Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-27 18:03 UTC

charliek / shed

Go · RustMIT★ 1 estrella⑂ 0 forksdesde ene 2026Ver en GitHub ↗

charliek/shed tiene un índice de salud de 59 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es AI Readiness (87/100) y la más baja, Community & Adoption (24/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

59
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

59
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Charlie KnudsenCuenta personal
60 seguidores67 repositorios públicosdesde sept 2008Smartthings

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/charliek/shedv0.8.0-44hace 8 días
Gogithub.com/charliek/shed/sdkv0.3.0-5hace 27 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

85Excelente · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
18/36Cadencia de commits — 26/52 semanas con commits
18/18Volumen de commits — 517 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year517
human_commit_share0,98
days_since_last_push0
active_weeks_last_year26
Cómo se puntúa
27/27Publica versiones — 28 versiones publicadas
36/36Recencia de las versiones — última versión hace 8 días
27/27Cadencia de publicación — una versión cada ~3,7 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count28
latest_release_tagv0.8.0
releases_from_tagsno
days_since_latest_release8
mean_days_between_releases3,7

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

24Crítico · 18% del índice global
Cómo se puntúa
0/60Estrellas — 1 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

56Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
22.3/46.8Resolución de issues — 48% de issues cerradas
35.9/38.3Aceptación de PR — 213/227 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/25 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs213
open_issues36
closed_issues33
issue_closed_ratio0,478
closed_unmerged_prs14
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
12.8/25Alcance del propietario — 60 seguidores de charliek
25/25Trayectoria — 67 repos públicos, cuenta de ~17 años
Datos de entrada utilizados
followers60
owner_typeUser
is_verified
owner_logincharliek
public_repos67
account_age_days6522
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 2 paquete(s) en go
35/35Recencia de publicación — última publicación hace 8 días
20/20Historial de versiones — 44 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/charliek/shed, github.com/charliek/shed/sdk
ecosystemsgo
any_deprecatedno
min_days_since_publish8

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

82Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 5 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yml
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 17 out of 17 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://charliek.github.io/shed/
0/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepagehttps://charliek.github.io/shed/
has_readme
has_docs_dir
has_descriptionno

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

38En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 17 out of 17 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/25 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 37 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3,8

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

87Excelente · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — CLAUDE.md, crates/CLAUDE.md, desktop/CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 98 de 98 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_filesCLAUDE.md, crates/CLAUDE.md, desktop/CLAUDE.md
agent_instruction_max_bytes23.595
Cómo se puntúa
18/18Arranque con un solo comando — .mise.toml, Makefile, desktop/Makefile
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yml
11/11Verificación estática de tipos — desktop/tauri/ui/tsconfig.json
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 84 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
1/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
Datos de entrada utilizados
has_nixno
has_tests
lockfilesCargo.lock, go.sum, package-lock.json, uv.lock
has_dockerfile
typed_language
bootstrap_files.mise.toml, Makefile, desktop/Makefile
has_devcontainerno
has_linter_config
typecheck_configsdesktop/tauri/ui/tsconfig.json
agent_commit_share0,84
toolchain_manifestscrates/Cargo.toml, crates/shed-app/Cargo.toml, crates/shed-broker/Cargo.toml, crates/shed-core-ffi/Cargo.toml, crates/shed-core/Cargo.toml, crates/shed-host-agent/Cargo.toml, crates/shedctl/Cargo.toml, desktop/tauri/src-tauri/Cargo.toml, go.mod, sdk/go.mod
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.1/55Tamaños de archivo manejables — 12/704 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes175.333
source_files_sampled704
oversized_source_files12

Datos clave

1estrellas de GitHub
1contribuidores
517commits en los últimos 12 meses
0días desde el último push
28versiones publicadas
1factor bus
36issues abiertas
crates.io, Go, PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch pypi package 'shed-docs' from its registry
  • Could not fetch pypi package 'shed-desktop-tools' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 3.8 / 10
3.8agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-27 18:03 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests17 out of 17 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/25 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities37 existing vulnerabilities detected
Dependencias directas 27
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/charliek/shed/sdkv0.0.0go.mod
Gogithub.com/anmitsu/go-shlexv0.0.0-20200514113438-38f4b401e2bego.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.28go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.44.0go.mod
Gogithub.com/creack/ptyv1.1.21go.mod
Gogithub.com/distribution/referencev0.6.0go.mod
Gogithub.com/firecracker-microvm/firecracker-go-sdkv1.0.1-0.20251224190957-6fb280e993d4go.mod
Gogithub.com/fsnotify/fsnotifyv1.10.1go.mod
Gogithub.com/gliderlabs/sshv0.3.8go.mod
Gogithub.com/go-chi/chi/v5v5.2.4go.mod
Gogithub.com/google/cel-gov0.28.1go.mod
Gogithub.com/google/go-containerregistryv0.21.5go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/hugelgupf/p9v0.3.0go.mod
Gogithub.com/mdlayher/vsockv1.2.1go.mod
Gogithub.com/sirupsen/logrusv1.9.4go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/vishvananda/netlinkv1.3.1go.mod
Gogolang.org/x/cryptov0.53.0go.mod
Gogolang.org/x/netv0.56.0go.mod
Gogolang.org/x/syncv0.21.0go.mod
Gogolang.org/x/sysv0.46.0go.mod
Gogolang.org/x/termv0.44.0go.mod
Gogopkg.in/natefinch/lumberjack.v2v2.2.1go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gogithub.com/google/uuidv1.6.0sdk/go.mod
Gogolang.org/x/cryptov0.53.0sdk/go.mod
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 6869,
      "has_wiki": true,
      "homepage": "https://charliek.github.io/shed/",
      "languages": {
        "Go": 3600834,
        "CSS": 7896,
        "HTML": 969,
        "Rust": 1975012,
        "Shell": 270023,
        "Swift": 517460,
        "Python": 679160,
        "Makefile": 43531,
        "Dockerfile": 54095,
        "JavaScript": 2394,
        "TypeScript": 151621,
        "Go Template": 2865
      },
      "pushed_at": "2026-07-27T14:15:31Z",
      "created_at": "2026-01-21T07:07:11Z",
      "owner_type": "User",
      "updated_at": "2026-07-24T04:40:49Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Rust"
      ]
    },
    "owner": {
      "blog": "http://www.charlieknudsen.com",
      "name": "Charlie Knudsen",
      "type": "User",
      "login": "charliek",
      "company": "Smartthings",
      "location": "Minneapolis, MN, US",
      "followers": 60,
      "avatar_url": "https://avatars.githubusercontent.com/u/24948?v=4",
      "created_at": "2008-09-17T04:57:28Z",
      "is_verified": null,
      "public_repos": 67,
      "account_age_days": 6522
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-18T21:50:49Z"
        },
        {
          "tag": "v0.7.10",
          "kind": "patch",
          "published_at": "2026-07-08T09:17:42Z"
        },
        {
          "tag": "v0.7.9",
          "kind": "patch",
          "published_at": "2026-07-08T08:14:58Z"
        },
        {
          "tag": "v0.7.8",
          "kind": "patch",
          "published_at": "2026-07-03T08:30:09Z"
        },
        {
          "tag": "v0.7.7",
          "kind": "patch",
          "published_at": "2026-07-01T14:47:57Z"
        },
        {
          "tag": "v0.7.6",
          "kind": "patch",
          "published_at": "2026-06-30T08:05:49Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-06-26T23:06:55Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2026-06-20T02:53:50Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-06-18T05:47:50Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-06-16T01:17:47Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-06-15T07:51:15Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-06-13T19:18:01Z"
        },
        {
          "tag": "v0.6.6",
          "kind": "patch",
          "published_at": "2026-06-13T02:53:19Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-06-08T06:44:04Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-06-07T05:35:38Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-06-07T01:24:21Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-06-06T14:15:41Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-06-03T17:50:31Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-03T05:30:38Z"
        },
        {
          "tag": "v0.5.9",
          "kind": "patch",
          "published_at": "2026-05-31T06:53:57Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-05-29T18:36:58Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-05-29T08:41:19Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-05-28T08:10:39Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-05-27T09:30:21Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-05-27T08:50:23Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-05-25T06:08:58Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-05-25T04:25:01Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-05-22T08:25:49Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d558f882cb0e2800a625a4a5c25a365b99326dfd",
          "body": "Follow-up to #279 (opencode watch): the desktop rc-sessions doc still described\nthe hub message feed + gated input / the `/messages` feed as codex-only. opencode\nnow produces the same normalized feed, so correct both mentions to codex/opencode.\n(docs/extensions/rc-helper.md was already updated in #279's doc sweep; this closes\nthe one spot it missed.)\n\n\nClaude-Session: https://claude.ai/code/session_011sS42YqNZMcSshCZVqLTa4\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(desktop): rc message feed is codex AND opencode (#282)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-24T04:40:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d180449eacc4dd35573a7f074ceec1df84bcd738",
          "body": "…ty (#279)\n\nAdds opencode \"watch the session\" support for RC sessions at parity with codex —\na live normalized message feed + precise working/needs_input activity — so\nshed-mobile can watch an opencode session. Observed via opencode's embedded\nHTTP+SSE server (bare TUI launched with --port), since i\n[…]\nre-in → capabilities), with codex adversarial review of the fold +\ntransport and a live core validation against a real opencode server.\n\nAlso makes the release-scripts self-test hermetic. Closes #280.",
          "is_bot": false,
          "headline": "opencode RC sessions: watch-the-session (feed + activity), codex pari…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-24T03:18:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "695a521be029504b7b51b63305ab56b1adb62a9c",
          "body": null,
          "is_bot": true,
          "headline": "chore(appcast): publish v0.8.0",
          "author_name": "charliek-release-bot[bot]",
          "author_login": "charliek-release-bot[bot]",
          "committed_at": "2026-07-18T22:06:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67dc73c02e0252a135c86509f78daa7f89131eea",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_011oYCxf3jiJ7fEchjaxpBnH",
          "is_bot": false,
          "headline": "chore(version): bump to 0.8.0",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-18T21:19:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f5f8b53da54ab09cfd28506ed58ecca1d3793229",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_011oYCxf3jiJ7fEchjaxpBnH",
          "is_bot": false,
          "headline": "docs(changelog): v0.8.0 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-18T21:19:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a425411fba3b5777b0171607cf8b9c1eb9b9fc1d",
          "body": "…st-agent / machine-rc / desktop) (#278)\n\n* feat(release): 4-component ship selector — server/host-agent/machine-rc/desktop (plan 002 C1)\n\nSplit the go component's ship selector into three: server (plugin.json,\nunchanged file), host-agent (new crates/shed-host-agent/VERSION), and\nmachine-rc (new cmd\n[…]\npped.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_011oYCxf3jiJ7fEchjaxpBnH\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Release component model: per-artifact selective shipping (server / ho…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-18T21:06:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "daad4977b9f37cb853dbc7e8f744ec88d54bd44f",
          "body": "…, rc-events, token FSM, Android-portability (#277)\n\nPhase A of the shed-mobile → shared-Rust-core program: additive, library-only\ngap-fill so the Flutter client can adopt shed-core/shed-app via FRB (kills\n~2,400 lines of hand-maintained Dart). No release, no deps, no ffi change.\n\n- Overview DTOs + \n[…]\ngate → simplify → codex review → fix. shed-core 274 tests,\nfull workspace + feature-matrix clippy green, reverse-dep AC clean, live\nwire-shape verified vs localmac. CodeRabbit + host-agent-diff green.",
          "is_bot": false,
          "headline": "feat(shed-core,shed-app): mobile-parity gap-fill — overview, sessions…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-18T00:35:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16503354c82f9eb9027384a701c9776ab6d0074e",
          "body": "…con (#276)\n\n* feat(tauri): auto-refresh the Sheds dashboard + refresh button; drop dead Add-host link\n\nThe Tauri app had NO poll for the shed list (the Swift app polls every 5s via\nAppModel.pollInterval), so a shed created out-of-band — `shed create` from the\nCLI, or another client — never appeared\n[…]\npped.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): Sheds dashboard auto-refresh + macOS Tahoe glass app i…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-17T05:48:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "51bd5449e8c73d6dd92f294e03193f81cc4690a8",
          "body": "…hed-host-agent install (3a.2) (#275)\n\n* refactor(host-agent): extract crates/shed-broker — the embeddable broker core\n\nMove the broker core (bus, supervisor, watcher, discovery, config, ssh/aws/\ndocker backends, egress, minter, bootstrap, controltoken, approval, audit,\ntouchid, LiveStatus snapshot,\n[…]\n/108.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): Tauri app embeds the credential broker — no separate s…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-17T04:34:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8acd4af3775768925d52ee627e57cd0ee29a7c7c",
          "body": "…iring) (#273)\n\nPorts the Go cmd/shed-host-agent credential broker (ssh-agent, AWS STS,\nDocker, egress audit, multi-server discovery/supervision, native Touch-ID\napproval) to Rust at crates/shed-host-agent, wire-compatible on both\nsurfaces (desktop UDS + shed-server plugin bus), and switches the shi\n[…]\nD sign-off on localmac.\n\nNo release: the shipped binary flips Go->Rust only on the next go-component\ntag, which is a separate deliberate action.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(host-agent): Rust port — 3a.1 complete (all surfaces + release w…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-14T05:36:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2246417f44a4e04b93c2e7ac91824f7b53bb4c78",
          "body": "feat(desktop): Tauri mac auto-update — real Sparkle, signed DMG packaging, beta release track",
          "is_bot": false,
          "headline": "Merge pull request #263 from charliek/feature/tauri-mac-updater",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T03:14:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac43f2d43230c5ee53fcc8f558a9d719519fa49e",
          "body": "… releases, doc wording\n\n- desktop-release-create marks '-' tags --prerelease so a Tauri rc never\n  becomes the repo's latest release\n- CHANGELOG/installation.md qualify notarization as credential-dependent\n  and call the fallback ad-hoc-signed (not unsigned)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QReoPKEdMBFuYDmL51LUDx",
          "is_bot": false,
          "headline": "fix: address CodeRabbit findings — prerelease flag on desktop-only rc…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T02:54:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "84a55b745f958ab4963aadd5aae3b442b090a17e",
          "body": "Document the Tauri mac Sparkle-updater rollout that C1-C3 shipped:\n\n- desktop/RELEASING.md: the Tauri beta flow (prerelease tags build the\n  Tauri DMG on the appcast beta channel, stable tags keep the Swift DMG;\n  mutually exclusive gates), the desktop-macos-tauri job's deltas\n  (tauri-dmg-mac, taur\n[…]\nity note.\n\nNo code files changed (md only); mkdocs build --strict clean.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QReoPKEdMBFuYDmL51LUDx",
          "is_bot": false,
          "headline": "docs(desktop): Tauri beta rollout, updater docs, changelog, skills",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T02:54:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6bd641f8b97dc865004ae9953e24f3e0c3821bfb",
          "body": "Prerelease desktop tags build/notarize/appcast the Tauri DMG (beta channel)\nwhile stable tags keep the Swift job (mutually exclusive gates incl.\nworkflow_dispatch); PR-time smoke runs the full bundle+sign path with\nplist/signing assertions incl. verbatim prerelease version.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QReoPKEdMBFuYDmL51LUDx",
          "is_bot": false,
          "headline": "ci: Tauri prerelease desktop job + PR-time bundle smoke",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T02:53:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "757b87adeaa70eeb9a122852c34803d259fa9daf",
          "body": "…s op\n\nLink the real Sparkle updater (tauri-plugin-sparkle-updater =0.2.4, macOS\nonly) and expose a drivable, Swift-parity update surface:\n\n- The plugin is registered ONLY on macOS AND outside test mode, so the\n  updater is never instantiated under the harness (enforced at\n  registration, not inside\n[…]\ncore-video, the plugin); no\nversion changes to shed-core/shed-app/tauri.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QReoPKEdMBFuYDmL51LUDx",
          "is_bot": false,
          "headline": "feat(tauri): Sparkle updater — gated integration, popover row, harnes…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T02:53:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1e3ca075fb2dbdeb1d32c70a1914af4bc73ae0f9",
          "body": "Align the Tauri mac bundle to the Swift app's identity so the eventual\nSwift->Tauri hop is a same-identity, same-key, in-place Sparkle update:\na mac-only tauri.macos.conf.json overlay (productName/mainBinaryName\nShedDesktop, identifier ai.stridelabs.ShedDesktop, embedded\nSparkle.framework) — the bas\n[…]\nframework prereqs on tauri-build/lint/test/run keep\nC2's build.rs green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QReoPKEdMBFuYDmL51LUDx",
          "is_bot": false,
          "headline": "feat(tauri): mac packaging — identity align, Sparkle staging, signed DMG",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T02:53:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7005e178eb773b3d261462264c12d16cc63d9bc1",
          "body": "… C+D shed side) (#259)\n\n* fix(rc): classify an authed cursor composer as ready\n\nThe authed cursor-agent screen was never captured live, so a logged-in\ncursor fell through to starting forever and waitUntilReady never\ndelivered the kickoff. Anchor ready on the live-captured composer\nplaceholder line \n[…]\nald).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01GhG7w8t6tsmSonSe9RxfbC\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: rc activity hub — live agent status + codex message feed (Phase…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-12T02:36:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bb54aa96be2badbc9522fe5663fd165a0188e206",
          "body": "* feat(tauri): provider-mode + per-shed-rule plumbing, appearance state\n\nBackend groundwork for the mac-parity Preferences window:\n- shed-app coordinator: set_provider_mode (validates aws-/docker-\n  credentials, rebuild + reevaluate) + provider_modes() read-back +\n  remove_shed_rule (single-rule rem\n[…]\n window; ui.modal is\n  create|launch|null; prefs.dump is the UI-truth surface\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(tauri): Preferences becomes a dedicated window (mac parity) (#258)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-11T23:54:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b494a0f899d219a4205f5147e85bc6ae06aaded2",
          "body": "… (#255)\n\n* feat(tauri): Plex theme foundation — IBM Plex fonts, mobile palette, sidebar/header reskin\n\nReplace the Linen/slate-blue theme with the shed-mobile Plex design language:\n- --shed-* tokens re-valued (light + dark) to the mobile palette (accent\n  #F2541B, warm-neutral surfaces); new status\n[…]\ne Rust-vs-Swift golden byte-diff)\n- skills/docs: down-host pattern documented\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): Tauri Plex redesign, Egress pane parity, owl app icons…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-11T16:20:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41d9959c3c3b47a95398a1da43f9336a14175b8a",
          "body": "…(#254)\n\n* refactor(rc): extract agent registry behind kind dispatch\n\nMove everything agent-specific in internal/ext/rc behind an AgentSpec\nregistry (inner-command construction, pane classification, trust\npre-seeding, permission-mode validation), keyed by kind via\nspecForKind(). claude and shell bec\n[…]\nk, not just the row, closing the remaining enrichment\nread-race flake window.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: multi-agent RC sessions (codex/opencode/cursor) + RC over HTTP …",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-11T00:35:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a113e5c33100af5016b1e9a7b653ce3eded4d2a",
          "body": "…eg 3a.1) (#253)\n\nPhase 3 leg 3a.1: a standalone, wire-compatible Rust port of the host-agent\n(`crates/shed-host-agent`), gated by a Go-vs-Rust differential harness. The Go\nserver, Go guest extensions, and the Go host-agent are unchanged.\n\nLanded:\n- Differential harness (`tests/host-agent-diff/`) — \n[…]\npackaging. The Rust daemon ships\nopt-in and is flipped to default only after the acceptance matrix is green.\n\nPlan: ~/.claude/plans/monorepo-phase3-host-agent-minter.md (and the parent/harness plans).",
          "is_bot": false,
          "headline": "feat(host-agent): Rust port — spike + SSH-bootstrap minter (Phase 3 l…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-11T00:20:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94585e5d2636a7a842db8f9441545c3d5d71f726",
          "body": "Triages the 16 post-import CodeRabbit findings from #249 across the Rust core\n(crates/) and the desktop app: shell-quote {shed} with one-pass template\nexpansion, fail-closed approval intake/expiry, SetPolicyRules reevaluate,\nshed-rule + RC + token-minter server identity, create HTTP idle-timeout +\n4\n[…]\nthe two Swift\n  minters can't diverge.\n- Widen the debug-bundle M0 size guard to 70 MB (toolchain drift on the\n  unstripped debug build; the shipped release bundle stays gated at 20 MB).\n\nCloses #249.",
          "is_bot": false,
          "headline": "fix: triage CodeRabbit findings from desktop import (#249) (#252)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-10T04:55:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e61e7fdd494609cd833fd0c5dab4dea5a4c3cfe",
          "body": "* docs(discovery): redefine Phase 3 as client-side Rust unification\n\nSupersedes the bundle-first host-agent absorption with: port the host-agent\nto a standalone Rust daemon (3a.1), absorb it in-process into the desktop\nclients (3a.2, where the install-story win lands), then port the CLI (3b).\nRevers\n[…]\n use.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): redefine Phase 3 as client-side Rust unification (#251)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-09T23:36:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ff2db59cc6435e03fcd487ccfaf401cde2498ff",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): maintainer confirmed the Sparkle feed-move hop",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-09T05:16:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1a9c4fb87d2fcb5cd26b9fb4dcd83f2abbea46f8",
          "body": "…needs trap) (#250)\n\ndesktop-apt-dispatch used the implicit success() gate over needs:\ndesktop-linux. On a combined tag, desktop-linux runs via if: always() over\na (correctly) skipped desktop-release-create, and that transitive skip\npoisons the downstream success() — so the dispatch skipped and apt \n[…]\nship_desktop + desktop-linux success, matching the other desktop jobs.\n\n\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(release): desktop-apt-dispatch skipped on combined tags (skipped-…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T09:55:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "68cf11eb15fe4899de2f74f91c3033bf4462ca31",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): Phase 2 release-time outcomes + apt-dispatch fix note",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T09:31:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "026a1571771caa7c94a2746518cc0c748661517d",
          "body": null,
          "is_bot": true,
          "headline": "chore(appcast): publish v0.7.10",
          "author_name": "charliek-release-bot[bot]",
          "author_login": "charliek-release-bot[bot]",
          "committed_at": "2026-07-08T09:23:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31a101f4f2e6076d1f7021eda2afa75c201b9cca",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.10",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T08:48:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ad08558b2f00db4f76b9953d351446d15c4c97a0",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.10 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T08:48:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "91f7e7d3f2ba0859aa2e064453070c1030574a4a",
          "body": "* feat(crates): import the shed-desktop Rust core workspace (Phase 2, 1/5)\n\nImported from charliek/shed-desktop@0b6026e (core/ -> crates/): shed-core,\nshed-core-ffi, shed-app, shedctl. Mechanical copy from git archive; no\ncontent changes. Part of docs/discovery/monorepo-consolidation.md Phase 2.\n\nCo\n[…]\nng).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: import shed-desktop into the monorepo (Phase 2) (#248)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T08:32:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "55efe7f0b407a68816b25af0ed880aa755b229ab",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.9",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T07:44:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7f9f7e79e3d8f7fd34220f4cbf61736464ff19e7",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.9 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T07:44:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b9d992a02b7563854bd7fdec739c2214859a185e",
          "body": "Auth & transport security discovery doc + cross-repo implementation plan\n(acceptance criteria, panel review, and implemented status). Adds both pages\nto the Discovery nav alongside the existing entries.",
          "is_bot": false,
          "headline": "docs(discovery): auth & transport security discovery + plan (#194)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-08T00:28:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9a7dbc66bf5806fe1c9a94282fa1ca23f7242fe",
          "body": "Phase 1 of the monorepo consolidation (docs/discovery/monorepo-consolidation.md):\nimports the shed-extensions Go module into this repo, builds the guest binaries\nin-tree, deletes the ghcr shed-extensions image publish, and consolidates the\nrelease pipeline so one vX.Y.Z tag produces every artifact b\n[…]\nrunning end-to-end). Pre-existing findings from review tracked in #244.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01ED6csoQ3peM3GHc4c1CtqY",
          "is_bot": false,
          "headline": "feat: import shed-extensions into the monorepo (Phase 1) (#243)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-07T14:28:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ebe47691b19e4417c17c15da0d5ac6e94cbc2c06",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_01EoHk27xjf1khfuijtcru6u",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.8",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-03T07:54:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "69b097626b0f38dc96633d9483b4fce26a6343ff",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_01EoHk27xjf1khfuijtcru6u",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.8 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-03T07:54:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f1dd11cc1935c792a3e03e367bb2916611adeed6",
          "body": "…(#241)\n\nAdd a \"Time synchronization\" section to the Firecracker operations reference,\nsymmetric with the VZ one: FC guests run systemd-timesyncd, and the agent\nno-ops because FC x86 has no RTC. Also correct two comments that said FC time\nis \"held by kvmclock\" — a live FC guest reports current_clock\n[…]\nonized: yes\", and /sys/class/rtc/\nwas absent.\n\nRefs #236\n\n\nClaude-Session: https://claude.ai/code/session_01EoHk27xjf1khfuijtcru6u\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(fc): document guest time-sync + correct the FC clocksource note …",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-03T07:30:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3a5c8b1b9792370b4f7bfbe668812785c0d5dd6e",
          "body": "* feat(agent): re-sync guest clock from host-backed RTC after host sleep\n\nA long-running VZ guest ships no time discipline. Its CLOCK_REALTIME is\nderived from a counter (arch_sys_counter) that freezes while the host\nsleeps; the guest is paused externally and never sees a resume event, so\nneither the\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EoHk27xjf1khfuijtcru6u\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: keep the guest clock correct across host sleep (#236) (#240)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-03T06:54:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c6f67581bf5613e80349852079111b21577a9c0",
          "body": "…survive the TTL (#237 follow-up) (#239)\n\n* fix(api): egress audit stream accepts control or credentials (GET-only) (#237 follow-up)\n\nGET /api/egress/stream is consumed by the host-agent (shed-extensions), which\nholds a credentials-scoped token — but after #237 it fell to the control-only\ndefault an\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EoHk27xjf1khfuijtcru6u\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: egress-stream scope + unify token refresh so background tunnels …",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-03T05:12:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce1514eb39e01a6f60e7e796ff71809a50cbf4bc",
          "body": "* fix(api): accept control or credentials scope on the Connect tunnel (#237)\n\nIn secure mode the Connect route (/api/sheds/*/connect/*) required the\ncredentials scope, so the CLI's control token was rejected (403) and every\n`shed forward` connection reset. But the route has two consumers: the CLI\n(`\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EoHk27xjf1khfuijtcru6u\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: shed tunnels on secure-mode servers from the CLI (#237) (#238)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-03T02:36:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e23fa36d8c56a1b3c4383f97146f44ced9b684d",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.7",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-01T14:15:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e435b5ee2e2ae059a0cf9bcbbe78d6d93fd2ea05",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.7 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-01T14:15:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "71dace50abf321d56b02a7f4d06ea09462bffcc5",
          "body": "…Timer (#235)\n\nFollow-up to #234: converts the last inlined copy of the SSE pump/drain/terminal machinery (handlePullImageSSE) to delegate to the shared Server.streamSSE, and decouples streamSSE from *PhaseTimer by passing a resolved (track backend.ProgressFunc, onFinish func(error)) pair — create/d\n[…]\n, nil). Pure server-side refactor, no wire-behavior change. Adds handler-level pull SSE tests + a timing-log guard (table-driven).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(api): share streamSSE for image pull, decouple it from Phase…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-01T14:07:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fc0391b8bf5a9e027b224a3883823787f4956abf",
          "body": "* fix(delete): fast destroy path — SIGKILL running sheds, skip graceful teardown (#232)\n\n`shed delete` of a running shed took ~30s: the teardown ran the guest shutdown\nhook + `sync` + a graceful VM shutdown before terminating. But delete always\ndiscards the writable upper, so that work is wasted. Ad\n[…]\n (a failed list → empty stdout would false-pass).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(delete): fast destroy path + SSE progress streaming (#232) (#234)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-01T13:23:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21daa47497fdc5c7e90aab631854ba069f4d5aa6",
          "body": "…s 8-bit-clean (#233)\n\n`shed exec <name> -- cmd` and interactive `shed console` share `sshToShed`,\nwhich always passed `ssh -t`. Single `-t` makes OpenSSH allocate a remote PTY\nwhenever the client's stdin is a terminal, and a PTY's ONLCR line discipline\nrewrites \\n→\\r\\n (and mangles control bytes) —\n[…]\ne): optional `--tty`/`--no-tty` override; converge the\nterm-detection helpers (isProgressTTY/stdioIsInteractive) onto one `isTTY`.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): auto-detect TTY for shed exec so captured/piped output stay…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-01T07:20:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7454fd9bb47472124e2d3aba2ffdc113d9809005",
          "body": "…Zed Remote-SSH) (#230)\n\n* fix(agent): separate exec stderr from stdout on the non-PTY channel (Zed Remote-SSH)\n\nZed Remote-SSH could not connect to a shed: the connection timed out at 60s\nwith \"client did not become ready within the timeout\". PR #225 fixed the stdin\ndesync but not this — a second, \n[…]\n5 vz against a dev server with the rebuilt\nimage.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(agent): separate exec stderr from stdout on the non-PTY channel (…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-07-01T05:06:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce4eb3a2ee5cf219f7fd265e9384afce8c7912f7",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.6",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T07:35:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "566f7aad6d4dff2f8cb3928c0a28323e2300ab54",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.6 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T07:35:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d9ccf434f1b6d4310bcfb94db1387e190c821cce",
          "body": "Advance the ARG SHED_EXT_VERSION pin (v0.4.7 → v0.4.9) in both the VZ and\nFirecracker base images so the extensions/full variants layer the latest\npublished shed-extensions guest binaries. v0.4.9 is the current release\n(2026-06-30); its multi-arch ghcr image carries both linux/arm64 (VZ) and\nlinux/amd64 (FC).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(images): bump baked shed-extensions to v0.4.9 (#229)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T07:31:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3d255d91683bf2f6b9c423485d886e0d80d88b3a",
          "body": "…) (#228)\n\n* fix(image): record ref-index on `shed image build` (#227)\n\n`shed image build` wrote only the cosmetic tag after Convert; it never\npopulated the ref-index. `shed create --image <ref>` resolves through the\nref-index (RefIndexGet), so a freshly built image was invisible to create —\nit reso\n[…]\nted the rebuilt\nagent — all with no manual steps.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(image+build): dev-image build resolution + agent cache-bust (#227…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T07:24:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da514858c5a26ee975751338a6a2f1e88da46cd5",
          "body": "* feat(sdk): bootstrap tokens via the system ssh client\n\nReplace the in-process x/crypto/ssh bootstrap (sdk.Bootstrap) with a shared\nsdk/bootstrap sub-package that shells out to the system ssh client, so the\nexchange transparently honors the user's agent, macOS Keychain,\n1Password/Secretive Identity\n[…]\nhost IdentityFile + IdentitiesOnly on the client.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sdk): bootstrap tokens via the system ssh client (#226)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T05:41:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c6919e8668a4bfd13b297927f25c361ab7d4a81",
          "body": "…down reliability (#222) (#225)\n\nFixes Zed Remote-SSH (#222) and hardens the in-VM agent's exec channel:\n\n- Blocking stdin reads replace the 500ms-deadline polling that desynced the framed binary protocol (the #222 blocker).\n- Drain stdout/stderr before reaping so cmd.Wait can't discard buffered out\n[…]\ndetection, PTY and non-PTY); use tmux/nohup to survive a disconnect (documented).\n\nUnit + end-to-end (real VZ VM) validated; adds an in-repo agent-testing skill. Dev-tooling follow-up tracked in #227.",
          "is_bot": false,
          "headline": "fix(agent): Zed Remote-SSH — blocking stdin reads + exec-channel tear…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T05:38:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85b9ca76494ffaeaaf6d2c26fbce4c567640a8f0",
          "body": "… (#223) (#224)\n\n* fix(tunnels): make tunnel-state writes transactional\n\nState load and save acquired the file lock separately, so a process that\nhad already loaded the file would overwrite it from its (possibly stale)\nin-memory map on the next Save() — silently dropping entries another\nprocess wrot\n[…]\nen(\":0\")+close pattern; the window is negligible.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tunnels): truly daemonize `shed tunnels start -d` + graceful stop…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-30T04:45:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "897e7798d36829953d89c00e8287b1cf691bf228",
          "body": "shed sessions run inside tmux on the default tmux server (no -f/-L), which\nreads /etc/tmux.conf on start. The base images installed tmux but shipped no\nconfig, so scrollback was unreachable (the alt-screen means tmux owns all of\nit) and Claude Code warned that focus-events were off.\n\nWrite /etc/tmux\n[…]\nry-limit 50000, focus-events on, escape-time 10,\n  default-terminal tmux-256color, terminal-overrides \",*256col*:Tc\"\n\nCloses #220.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(images): bake sane tmux defaults into vz + firecracker base images",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-28T20:57:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "37f35b46af7cda1daf062d08809d921cfd81c794",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.5",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-26T22:39:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "26f9181c2420f9e53b7d6c1111cfb81faf8dc89a",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.5 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-26T22:39:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d57595c406f026c7040d789853709dd43d74334b",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: bump SHED_EXT_VERSION to v0.4.7",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-26T22:39:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9ced4ebe90f9ffb4b6ed78d1f208bba126e9fa99",
          "body": "…data, attach RC mode, shed-plan skill) (#218)\n\n* feat(sessions): surface RC session metadata in `shed sessions`\n\nEnrich `rc-*` tmux sessions with RC Session Convention metadata (kind, state,\ndisplay name, made-by) by querying the in-shed `shed-ext-rc` binary over SSH and\ndecoding its neutral JSON D\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VKK9rnAvfA956WBfjtLEXt\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: send a plan to a shed and run it autonomously (sessions RC meta…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-26T22:18:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bcba5754eecff33b389213d083e76a58d62ee5f4",
          "body": "…(#214) (#216)\n\n* feat(egress): user-profile store + config∪user resolution (plumbing)\n\nAdd config.UserProfileStore — a runtime, user-editable egress-profile\nstore (one <name>.yaml per profile, atomic temp+rename, RWMutex-guarded,\ndeep-copy reads, fail-hard load, lowercase names) — and thread it int\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "egress: user-managed named profiles (runtime, no server-config edit) …",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-21T16:04:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dcb27535dcc8993c9a0d8cbbf5337b290d99b4ab",
          "body": "…s fixes (#215)\n\n* fix(egress): emit snake_case keys in `shed egress show --json`\n\nconfig.EgressProfile carried only yaml tags, so the `rules` map in\n`shed egress show --json` (GET /api/egress/{name}) serialized with\nPascalCase keys (Mode/Allow/Deny/Rule) plus a noisy \"Deny\":null —\ninconsistent with\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "egress: snake_case `show --json` + recommended starter profiles + doc…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-21T03:23:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ba4ba37172a09b2013a51e70a51b46037b8a311d",
          "body": "fix(packaging): absolute shed-server path in postinst config-validate",
          "is_bot": false,
          "headline": "Merge pull request #213 from charliek/fix/postinst-validate-abspath",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T07:00:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c356ccabf08a28cdb264f3b9465239ada3c9ad35",
          "body": "…date\n\ndpkg runs maintainer scripts with a minimal PATH\n(/usr/sbin:/usr/bin:/sbin:/bin) that excludes /usr/local/bin, where\nshed-server is installed (matching the unit's ExecStart). So the upgrade\npreflight `shed-server --config … config-validate` failed with\n\"shed-server: command not found\", which \n[…]\ntruction (so a copy-paste works regardless of\nsudo's secure_path). No behavior change when the config genuinely fails to\nvalidate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(packaging): use absolute shed-server path in postinst config-vali…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T06:56:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5331089010bbf3142ca30ef351167a89be1e2c40",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.4",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T02:20:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8ee8a2f98839feb542651f45e960c11fcc59168f",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.4 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T02:20:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e57d72e2b30c2d360c04d682591a474c33153cd0",
          "body": "…#212)\n\nbind_address now rejects a malformed value (a hostname, a typo, or a zoned IPv6)\nat config-validate time with a clear message, instead of failing cryptically at\nnet.Listen on startup. It accepts the special tokens (\"\", \"*\", \"localhost\") and\nany IP literal; the format check runs before the op\n[…]\ne same drift-prevention as the\nshared loader defaulting.\n\n\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): validate bind_address format; unify removed-key scans (…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T02:16:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a32e870a632edd4dcaed559e8776cf49ec68a0c",
          "body": "Bake shed-ext-rc into the full image (shed-extensions v0.4.6)",
          "is_bot": false,
          "headline": "Merge pull request #211 from charliek/feat/shed-ext-rc-binary",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T02:07:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a476d597eb2163a7b97ea894d2f104bebeada0e",
          "body": "Install the new `shed-ext-rc` guest binary in the vz + firecracker image\nbuilds, the same way as the other shed-extensions binaries (from the pinned\nextensions image, in the shed-{vz,fc}-extensions stage that shed-{vz,fc}-full\ninherits). It's a one-shot CLI like docker-credential-shed — no systemd u\n[…]\n4.6 (also picks up the v0.4.4/v0.4.5\nhost-agent token + config fixes). Verified the v0.4.6 image ships\n/usr/local/bin/shed-ext-rc.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bake shed-ext-rc into the full image (shed-extensions v0.4.6)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T01:57:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e54ae83f34fc6ca45e601c48522b12cabdbbcbb",
          "body": "feat!: local-first network surface for v0.7.4 — bind_address, single listener, optional http_port",
          "is_bot": false,
          "headline": "Merge pull request #210 from charliek/feat/auth-binding-localfirst",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-20T00:04:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "091750e0a9dc3262d4ef40b4dafd2bb86e12ac96",
          "body": "Both loaders (serve + config-validate) duplicated the mode-derived and common\nzero-value defaults (http_port, https_port, ssh_port, log_level, terminal). Pull\nthem into applyModeAndCommonDefaults so the two paths can't drift — addresses\nCodeRabbit's review on #210.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "refactor(config): extract shared loader defaulting (CodeRabbit)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T21:50:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5530b83de7373cd927c42ee174baf95aca452ce0",
          "body": "The v0.7.4 loopback default would otherwise leave the remote FC parallel-dev\nserver (mini3, driven from the dev workstation by test-integration-dev-fc) bound\nto loopback and unreachable — set bind_address: 0.0.0.0 + allow_insecure_exposure\nthere. The Mac VZ parallel-dev config sets bind_address: 127\n[…]\no document intent and\navoid the startup migration warning.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "chore(configs): set bind_address on the parallel-dev configs",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T21:20:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cdac8a5808aeb24aa297959268ff115b1359722d",
          "body": "…ault)\n\nAdds the v0.7.3 to v0.7.4 upgrade guide and a CHANGELOG entry, and reworks the\nsecurity + getting-started docs for the new model: internal_http_port removed\n(single listener per mode), http_bind/ssh_bind unified into bind_address\n(loopback default in both modes), allow_insecure_exposure ack \n[…]\ntrix\nreferences are removed. mkdocs --strict builds clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "docs: rework auth/network docs for v0.7.4 (bind_address, loopback def…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T21:16:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6dc43295e61119a715f93804765714532c6565f7",
          "body": "…on warning\n\nFresh-install configs now make the local-development default explicit and\ndiscoverable: the brew formula (.goreleaser.yaml, both backends) and the apt\ntemplate (packaging/server.yaml.tmpl) ship bind_address: 127.0.0.1 with inline\nguidance for exposing off-box (secure mode, or open + all\n[…]\nather than naming only the v0.6.0 base_rootfs/images keys.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "build(packaging): ship loopback bind_address default + v0.7.4 migrati…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T20:57:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6931accc3b86f931f55c34de124de6b622d3f2c3",
          "body": "…opback\n\nReplaces the per-listener http_bind/ssh_bind with a single bind_address that\ngoverns every listener (HTTP, HTTPS, SSH), and flips the default to loopback\n(127.0.0.1) in BOTH open and secure mode — shed is a local-development tool\nunless explicitly exposed. Binding a non-loopback interface i\n[…]\nsecure_exposure in open mode)\nto reach the server off-box.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "feat(server)!: unify http_bind/ssh_bind into bind_address, default lo…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T20:49:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4cef6636048d13c78125187b56da812a7e0a0a47",
          "body": "Secure mode serves no plain HTTP, so http_port is vestigial there. Both config\nloaders now drop http_port in secure mode (and default it to 8080 in open); a\nshared validateHTTPPort() helper gates the range check by mode (required 1..65535\nin open, optional/0 in secure); and http_port gains `omitempt\n[…]\n(it previously\naccepted it). Valid configs are unaffected.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "feat(server): make http_port optional, required only for open mode",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T20:34:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c8b5fe1f8251507100e4da809f1df5c966ddaf0b",
          "body": "Secure mode no longer has any plaintext escape hatch. The credential bus\n(/api/plugins/*) and the Connect tunnel (/api/sheds/*/connect/*) now ride the\nsingle public listener — plain HTTP in open mode, pinned TLS in secure mode —\ngated by the credentials scope in secure mode. Collapses Router()/Inter\n[…]\nl_http_port is removed; configs carrying it fail to start.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01JUFYH4WHfbtQ3YFhMQUBkP",
          "is_bot": false,
          "headline": "refactor(server)!: drop internal_http_port — one listener per mode",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-19T20:17:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "27b701c6b4c31bcc68f03ae399315011244aa7f7",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.3",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-18T05:08:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "380a6a6ccd7518759a783dd96f677d6293a82285",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.3 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-18T05:08:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5f3770782451475a7c48f77787eff01367aaab6b",
          "body": "…ver list, default-TLS add (#209)\n\n* feat(api): report https_port on /api/info\n\nAdd HTTPSPort to ServerInfo, populated from the server's configured HTTPSPort, so a client can learn a secure server's TLS endpoint from /api/info. Omitted (omitempty) in open mode and decoded as a zero value by older cl\n[…]\nest case. Addresses CodeRabbit PR review on #209.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: secure-server CLI UX — https_port on /api/info, security in ser…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-18T05:06:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c51f6fc6c000ed9cd37d3a033305accf06917f1a",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.2",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-16T00:49:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "93eb08ac9609a7951f9d33df0aac0ab447c8b41f",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.2 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-16T00:49:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3521a237060506dbd623d4ee85fe671e3000078d",
          "body": "Pull the v0.4.3 shed-extensions guest binaries (host-agent: mint credential tokens only for secure https servers) into the vz/full + fc image variants.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(images): bump SHED_EXT_VERSION to v0.4.3",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-16T00:45:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a18533755b2c92dae0395bb4adfd402883ad75a7",
          "body": "…(v0.7.2) (#208)\n\n* feat(auth): collapse auth surface — secure is TLS-only, https⟺secure (breaking)\n\nSimplify the v0.7.x auth surface to a clean binary posture so two invariants always hold: tokens ⟺ TLS ⟺ secure, and https ⟺ secure.\n\n- Drop the independent auth.http.mode knob (and HTTPAuthConfig): \n[…]\nTPEnabled → table-driven t.Run (repo convention).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(auth): collapse auth surface — secure is TLS-only, https⟺secure …",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-16T00:35:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b6d65ff76c87185bf6df9af6d56146e7cf3553fa",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.1",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-15T07:07:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "637a0d7d616cc460cc6f9d8996efc745b1ac3cac",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.1 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-15T07:06:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "accc9159f27592c07817eaa2d2e154696e5fdcbf",
          "body": "… binary auth.mode (#207)\n\n* feat(authtoken): opaque server-tracked token store (auth v2 foundation)\n\nIntroduce internal/authtoken: short-lived, scoped bearer tokens keyed by\nSHA-256(plaintext) and bound to the minting SSH key fingerprint (subject).\nMint / Validate / RevokeBySubject / RevokeByID / L\n[…]\noken.get). Both vz/ and firecracker/ Dockerfiles.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(auth): secure-by-default auth — SSH-bootstrapped opaque tokens +…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-15T07:04:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e62ea146d4bd4671d585acf91fec37de5479ebb",
          "body": "Level-1 (cooperative, off-by-default) egress control: a shed-egress-proxy child of shed-server evaluates composable CEL profiles per shed (resolve-and-pin, always-on deny-CIDR guards, fail-closed), injects HTTP(S)_PROXY + an in-guest dockerd drop-in, and records durable audit (JSONL + ring + SSE). s\n[…]\nive on VZ + FC (allow/deny) + the no-regression suite; reviewed by Codex + CodeRabbit. Part of #203 (does not close it). See docs/reference/egress.md for the honest cooperative-not-a-boundary posture.",
          "is_bot": false,
          "headline": "feat(egress): opt-in audit-first egress control across VZ + FC (#203)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-14T06:56:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5170f068260e7b5dbe672f5b8686073c057b2534",
          "body": "Detect the host egress path MTU at VM start and lower the guest interface to\nmatch (passed via a shed.mtu= kernel arg); on a normal 1500 path nothing\nchanges, so no penalty for the common no-VPN case. VZ also MSS-clamps Docker\ncontainer egress; the FC clamp is deferred (#202, kernel lacks xt_TCPMSS).\nAdds an optional vz/firecracker guest_mtu override.\n\nValidated end-to-end on VZ against the parallel dev server. Follow-ups: #202\n(FC clamp), #203 (gvproxy evaluation).\n\nCloses #196.",
          "is_bot": false,
          "headline": "fix(net): auto-detect guest MTU for VPN/reduced-MTU paths (#196) (#201)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T19:36:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17a27516c18a751fd8a0a619184059b3ebbe6438",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.7.0",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T18:41:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "00e669f22dce2a53a8f213f2d2e0bf670e1000a3",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.7.0 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T18:41:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2d761b7ee979069468a4b97b6cbf3e83b4efc91c",
          "body": "Pulls the v0.4.1 guest-binary image (host-agent pinned-TLS + scoped-token\nrelease). Guest binaries are unchanged from v0.4.0; this keeps shed's\npinned extensions version aligned with the released host-agent.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): bump shed-extensions to v0.4.1 (#200)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T18:40:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cca2f088425e9f37085994ce773fb5dc14c292f2",
          "body": "Adds an optional, default-off authentication + transport-encryption model so shed-server can run on a public-internet VPS, while Tailscale/LAN stays the unchanged primary path.\n\n- SSH key allowlist with GitHub seeding + fail-closed last-known-good cache\n- Scoped HTTP bearer tokens (control/credentia\n[…]\nd/internal_http_port/trusted_proxy)\n- Docs: reference/security.md, guides/vps-deployment.md, upgrades/v0.6-to-v0.7.md\n\nAll controls default-off; existing deployments are byte-identical until opted in.",
          "is_bot": false,
          "headline": "feat: optional auth + pinned TLS for public-VPS deployment (#198)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T18:24:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b03e4d569e9546f12b870a474a9768193cc39dc",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.6.6",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T02:20:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e616fe2580e9360f81eb7b0cde882fbe5ebac155",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.6.6 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T02:20:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "56768d697ecb8eb8024566bfe784477a35995323",
          "body": "Pulls the v0.4.0 guest binaries into the `extensions`/`full` rootfs images\n(vz + firecracker). v0.4.0 brings the always-on fixed-path credential sockets +\nlive-only `shed-host-agent status`, and opt-in AWS passthrough mode for SSO/SAML.\n\nHost-side only: the guest binaries' interface is unchanged, so\n[…]\nno other shed\nchanges are required. The multi-arch image ghcr.io/charliek/shed-extensions:v0.4.0\n(linux/amd64+arm64) is published.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): bump shed-extensions to v0.4.0 (#197)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T02:05:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1a15a87064ebcc1e8d10710f3dcd4fb477dc2f2b",
          "body": "…tus` (#195)\n\nThe shed-host-agent approval socket is now always served at a fixed path — drop\nthe `desktop:` block (`enabled`/`socket_path`/`timeout_ms`) from the macOS\nquickstart config; routing approvals to shed-desktop only needs each provider's\npolicy set to `shed-desktop`. Verify with bare `she\n[…]\nl top-level `approval_timeout`.\n\nRequires shed-extensions with the always-on socket change (status no longer\nreads a config file).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(quickstart): host-agent approval channel is always-on; bare `sta…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-13T01:53:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "091829053f187c540b6e819127b97c4010db2b67",
          "body": "WS1: shed exec / interactive logins now export SHED_WORKSPACE (landing dir) and\nSHED_ADD_DIRS (colon-joined --add-dir targets), mirroring the provisioning-hook env\n(shared config.ProjectAddDirTargets; hook parity via Provisioner.SetAddDirs).\n\nWS2: fix the ${shed.version} token docs (configuration.md\n[…]\n verify walkthrough), vz/fc-setup\nre-scoped to Developer Setup, quick-start router, nav grouping, cli.md env-var docs,\nand a slimmed README. Also fixes two pre-existing mkdocs cross-reference anchors.",
          "is_bot": false,
          "headline": "feat(exec): SHED_WORKSPACE/SHED_ADD_DIRS env vars + docs refresh (#193)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-09T00:19:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e904fa09d3f3da2ff913eabe3b0a05b37f43155f",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(version): bump to 0.6.5",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-08T06:07:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e813fb85a1e7302f53e6f3bc4386d79e1d4030f9",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): v0.6.5 entry",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-08T06:07:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5e19beeae2c61ca0aae9b517fb5062dfc3ff30a6",
          "body": "…d-extensions v0.3.7 (#192)\n\n* feat(fc): enable docker0 bridge via custom kernel netfilter; bump shed-extensions v0.3.7\n\nFirecracker can now run Docker's default docker0 bridge (so `docker run`,\npublished ports, outbound NAT, and Testcontainers work — matching VZ), instead\nof only `--network host` +\n[…]\ngging note (the `echo '{}'` remedy is unchanged).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(fc): enable docker0 bridge via custom kernel netfilter; bump she…",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-08T05:38:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d5e5d63068b54ddea107b693d5464f7113367190",
          "body": "* feat(vz): enable docker's default docker0 bridge in the full image\n\nThe VZ `full` image shipped daemon.json with `bridge: none`, which disables\ndocker's default bridge — so plain `docker run`, published ports, and\nTestcontainers (anything on the default network) got no IP/ports; only\n`docker compo\n[…]\nrial\" cross-reference in the\nTypeScript tutorial.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vz): enable docker0 default bridge in the full image (#191)",
          "author_name": "Charlie Knudsen",
          "author_login": "charliek",
          "committed_at": "2026-06-08T03:17:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 28,
      "commits_last_year": 517,
      "latest_release_at": "2026-07-18T21:50:49Z",
      "latest_release_tag": "v0.8.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 26,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 3.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/charliek/shed",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/charliek/shed",
          "is_deprecated": false,
          "latest_version": "v0.8.0",
          "repository_url": "https://github.com/charliek/shed",
          "versions_count": 44,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T21:19:48Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        },
        {
          "name": "github.com/charliek/shed/sdk",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/charliek/shed/sdk",
          "is_deprecated": false,
          "latest_version": "v0.3.0",
          "repository_url": "https://github.com/charliek/shed",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-30T05:41:55Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 27
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 37
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        ".mise.toml",
        "Makefile",
        "desktop/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "desktop/tauri/ui/tsconfig.json"
      ],
      "toolchain_manifests": [
        "crates/Cargo.toml",
        "crates/shed-app/Cargo.toml",
        "crates/shed-broker/Cargo.toml",
        "crates/shed-core-ffi/Cargo.toml",
        "crates/shed-core/Cargo.toml",
        "crates/shed-host-agent/Cargo.toml",
        "crates/shedctl/Cargo.toml",
        "desktop/tauri/src-tauri/Cargo.toml",
        "go.mod",
        "sdk/go.mod"
      ],
      "largest_source_bytes": 175333,
      "source_files_sampled": 704,
      "oversized_source_files": 12,
      "agent_instruction_files": [
        "CLAUDE.md",
        "crates/CLAUDE.md",
        "desktop/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 23595
    },
    "dependencies": {
      "manifests": [
        "crates/Cargo.toml",
        "desktop/pyproject.toml",
        "go.mod",
        "pyproject.toml",
        "sdk/go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "go",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "github.com/charliek/shed/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/anmitsu/go-shlex",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20200514113438-38f4b401e2be"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.28"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "github.com/creack/pty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.21"
        },
        {
          "name": "github.com/distribution/reference",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.0"
        },
        {
          "name": "github.com/firecracker-microvm/firecracker-go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.1-0.20251224190957-6fb280e993d4"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.1"
        },
        {
          "name": "github.com/gliderlabs/ssh",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.8"
        },
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.4"
        },
        {
          "name": "github.com/google/cel-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.28.1"
        },
        {
          "name": "github.com/google/go-containerregistry",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.5"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/hugelgupf/p9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.0"
        },
        {
          "name": "github.com/mdlayher/vsock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.1"
        },
        {
          "name": "github.com/sirupsen/logrus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.4"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/vishvananda/netlink",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.1"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.53.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.56.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.46.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.44.0"
        },
        {
          "name": "gopkg.in/natefinch/lumberjack.v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.2.1"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.53.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 213,
        "open_issues": 36,
        "closed_ratio": 0.478,
        "closed_issues": 33,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "charliek",
          "commits": 510,
          "avatar_url": "https://avatars.githubusercontent.com/u/24948?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "docs.yml",
        "publish-images.yaml",
        "sanity-check-app.yml",
        "smoke-linux.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "go.sum",
        "package-lock.json",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "17 out of 17 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 1,
            "reason": "dependency not pinned by hash detected -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "37 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d558f882cb0e2800a625a4a5c25a365b99326dfd",
        "ran_at": "2026-07-27T18:03:24Z",
        "aggregate_score": 3.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T04:41:23Z",
      "oldest_open_prs": [
        {
          "number": 283,
          "created_at": "2026-07-25T23:54:34Z",
          "last_comment_at": "2026-07-26T01:03:52Z",
          "last_comment_author": "charliek"
        }
      ],
      "last_merged_pr_at": "2026-07-24T04:40:44Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 41,
          "created_at": "2026-03-29T17:24:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 97,
          "created_at": "2026-05-20T03:37:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 109,
          "created_at": "2026-05-25T16:48:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 110,
          "created_at": "2026-05-25T16:48:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 111,
          "created_at": "2026-05-25T16:48:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 112,
          "created_at": "2026-05-25T16:49:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 113,
          "created_at": "2026-05-25T16:49:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 114,
          "created_at": "2026-05-25T16:50:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 115,
          "created_at": "2026-05-25T16:50:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 116,
          "created_at": "2026-05-25T17:22:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 134,
          "created_at": "2026-05-29T01:03:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 183,
          "created_at": "2026-06-06T17:14:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 202,
          "created_at": "2026-06-13T19:35:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 203,
          "created_at": "2026-06-13T19:35:40Z",
          "last_comment_at": "2026-06-14T07:21:44Z",
          "last_comment_author": "charliek"
        },
        {
          "number": 205,
          "created_at": "2026-06-14T07:21:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 206,
          "created_at": "2026-06-14T18:03:05Z",
          "last_comment_at": "2026-07-26T07:38:15Z",
          "last_comment_author": "charliek"
        },
        {
          "number": 219,
          "created_at": "2026-06-26T23:51:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 221,
          "created_at": "2026-06-29T23:21:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 231,
          "created_at": "2026-07-01T06:09:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 244,
          "created_at": "2026-07-07T14:25:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/charliek/shed",
    "host": "github.com",
    "name": "shed",
    "owner": "charliek"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 38,
        "vitality": 85,
        "community": 24,
        "governance": 56,
        "engineering": 82
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 85,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "commits_last_year": 517,
              "human_commit_share": 0.98,
              "days_since_last_push": 0,
              "active_weeks_last_year": 26
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "26/52 weeks with commits",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 26
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "517 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 517
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 28,
              "latest_release_tag": "v0.8.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 3.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "28 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 28
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 3,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 3 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "merged_prs": 213,
              "open_issues": 36,
              "closed_issues": 33,
              "issue_closed_ratio": 0.478,
              "closed_unmerged_prs": 14
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "48% of issues closed",
                "points": 22.3,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 48
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "213/227 decided PRs merged",
                "points": 35.9,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 213,
                      "decided": 227
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "followers": 60,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "charliek",
              "public_repos": 67,
              "account_age_days": 6522
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "60 followers of charliek",
                "points": 12.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 60,
                      "login": "charliek"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "67 public repos, account ~17 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 67
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 17
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/charliek/shed",
                "github.com/charliek/shed/sdk"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "44 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 44
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 82,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "17 out of 17 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://charliek.github.io/shed/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://charliek.github.io/shed/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 38,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "17 out of 17 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 0.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "37 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 87,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md",
                "crates/CLAUDE.md",
                "desktop/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 23595
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md, crates/CLAUDE.md, desktop/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md, crates/CLAUDE.md, desktop/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 83,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "go.sum",
                "package-lock.json",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                ".mise.toml",
                "Makefile",
                "desktop/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "desktop/tauri/ui/tsconfig.json"
              ],
              "agent_commit_share": 0.84,
              "toolchain_manifests": [
                "crates/Cargo.toml",
                "crates/shed-app/Cargo.toml",
                "crates/shed-broker/Cargo.toml",
                "crates/shed-core-ffi/Cargo.toml",
                "crates/shed-core/Cargo.toml",
                "crates/shed-host-agent/Cargo.toml",
                "crates/shedctl/Cargo.toml",
                "desktop/tauri/src-tauri/Cargo.toml",
                "go.mod",
                "sdk/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": ".mise.toml, Makefile, desktop/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".mise.toml, Makefile, desktop/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "desktop/tauri/ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "desktop/tauri/ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "84 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 84,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 175333,
              "source_files_sampled": 704,
              "oversized_source_files": 12
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "12/704 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 704,
                      "oversized": 12
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch pypi package 'shed-docs' from its registry",
    "Could not fetch pypi package 'shed-desktop-tools' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T18:03:41.606375Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/charliek/shed.svg",
  "full_name": "charliek/shed",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.