto", "direct": false, "version": "0.2.9", "ecosystem": "crates" }, { "name": "generic-array", "direct": false, "version": "0.14.7", "ecosystem": "crates" }, { "name": "getrandom", "direct": false, "version": "0.2.17", "ecosystem": "crates" }, { "name": "hashbrown", "direct": false, "version": "0.17.1", "ecosystem": "crates" }, { "name": "hex", "direct": false, "version": "0.4.3", "ecosystem": "crates" }, { "name": "indexmap", "direct": false, "version": "2.14.0", "ecosystem": "crates" }, { "name": "itoa", "direct": false, "version": "1.0.18", "ecosystem": "crates" }, { "name": "libc", "direct": false, "version": "0.2.186", "ecosystem": "crates" }, { "name": "memchr", "direct": false, "version": "2.8.3", "ecosystem": "crates" }, { "name": "pkcs8", "direct": false, "version": "0.10.2", "ecosystem": "crates" }, { "name": "proc-macro2", "direct": false, "version": "1.0.106", "ecosystem": "crates" }, { "name": "quote", "direct": false, "version": "1.0.46", "ecosystem": "crates" }, { "name": "rand_core", "direct": false, "version": "0.6.4", "ecosystem": "crates" }, { "name": "rustc_version", "direct": false, "version": "0.4.1", "ecosystem": "crates" }, { "name": "ryu-js", "direct": false, "version": "0.2.2", "ecosystem": "crates" }, { "name": "semver", "direct": false, "version": "1.0.28", "ecosystem": "crates" }, { "name": "serde", "direct": false, "version": "1.0.228", "ecosystem": "crates" }, { "name": "serde_core", "direct": false, "version": "1.0.228", "ecosystem": "crates" }, { "name": "serde_derive", "direct": false, "version": "1.0.228", "ecosystem": "crates" }, { "name": "serde_jcs", "direct": false, "version": "0.1.0", "ecosystem": "crates" }, { "name": "serde_json", "direct": false, "version": "1.0.150", "ecosystem": "crates" }, { "name": "sha2", "direct": false, "version": "0.10.9", "ecosystem": "crates" }, { "name": "signature", "direct": false, "version": "2.2.0", "ecosystem": "crates" }, { "name": "spki", "direct": false, "version": "0.7.3", "ecosystem": "crates" }, { "name": "subtle", "direct": false, "version": "2.6.1", "ecosystem": "crates" }, { "name": "syn", "direct": false, "version": "2.0.118", "ecosystem": "crates" }, { "name": "typenum", "direct": false, "version": "1.20.1", "ecosystem": "crates" }, { "name": "unicode-ident", "direct": false, "version": "1.0.24", "ecosystem": "crates" }, { "name": "version_check", "direct": false, "version": "0.9.5", "ecosystem": "crates" }, { "name": "wasi", "direct": false, "version": "0.11.1+wasi-snapshot-preview1", "ecosystem": "crates" }, { "name": "zeroize", "direct": false, "version": "1.9.0", "ecosystem": "crates" }, { "name": "zmij", "direct": false, "version": "1.0.23", "ecosystem": "crates" }, { "name": "build", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "ecdsa", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "hypothesis", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "inspect-ai", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "jsonschema", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "mypy", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "opentimestamps", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "pytest", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "pyyaml", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "rfc3161-client", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "ruff", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "sd-jwt", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "setuptools", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "z3-solver", "direct": false, "version": null, "ecosystem": "pypi" } ], "collected": true, "truncated": false, "total_count": 62, "direct_count": 2, "indirect_count": 60 } }, "maintainership": { "issues": { "open_prs": 0, "merged_prs": 109, "open_issues": 5, "closed_ratio": 0.444, "closed_issues": 4, "closed_unmerged_prs": 9 }, "bus_factor": 1, "bot_contributors": 1, "top_contributors": [ { "type": "User", "login": "b7n0de", "commits": 130, "avatar_url": "https://avatars.githubusercontent.com/u/45888075?v=4" }, { "type": "User", "login": "tuodijihua", "commits": 3, "avatar_url": "https://avatars.githubusercontent.com/u/158809980?v=4" }, { "type": "User", "login": "MarkovianProtocol", "commits": 1, "avatar_url": "https://avatars.githubusercontent.com/u/292588966?v=4" } ], "contributors_sampled": 3, "top_contributor_share": 0.97 }, "quality_signals": { "has_ci": true, "has_tests": true, "ci_workflows": [ "ci.yml", "codeql.yml", "demo-reproducible.yml", "fork-pr-isolation.yml", "published-artifact-gate.yml", "release-integrity.yml", "release.yml", "reusable-build-attest.yml", "scorecard.yml" ], "has_docs_dir": true, "linter_configs": [], "has_editorconfig": false, "has_linter_config": false, "has_precommit_config": false }, "security_signals": { "lockfiles": [ "Cargo.lock" ], "scorecard": { "checks": [ { "name": "Binary-Artifacts", "score": 9, "reason": "binaries present in source code", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts" }, { "name": "Branch-Protection", "score": 3, "reason": "branch protection is not maximal on development and all release branches", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection" }, { "name": "CI-Tests", "score": 10, "reason": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests" }, { "name": "CII-Best-Practices", "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices" }, { "name": "Code-Review", "score": 2, "reason": "Found 2/10 approved changesets -- score normalized to 2", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review" }, { "name": "Contributors", "score": 0, "reason": "project has 0 contributing companies or organizations -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors" }, { "name": "Dangerous-Workflow", "score": 10, "reason": "no dangerous workflow patterns detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow" }, { "name": "Dependency-Update-Tool", "score": 10, "reason": "update tool detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool" }, { "name": "Fuzzing", "score": 10, "reason": "project is fuzzed", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing" }, { "name": "License", "score": 10, "reason": "license file detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license" }, { "name": "Maintained", "score": 0, "reason": "project was created within the last 90 days. Please review its contents carefully", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained" }, { "name": "Packaging", "score": 10, "reason": "packaging workflow detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging" }, { "name": "Pinned-Dependencies", "score": 3, "reason": "dependency not pinned by hash detected -- score normalized to 3", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies" }, { "name": "SAST", "score": 10, "reason": "SAST tool is run on all commits", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast" }, { "name": "Security-Policy", "score": 10, "reason": "security policy file detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy" }, { "name": "Signed-Releases", "score": 0, "reason": "Project has not signed or included provenance with any releases.", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases" }, { "name": "Token-Permissions", "score": 10, "reason": "GitHub workflow tokens follow principle of least privilege", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions" }, { "name": "Vulnerabilities", "score": 10, "reason": "0 existing vulnerabilities detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities" } ], "commit": "defc3ee24cc2ef5e07d41b29bf271890d447846e", "ran_at": "2026-07-23T12:24:22Z", "aggregate_score": 6.6, "scorecard_version": "v5.5.0" }, "has_codeql_workflow": true, "has_security_policy": true, "has_dependabot_config": true }, "contribution_flow": { "collected": true, "ci_last_run_at": "2026-07-23T11:48:31Z", "oldest_open_prs": [], "last_merged_pr_at": "2026-07-23T11:08:29Z", "ci_last_conclusion": "SUCCESS", "oldest_open_issues": [ { "number": 7, "created_at": "2026-07-05T00:44:01Z", "last_comment_at": "2026-07-21T14:26:40Z", "last_comment_author": "b7n0de" }, { "number": 24, "created_at": "2026-07-07T18:00:37Z", "last_comment_at": "2026-07-07T18:16:38Z", "last_comment_author": "b7n0de" }, { "number": 26, "created_at": "2026-07-07T19:31:43Z", "last_comment_at": "2026-07-09T23:34:54Z", "last_comment_author": "b7n0de" }, { "number": 27, "created_at": "2026-07-07T19:31:45Z", "last_comment_at": null, "last_comment_author": null }, { "number": 55, "created_at": "2026-07-11T08:01:46Z", "last_comment_at": null, "last_comment_author": null } ] } }, "config": { "disabled_metrics": [], "disabled_categories": [], "disabled_components": {} }, "source": { "url": "https://github.com/b7n0de/proofbundle", "host": "github.com", "name": "proofbundle", "owner": "b7n0de" }, "metrics": { "overall": { "key": "overall", "band": "moderate", "name": "Overall health", "note": null, "notes": [], "value": 64, "inputs": { "security": 73, "vitality": 70, "community": 49, "governance": 48, "engineering": 81 }, "components": [] }, "categories": [ { "key": "vitality", "band": "good", "name": "Vitality", "value": 70, "weight": 0.22, "metrics": [ { "key": "development_activity", "band": "moderate", "name": "Development activity", "note": null, "notes": [], "value": 57, "inputs": { "commits_last_year": 560, "human_commit_share": 0.95, "days_since_last_push": 0, "active_weeks_last_year": 4 }, "components": [ { "key": "push_recency", "name": "Push recency", "detail": "last push 0 days ago", "points": 36, "status": "met", "details": [ { "code": "push_recency", "params": { "days": 0 } } ], "max_points": 36 }, { "key": "commit_cadence", "name": "Commit cadence", "detail": "4/52 weeks with commits", "points": 2.8, "status": "partial", "details": [ { "code": "commit_cadence_weeks", "params": { "weeks": 4 } } ], "max_points": 36 }, { "key": "commit_volume", "name": "Commit volume", "detail": "560 commits in the last year", "points": 18, "status": "met", "details": [ { "code": "commits_last_year", "params": { "count": 560 } } ], "max_points": 18 }, { "key": "openssf_scorecard_maintained", "name": "OpenSSF Scorecard: Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "release_discipline", "band": "excellent", "name": "Release discipline", "note": null, "notes": [], "value": 90, "inputs": { "releases_count": 47, "latest_release_tag": "v3.7.0", "releases_from_tags": false, "days_since_latest_release": 0, "mean_days_between_releases": 0.8 }, "components": [ { "key": "ships_releases", "name": "Ships releases", "detail": "47 releases published", "points": 27, "status": "met", "details": [ { "code": "releases_published", "params": { "count": 47 } } ], "max_points": 27 }, { "key": "release_recency", "name": "Release recency", "detail": "latest release 0 days ago", "points": 36, "status": "met", "details": [ { "code": "release_recency", "params": { "days": 0 } } ], "max_points": 36 }, { "key": "release_cadence", "name": "Release cadence", "detail": "a release every ~0.8 days", "points": 27, "status": "met", "details": [ { "code": "release_cadence", "params": { "gap": 0.8 } } ], "max_points": 27 }, { "key": "openssf_scorecard_signed_releases", "name": "OpenSSF Scorecard: Signed-Releases", "detail": "Project has not signed or included provenance with any releases.", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "abandonment", "band": "excellent", "name": "Abandonment", "note": null, "notes": [], "value": 100, "inputs": { "cap": null, "state": "unverified", "guards": [], "signals": [], "red_flag": false, "multiplier_pct": 100, "declared_reason": null, "unverified_reason": "repository_too_young", "unanswered_open_prs": null, "unanswered_open_issues": null, "days_since_last_merged_pr": null, "days_since_last_human_commit": null, "days_since_last_human_commit_is_floor": false }, "components": [ { "key": "project_is_still_maintained", "name": "Project is still maintained", "detail": "maintenance record not established from the collected data", "points": 100, "status": "met", "details": [ { "code": "abandonment_unverified", "params": {} } ], "max_points": 100 } ] } ], "description": "Is the project alive — is code being written and are releases shipping?" }, { "key": "community", "band": "at_risk", "name": "Community & Adoption", "value": 49, "weight": 0.18, "metrics": [ { "key": "popularity", "band": "critical", "name": "Popularity & adoption", "note": null, "notes": [], "value": 1, "inputs": { "forks": 2, "stars": 2, "watchers": 0, "growth_state": "unverified", "growth_factor_pct": 100, "growth_unverified_reason": "no_history" }, "components": [ { "key": "stars", "name": "Stars", "detail": "2 stars", "points": 0, "status": "missed", "details": [ { "code": "stars", "params": { "count": 2 } } ], "max_points": 60 }, { "key": "forks", "name": "Forks", "detail": "2 forks", "points": 0, "status": "missed", "details": [ { "code": "forks", "params": { "count": 2 } } ], "max_points": 25 }, { "key": "watchers", "name": "Watchers", "detail": "0 watchers", "points": 0, "status": "missed", "details": [ { "code": "watchers", "params": { "count": 0 } } ], "max_points": 15 } ] }, { "key": "community_health", "band": "excellent", "name": "Community health", "note": null, "notes": [], "value": 92, "inputs": { "has_readme": true, "has_license": true, "has_contributing": true, "has_issue_template": false, "has_code_of_conduct": true, "has_pull_request_template": true }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 22.5, "status": "met", "details": [], "max_points": 22.5 }, { "key": "license", "name": "License", "detail": "recognized license (MIT)", "points": 22.5, "status": "met", "details": [ { "code": "license_standard", "params": {} }, { "code": "license_spdx", "params": { "spdx": "MIT" } } ], "max_points": 22.5 }, { "key": "contributing_guide", "name": "CONTRIBUTING guide", "detail": null, "points": 18, "status": "met", "details": [], "max_points": 18 }, { "key": "code_of_conduct", "name": "Code of conduct", "detail": null, "points": 13.5, "status": "met", "details": [], "max_points": 13.5 }, { "key": "issue_template", "name": "Issue template", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 7.2 }, { "key": "pr_template", "name": "PR template", "detail": null, "points": 6.3, "status": "met", "details": [], "max_points": 6.3 } ] }, { "key": "ecosystem_adoption", "band": "moderate", "name": "Ecosystem adoption (downloads)", "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "registry_dependents" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 64, "inputs": { "packages": [ "proofbundle" ], "dependents": null, "ecosystems": "pypi", "total_downloads": null, "monthly_downloads": 6574 }, "components": [ { "key": "monthly_downloads", "name": "Monthly downloads", "detail": "6,574 downloads/month across pypi", "points": 50.9, "status": "partial", "details": [ { "code": "downloads_monthly", "params": { "count": 6574, "ecosystems": "pypi" } } ], "max_points": 80 }, { "key": "registry_dependents", "name": "Registry dependents", "detail": "not reported by this ecosystem", "points": 0, "status": "excluded", "details": [ { "code": "not_reported_by_this_ecosystem", "params": {} } ], "max_points": 20 } ] } ], "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?" }, { "key": "governance", "band": "at_risk", "name": "Sustainability & Governance", "value": 48, "weight": 0.24, "metrics": [ { "key": "maintainer_resilience", "band": "critical", "name": "Maintainer resilience (bus factor)", "note": null, "notes": [], "value": 14, "inputs": { "bus_factor": 1, "contributors_sampled": 3, "top_contributor_share": 0.97 }, "components": [ { "key": "bus_factor", "name": "Bus factor", "detail": "1 contributor(s) cover half of all commits", "points": 9, "status": "partial", "details": [ { "code": "bus_factor", "params": { "count": 1 } } ], "max_points": 54 }, { "key": "commit_distribution", "name": "Commit distribution", "detail": "top contributor authored 97% of commits", "points": 0.7, "status": "partial", "details": [ { "code": "top_contributor_share", "params": { "share": 97 } } ], "max_points": 22.5 }, { "key": "contributor_breadth", "name": "Contributor breadth", "detail": "3 contributors", "points": 4.1, "status": "partial", "details": [ { "code": "contributors_sampled", "params": { "count": 3 } } ], "max_points": 13.5 }, { "key": "openssf_scorecard_contributors", "name": "OpenSSF Scorecard: Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "responsiveness", "band": "moderate", "name": "Issue & PR responsiveness", "note": null, "notes": [], "value": 59, "inputs": { "merged_prs": 109, "open_issues": 5, "closed_issues": 4, "issue_closed_ratio": 0.444, "closed_unmerged_prs": 9 }, "components": [ { "key": "issue_resolution", "name": "Issue resolution", "detail": "44% of issues closed", "points": 20.8, "status": "partial", "details": [ { "code": "issues_closed_share", "params": { "share": 44 } } ], "max_points": 46.75 }, { "key": "pr_acceptance", "name": "PR acceptance", "detail": "109/118 decided PRs merged", "points": 35.3, "status": "partial", "details": [ { "code": "decided_prs_merged", "params": { "merged": 109, "decided": 118 } } ], "max_points": 38.25 }, { "key": "openssf_scorecard_code_review", "name": "OpenSSF Scorecard: Code-Review", "detail": "Found 2/10 approved changesets -- score normalized to 2", "points": 3, "status": "partial", "details": [], "max_points": 15 } ] }, { "key": "stewardship", "band": "at_risk", "name": "Ownership & stewardship", "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "verified_domain" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 37, "inputs": { "followers": 2, "owner_type": "User", "is_verified": null, "owner_login": "b7n0de", "public_repos": 3, "account_age_days": 2777 }, "components": [ { "key": "ownership_backing", "name": "Ownership backing", "detail": "personal (user) account", "points": 10, "status": "partial", "details": [ { "code": "owner_personal", "params": {} } ], "max_points": 30 }, { "key": "verified_domain", "name": "Verified domain", "detail": "not applicable to user accounts", "points": 0, "status": "excluded", "details": [ { "code": "not_applicable_to_user_accounts", "params": {} } ], "max_points": 20 }, { "key": "owner_reach", "name": "Owner reach", "detail": "2 followers of b7n0de", "points": 3.4, "status": "partial", "details": [ { "code": "owner_followers", "params": { "count": 2, "login": "b7n0de" } } ], "max_points": 25 }, { "key": "track_record", "name": "Track record", "detail": "3 public repos, account ~7 yr old", "points": 16.4, "status": "partial", "details": [ { "code": "public_repos", "params": { "count": 3 } }, { "code": "account_age_years", "params": { "years": 7 } } ], "max_points": 25 } ] }, { "key": "package_maintenance", "band": "excellent", "name": "Package maintenance", "note": null, "notes": [], "value": 100, "inputs": { "packages": [ "proofbundle" ], "ecosystems": "pypi", "any_deprecated": false, "min_days_since_publish": 0 }, "components": [ { "key": "published_resolvable", "name": "Published & resolvable", "detail": "1 package(s) on pypi", "points": 25, "status": "met", "details": [ { "code": "packages_published", "params": { "count": 1, "ecosystems": "pypi" } } ], "max_points": 25 }, { "key": "publish_recency", "name": "Publish recency", "detail": "latest publish 0 days ago", "points": 35, "status": "met", "details": [ { "code": "publish_recency", "params": { "days": 0 } } ], "max_points": 35 }, { "key": "version_history", "name": "Version history", "detail": "41 published versions", "points": 20, "status": "met", "details": [ { "code": "published_versions", "params": { "count": 41 } } ], "max_points": 20 }, { "key": "not_deprecated", "name": "Not deprecated", "detail": "active, not deprecated or yanked", "points": 20, "status": "met", "details": [ { "code": "package_not_deprecated", "params": {} } ], "max_points": 20 } ] } ], "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?" }, { "key": "engineering", "band": "good", "name": "Engineering Quality", "value": 81, "weight": 0.2, "metrics": [ { "key": "engineering_practices", "band": "moderate", "name": "Engineering practices", "note": null, "notes": [], "value": 68, "inputs": { "has_ci": true, "has_tests": true, "has_editorconfig": false, "has_linter_config": false, "has_precommit_config": false }, "components": [ { "key": "ci_workflows", "name": "CI workflows", "detail": "9 workflow(s)", "points": 24, "status": "met", "details": [ { "code": "ci_workflows", "params": { "count": 9 } } ], "max_points": 24 }, { "key": "tests_present", "name": "Tests present", "detail": null, "points": 24, "status": "met", "details": [], "max_points": 24 }, { "key": "linter_config", "name": "Linter config", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 16 }, { "key": "pre_commit_hooks", "name": "Pre-commit hooks", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 9.6 }, { "key": "editorconfig", "name": ".editorconfig", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 6.4 }, { "key": "openssf_scorecard_ci_tests", "name": "OpenSSF Scorecard: CI-Tests", "detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10", "points": 20, "status": "met", "details": [], "max_points": 20 } ] }, { "key": "documentation", "band": "excellent", "name": "Documentation", "note": null, "notes": [], "value": 100, "inputs": { "topics": [ "attestation", "cryptography", "ed25519", "merkle", "provenance", "python", "rfc6962", "sd-jwt", "transparency-log", "verifiable-credentials", "merkle-tree", "sigstore", "supply-chain-security", "ai-evaluation", "ai-safety", "llm-evaluation", "receipts", "attestations", "evidence" ], "has_wiki": true, "homepage": "https://b7n0de.com/proofbundle", "has_readme": true, "has_docs_dir": true, "has_description": true }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 30, "status": "met", "details": [], "max_points": 30 }, { "key": "documentation_directory", "name": "Documentation directory", "detail": null, "points": 25, "status": "met", "details": [], "max_points": 25 }, { "key": "documentation_homepage_site", "name": "Documentation / homepage site", "detail": "https://b7n0de.com/proofbundle", "points": 15, "status": "met", "details": [], "max_points": 15 }, { "key": "repository_description", "name": "Repository description", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "topics", "name": "Topics", "detail": "19 topics", "points": 10, "status": "met", "details": [ { "code": "topics_count", "params": { "count": 19 } } ], "max_points": 10 }, { "key": "wiki", "name": "Wiki", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 } ] } ], "description": "Are baseline engineering and documentation practices in place?" }, { "key": "security", "band": "good", "name": "Security", "value": 73, "weight": 0.16, "metrics": [ { "key": "security_posture", "band": "moderate", "name": "Security posture", "note": null, "notes": [], "value": 66, "inputs": { "source": "openssf_scorecard", "checks_evaluated": 18, "scorecard_version": "v5.5.0", "checks_inconclusive": 0, "scorecard_aggregate": 6.6 }, "components": [ { "key": "binary_artifacts", "name": "Binary-Artifacts", "detail": "binaries present in source code", "points": 6.8, "status": "partial", "details": [], "max_points": 7.5 }, { "key": "branch_protection", "name": "Branch-Protection", "detail": "branch protection is not maximal on development and all release branches", "points": 2.2, "status": "partial", "details": [], "max_points": 7.5 }, { "key": "ci_tests", "name": "CI-Tests", "detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "cii_best_practices", "name": "CII-Best-Practices", "detail": "no effort to earn an OpenSSF best practices badge detected", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "code_review", "name": "Code-Review", "detail": "Found 2/10 approved changesets -- score normalized to 2", "points": 1.5, "status": "partial", "details": [], "max_points": 7.5 }, { "key": "contributors", "name": "Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "dangerous_workflow", "name": "Dangerous-Workflow", "detail": "no dangerous workflow patterns detected", "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "dependency_update_tool", "name": "Dependency-Update-Tool", "detail": "update tool detected", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 }, { "key": "fuzzing", "name": "Fuzzing", "detail": "project is fuzzed", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "license", "name": "License", "detail": "license file detected", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "maintained", "name": "Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "packaging", "name": "Packaging", "detail": "packaging workflow detected", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "pinned_dependencies", "name": "Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 3", "points": 1.5, "status": "partial", "details": [], "max_points": 5 }, { "key": "sast", "name": "SAST", "detail": "SAST tool is run on all commits", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "security_policy", "name": "Security-Policy", "detail": "security policy file detected", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "signed_releases", "name": "Signed-Releases", "detail": "Project has not signed or included provenance with any releases.", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "token_permissions", "name": "Token-Permissions", "detail": "GitHub workflow tokens follow principle of least privilege", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 }, { "key": "vulnerabilities", "name": "Vulnerabilities", "detail": "0 existing vulnerabilities detected", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 } ] }, { "key": "dependency_advisories", "band": "excellent", "name": "Dependency advisories", "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 46 resolved dependencies against OSV; 16 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "indirect_dependencies_free_of_known_advisories", "no_advisories_left_outstanding" ] } }, { "code": "weights_renormalized", "params": {} }, { "code": "advisories_scope_repository", "params": { "assessed": 46 } }, { "code": "advisories_unassessed", "params": { "count": 16 } }, { "code": "advisories_repo_graph_caveat", "params": {} }, { "code": "advisories_reachability", "params": {} } ], "value": 100, "inputs": { "source": "osv", "advisories": 0, "affected_packages": 0, "assessed_packages": 46, "unassessed_packages": 16, "affected_by_severity": "none", "direct_affected_packages": 0 }, "components": [ { "key": "direct_dependencies_free_of_known_advisories", "name": "Direct dependencies free of known advisories", "detail": "no direct dependency carries a known advisory", "points": 35, "status": "met", "details": [ { "code": "no_direct_advisories", "params": {} } ], "max_points": 35 }, { "key": "indirect_dependencies_free_of_known_advisories", "name": "Indirect dependencies free of known advisories", "detail": "transitive set not separable from development and test dependencies in this scope", "points": 0, "status": "excluded", "details": [ { "code": "advisories_scope_not_separable", "params": {} } ], "max_points": 25 }, { "key": "no_advisories_left_outstanding", "name": "No advisories left outstanding", "detail": "no advisory carries a publication date", "points": 0, "status": "excluded", "details": [ { "code": "advisories_no_publication_date", "params": {} } ], "max_points": 40 } ] }, { "key": "malicious_dependencies", "band": "excellent", "name": "Malicious dependencies", "note": null, "notes": [], "value": 100, "inputs": { "source": "osv", "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored", "packages": [], "red_flag": false, "assessed_packages": 46, "malicious_packages": 0, "direct_malicious_packages": 0, "withdrawn_malicious_packages": 0, "installable_malicious_packages": 0 }, "components": [ { "key": "no_dependency_reported_as_a_malicious_package", "name": "No dependency reported as a malicious package", "detail": "no dependency is reported as a malicious package", "points": 100, "status": "met", "details": [ { "code": "no_malicious_dependencies", "params": {} } ], "max_points": 100 } ] } ], "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?" }, { "key": "ai_readiness", "band": "moderate", "name": "AI Readiness", "value": 63, "weight": 0, "metrics": [ { "key": "ai_agent_context", "band": "at_risk", "name": "Agent context & guidance", "note": null, "notes": [], "value": 40, "inputs": { "has_llms_txt": false, "legible_history_share": 0.979, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "components": [ { "key": "agent_instructions", "name": "Agent instructions", "detail": "no CLAUDE.md / AGENTS.md / editor rules", "points": 0, "status": "missed", "details": [ { "code": "no_agent_instructions", "params": {} } ], "max_points": 45 }, { "key": "machine_readable_docs_llms_txt", "name": "Machine-readable docs (llms.txt)", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 15 }, { "key": "legible_commit_history", "name": "Legible commit history", "detail": "93 of 95 human commits state their intent (structured subject or explanatory body)", "points": 40, "status": "met", "details": [ { "code": "legible_history", "params": { "legible": 93, "sampled": 95 } } ], "max_points": 40 } ] }, { "key": "ai_verify_loop", "band": "good", "name": "Verify loop (build / test / typecheck)", "note": null, "notes": [], "value": 82, "inputs": { "has_nix": false, "has_tests": true, "lockfiles": [ "Cargo.lock" ], "has_dockerfile": true, "typed_language": false, "bootstrap_files": [ "Makefile" ], "has_devcontainer": false, "has_linter_config": false, "typecheck_configs": [ "src/proofbundle/py.typed" ], "agent_commit_share": 0.59, "toolchain_manifests": [ "tools/pb_verify_rs/Cargo.toml" ], "dependency_bot_commit_share": 0.05 }, "components": [ { "key": "one_command_bootstrap", "name": "One-command bootstrap", "detail": "Makefile", "points": 18, "status": "met", "details": [ { "code": "file_list", "params": { "files": "Makefile" } } ], "max_points": 18 }, { "key": "automated_tests", "name": "Automated tests", "detail": null, "points": 22, "status": "met", "details": [], "max_points": 22 }, { "key": "lint_format_config", "name": "Lint / format config", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 11 }, { "key": "static_type_checking", "name": "Static type checking", "detail": "src/proofbundle/py.typed", "points": 11, "status": "met", "details": [ { "code": "file_list", "params": { "files": "src/proofbundle/py.typed" } } ], "max_points": 11 }, { "key": "reproducible_environment", "name": "Reproducible environment", "detail": "Dockerfile, lockfile", "points": 10, "status": "met", "details": [ { "code": "file_list", "params": { "files": "Dockerfile, lockfile" } } ], "max_points": 10 }, { "key": "demonstrated_agent_practice", "name": "Demonstrated agent practice", "detail": "59 of the last 100 commits agent-authored or agent-credited", "points": 10, "status": "met", "details": [ { "code": "agent_authored_commits", "params": { "count": 59, "sampled": 100 } } ], "max_points": 10 }, { "key": "automated_maintenance", "name": "Automated maintenance", "detail": "5 of the last 100 commits are automated dependency updates", "points": 8, "status": "met", "details": [ { "code": "dependency_bot_commits", "params": { "count": 5, "sampled": 100 } } ], "max_points": 8 }, { "key": "openssf_scorecard_pinned_dependencies", "name": "OpenSSF Scorecard: Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 3", "points": 3, "status": "partial", "details": [], "max_points": 10 } ] }, { "key": "ai_code_legibility", "band": "good", "name": "Code legibility for models", "note": null, "notes": [], "value": 81, "inputs": { "primary_language": "Python", "largest_source_bytes": 171563, "source_files_sampled": 257, "oversized_source_files": 3 }, "components": [ { "key": "type_checkable_code", "name": "Type-checkable code", "detail": "Python with type-check config (src/proofbundle/py.typed)", "points": 27, "status": "partial", "details": [ { "code": "typecheck_config_language", "params": { "files": "src/proofbundle/py.typed", "language": "Python" } } ], "max_points": 45 }, { "key": "manageable_file_sizes", "name": "Manageable file sizes", "detail": "3/257 source files over 60KB", "points": 54.4, "status": "partial", "details": [ { "code": "oversized_source_files", "params": { "kb": 60, "sampled": 257, "oversized": 3 } } ], "max_points": 55 } ] }, { "key": "ai_interfaces", "band": "at_risk", "name": "Machine-readable interfaces", "note": null, "notes": [], "value": 40, "inputs": { "example_dirs": [ "examples" ], "has_mcp_signal": false, "api_schema_files": [] }, "components": [ { "key": "api_schema_openapi_graphql_proto", "name": "API schema (OpenAPI/GraphQL/proto)", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 40 }, { "key": "mcp_server", "name": "MCP server", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 20 }, { "key": "runnable_examples", "name": "Runnable examples", "detail": "examples", "points": 40, "status": "met", "details": [ { "code": "file_list", "params": { "files": "examples" } } ], "max_points": 40 } ] } ], "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score." } ], "metrics_version": "1.13.0" }, "warnings": [ "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token", "deps.dev does not index pypi:proofbundle@3.7.0; advisories assessed against the repository dependency graph instead" ], "report_type": "repository", "generated_at": "2026-07-23T12:24:39.941015Z", "schema_version": "0.27.0", "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/b7n0de/proofbundle.svg", "full_name": "b7n0de/proofbundle", "license_state": "standard", "license_spdx": "MIT" }, "repoMeta": null, "notFound": false, "related": [ { "id": 30197, "full_name": "microsoft/agent-governance-toolkit", "url": "https://github.com/microsoft/agent-governance-toolkit", "description": "AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.", "ecosystem": "npm", "ecosystems": [ "npm", "go", "crates" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "agent-framework", "ai-agents", "ai-safety", "compliance", "governance", "microsoft", "owasp", "policy-engine", "python", "security", "trust", "zero-trust", "antigravity", "cli", "agent", "policy", "claude-code", "mcp", "copilot", "opencode", "agentmesh", "identity", "audit" ], "license_spdx": "MIT", "license_state": "standard", "stars": 4869, "forks": 772, "watchers": 66, "monthly_downloads": 12295, "latest_score": 86, "latest_band": "excellent", "latest_scanned_at": "2026-07-20T23:06:13.846894Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 9450, "full_name": "chainloop-dev/chainloop", "url": "https://github.com/chainloop-dev/chainloop", "description": "SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more", "ecosystem": "go", "ecosystems": [ "go" ], "primary_language": "Go", "languages": [ "Go" ], "topics": [ "compliance", "cyclonedx", "devsecops", "sbom", "sbom-distribution", "security", "spdx", "supply-chain-security", "metadata-platform", "sbom-discovery", "license", "open-source-licensing", "ospo", "oss-compliance", "regulated-industry", "attestation", "in-toto", "slsa", "slsa-provenance" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 570, "forks": 53, "watchers": 8, "monthly_downloads": null, "latest_score": 85, "latest_band": "excellent", "latest_scanned_at": "2026-07-16T01:23:17.566089Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 139, "full_name": "apache/superset", "url": "https://github.com/apache/superset", "description": "Apache Superset is a Data Visualization and Data Exploration Platform", "ecosystem": "npm", "ecosystems": [ "npm", "pypi" ], "primary_language": "TypeScript", "languages": [ "TypeScript", "Python", "Jupyter Notebook" ], "topics": [ "superset", "apache", "apache-superset", "data-visualization", "data-viz", "analytics", "business-intelligence", "data-science", "data-engineering", "asf", "bi", "business-analytics", "data-analytics", "data-analysis", "python", "react", "sql-editor", "flask", "extensions", "visualization", "embed", "embedded", "sdk", "iframe", "dashboard", "chart", "cli", "development-tools" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 73846, "forks": 17889, "watchers": 1535, "monthly_downloads": 1098754, "latest_score": 97, "latest_band": "excellent", "latest_scanned_at": "2026-07-15T20:41:37.957488Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 10747, "full_name": "scikit-learn/scikit-learn", "url": "https://github.com/scikit-learn/scikit-learn", "description": "scikit-learn: machine learning in Python", "ecosystem": "pypi", "ecosystems": [ "pypi" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "machine-learning", "python", "statistics", "data-science", "data-analysis" ], "license_spdx": "BSD-3-Clause", "license_state": "standard", "stars": 66748, "forks": 27200, "watchers": 2124, "monthly_downloads": 216399843, "latest_score": 95, "latest_band": "excellent", "latest_scanned_at": "2026-07-22T01:48:23.800991Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "organic", "abandonment_state": "maintained", "red_flags": [], "badge_url": "" }, { "id": 30859, "full_name": "deepset-ai/haystack", "url": "https://github.com/deepset-ai/haystack", "description": "Open-source AI orchestration framework for building context-engineered, production-ready LLM applications. Design modular pipelines and agent workflows with explicit control over retrieval, routing, memory, and generation. Built for scalable agents, RAG, multimodal applications, semantic search, and conversational systems.", "ecosystem": "pypi", "ecosystems": [ "pypi", "npm" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "nlp", "question-answering", "pytorch", "semantic-search", "information-retrieval", "summarization", "transformers", "machine-learning", "ai", "python", "large-language-models", "generative-ai", "llm", "rag", "retrieval-augmented-generation", "agents", "agent", "gemini", "gpt-4", "orchestration", "bert", "qa", "reader", "retriever", "albert", "language-model", "mrc", "roberta", "search", "squad", "transfer-learning", "transformer" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 25959, "forks": 2941, "watchers": 160, "monthly_downloads": 1022672, "latest_score": 93, "latest_band": "excellent", "latest_scanned_at": "2026-07-21T02:32:10.344140Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 21284, "full_name": "optuna/optuna", "url": "https://github.com/optuna/optuna", "description": "A hyperparameter optimization framework", "ecosystem": "pypi", "ecosystems": [ "pypi" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "python", "machine-learning", "parallel", "distributed", "hyperparameter-optimization" ], "license_spdx": "MIT", "license_state": "standard", "stars": 14521, "forks": 1356, "watchers": 122, "monthly_downloads": 15935670, "latest_score": 93, "latest_band": "excellent", "latest_scanned_at": "2026-07-18T12:57:58.825568Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" } ] } }
Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-23 12:24 UTC

b7n0de / proofbundle

Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth

PythonMIT★ 2 estrellas⑂ 2 forksdesde jul 2026Ver en GitHub ↗

b7n0de/proofbundle tiene un índice de salud de 64 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Engineering Quality (81/100) y la más baja, Sustainability & Governance (48/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

64
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

64
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

kraxoCuenta personal
2 seguidores3 repositorios públicosdesde dic 2018

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
PyPIproofbundle3.7.0657441hace 0 díascryptographymerkletransparency-loged25519sd-jwtverifiable-credentialsattestationprovenancerfc6962

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

70Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
2.8/36Cadencia de commits — 4/52 semanas con commits
18/18Volumen de commits — 560 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year560
human_commit_share0,95
days_since_last_push0
active_weeks_last_year4
Cómo se puntúa
27/27Publica versiones — 47 versiones publicadas
36/36Recencia de las versiones — última versión hace 0 días
27/27Cadencia de publicación — una versión cada ~0,8 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count47
latest_release_tagv3.7.0
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases0,8

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

49En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 2 estrellas
0/25Forks — 2 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks2
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template
Cómo se puntúa
50.9/80Descargas mensuales — 6574 descargas/mes en pypi
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesproofbundle
dependents
ecosystemspypi
total_downloads
monthly_downloads6574
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

48En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0.7/22.5Distribución de commits — el principal contribuyente firma el 97% de los commits
4.1/13.5Amplitud de contribuyentes — 3 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled3
top_contributor_share0,97
Cómo se puntúa
20.8/46.8Resolución de issues — 44% de issues cerradas
35.3/38.3Aceptación de PR — 109/118 PR decididos fusionados
3/15OpenSSF Scorecard: Code-Review — Found 2/10 approved changesets -- score normalized to 2
Datos de entrada utilizados
merged_prs109
open_issues5
closed_issues4
issue_closed_ratio0,444
closed_unmerged_prs9
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
3.4/25Alcance del propietario — 2 seguidores de b7n0de
16.4/25Trayectoria — 3 repos públicos, cuenta de ~7 años
Datos de entrada utilizados
followers2
owner_typeUser
is_verified
owner_loginb7n0de
public_repos3
account_age_days2777
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en pypi
35/35Recencia de publicación — última publicación hace 0 días
20/20Historial de versiones — 41 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesproofbundle
ecosystemspypi
any_deprecatedno
min_days_since_publish0

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

81Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 9 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 15 out of 15 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentación

100Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://b7n0de.com/proofbundle
10/10Descripción del repositorio
10/10Topics — 19 topics
10/10Wiki
Datos de entrada utilizados
topicsattestation, cryptography, ed25519, merkle, provenance, python, rfc6962, sd-jwt, transparency-log, verifiable-credentials, merkle-tree, sigstore, supply-chain-security, ai-evaluation, ai-safety, llm-evaluation, receipts, attestations, evidence
has_wiki
homepagehttps://b7n0de.com/proofbundle
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

73Bueno · 16% del índice global
Cómo se puntúa
6.8/7.5Binary-Artifacts — binaries present in source code
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 15 out of 15 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
1.5/7.5Code-Review — Found 2/10 approved changesets -- score normalized to 2
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate6,6
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
0/25Dependencias indirectas libres de avisos conocidos — el conjunto transitivo no es separable de las dependencias de desarrollo y prueba en este alcance
0/40Sin avisos pendientes — ningún aviso tiene fecha de publicación
Datos de entrada utilizados
sourceosv
advisories0
affected_packages0
assessed_packages46
unassessed_packages16
affected_by_severitynone
direct_affected_packages0
Excluidos de la puntuación (sin datos o no aplicable): Dependencias indirectas libres de avisos conocidos, Sin avisos pendientes. Los pesos restantes se han renormalizado. Se cotejaron 46 dependencias resueltas con OSV. 16 no pudieron evaluarse: sin versión resuelta, ecosistema no admitido o fuera de la lista de paquetes informada. Este repositorio no publica ningún paquete que el índice resuelva, por lo que se evaluó en su lugar el grafo de dependencias del repositorio. Ese grafo mezcla fijaciones de desarrollo y prueba con las dependencias distribuidas, de modo que solo se puntúan las dependencias declaradas en tiempo de ejecución; los hallazgos transitivos se informan como contexto y quedan excluidos de la puntuación. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

63Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 93 de 95 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,979
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Makefile
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — src/proofbundle/py.typed
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 59 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 5 de los últimos 100 commits son actualizaciones automáticas de dependencias
3/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
Datos de entrada utilizados
has_nixno
has_tests
lockfilesCargo.lock
has_dockerfile
typed_languageno
bootstrap_filesMakefile
has_devcontainerno
has_linter_configno
typecheck_configssrc/proofbundle/py.typed
agent_commit_share0,59
toolchain_manifeststools/pb_verify_rs/Cargo.toml
dependency_bot_commit_share0,05
Cómo se puntúa
27/45Código verificable por tipos — Python con configuración de verificación de tipos (src/proofbundle/py.typed)
54.4/55Tamaños de archivo manejables — 3/257 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePython
largest_source_bytes171.563
source_files_sampled257
oversized_source_files3
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
0/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signalno
api_schema_files

Datos clave

2estrellas de GitHub
3contribuidores
560commits en los últimos 12 meses
0días desde el último push
47versiones publicadas
1factor bus
5issues abiertas
PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index pypi:proofbundle@3.7.0; advisories assessed against the repository dependency graph instead

Más detalle

Historial de estrellas y forks 0 ★ / 2 ⇿
0Estrellas
2Forks
19Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

111222212026-072026-072026-07
Mayor 2Menor 5Parche 9
OpenSSF Scorecard 6.6 / 10
6.6agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-23 12:24 UTC

9Binary-Artifactsbinaries present in source code
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests15 out of 15 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
2Code-ReviewFound 2/10 approved changesets -- score normalized to 2
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Dependencias directas 2
RegistroPaqueteRestricción de versiónManifiesto
PyPIcryptography>=42pyproject.toml
PyPIrfc8785>=0.1.4pyproject.toml
Todas las dependencias 62

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 2 paquetes directos y 60 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
PyPIcryptographydirecta
PyPIrfc8785directa
crates.iobase640.22.1indirecta
crates.iobase64ct1.8.3indirecta
crates.ioblock-buffer0.10.4indirecta
crates.iocfg-if1.0.4indirecta
crates.ioconst-oid0.9.6indirecta
crates.iocpufeatures0.2.17indirecta
crates.iocrypto-common0.1.7indirecta
crates.iocurve25519-dalek4.1.3indirecta
crates.iocurve25519-dalek-derive0.1.1indirecta
crates.ioder0.7.10indirecta
crates.iodigest0.10.7indirecta
crates.ioed255192.2.3indirecta
crates.ioed25519-dalek2.2.0indirecta
crates.ioequivalent1.0.2indirecta
crates.iofiat-crypto0.2.9indirecta
crates.iogeneric-array0.14.7indirecta
crates.iogetrandom0.2.17indirecta
crates.iohashbrown0.17.1indirecta
crates.iohex0.4.3indirecta
crates.ioindexmap2.14.0indirecta
crates.ioitoa1.0.18indirecta
crates.iolibc0.2.186indirecta
crates.iomemchr2.8.3indirecta
crates.iopkcs80.10.2indirecta
crates.ioproc-macro21.0.106indirecta
crates.ioquote1.0.46indirecta
crates.iorand_core0.6.4indirecta
crates.iorustc_version0.4.1indirecta
crates.ioryu-js0.2.2indirecta
crates.iosemver1.0.28indirecta
crates.ioserde1.0.228indirecta
crates.ioserde_core1.0.228indirecta
crates.ioserde_derive1.0.228indirecta
crates.ioserde_jcs0.1.0indirecta
crates.ioserde_json1.0.150indirecta
crates.iosha20.10.9indirecta
crates.iosignature2.2.0indirecta
crates.iospki0.7.3indirecta
crates.iosubtle2.6.1indirecta
crates.iosyn2.0.118indirecta
crates.iotypenum1.20.1indirecta
crates.iounicode-ident1.0.24indirecta
crates.ioversion_check0.9.5indirecta
crates.iowasi0.11.1+wasi-snapshot-preview1indirecta
crates.iozeroize1.9.0indirecta
crates.iozmij1.0.23indirecta
PyPIbuildindirecta
PyPIecdsaindirecta
PyPIhypothesisindirecta
PyPIinspect-aiindirecta
PyPIjsonschemaindirecta
PyPImypyindirecta
PyPIopentimestampsindirecta
PyPIpytestindirecta
PyPIpyyamlindirecta
PyPIrfc3161-clientindirecta
PyPIruffindirecta
PyPIsd-jwtindirecta
PyPIsetuptoolsindirecta
PyPIz3-solverindirecta
Avisos de dependencias 0

Este repositorio no publica ningún paquete que el índice resuelva, así que se evaluó su propio grafo de dependencias — 46 paquetes, que incluyen también fijaciones de desarrollo y prueba que nunca se distribuyen: 0 tienen avisos conocidos, de los cuales 0 son directas. 16 no pudieron evaluarse: sin versión resuelta, ecosistema no admitido, o fuera de la lista de paquetes informada.

Ningún aviso conocido afecta a las dependencias evaluadas.

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "attestation",
        "cryptography",
        "ed25519",
        "merkle",
        "provenance",
        "python",
        "rfc6962",
        "sd-jwt",
        "transparency-log",
        "verifiable-credentials",
        "merkle-tree",
        "sigstore",
        "supply-chain-security",
        "ai-evaluation",
        "ai-safety",
        "llm-evaluation",
        "receipts",
        "attestations",
        "evidence"
      ],
      "is_fork": false,
      "size_kb": 21206,
      "has_wiki": true,
      "homepage": "https://b7n0de.com/proofbundle",
      "languages": {
        "TeX": 3112,
        "Rust": 65539,
        "Shell": 3188,
        "Python": 2932897,
        "Makefile": 1927,
        "Dockerfile": 293
      },
      "pushed_at": "2026-07-23T11:33:57Z",
      "created_at": "2026-07-01T10:35:23Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T11:08:34Z",
      "description": "Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://b7n0de.com",
      "name": "kraxo",
      "type": "User",
      "login": "b7n0de",
      "company": null,
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/45888075?v=4",
      "created_at": "2018-12-15T01:11:41Z",
      "is_verified": null,
      "public_repos": 3,
      "account_age_days": 2777
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2026-07-23T11:34:27Z"
        },
        {
          "tag": "corpus-review-2026-07-22-iter9",
          "kind": "other",
          "published_at": "2026-07-22T16:36:56Z"
        },
        {
          "tag": "v3.6.3",
          "kind": "patch",
          "published_at": "2026-07-22T08:59:57Z"
        },
        {
          "tag": "corpus-review-2026-07-22",
          "kind": "other",
          "published_at": "2026-07-22T06:56:24Z"
        },
        {
          "tag": "corpus-review-2026-07-19",
          "kind": "other",
          "published_at": "2026-07-19T23:27:22Z"
        },
        {
          "tag": "v3.6.2",
          "kind": "patch",
          "published_at": "2026-07-19T17:51:06Z"
        },
        {
          "tag": "v3.6.1",
          "kind": "patch",
          "published_at": "2026-07-18T23:42:27Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-07-17T13:48:32Z"
        },
        {
          "tag": "corpus-review-2026-07-17",
          "kind": "other",
          "published_at": "2026-07-17T17:49:35Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-07-16T11:46:57Z"
        },
        {
          "tag": "v3.2.3",
          "kind": "patch",
          "published_at": "2026-07-15T16:39:50Z"
        },
        {
          "tag": "v3.2.2",
          "kind": "patch",
          "published_at": "2026-07-15T13:10:29Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2026-07-14T22:28:46Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-07-14T18:59:24Z"
        },
        {
          "tag": "v3.1.3",
          "kind": "patch",
          "published_at": "2026-07-13T17:38:33Z"
        },
        {
          "tag": "v3.1.2",
          "kind": "patch",
          "published_at": "2026-07-13T10:36:45Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2026-07-13T09:05:24Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-07-12T22:49:44Z"
        },
        {
          "tag": "v3.0.1",
          "kind": "patch",
          "published_at": "2026-07-12T14:22:55Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-07-12T02:41:09Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-07-10T18:54:46Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-07-09T20:37:40Z"
        },
        {
          "tag": "v2.0.0b3",
          "kind": "other",
          "published_at": "2026-07-06T19:00:46Z"
        },
        {
          "tag": "v2.0.0b2",
          "kind": "other",
          "published_at": "2026-07-05T18:36:11Z"
        },
        {
          "tag": "v1.9.2",
          "kind": "patch",
          "published_at": "2026-07-05T14:08:12Z"
        },
        {
          "tag": "v2.0.0b1",
          "kind": "other",
          "published_at": "2026-07-03T06:45:40Z"
        },
        {
          "tag": "v1.9.1",
          "kind": "patch",
          "published_at": "2026-07-02T21:56:38Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-07-02T20:47:20Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-07-02T17:43:59Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-07-02T16:49:36Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-07-02T14:23:47Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-07-02T12:47:48Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-07-02T11:48:11Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-07-02T01:25:50Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-02T00:26:17Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-01T23:30:55Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-07-01T20:46:50Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-01T20:44:12Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-07-01T18:44:22Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-01T18:12:52Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-01T18:00:32Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-01T17:33:26Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-07-01T15:57:02Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-01T15:40:13Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-01T15:10:19Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-01T11:10:57Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-01T10:58:06Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "defc3ee24cc2ef5e07d41b29bf271890d447846e",
          "body": "release prep: version 3.7.0, changelog for both adapters, clamp-branch test",
          "is_bot": false,
          "headline": "Merge pull request #127 from b7n0de/release/v3.7.0-changelog-version",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-23T11:08:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "418b1538407a5c9cb996b49e3626f0ccf6b9ced7",
          "body": "Six-lens falsification-first audit with refute-to-kill jury on commit 02509ca3 (version bump\nPR head): zero confirmed findings; four standing regression targets plus the two learned\nregister-integrity classes attacked by name and confirmed fail-closed. Two honest residuals\nrecorded (register freshness binding P2, dependency-free wording) as pre-publication follow-ups.\nSatisfies the version-coupled audit-record requirement (F7 / pre_tag_audit_gate).",
          "is_bot": false,
          "headline": "audit: pre-tag adversarial audit record for the 3.7.0 candidate",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-23T08:59:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02509ca3c7c787772395123de561762b2109e4bc",
          "body": "…h test\n\n- CHANGELOG: [3.7.0] section (lm-eval sample-count provenance #116 by @tuodijihua closing #115,\n  conformance-crossimpl acceptance target folded from [Unreleased], CONFORMANCE/COMMERCIAL_BOUNDARY\n  docs #107, Dependabot consolidation #119-#126); editorial note in [3.6.3] documenting that #1\n[…]\nff.\n- One test for the clamp branch: effective > original yields skipped_samples 0 with raw counts visible.\n\nRelease, tag and PyPI publish are explicitly OUT of scope here (separate owner-gated step).",
          "is_bot": false,
          "headline": "release prep: version 3.7.0, changelog for both adapters, clamp-branc…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-23T08:16:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55da43da7e13d904084753d785d3203ac917f86f",
          "body": "…oundary\n\ndocs: conformance authority policy + commercial boundary (W5)",
          "is_bot": false,
          "headline": "Merge pull request #107 from b7n0de/docs/conformance-and-commercial-b…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-23T08:02:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aca1fb5f7f7d38cb461e1078b40aec32493b52fc",
          "body": "…ovenance\n\nBind lm-eval sample count provenance",
          "is_bot": false,
          "headline": "Merge pull request #116 from tuodijihua/agent/lm-eval-sample-count-pr…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-23T07:46:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c830f57c7679f204db159836521ce8f56858642",
          "body": "…-73adf09e94\n\nci: bump the actions group with 2 updates",
          "is_bot": false,
          "headline": "Merge pull request #126 from b7n0de/dependabot/github_actions/actions…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-23T07:24:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f521b40a09bd54c9ce3f0be69e81b73fd2e94cc2",
          "body": "Bumps the actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).\n\n\nUpdates `github/codeql-action/init` from 4.37.0 to 4.37.3\n- [Release notes](https://github.com/github/codeql-act\n[…]\nnalyze\n  dependency-version: 4.37.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump the actions group with 2 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T23:53:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "748d57e8dcd9b724057e27a17663ceac1d697fdd",
          "body": "ci: group actions updates, fix dependabot label config",
          "is_bot": false,
          "headline": "Merge pull request #125 from b7n0de/ci/dependabot-groups-labels",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T23:51:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7df8f5cb4b9df3a5333db79bbf827d0ffaa4c849",
          "body": "…/setup-python-7.0.0\n\nci: bump actions/setup-python from 6.3.0 to 7.0.0",
          "is_bot": false,
          "headline": "Merge pull request #120 from b7n0de/dependabot/github_actions/actions…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T22:05:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "321505a99adc4493c23f1608e3964e341a36e0cd",
          "body": null,
          "is_bot": false,
          "headline": "ci: group actions updates, fix dependabot label config",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-22T21:19:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d683a196ce609aae1c2e6abc67557f06a81ab58a",
          "body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.3.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b\n[…]\npendency-name: actions/setup-python\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/setup-python from 6.3.0 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T19:25:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f1591631a70cac40da8406c161fa9b4cd8244be",
          "body": "…-action-pypi-publish-1.14.1\n\nci: bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1",
          "is_bot": false,
          "headline": "Merge pull request #122 from b7n0de/dependabot/github_actions/pypa/gh…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T19:23:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76c5cfd2b71672b60eda976bc2e4cbea21a37ae2",
          "body": "…codeql-action/upload-sarif-4.37.3\n\nci: bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3",
          "is_bot": false,
          "headline": "Merge pull request #121 from b7n0de/dependabot/github_actions/github/…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T19:23:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33ed94f7544ee169d6cf5169848b8d2ae0d2f05c",
          "body": "…/checkout-7.0.1\n\nci: bump actions/checkout from 7.0.0 to 7.0.1",
          "is_bot": false,
          "headline": "Merge pull request #119 from b7n0de/dependabot/github_actions/actions…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T19:23:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48165fca397161647bd18ff27234823bde921c75",
          "body": "Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.14.0 to 1.14.1.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...ba38be9e\n[…]\n-name: pypa/gh-action-pypi-publish\n  dependency-version: 1.14.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:55:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b34c19fa72f1f5f03fd8abd8c2dce3f86312845b",
          "body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\n github/codeql-action/upload-sarif\n  dependency-version: 4.37.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:55:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5186239f50e27a127dd1b31e6403d8fa258eb387",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 7.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/checkout from 7.0.0 to 7.0.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:54:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "21f48264f0b3e1d9bb8a29de6dc696f021cdebbf",
          "body": "…-20260722\n\ndocs: scrub internal platform name from public audit/roadmap docs",
          "is_bot": false,
          "headline": "Merge pull request #118 from b7n0de/docs/scrub-internal-platform-name…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T13:17:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11cfb434719d893a3e8d7ed1f0cbee713e72eebf",
          "body": "Replace 3 references to the maintainer's private monorepo name + internal paths\n(office/governance/, globe/staging/) with a neutral descriptor in docs/audit/BASELINE_3_1_2.md\nand docs/roadmap/FRONTLOAD.md. These leaked internal infrastructure structure into the public repo.\nMeaning preserved. CHANGELOG.md:1513 keeps its historical, documentary mention (a monorepo path\n\"that never shipped here\", no platform name) intentionally, see PR note.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: scrub internal platform name from public audit/roadmap docs",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-22T13:12:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3898b18e381cd1f752076b6c35a572dfa5adc5ad",
          "body": "release: 3.6.3 (never-raise residual, BETA, relation EXPERIMENTAL)",
          "is_bot": false,
          "headline": "Merge pull request #117 from b7n0de/release/3.6.3",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-22T08:58:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45da1500118d17b9c344aceaa1dbc0bf0672116c",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 3.6.3 (never-raise residual, BETA, relation EXPERIMENTAL)",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-22T07:58:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb81c2cc72ddbe1f1d052dcd0f4d6b05d1b420ca",
          "body": null,
          "is_bot": false,
          "headline": "Bind lm-eval sample count provenance",
          "author_name": "tuodijihua",
          "author_login": "tuodijihua",
          "committed_at": "2026-07-22T00:30:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ad801fb84632df00ab8b9c8bf7722c38eaeb26a",
          "body": "…venance\n\nBind Inspect scorer provenance and sample count",
          "is_bot": false,
          "headline": "Merge pull request #112 from tuodijihua/agent/bind-inspect-scorer-pro…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-21T15:22:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9e4133f96941eb2bbab95d17bd187bf4d33355d",
          "body": "chore: remove internal codename from public comments and docs (no behavior or data change)",
          "is_bot": false,
          "headline": "Merge pull request #114 from b7n0de/chore/external-naming-rename",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-21T14:19:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d97d9c08ec3bb7fbbc8cfa2fbbc8cb7bdc5ab2c1",
          "body": "…al naming rule)\n\nReplaces the internal gate codename with its external name in comments, docstrings\nand headings only, no behavior or data change. The name reached public main via the\nrootcommit corpus PR; the external naming rule keeps it off outward-facing surfaces.\n\nFiles: src/proofbundle/anchor\n[…]\nanchor/rootcommit/README.md,\naudit_artifacts/360/pre_tag_adversarial_audit_360.md. Vendored upstream vectors and\nmanifests untouched; digest pins remain valid. Full test suite 2030 passed, ruff clean.",
          "is_bot": false,
          "headline": "chore: remove internal codename from public comments and docs (extern…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-21T14:13:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6e1420c8308836f39ffab7f356ef4f9c3f4de19",
          "body": "corpus: MarkovianProtocol rootcommit v1 + v2-sig vectors (9) with own verifier, pinned at 9034202, credit Colin",
          "is_bot": false,
          "headline": "Merge pull request #113 from b7n0de/corpus/rootcommit-colin-9034202",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-21T12:04:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10e76569c048325ef7cb457e004e69d7d9048524",
          "body": "…ned at 9034202, with own independent verifier; credit Colin\n\nVendors the upstream rootcommit conformance corpus (rootcommit/v1: 4 vectors;\nrootcommit/v2-sig: 5 vectors; plus the two upstream manifests) as pure data,\nbyte-identical, with all 11 per-file SHA-256 digests pinned at commit 9034202.\nCred\n[…]\ng signature check needs the optional extra proofbundle[rootcommit]\n(ecdsa); without it sig_ok is None (status no_sig_lib), never a silent pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "corpus: add MarkovianProtocol rootcommit v1 + v2-sig vectors (9), pin…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-21T11:09:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29f2a02fb9fd7f1ef8910bfd7d64cc34d5a21b4d",
          "body": "Signed-off-by: tuodijihua <158809980+tuodijihua@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: allow numeric Inspect provenance fields",
          "author_name": "tuodijihua",
          "author_login": "tuodijihua",
          "committed_at": "2026-07-21T05:05:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "acd2195400d6846907a9ee4a874c1193737fc7f9",
          "body": null,
          "is_bot": false,
          "headline": "Bind Inspect scorer provenance and sample count",
          "author_name": "tuodijihua",
          "author_login": "tuodijihua",
          "committed_at": "2026-07-20T21:52:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32661bf1cf2904129abd9518ca3237b93ef741a7",
          "body": "…rename\n\nchore: rename internal review-gate codename to external adversarial-audit vocabulary (rename-only)",
          "is_bot": false,
          "headline": "Merge pull request #111 from b7n0de/chore/external-adversarial-vocab-…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-20T06:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da62821e56d4e117520de8bd152c0080092beb5f",
          "body": "fix(never-raise): 3.6.3 residual — close the three r7 sites + anchors_chia_add per-site guard (+ Berkeley re-gate siblings)",
          "is_bot": false,
          "headline": "Merge pull request #110 from b7n0de/fix/never-raise-residual-363",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-20T06:52:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16b1c1296f885fdc81b10ec2e73df2763bca29be",
          "body": "…ry (rationale text)\n\nReplace the internal review-gate codename with \"adversarial deep audit\" in the\nwrong-payloadtype-target case rationale (case.json) and the matching generator string +\ncomment (generate_vectors.py). Safe to edit (verified): the `rationale` field is\nschema-typed as any string and\n[…]\n2 relation vectors\ndifferential, Python==Rust) — including this vector.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "test(conformance): rename internal gate codename to external vocabula…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-20T01:31:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd696646ce4aac49da0e87f87cf4458e9decc5da",
          "body": "…(comments)\n\nComment-only rename in scripts/mutation_check.py (two operator-provenance comments) and\nscripts/findings_register.py (one explanatory comment). No behavior change: the mutation\noperators are content-pinned (exact code-string match), so these comment edits do not\ntouch any operator targe\n[…]\n repo-wide\ncodename grep reaches zero (scripts/ is living public code).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "chore(scripts): rename internal gate codename to external vocabulary …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-20T01:31:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2dc92e5884ed3236757865a452fbf63d7a91c192",
          "body": "… ADR 0006)\n\nReplace the internal review-gate codename with its external adversarial-audit\nvocabulary in docs/ANCHORS.md and docs/adr/0006-anchor-longevity.md. Both occurrences\nare parenthetical/attributional (\"... <codename> audit 2026-07-16, corrected\n2026-07-17\"); the surrounding sentence meaning\n[…]\nunchanged (checked per ADR review\nrule). No technical claim is altered.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "docs: rename internal gate codename to external vocabulary (ANCHORS +…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-20T01:31:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e6d524d72b9483ec3de1662b9c8a03b1009ab16",
          "body": "… + editorial note\n\nReplace the internal review-gate codename with its external adversarial-audit\nvocabulary throughout CHANGELOG.md and add a dated one-line editorial note at the head\ndeclaring the swap. Content unchanged (No-Overclaim / No-Fake): only the codename is\nreplaced. One anti-stutter cas\n[…]\nl adversarial deep-gate WITHSTANDS\" (avoids \"adversarial adversarial\").\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "docs(changelog): rename internal gate codename to external vocabulary…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-20T01:31:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d0c41233373a4239df7964c9796f380ade0bca8",
          "body": "… vocabulary (src + tests comments)\n\nComment/docstring-only rename across src/ and tests/ — the internal review-gate\ncodename is replaced by its external adversarial-audit vocabulary so the public\npackage carries no internal codename. No behavior change: every changed line is a\ncomment or docstring;\n[…]\no retarget needed) and a representative sample still\nkills as expected.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "refactor: rename internal gate codename to external adversarial-audit…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-20T01:31:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5333395d20a30974454339b36b781bdba7d6d2cc",
          "body": "…ngs found by the Berkeley re-gate\n\nThe Berkeley NORMAL 3L/3I re-gate of the R7 fixes falsified iteration 1: 23 sibling\nnever-raise escapes in evaluate_relations_policy, one param over from R7-2 (same class).\nFixed and re-gated to 0 escapes:\n\n- non-dict lineage_result crashed the reject_superseded b\n[…]\n2 -> 3, 0 escapes; DEEP release-cert is the\nseparate Owner-gated step).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): 3.6.3 R7-2b — close evaluate_relations_policy sibli…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-20T00:07:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "294633d520948c36c5be1bed287e33a6c454a0da",
          "body": "…_chia_add per-site guard\n\nCloses the never-raise residual 3.6.2 shipped deferred (Berkeley NORMAL re-gate of the\n3.6.2 candidate, r7). All three are P3/P4 direct-low-level-API robustness gaps on\nself-documented never-raise surfaces; NONE is reachable through the high-level\nsigned-envelope verify pa\n[…]\nt). Full suite green (1860 passed). CHANGELOG 3.6.3 (Unreleased) added.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): 3.6.3 residual — close the three r7 sites + anchors…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T23:57:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "59e2755fcd8115ddc15c452c035339cad901fb33",
          "body": "test(anchors): vendor tlog-bitcoin-anchor conformance vectors + cross-impl binding tests (Stufe A)",
          "is_bot": false,
          "headline": "Merge pull request #109 from b7n0de/feat/markovian-tlog-anchor-vectors",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-19T23:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7d538cbc04cfe0933d43486163f16c7b22a42da",
          "body": "…-impl binding tests\n\nStufe A of the Markovian interop follow-up. Vendors the upstream C2SP\ntlog-bitcoin-anchor conformance corpus (MarkovianProtocol/tlog-bitcoin-anchor\n@ aaea18d, MIT) as PURE DATA under tests/fixtures/anchors/tlog_bitcoin_anchor/,\ndigest-pinned in MANIFEST.json with full attributi\n[…]\nl closed (status unbound).\nFully offline (no calendar, no Bitcoin node). A byte change to any vendored file\nfails the MANIFEST digest-pin test.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(anchors): vendor tlog-bitcoin-anchor conformance vectors + cross…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T23:11:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9285bc6a140fbfa89493b3caa18b8726e181324",
          "body": "…ossimpl\n\nconformance: graduate decision-receipt cross-impl to full v0.1 (block 958761)",
          "is_bot": false,
          "headline": "Merge pull request #108 from b7n0de/conformance/markovian-graduate-cr…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-19T22:29:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d10eb07bf01b2fa53d31f218aa50ce6e90de9827",
          "body": "…ull v0.1 (block 958761)\n\nColin (MarkovianProtocol/audit-anchor@ff6a000) regenerated the decision-receipt vector\nagainst the enforced decision-receipt/v0.1 schema and re-anchored it to a confirmed\nBitcoin block. This graduates the canonicalization-only iteration to the first full\nend-to-end decision\n[…]\nps in the vector fail closed (root binding / anchor); a wrong or\nabsent relying-party header does not confirm (block_mismatch / needs rpTrust).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(conformance): graduate the decision-receipt cross-impl case to f…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T20:31:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b7d512dbe23f6bb008ff9ef10f11f74c705b2caa",
          "body": "…erated Berkeley re-gates)\n\nproofbundle 3.6.2 — security patch: bug-hunt + 5 iterated Berkeley re-gates (never-raise/DoS)",
          "is_bot": false,
          "headline": "Merge #106: proofbundle 3.6.2 — security patch (never-raise/DoS, 5 it…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-19T17:50:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b4415f5011a9680a8b016fb5bbdcb65e7ba5c66",
          "body": "…Checkliste §9 + Phase 4)\n\nCONFORMANCE.md: the corpus as original authority — core vs external vectors,\ndigest pinning, attribution, negative tests, offline reproducibility, NO silent\nchanges to accepted vectors (versioned successors instead), change process.\nComplements conformance/README.md (mecha\n[…]\nrs,\nbasic integrations) free forever; commercial layer adds operations/reporting/\ngovernance around the core, never removes trust from it. Honest status note:\nno commercial layer exists as of 2026-07.",
          "is_bot": false,
          "headline": "docs: conformance authority policy + commercial boundary (W5, Schutz-…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T15:58:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d458e831f445c6e8d830a90cebe4d482e102d52",
          "body": "…e) coercion\n\nThe r3 never-raise fix changed verify_ecdsa_p256's verify call from\npub.verify(der_sig, message, ...) to pub.verify(der_sig, bytes(message), ...),\nwhich made the line-pinned mutation operator pattern stale (GAP in CI,\n75/76 ok). Re-targeted to the current text; verified end-to-end locally:\npattern found, mutant applied -> TestVerifyEcdsaP256 goes red (killed),\nrestore -> green. No production code change.",
          "is_bot": false,
          "headline": "test: re-target ES256 fail-open mutation operator to the bytes(messag…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T15:50:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d8ad9391cb2b3a41e3fb5438bb1c4d2b0beaaa3",
          "body": "…elease-scope honesty\n\nErgaenzt den 3.6.2-Eintrag um die codebase-weite never-raise-Klassen-Schliessung (r5-r6, _as_dict/_as_list\n+ Element/kwarg-Guards ueber 16 Module) + ehrliche Release-Scope-Notiz (No-Overclaim): der Klassen-Fix ist\ngross + verifiziert (1859 Tests, nested-fuzz 0 Escapes) aber NICHT als vollstaendig behauptet; Rest -> 3.6.3.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): 3.6.2 — nested-config-subfield class fix (r5-r6) + r…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T13:37:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3f8e94d1c092af958a2050424bce9a6f52c14d18",
          "body": "…sdjwt_vc/renewal/automation)\n\nNORMAL re-gate r6 found the SAME nested-config-subfield class in modules r5 never touched (the class is\ncodebase-wide, converging module-by-module). r5 closed 5 modules (policy/relation/anchors/automation/\npublic_transparency); r6 confirmed 5 escapes in trust_pack/sdjw\n[…]\nkipped. (anchors_chia_add transform reverted — it broke\nthe lock context-manager tests and was not an escape; needs careful per-site handling.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): codebase-wide class-fix for r6 escapes (trust_pack/…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T12:34:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "af12cf91093ff0849bcd6851e80abbff8c95b298",
          "body": "…apes (r5, 16 confirmed)\n\nRound-5 DEEP re-gate proved the class was NOT converging via point fixes (5->12->16): the systemic\nidiom `(cfg.get(k) or {})` only replaces FALSY, so a truthy non-container (int/str) and non-dict/\nunhashable LIST ELEMENTS slipped through into .get()/iteration/set()/`in`.\n\nC\n[…]\n levels) = 0 escapes (CONVERGED);\nfull suite 1858 passed / 158 skipped, no regression. Pinned in test_round5_nested_config_subfield_regression.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): SYSTEMATIC class-fix for nested-config-subfield esc…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T11:48:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c2fe20bd2d81d092797ad125de83cbd7df7eae55",
          "body": "…the 12 round-4 escapes\n\nOwner directive: optimise the Berkeley gate so this class is captured in CI going forward, not only found\nby the expensive jury. The auto-enumerated denominator fuzzed ONLY the primary arg; the round-4 escapes\nlived in non-primary/nested/value slots.\n\n- _NAME_PATTERN += eval\n[…]\ngenerator-hardening, each finding a permanent corpus entry that can never silently regress.\n\nAll 4 property tests green; discovery floor holds.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(berkeley-v4): broaden never-raise denominator to G1/G2/G4 + pin …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T10:40:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "de19c5b126668fb766c7386910a9080ca254900e",
          "body": "…nested-non-primary + value guards\n\nRound-4 DEEP re-gate (wf_ce96dfb8) confirmed the class was bigger than r3's point fixes: the G1\nnon-primary-arg gap lives at SHARED SINKS and NESTED sub-fields, not just one caller.\n\n- checkpoint.witness_quorum: guard witness_vkeys IN THE SINK (verify_witnessed_ch\n[…]\ne_relation_resolution + non-dict relation_signer.\n\nAll 12 escape repros now fail-closed (typed / verdict-dict / skip); 42 affected tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): 12 Berkeley re-gate round-4 escapes — sink-level + …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T10:37:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "956cbe5c3a4eaa8194ac8d99ea247068c4afaf2f",
          "body": "…required_checks/fields type-guards\n\nBerkeley DEEP re-gate (round r3, wf_73054658) DOES_NOT_WITHSTAND: 1 P3 survivor + 4 completeness-critic\nescapes across the property-test's structural denominator gaps (non-primary args, name families, modules).\n\n- signature.verify_ed25519 / verify_ecdsa_p256: gua\n[…]\nields` (skip, not-applicable).\n\nAll 5 escape repros now fail-closed (typed error / False / level=None); 41 affected tests green, no regression.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): 5 Berkeley re-gate escapes — message/witness_vkeys/…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T09:37:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ce01a936391f53b0675ee2e6630b9d01ba52942",
          "body": "… load_claim_text, and BROADEN the denominator\n\nThe WITHSTANDS re-gate found the never-raise class still open on the predicate-validation surface, AND the\ncompleteness critic exposed that the round-7 property test's own denominator was incomplete — the exact\nclass-level-thinking failure v4 warns abo\n[…]\nor by design.\n\nBroadened one-pass sweep: 70 surfaces x 15 corpus vectors = 1050 calls, ZERO escapes. Full suite 1856 passed,\nruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 8 — subject_binding RecursionError root +…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T08:22:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "412cb1c8badfd23ad4fe8c41bc1820de6b3b69ef",
          "body": "…te v4 centerpiece, in-repo PoC)\n\nThe round-by-round re-gates converged 11 -> 3 -> 2 -> 1 but never to zero in one round because the fix target\nwas \"the one repro\" and the surface FAMILY was never an explicit machine-checked denominator. This test is that\ndenominator: it auto-discovers every public \n[…]\n-gate v4 thesis (make v3 §15/§17/§18 executable and required: enumerate the\nfamily, close the CLASS, not the instance). Full suite 1856 passed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: auto-enumerated never-raise class-closure property (Berkeley-ga…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T07:26:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a97f1b4e57b044d9a72bf1008495070ce378aba6",
          "body": "…CLASS with a shared property test\n\nThe round-7 re-gate + completeness critic found the never-raise \"non-str/non-bytes/non-dict primary arg\nreaches an unguarded .split()/len()/.get()\" class was swept surface-by-surface and left four unswept siblings\nin the SD-JWT / eval-claim family. Per the critic'\n[…]\nface that forgets the primary-arg guard now fails here, not in a future re-gate round.\n\nFull suite 1854 passed, 158 skipped, ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 7 — close the primary-arg type-confusion …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T07:01:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "009765faca7efb036fab8bd6b53292b80942ea70",
          "body": "… pre-decode DoS, convergence 11->3->2->1->0\n\nThe round-6 re-gate returned DOES_NOT_WITHSTAND with a SINGLE confirmed escape (down from 2), and the\ncompleteness critic (350 hostile cases across 30+ verify surfaces) confirmed it is the ONLY reachable\nin-contract raw-escape left. All fixed; full suite\n[…]\n proofbundle[anchors]+FIPS-204 build to fuzz):\nanchors_ots / anchors_rfc3161 deserialize+verify internals and the real PQ signature-parse path.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 6 — last in-contract RecursionError + JWT…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T06:21:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e2ccc2934acfb5cea7ffab8c1096b58caab7d860",
          "body": "… (dsse/anchor/pqsig), convergence 11->3->2->0\n\nThe round-5 re-gate returned DOES_NOT_WITHSTAND with only 2 confirmed escapes (down from 3) + a completeness\nfinding — all the same sibling-escape / non-JCS-value classes at the last few surfaces the earlier rounds had\nnot reached. All repro-confirmed;\n[…]\nz; the pqsig public exports raising\nPQUnavailable on a non-PQ build is by-design (returning False would be a No-Fake violation) and left as-is.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 5 — the last public-surface sibling leaks…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T05:26:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4898809fc213b5baced45424c9eb63e15b2c61aa",
          "body": "…ted mktemp, in a regression test\n\nCodeQL flagged 1 high-severity alert on PR #106: the round-4 regression helper `_node_heavy_file` used\n`tempfile.mktemp()` (deprecated: it returns a name without creating the file, a name-then-open TOCTOU race).\nSwitched to `tempfile.mkstemp()`, which creates the f\n[…]\nrrence; the test's intent (a >200k-node JSON file to exercise the node-budget verify path) is unchanged.\n\n28 regression tests pass, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: CodeQL py/insecure-temporary-file — use mkstemp, not the depreca…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T04:42:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e5e7a54b632e9ec029d5e088d1309759287a7fc7",
          "body": "…llide with the earlier relations SET\n\nCI `mypy src` (the `test` job runs mypy before pytest) failed with 2 errors in outcome.py: the automation\nfail-open clamp (commit e103b89) reused the local name `_codes`, which verify_outcome_receipt already binds\nas a SET at line 798 (`{v[\"code\"] for v in _vio\n[…]\nno other type errors from the round-3/4/5 never-raise work.\n\nBehaviour-preserving (variable rename only); outcome tests 110 passed, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: mypy — rename the automation-blocker code list so it does not co…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T04:37:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0f87d2959f6f78c00fb3bdfe31fd2dbf63251ecf",
          "body": "…could not reach (convergence 11->3->0)\n\nA fresh Berkeley DEEP re-gate against the round-4 HEAD returned DOES_NOT_WITHSTAND with only 3 confirmed\nescapes (down from 11) + 2 completeness-critic escapes — all the SAME two classes (structural-budget bypass on\na direct object, and file-read/PQ-sibling D\n[…]\nlable input rather than raise a ProofBundleError\nsibling. 6 new round-5 regression tests (PQ-robust: assert 'returns a verdict, never raises').\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 4 — same classes at the surfaces round-3 …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T04:32:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "231c32e85988c2b856fbacab2cc08b393b9ad3bc",
          "body": "…intoto ValueError family + file DoS\n\nA fresh Berkeley DEEP re-gate (6 lenses x 3 skeptics + completeness critic, 44 agents) against the round-3\nHEAD returned DOES_NOT_WITHSTAND with 11 confirmed escapes + 2 from the completeness critic. The round-3\nwidening had fixed the INNER loads_strict except s\n[…]\nleError, honoring the test's own stated intent) instead of the raw subclass.\n7 new round-4 regression tests in test_bughunt_361_never_raise.py.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 3 — close the FLAGSHIP verify surfaces + …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T03:33:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "550a8556832eee04db3491289e45cc5fa1dd8129",
          "body": "…ass (repro-confirmed)\n\nA deterministic pre-sweep + executable repro proved the never-raise-BASE class was still open at the\nLIBRARY level (the CLI class was already closed by main()'s catch-all in the prior commit). Several PUBLIC\nverify surfaces funnel an embedded SD-JWT / claim payload through lo\n[…]\natch base).\n\nRegression tests: 4 new library-surface cases in test_bughunt_361_never_raise.py.\nFull suite 1832 passed, 158 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 3 — close the library never-raise-base cl…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T02:28:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f380e3bfc161f61e1c01c27a2a996d41803cabc1",
          "body": "… P1 siblings\n\nThe round-2 re-gate proved the never-raise contract was incomplete as a CLASS, not point bugs: fixes\nRAISED BundleFormatError but the CONSUMING handlers caught only subclasses, so siblings (BudgetExceeded,\nPQUnavailable) escaped — the exact never_raise_fix_must_wrap_all_and_catch_base\n[…]\ninstead of read_bytes() — a large card is\n  legitimate (not capped) but /dev/zero no longer grows to a raw MemoryError out of the never-raise surface.\n\nFull suite 1826 passed, 158 skipped, ruff clean.",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate round 2 — systematic never-raise-base close + 2…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T02:08:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e103b89bef536c99dcacef380b8783b40e80a9dc",
          "body": "…missed + version 3.6.2\n\nThe Berkeley DEEP release-gate (verify-before-release) refused the first 3.6.2 fix pass and named two\nP1 siblings + an incomplete sweep — generator-hardening, not point-fixtures:\n\n- outcome.py (P1 fail-open sibling of the first outcome fix): the clamp fired ONLY on\n  relatio\n[…]\nely exceed the verify budget) is hashed in 1 MiB chunks instead.\n\nVersion bumped to 3.6.2 (pyproject + __init__ + CITATION + CHANGELOG). Regression tests extended;\nfull suite 1826 passed, 158 skipped.",
          "is_bot": false,
          "headline": "fix: Berkeley re-gate remediation — 2 P1 siblings the first fix pass …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T01:35:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "423678548732d5da06bb2492c9573e566a38f0f3",
          "body": "…g-hunt 3.6.2)\n\nThe 3.6.1 never-raise hardening wrapped some public entrypoints (load_bundle, checkpoint) but the\nadversarial re-audit found unwrapped siblings + two unbounded-read DoS holes. Each surface must map\nhostile untrusted input to a typed fail-closed result, never a raw exception (crash/Do\n[…]\nM\n  the process; new _read_capped() bounds the read at the input_bytes budget (15 call sites hardened).\n\nRegression tests in tests/test_bughunt_361_never_raise.py; full suite 1823 passed, 158 skipped.",
          "is_bot": false,
          "headline": "fix: eight never-raise / DoS sibling holes the 3.6.1 sweep missed (bu…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T01:08:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8385b3025506f7c02651e986cbe05b87796a655",
          "body": "…bug-hunt 3.6.2)\n\nAn adversarial re-audit of 3.6.1 found the never-raise fix did not cover all siblings AND two\ngenuine trust-policy fail-opens on the automation-verdict surface (the surface the docs recommend\nfor automation gating; .ok was already False, so an ok-only caller was safe, but a caller \n[…]\nirections:\nfail-closed on violation, no over-fire on the safe case) in tests/test_bughunt_361_automation_failopen.py;\n59 decision + 119 outcome/relation tests still pass. No crypto verdict is touched.",
          "is_bot": false,
          "headline": "fix: two P1 fail-opens on the .automation.safeForAutomation surface (…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-19T00:56:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "76c096efc95028629b4b8a68907e45d7583f669f",
          "body": "Names the cross-implementation acceptance gate. The independent Rust second-verifier\n(tools/pb_verify_rs) must AGREE with Python over the verifier core via the existing\ncrosscheck.py harness: content root (RFC 8785), DSSE/Ed25519 verify (real + tampered),\nduplicate-key reject, RFC 6962 Merkle head, \n[…]\nocal + acceptance gate, closing the #55 S2 accept criterion with existing code.\nCI/test-only, no package change. Verified: make conformance-crossimpl exits 0.\n\nCo-authored-by: kraxo <kraxo@b7n0de.com>",
          "is_bot": false,
          "headline": "feat: make conformance-crossimpl acceptance target (#55 S2) (#105)",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-19T00:41:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17e59e1972d827e8793bd623ee6cf15f56c2b7d4",
          "body": "…#104)\n\n6-lens/Berkeley-gated readability rewrite (README-audit verdict was TEILWEISE SOTA).\nCompresses the 65-line 'What's in the box' wall-of-text to scannable one-line bullets\n(exact flags/exit-codes/version history now live in the already-linked docs + CHANGELOG),\nslims '60-second try' to the tw\n[…]\naveats move into the linked docs (nothing lost, zero dead links — all 24\ninternal doc links verified to exist). Length now within the SOTA 500-1500-word band.\n\nCo-authored-by: kraxo <kraxo@b7n0de.com>",
          "is_bot": false,
          "headline": "docs: README SOTA readability pass — 317->205 lines, no claims lost (…",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-19T00:11:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c9877413d605532f4a8477564e258c79f7f5ef3",
          "body": "proofbundle 3.6.1 — security patch: close all 8 Teil-1/Teil-2 audit findings (Python + Rust), Berkeley-Gate green",
          "is_bot": false,
          "headline": "Merge pull request #103 from b7n0de/fix/subject-pin-361-P0",
          "author_name": "kraxo",
          "author_login": "b7n0de",
          "committed_at": "2026-07-18T23:39:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54729dee019dae09369f63b0cf3ffba89cf1fac1",
          "body": "…rewrites (CI mutation gap fix)\n\nThe mutation CI job failed: FAILED (76 operators, 3 gaps) — three line/pattern-pinned mutation operators\nno longer matched the source because the very fixes they guard were rewritten (the known re-stale-on-\nrewrite class). NOT a real test-suite weakness: the guards a\n[…]\nhe SAME semantic guard-disable/invert as before (killed by the same tests), just on the\nmoved code. Patterns grep-unique in the current source.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mutation): retarget 3 stale operators after the Teil-2/DEEP-gate …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T21:20:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "374edde943668a11e0bfbc2301957fe66fda9a30",
          "body": "…s (DEEP gate RT-04 closure)\n\nThe release-grade DEEP gate re-confirmed RT-01/RT-02/RT-03 fail-closed and narrowed RT-04 to one root\nclass: a public verify_/load_ export leaking a RAW exception on a wrong-TYPE (not wrong-value) untrusted\nargument. Three one-line guards, mirroring the existing witness\n[…]\nrror, zero raw leaks. Regression tests CheckpointNonStrNoteTyped\n+ load_bundle wrong-type-path. Full suite 1963 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): typed guards on 3 public exports for wrong-TYPE arg…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T19:23:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9aa322b3fb9b25cf279fa8366f82433a170ef5b",
          "body": "… + FIFO hang (DEEP gate RT-04 file/path)\n\nThe release-grade DEEP Berkeley-Gate (RT-01..RT-04 pre-registered) confirmed 3.6.1 fixes the two v3.6.0\nescapes — RT-01 (subject absent -> RELATION_TARGET_SUBJECT_MISSING) and RT-02 (JCS/rfc8785 absent minimal-\ninstall -> fail-closed) both hold — but caught\n[…]\n\na normal bundle still loads. Regression tests LoadBundleFilePathClass (device/FIFO/oversized). Full suite\n1960 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): bound load_bundle file read — /dev/zero MemoryError…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T18:58:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7404068d4753b1eb1b749eefb37d67d264c8b166",
          "body": "…ed_tree_size DoS, tlog witnesses shape, sdist test)\n\nThe 6-lens Berkeley gate on ca392f8 confirmed exactly 3 P2 defects (and re-cleared L1 canonicality \\A..\\Z,\nL2 RT-09 direct-dict budgets, L4 relation subject-pin, L5 register deny-by-default — no crypto false-accept,\nno fail-open). All three are n\n[…]\nailed), the L6-01 test SKIPs; CLI verify-proof on a malformed proof prints a\nclean fail-closed verdict (exit 1) in text and json, no traceback.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise+packaging): 3 real 6-lens findings on ca392f8 (expect…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T16:13:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ca392f8f43b3974f6ae02f05db4bfe0acf701563",
          "body": "…invisible/confusable severity)\n\nThe 6-lens gate confirmed 1 P2 (and re-confirmed A1-A8/A10/A12 + crypto/budget/relation/packaging all\nhold): verify_and_count's severity fold was ALLOW-by-default (anything not exactly {P0,P1} after\n.strip().upper() was silently non-gating) while status is DENY-by-de\n[…]\nTrue, 17 evaluated).\n\nRegression tests added (hidden-open-P0 wiring + known/unknown allowlist). Full suite 1955 passed /\n7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(register): severity deny-by-default + Unicode fold (6-lens L5-01 …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T15:23:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a9269f6510edff905b1a501864f77ebab01fc933",
          "body": "…ns L1-01 trailing-newline)\n\nThe 6-lens gate confirmed 1 P2 canonicality false-PASS (and re-confirmed RT-09/RT-10/relation/\npackaging/malformed-type all hold): decision/outcome `_SHA256_HEX` used `re.compile(r\"^[0-9a-f]{64}$\")`,\nbut `$` matches BEFORE a trailing newline in Python, so a sha256 digest\n[…]\ned / 7 skipped, ruff clean. Not a signature forgery (the receipt\nmust be authentically signed); a strictness/canonicality gap, no One-Way-Door.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(canonicality): anchor every validator with \\A..\\Z, not ^..$ (6-le…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T14:48:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8e76cd5cee86f63d4945860953c829b46ae4141",
          "body": "…BDOS-01, int<->str cap parity)\n\nThe 6-lens gate confirmed 1 remaining P2 (and re-confirmed RT-09/RT-10/crypto/relation/packaging and\nverify_evidence_pack/verify_sample_opening/recompute all hold): verify_bundle(dict) leaked a raw\nValueError on a huge merkle.tree_size / leaf_index (e.g. 10**5000). R\n[…]\n raw ValueError; a legit small tree_size is\nunaffected.\n\nRegression test added (bidirectional). Full suite 1952 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): bound integer magnitude in _require_int (6-lens L2-…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T14:23:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "74c882aaad67673fae6d1a3b16bd39d486f38f1c",
          "body": "…ree (release-vorlauf)\n\nAdded \"Addendum 2 — reconciled to the shipped v3.6.1 release tree\" to the pre-tag adversarial audit\nrecord. Every number carries its command source (No-Fake, vorlauf P5), and figures that changed vs the\nv3.6.0 addendum are called out so nothing contradicts the shipped state:\n\n[…]\nl branch-base snapshot, not the shipped count.\n- 0 open P0/P1 holds (signed register). Status boundary unchanged (BETA, EXPERIMENTAL relation).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(pre-tag): P5 reconcile the audit addendum to the shipped 3.6.1 t…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T13:49:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8fe8b629d40c2fd1bf8dd68731156cef739e4fda",
          "body": "…attest-dryrun startup failure\n\nThe published-artifact-gate's reusable-attest-dryrun job called reusable-build-attest.yml whose\nbuild-attest job declares id-token:write + attestations:write, but the workflow-wide contents:read\ncannot be exceeded by a called workflow -> the run was refused at startup\n[…]\n from PR #102 per Owner-GO, so 3.6.1 carries the fix without a separate merge). The\nreusable workflow is unchanged; CI-only, no package change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(pag): integrate PR #102 permission fix into 3.6.1 (P3) — reusable-…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T13:46:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "710357a8ad9ca36a554385422f49cf51f98a3f0f",
          "body": "…typed errors (6-lens L2/L3)\n\nThe 6-lens gate confirmed 2 P2 fail-closed defects on SECONDARY exported surfaces (it also\nre-confirmed RT-09/RT-10/crypto/relation and every primary verify_* surface hold):\n\n- L2-BDOS-01: recompute_merkle_root_b64(dict) walked merkle.inclusion_proof_b64 with an INERT\n \n[…]\n\n\nRegression tests added (load_bundle malformed matrix; recompute 100k-proof fast fail-closed).\nFull suite 1951 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise+dos): recompute_merkle_root_b64 budget + load_bundle …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T13:37:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5d35b6a371ef1c63561ba8c6304a3a4b270143d7",
          "body": "…enewal_policy (6-lens L2-01/L3-02)\n\nThe 6-lens gate confirmed 2 P2 never-raise leaks, both the recurring class \"an exported\nverify_*/evaluate_* surface missing a guard its sibling already has\". (My earlier claim that\nverify_prereg was clean was wrong — I tested with an empty claim, which short-circ\n[…]\nnd shape\nsurfaces are the three now-guarded ones plus verify_sequence.\n\nRegression tests added. Full suite 1949 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): sibling-guard parity for verify_prereg + evaluate_r…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T13:04:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4737356ee318af768a60b7c2b236871ef250f219",
          "body": "…e never-raise + bare-eval clean-skips)\n\nThe 6-lens gate confirmed 4 findings; after per-finding live re-verification against the\neditable HEAD (No-Fake), 3 were real and 1 (L2-01 verify_prereg) was a FALSE finding — the\ngate's own probe env had a stale build; verify_prereg already returns a fail-cl\n[…]\nession tests added (verify_evaluation_card bad paths; verify_sample_opening non-ASCII).\nFull in-repo suite 1947 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise+packaging): 3 real 6-lens findings (evalcard/persampl…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T12:35:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1d1d71d80e747ebeca6112d17b99c090c53ebf2",
          "body": "…widen pre_tag negation\n\nThe single-round 6-lens Berkeley gate confirmed 1 P0 (and confirmed every other RT-10\nguard HELD live: absent/empty/foreign-key/tamper/dangling/self-supersede/non-string-id/\nlist-typed severity-status/dup-id downgrade/lowercase p0/status!='closed').\n\n- L5-01 (P0, fail-open):\n[…]\nion tests added (rings -> anomaly, linear chain -> legit; the concession\nwords -> not counted). Full suite 1945 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(register): P0 supersession-cycle fail-open (6-lens gate L5-01) + …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T11:52:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5bf162451046cc4dc6e5196690dfc5c70e43b357",
          "body": "…rify_dual_hash guard (P2 L3-02)\n\nThe single-round 6-lens Berkeley gate confirmed 2 findings (and confirmed the crypto/\ncanonicality, RT-09 direct-dict budgets incl. string_len, relation subject-pin, and RT-10\nregister/pre_tag surfaces all WITHSTOOD). Both fixed:\n\n- L6-01 (P1) from-sdist \"pip instal\n[…]\ndded (verify_dual_hash non-bytes; the 5 module-skip guards exercised by the\ncleanroom). Full in-repo suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(packaging+never-raise): from-sdist test invariant (P1 L6-01) + ve…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T11:19:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bfae68b63bb4cb1ac21b2babc4990cec03fc2281",
          "body": "…ound gate L3-01/L3-02)\n\nThe corrected single-round 6-lens Berkeley gate (PUBLIC-contract scoped, no more\ninternal-helper over-confirmation) confirmed 2 P2 never-raise leaks on exported\nrelying-party surfaces; both fixed with zero behavioural change on valid input:\n\n- L3-01 verify_bundle(str) / reco\n[…]\nf-element; first==second None-roots) is now typed-error\nor fail-closed False, 0 raw exceptions. Full suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(never-raise): close 2 public raw-exception leaks (6-lens single-r…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T10:39:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aa502badaaccd1a5cc0b8e563bcdc063f6afe7a8",
          "body": "…ster severity type-confusion P1)\n\nA 6-lens Berkeley re-gate (Owner-tuned agent budget) surfaced further findings; after\nrigorous per-finding verification (PUBLIC never-raise contract applies to exported\nverify_*/evaluate_* only — internal helpers may raise, their public callers wrap them) 3\nwere re\n[…]\n, and\nthe strict public sweep confirms no public caller leaks their TypeError. Not over-fixed.\n\nFull suite 1941 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(teil5): remediate 6-lens Berkeley re-gate — 3 real findings (regi…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T10:07:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "297a9a61818563065a4dfff9c483ba725fb6527a",
          "body": "…5 fixes\n\nA faithful Berkeley re-gate (10 attack classes incl. RT-09 direct-dict + RT-10\nassertion-by-absence, 3-juror refute-to-kill) found 6 real defects in this session's\nown Teil-5 work. All fixed with bidirectional regression tests:\n\n- RT10-REG-01 (P1, fail-open): findings_register.verify_and_c\n[…]\nsstehend/... The genuine 3.6.0 record\n  still passes.\n\nFull suite 1938 passed / 7 skipped. ruff clean. CHANGELOG updated to the hardened state.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(teil5): remediate 6 Berkeley-gate FIX_FIRST findings on the Teil-…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T09:15:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "93c1dbbc2267c8e2d329f776a76aecba6dac0dcc",
          "body": "…toolchain\n\ncargo fmt --check disagreed with the runner's rustfmt on line breaks at\nmain.rs:1132/1496 because the toolchain was unpinned (rustfmt/clippy output is\nversion-dependent). Pin the exact toolchain in tools/pb_verify_rs/rust-toolchain.toml\n(1.95.0 + rustfmt + clippy), reformat main.rs with \n[…]\ne pinned toolchain.\n\nFindings register: PB-2026-0718-15 open -> closed (regenerated + re-signed, pinned\npubkey stable). 0 open P0/P1 unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rust): PB-2026-0718-15 deterministic cargo fmt/clippy via pinned …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T08:22:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e1bb2f37a41738b36b62f1bbdd4d4d0999801e9a",
          "body": "…ces stale-substring C12.2 (PB-2026-0718-14)\n\nThe audit_candidate_matrix C12.2 \"0 open P0/P1\" check derived PASS from a lexical\n\"0 open P0/P1\" substring in a version-scoped .md, with NO freshness / supersession /\nsignature / contradiction check. A STALE record that still said \"0 open\" granted PASS\nw\n[…]\n\nsubstring semantics to the register (absent -> FAIL, not PENDING; a fake .md grants nothing).\n\nFull suite 1932 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(audit-candidate): RT-10 signed structured findings register repla…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T08:17:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "01ab3805c0907d8ffef0e3fa27f2cb557ad766ac",
          "body": "…y path (PB-2026-0718-16)\n\nThe input_bytes + json_nodes + json_depth budget lives in loads_strict, which a STR\nbundle path funnels through (load_bundle -> loads_strict). A caller that hands an\nALREADY-PARSED dict to verify_bundle(dict) bypassed that chokepoint, so the structural\nbudget was INERT on \n[…]\n Shallow bundles unaffected.\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors::test_rt09_direct_dict_structural_budget\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(budget): RT-09 enforce structural budget on the direct-dict verif…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T07:45:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "805d68e1e861cc0b85d87ac08cc7411f82e6df87",
          "body": "…-0718 thorough-sweep closure)\n\nevaluate_public_transparency built a named-status dict verdict but a non-str\nsigned_note (123/None/list) hit an early string op → raw AttributeError before\nthe fail-closed path. Coerce a non-str note to \"\" so every checkpoint parse\nfails gracefully (all statuses FAIL)\n[…]\nrdict).\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors\n  ::test_evaluate_public_transparency_non_str_note_is_verdict\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(public_transparency): never-raise on non-str signed_note (PB-2026…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T07:33:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1f939d5d2783aa5ec0fca6841d11def185cc8a35",
          "body": "…athTypedErrors regression\n\nThe new CallerPathTypedErrors regression test (pinning the bc0028a caller-path fixes) exposed a second\nvkey parser: verify_cosignature routes through _parse_witness_vkey (NOT _parse_vkey), which still raised a\nraw AttributeError on a non-str vkey. Added the same isinstanc\n[…]\ney was a valid str, not None/int.)\n\nFull suite 1924 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): _parse_witness_vkey typed on non-str vkey + CallerP…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T07:27:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bc0028a98f7d6d78a0bffb166feefc60140c9a67",
          "body": "… checkpoint non-str vkey (final sweep)\n\nA comprehensive gate-substitute sweep (every public verify surface x budget/malformed-JSON/type-confusion,\n74 surface-attack combinations across 50 functions) confirmed the whole surface is never-raise for untrusted\nWIRE input, and closed the last two raw-exc\n[…]\nff clean; sweep CLEAN (no raw non-typed exception on any probed input).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): typed caller-path errors — verify_bundle bad-path +…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T07:23:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b9b8aeb5b5e1de481b6a979f5adf37292fec07c3",
          "body": "…al sweep)\n\nThe comprehensive verify_* sweep found verify_sdjwt_vc raised a raw AttributeError on a non-dict policy\n(policy.get(...)) — the same type-confusion class as decision/outcome/relation_statement. Now a fail-closed\nverdict (ok=False). (bundle.verify_bundle(<huge str>) -> OSError is the docu\n[…]\n wire input; left for the gate to adjudicate.) Suite green; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): verify_sdjwt_vc fail-closed on non-dict policy (fin…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T06:25:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d191e844a15142e2ff63525de4c5b8f98dae2994",
          "body": "…rs never-raise, HF token budget-consistent\n\nTo break the round-by-round pattern (each Berkeley RE-GATE found the budget-leak class on one more verify\nsurface), a full sweep of every loads_strict call site closed the remaining ones in one batch:\n\n- intoto verify_intoto_dsse / verify_eval_result_dsse\n[…]\nFalse + duplicate named in detail). Full suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): proactive loads_strict-sweep — in-toto DSSE verifie…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T06:23:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6a3dec77bfb2daa7540c09fc9ef8dcbeb1c33a0e",
          "body": "…get family + relstmt policy + CLI inspect)\n\nThe Berkeley gate on ee923a4 found the never-raise budget class STILL LIVE on the SD-JWT family (which I had\nonly fixed for TYPE-confusion, not budget) plus two more:\n\nBUDGET (P1 x5) verify_status_snapshot / verify_key_binding / verify_sd_jwt (header+payl\n[…]\nicyGuard, CliInspectLoneSurrogate).\nFull suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): close 9 final Berkeley RE-GATE findings (SD-JWT bud…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T06:10:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee923a48923806c0a233d90a6daa2bd83f6818ce",
          "body": "…part deferred to 3.6.2)\n\nThe CI fmt/clippy gate I added turned the previously-green advisory rust-parity check RED: the runner's\nrustfmt formats differently than the local toolchain (rust 1.95.0) — Diff at main.rs:1132/1496 — a classic\nrustfmt version drift. The code stays cargo-fmt + clippy-clean \n[…]\n a red advisory check (No-Fake: a red check must be a real regression).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "ci(rust): revert version-fragile fmt/clippy gate (PB-2026-0718-15 CI …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T05:33:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29bbbbc38db87e41caa205376fb54992609c6fd0",
          "body": "…gate to the rust job\n\nCatches a fmt/clippy regression in the Rust second-verifier going forward (advisory rust job, annotates).\nPlus the CHANGELOG entry for the fmt/clippy code fix.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "ci(rust): PB-2026-0718-15 add cargo fmt --check + clippy -D warnings …",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T05:29:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e9dbc7f4c20f77bbabf849811de2a1d0224dae3",
          "body": "…rity preserved)\n\nTeil-5 finding: the Rust second-verifier tree was not fmt-clean and clippy -D warnings failed\n(collapsible-match in the same-key fail-closed branch, a redundant closure). Applied `cargo fmt` and the\ntwo machine-applicable clippy fixes.\n\nNo behavior change: the fixes are cosmetic (f\n[…]\nn vectors and the same-key branch clippy touched). Release build\nclean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "style(rust): PB-2026-0718-15 cargo fmt + clippy -D warnings green (pa…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T05:28:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7f6a6dc323225f329ab306c18d27bbbe3f2d09c3",
          "body": "…erification core (direct dict path)\n\nTeil-5 finding (Berkeley GATE-T5-02): the merkle_path budget (256) was defined but enforced NOWHERE.\nverify_inclusion / verify_consistency ran a per-step hash loop over an unbounded proof list, and the 8 MiB\ninput_bytes byte-proxy never applies when a bundle is \n[…]\nfails, legit small proof verifies).\nFull suite 1919 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(budget): PB-2026-0718-16 enforce merkle-path step budget in the v…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T05:25:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c13159130dc6e13cd2ac1064a25b9cb4c93eb5c8",
          "body": "…asses vacuously on singletons\n\nTeil-4 finding: the corpus-integrity comparator grouped cases by crossFormatId and SKIPPED any group with\n< 2 members. All six xfmt-* groups had exactly one member, so the \"same scenario agrees across formats\"\ncheck was vacuously true and reported ok=true while verify\n[…]\ntic contradictory pair fails; an agreeing pair passes. Full suite 1916.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(conformance): PB-2026-0718-11 cross-format comparator no longer p…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T05:14:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb52ca062489eb0ec158092da483b2cbcbaa3c87",
          "body": "…pe-confused input\n\nExtends the breadth sweep: verify_sd_jwt (dict-returning, untrusted SD-JWT compact from a holder) raised a\nraw AttributeError on a non-str compact (.split(\"~\")); verify_commitment raised a raw AttributeError on a\nnon-str PRESENTED identifier (identifier.encode() inside salted_com\n[…]\nff clean. Regression cases added to tests/test_sibling_never_raise_361.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
          "is_bot": false,
          "headline": "fix(never-raise): verify_sd_jwt + verify_commitment fail-closed on ty…",
          "author_name": "kraxo",
          "author_login": null,
          "committed_at": "2026-07-18T05:04:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 47,
      "commits_last_year": 560,
      "latest_release_at": "2026-07-23T11:34:27Z",
      "latest_release_tag": "v3.7.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "proofbundle",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "cryptography",
            "merkle",
            "transparency-log",
            "ed25519",
            "sd-jwt",
            "verifiable-credentials",
            "attestation",
            "provenance",
            "rfc6962",
            "Development Status :: 4 - Beta",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: MIT License",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.14",
            "Topic :: Security :: Cryptography"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/proofbundle/",
          "is_deprecated": false,
          "latest_version": "3.7.0",
          "repository_url": "https://github.com/b7n0de/proofbundle",
          "versions_count": 41,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 6574,
          "first_published_at": "2026-07-01T15:10:44.562607Z",
          "latest_published_at": "2026-07-23T11:48:28.208813Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-06",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 5
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "src/proofbundle/py.typed"
      ],
      "toolchain_manifests": [
        "tools/pb_verify_rs/Cargo.toml"
      ],
      "largest_source_bytes": 171563,
      "source_files_sampled": 257,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 46,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 16,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "cryptography",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=42"
        },
        {
          "name": "rfc8785",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.1.4"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "cryptography",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "rfc8785",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "base64",
            "direct": false,
            "version": "0.22.1",
            "ecosystem": "crates"
          },
          {
            "name": "base64ct",
            "direct": false,
            "version": "1.8.3",
            "ecosystem": "crates"
          },
          {
            "name": "block-buffer",
            "direct": false,
            "version": "0.10.4",
            "ecosystem": "crates"
          },
          {
            "name": "cfg-if",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "const-oid",
            "direct": false,
            "version": "0.9.6",
            "ecosystem": "crates"
          },
          {
            "name": "cpufeatures",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "crates"
          },
          {
            "name": "crypto-common",
            "direct": false,
            "version": "0.1.7",
            "ecosystem": "crates"
          },
          {
            "name": "curve25519-dalek",
            "direct": false,
            "version": "4.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "curve25519-dalek-derive",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "der",
            "direct": false,
            "version": "0.7.10",
            "ecosystem": "crates"
          },
          {
            "name": "digest",
            "direct": false,
            "version": "0.10.7",
            "ecosystem": "crates"
          },
          {
            "name": "ed25519",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "crates"
          },
          {
            "name": "ed25519-dalek",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "equivalent",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "crates"
          },
          {
            "name": "fiat-crypto",
            "direct": false,
            "version": "0.2.9",
            "ecosystem": "crates"
          },
          {
            "name": "generic-array",
            "direct": false,
            "version": "0.14.7",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "crates"
          },
          {
            "name": "hashbrown",
            "direct": false,
            "version": "0.17.1",
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "crates"
          },
          {
            "name": "indexmap",
            "direct": false,
            "version": "2.14.0",
            "ecosystem": "crates"
          },
          {
            "name": "itoa",
            "direct": false,
            "version": "1.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "libc",
            "direct": false,
            "version": "0.2.186",
            "ecosystem": "crates"
          },
          {
            "name": "memchr",
            "direct": false,
            "version": "2.8.3",
            "ecosystem": "crates"
          },
          {
            "name": "pkcs8",
            "direct": false,
            "version": "0.10.2",
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro2",
            "direct": false,
            "version": "1.0.106",
            "ecosystem": "crates"
          },
          {
            "name": "quote",
            "direct": false,
            "version": "1.0.46",
            "ecosystem": "crates"
          },
          {
            "name": "rand_core",
            "direct": false,
            "version": "0.6.4",
            "ecosystem": "crates"
          },
          {
            "name": "rustc_version",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "ryu-js",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "1.0.28",
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_core",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_derive",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_jcs",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": false,
            "version": "1.0.150",
            "ecosystem": "crates"
          },
          {
            "name": "sha2",
            "direct": false,
            "version": "0.10.9",
            "ecosystem": "crates"
          },
          {
            "name": "signature",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "spki",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "crates"
          },
          {
            "name": "subtle",
            "direct": false,
            "version": "2.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "syn",
            "direct": false,
            "version": "2.0.118",
            "ecosystem": "crates"
          },
          {
            "name": "typenum",
            "direct": false,
            "version": "1.20.1",
            "ecosystem": "crates"
          },
          {
            "name": "unicode-ident",
            "direct": false,
            "version": "1.0.24",
            "ecosystem": "crates"
          },
          {
            "name": "version_check",
            "direct": false,
            "version": "0.9.5",
            "ecosystem": "crates"
          },
          {
            "name": "wasi",
            "direct": false,
            "version": "0.11.1+wasi-snapshot-preview1",
            "ecosystem": "crates"
          },
          {
            "name": "zeroize",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "zmij",
            "direct": false,
            "version": "1.0.23",
            "ecosystem": "crates"
          },
          {
            "name": "build",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "ecdsa",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "inspect-ai",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "mypy",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "opentimestamps",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3161-client",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "ruff",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sd-jwt",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "z3-solver",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 62,
        "direct_count": 2,
        "indirect_count": 60
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 109,
        "open_issues": 5,
        "closed_ratio": 0.444,
        "closed_issues": 4,
        "closed_unmerged_prs": 9
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "b7n0de",
          "commits": 130,
          "avatar_url": "https://avatars.githubusercontent.com/u/45888075?v=4"
        },
        {
          "type": "User",
          "login": "tuodijihua",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/158809980?v=4"
        },
        {
          "type": "User",
          "login": "MarkovianProtocol",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/292588966?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.97
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "demo-reproducible.yml",
        "fork-pr-isolation.yml",
        "published-artifact-gate.yml",
        "release-integrity.yml",
        "release.yml",
        "reusable-build-attest.yml",
        "scorecard.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 2,
            "reason": "Found 2/10 approved changesets -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "defc3ee24cc2ef5e07d41b29bf271890d447846e",
        "ran_at": "2026-07-23T12:24:22Z",
        "aggregate_score": 6.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T11:48:31Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-23T11:08:29Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 7,
          "created_at": "2026-07-05T00:44:01Z",
          "last_comment_at": "2026-07-21T14:26:40Z",
          "last_comment_author": "b7n0de"
        },
        {
          "number": 24,
          "created_at": "2026-07-07T18:00:37Z",
          "last_comment_at": "2026-07-07T18:16:38Z",
          "last_comment_author": "b7n0de"
        },
        {
          "number": 26,
          "created_at": "2026-07-07T19:31:43Z",
          "last_comment_at": "2026-07-09T23:34:54Z",
          "last_comment_author": "b7n0de"
        },
        {
          "number": 27,
          "created_at": "2026-07-07T19:31:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 55,
          "created_at": "2026-07-11T08:01:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/b7n0de/proofbundle",
    "host": "github.com",
    "name": "proofbundle",
    "owner": "b7n0de"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 73,
        "vitality": 70,
        "community": 49,
        "governance": 48,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "commits_last_year": 560,
              "human_commit_share": 0.95,
              "days_since_last_push": 0,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "560 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 560
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 47,
              "latest_release_tag": "v3.7.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "47 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 47
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 49,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 2,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "proofbundle"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 6574
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "6,574 downloads/month across pypi",
                "points": 50.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 6574,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 14,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.97
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 97% of commits",
                "points": 0.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "merged_prs": 109,
              "open_issues": 5,
              "closed_issues": 4,
              "issue_closed_ratio": 0.444,
              "closed_unmerged_prs": 9
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "44% of issues closed",
                "points": 20.8,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 44
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "109/118 decided PRs merged",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 109,
                      "decided": 118
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/10 approved changesets -- score normalized to 2",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "followers": 2,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "b7n0de",
              "public_repos": 3,
              "account_age_days": 2777
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of b7n0de",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "b7n0de"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "3 public repos, account ~7 yr old",
                "points": 16.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 3
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "proofbundle"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "41 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 41
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "attestation",
                "cryptography",
                "ed25519",
                "merkle",
                "provenance",
                "python",
                "rfc6962",
                "sd-jwt",
                "transparency-log",
                "verifiable-credentials",
                "merkle-tree",
                "sigstore",
                "supply-chain-security",
                "ai-evaluation",
                "ai-safety",
                "llm-evaluation",
                "receipts",
                "attestations",
                "evidence"
              ],
              "has_wiki": true,
              "homepage": "https://b7n0de.com/proofbundle",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://b7n0de.com/proofbundle",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "19 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 73,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 6.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/10 approved changesets -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 46 resolved dependencies against OSV; 16 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 46
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 16
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 46,
              "unassessed_packages": 16,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 46,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 63,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.979,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "93 of 95 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 93,
                      "sampled": 95
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "src/proofbundle/py.typed"
              ],
              "agent_commit_share": 0.59,
              "toolchain_manifests": [
                "tools/pb_verify_rs/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.05
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "src/proofbundle/py.typed",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "src/proofbundle/py.typed"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "59 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 59,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "5 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 5,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 171563,
              "source_files_sampled": 257,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (src/proofbundle/py.typed)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "src/proofbundle/py.typed",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/257 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 257,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index pypi:proofbundle@3.7.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T12:24:39.941015Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/b7n0de/proofbundle.svg",
  "full_name": "b7n0de/proofbundle",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasPyPI.