Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-25 09:49 UTC

cyanheads / mcp-ts-core

Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.

TypeScriptApache-2.0★ 147 estrellas⑂ 29 forksdesde mar 2025Ver en GitHub ↗

cyanheads/mcp-ts-core tiene un índice de salud de 65 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (93/100) y la más baja, Security (47/100). Se actualizó por última vez hace 3 días. Una sola persona concentra la mayor parte del trabajo reciente.

65
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

65
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Casey HandCuenta personal
175 seguidores146 repositorios públicosdesde dic 2014

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

93Excelente · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 3 días
23.5/36Cadencia de commits — 34/52 semanas con commits
18/18Volumen de commits — 1289 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year1289
human_commit_share1
days_since_last_push3
active_weeks_last_year34
Cómo se puntúa
27/27Publica versiones — 33 versiones publicadas
36/36Recencia de las versiones — última versión hace 5 días
27/27Cadencia de publicación — una versión cada ~4,2 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count33
latest_release_tagv0.10.15
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases4,2
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

56Moderado · 18% del índice global
Cómo se puntúa
35.1/60Estrellas — 147 estrellas
12.1/25Forks — 29 forks
0/15Observadores — 2 observadores
Datos de entrada utilizados
forks29
stars147
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
62/80Descargas mensuales — 44.618 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@cyanheads/mcp-ts-core
dependents
ecosystemsnpm
total_downloads
monthly_downloads44.618
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

55Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0.1/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
2.7/13.5Amplitud de contribuyentes — 2 contribuyentes
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Datos de entrada utilizados
bus_factor1
contributors_sampled2
top_contributor_share0,995
Cómo se puntúa
35.9/46.8Resolución de issues — 77% de issues cerradas
19.1/38.3Aceptación de PR — 13/26 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs13
open_issues59
closed_issues195
issue_closed_ratio0,768
closed_unmerged_prs13
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
16.1/25Alcance del propietario — 175 seguidores de cyanheads
25/25Trayectoria — 146 repos públicos, cuenta de ~11 años
Datos de entrada utilizados
followers175
owner_typeUser
is_verified
owner_logincyanheads
public_repos146
account_age_days4225
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 142 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@cyanheads/mcp-ts-core
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

70Bueno · 20% del índice global
Cómo se puntúa
0/24Flujos de trabajo de CI
24/24Pruebas presentes
16/16Configuración de linter — biome.json
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_cino
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

100Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://www.npmjs.com/package/@cyanheads/mcp-ts-core
10/10Descripción del repositorio
10/10Topics — 10 topics
10/10Wiki
Datos de entrada utilizados
topicsmcp, mcp-server, model-context-protocol, ai, opentelemetry, cloudflare-workers, agent-native, framework, typescript, cyanheads
has_wiki
homepagehttps://www.npmjs.com/package/@cyanheads/mcp-ts-core
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

47En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
0/10Dangerous-Workflow — sin datos
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — sin datos
0/5Pinned-Dependencies — sin datos
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — sin datos
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate3,7
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Los pesos restantes se han renormalizado.
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
13.2/25Dependencias indirectas libres de avisos conocidos — 1 afectados: @hono/node-server 1.19.15 (moderate 5.9)
40/40Sin avisos pendientes — ningún aviso lleva público más de 90 días
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages115
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Se cotejó el cierre de dependencias en tiempo de ejecución de npm:@cyanheads/mcp-ts-core@0.10.15 —lo que arrastra la instalación del paquete publicado—: 115 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

74Bueno · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 100 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md
agent_instruction_max_bytes39.823
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
11/11Configuración de lint / formato — biome.json
11/11Verificación estática de tipos — tsconfig.json
10/10Entorno reproducible — Dockerfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — sin datos
Datos de entrada utilizados
has_nixno
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainerno
has_linter_config
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Pinned-Dependencies. Los pesos restantes se han renormalizado.
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
55/55Tamaños de archivo manejables — 0/445 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes54.037
source_files_sampled445
oversized_source_files0
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signal
api_schema_files

Datos clave

147estrellas de GitHub
2contribuidores
1289commits en los últimos 12 meses
3días desde el último push
33versiones publicadas
1factor bus
59issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package '{{PACKAGE_NAME}}' from its registry

Más detalle

Historial de estrellas y forks 0 ★ / 29 ⇿
0Estrellas
29Forks
28Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

0510152025302922025-042025-112026-07
Mayor 0Menor 1Parche 27

Cada punto abarca 2 días.

OpenSSF Scorecard 3.7 / 10
3.7agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-25 09:49 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
n/dDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
n/dPackagingpackaging workflow not detected
n/dPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
n/dToken-PermissionsNo tokens found
1Vulnerabilities9 existing vulnerabilities detected
Dependencias directas 13
RegistroPaqueteRestricción de versiónManifiesto
npm@hono/mcp^0.3.1package.json
npm@hono/node-server^2.0.10package.json
npm@modelcontextprotocol/ext-apps^1.7.4package.json
npm@modelcontextprotocol/sdk^1.29.0package.json
npm@opentelemetry/api^1.9.1package.json
npmdotenv^17.4.2package.json
npmhono^4.12.30package.json
npmjose^6.2.3package.json
npmpino^10.3.1package.json
npmzod^4.4.3package.json
npm@cyanheads/mcp-ts-core^{{FRAMEWORK_VERSION}}templates/package.json
npmpino-pretty^13.1.3templates/package.json
npmzod{{ZOD_VERSION}}templates/package.json
Todas las dependencias 66

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 13 paquetes directos y 53 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
npm@cyanheads/mcp-ts-core^{{FRAMEWORK_VERSION}}directa
npm@hono/mcp^0.3.1directa
npm@hono/node-server^2.0.10directa
npm@modelcontextprotocol/ext-apps^1.7.4directa
npm@modelcontextprotocol/sdk^1.29.0directa
npm@opentelemetry/api^1.9.1directa
npmdotenv^17.4.2directa
npmhono^4.12.30directa
npmjose^6.2.3directa
npmpino^10.3.1directa
npmpino-pretty^13.1.3directa
npmzod^4.4.3directa
npmzod{{ZOD_VERSION}}directa
npm@biomejs/biome2.5.4indirecta
npm@cloudflare/vitest-pool-workers^0.18.4indirecta
npm@cloudflare/workers-types5.20260706.1indirecta
npm@duckdb/node-api^1.5.4-r.1indirecta
npm@hono/otel^1.1.2indirecta
npm@opentelemetry/exporter-metrics-otlp-http^0.220.0indirecta
npm@opentelemetry/exporter-trace-otlp-http^0.220.0indirecta
npm@opentelemetry/instrumentation-http^0.220.0indirecta
npm@opentelemetry/instrumentation-pino^0.66.0indirecta
npm@opentelemetry/resources^2.9.0indirecta
npm@opentelemetry/sdk-metrics^2.9.0indirecta
npm@opentelemetry/sdk-node^0.220.0indirecta
npm@opentelemetry/sdk-trace-node^2.9.0indirecta
npm@opentelemetry/semantic-conventions^1.43.0indirecta
npm@socketsecurity/bun-security-scanner^1.1.2indirecta
npm@supabase/supabase-js^2.110.6indirecta
npm@types/bun^1.3.14indirecta
npm@types/node26.1.1indirecta
npm@types/papaparse^5.5.2indirecta
npm@types/sanitize-html^2.16.1indirecta
npm@types/validator^13.15.10indirecta
npm@vitest/coverage-istanbul4.1.10indirecta
npm@vitest/ui4.1.10indirecta
npmbetter-sqlite3^12.11.1indirecta
npmbun-types^1.3.14indirecta
npmchrono-node^2.10.0indirecta
npmclipboardy^5.3.1indirecta
npmdefuddle^0.19.1indirecta
npmdepcheck^1.4.7indirecta
npmdiff^9.0.0indirecta
npmexeca^9.6.1indirecta
npmfast-check^4.9.0indirecta
npmfast-xml-parser^5.10.1indirecta
npmignore^7.0.5indirecta
npmignore^7.0.6indirecta
npmjs-yaml^5.2.1indirecta
npmlinkedom^0.18.13indirecta
npmnode-cron^4.6.0indirecta
npmopenai^6.46.0indirecta
npmpapaparse^5.5.4indirecta
npmpartial-json^0.1.7indirecta
npmpdf-lib^1.17.1indirecta
npmrepomix^1.16.1indirecta
npmsanitize-html^2.17.6indirecta
npmtsc-alias^1.9.0indirecta
npmtsc-alias^1.9.1indirecta
npmtypedoc^0.28.20indirecta
npmtypescript^6.0.3indirecta
npmunpdf^1.6.2indirecta
npmvalidator^13.15.35indirecta
npmvite8.1.5indirecta
npmvitest^4.1.10indirecta
npmvitest^4.1.9indirecta
Avisos de dependencias 1

Instalar npm:@cyanheads/mcp-ts-core@0.10.15 arrastra 115 paquetes, directos y transitivos: 1 tienen avisos conocidos, de los cuales 0 son dependencias directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
@hono/node-server1.19.15indirectamoderada12.0.5

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "mcp",
        "mcp-server",
        "model-context-protocol",
        "ai",
        "opentelemetry",
        "cloudflare-workers",
        "agent-native",
        "framework",
        "typescript",
        "cyanheads"
      ],
      "is_fork": false,
      "size_kb": 8898,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
      "languages": {
        "Shell": 102,
        "Dockerfile": 9732,
        "JavaScript": 109642,
        "TypeScript": 3872892
      },
      "pushed_at": "2026-07-22T01:11:54Z",
      "created_at": "2025-03-20T05:07:04Z",
      "owner_type": "User",
      "updated_at": "2026-07-24T18:42:03Z",
      "description": "Agent-native TypeScript framework for building MCP servers. Declarative definitions with auth, multi-backend storage, OpenTelemetry, and first-class support for Bun/Node/Cloudflare Workers.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://caseyjhand.com",
      "name": "Casey Hand",
      "type": "User",
      "login": "cyanheads",
      "company": null,
      "location": "Seattle, WA",
      "followers": 175,
      "avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4",
      "created_at": "2014-12-29T13:01:12Z",
      "is_verified": null,
      "public_repos": 146,
      "account_age_days": 4225
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.15",
          "kind": "patch",
          "published_at": "2026-07-19T12:24:31Z"
        },
        {
          "tag": "v0.10.14",
          "kind": "patch",
          "published_at": "2026-07-06T08:08:16Z"
        },
        {
          "tag": "v0.10.13",
          "kind": "patch",
          "published_at": "2026-07-05T18:04:33Z"
        },
        {
          "tag": "v0.10.12",
          "kind": "patch",
          "published_at": "2026-07-05T08:45:52Z"
        },
        {
          "tag": "v0.10.11",
          "kind": "patch",
          "published_at": "2026-07-05T05:59:38Z"
        },
        {
          "tag": "v0.10.10",
          "kind": "patch",
          "published_at": "2026-06-30T09:19:32Z"
        },
        {
          "tag": "v0.10.9",
          "kind": "patch",
          "published_at": "2026-06-20T07:52:14Z"
        },
        {
          "tag": "v0.10.8",
          "kind": "patch",
          "published_at": "2026-06-19T23:56:33Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2026-06-19T21:26:53Z"
        },
        {
          "tag": "v0.10.6",
          "kind": "patch",
          "published_at": "2026-06-11T20:27:22Z"
        },
        {
          "tag": "v0.10.5",
          "kind": "patch",
          "published_at": "2026-06-11T16:51:26Z"
        },
        {
          "tag": "v0.10.4",
          "kind": "patch",
          "published_at": "2026-06-11T01:20:20Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-06-10T23:14:46Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-06-10T17:48:09Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-06-08T14:46:42Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-05T12:16:41Z"
        },
        {
          "tag": "v0.9.21",
          "kind": "patch",
          "published_at": "2026-06-02T09:05:28Z"
        },
        {
          "tag": "v0.9.20",
          "kind": "patch",
          "published_at": "2026-06-02T03:44:02Z"
        },
        {
          "tag": "v0.9.19",
          "kind": "patch",
          "published_at": "2026-05-31T11:08:20Z"
        },
        {
          "tag": "v0.9.18",
          "kind": "patch",
          "published_at": "2026-05-31T10:18:08Z"
        },
        {
          "tag": "v0.9.17",
          "kind": "patch",
          "published_at": "2026-05-31T05:42:27Z"
        },
        {
          "tag": "v0.9.16",
          "kind": "patch",
          "published_at": "2026-05-30T03:28:09Z"
        },
        {
          "tag": "v0.9.15",
          "kind": "patch",
          "published_at": "2026-05-30T02:47:15Z"
        },
        {
          "tag": "v0.9.14",
          "kind": "patch",
          "published_at": "2026-05-29T11:58:20Z"
        },
        {
          "tag": "v0.9.13",
          "kind": "patch",
          "published_at": "2026-05-29T01:58:44Z"
        },
        {
          "tag": "v0.9.12",
          "kind": "patch",
          "published_at": "2026-05-29T00:42:33Z"
        },
        {
          "tag": "v0.9.11",
          "kind": "patch",
          "published_at": "2026-05-28T08:26:20Z"
        },
        {
          "tag": "v0.9.10",
          "kind": "patch",
          "published_at": "2026-05-27T04:33:29Z"
        },
        {
          "tag": "v0.9.9",
          "kind": "patch",
          "published_at": "2026-05-24T10:13:49Z"
        },
        {
          "tag": "v0.9.8",
          "kind": "patch",
          "published_at": "2026-05-24T09:30:02Z"
        },
        {
          "tag": "v0.9.7",
          "kind": "patch",
          "published_at": "2026-05-23T16:45:02Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2026-05-23T10:27:23Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-05-23T08:40:15Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
          "body": "…fields, expectedStatuses opt-out",
          "is_bot": false,
          "headline": "chore(release): 0.10.15 — Retry-After honoring, canonical HTTP error …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:20:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac3b9e5aee765fdbacc4415b997ab0f9925284d7",
          "body": "Dependency arrows of note: @biomejs/biome 2.5.2 -> 2.5.4 (biome.json\nschema migrated via 'bunx biome migrate'), @cloudflare/vitest-pool-workers\n^0.18.0 -> ^0.18.4, @opentelemetry/semantic-conventions ^1.41.1 -> ^1.43.0,\nhono ^4.12.27 -> ^4.12.30, vite 8.1.3 -> 8.1.5, vitest/@vitest/coverage-istanbul\n[…]\n'\ncasts; fixed across 7 test files by extracting the cast to a local\nbefore the property access (behavior-preserving). The remaining 2 test\nfiles carry only Biome's it.each argument-list reformatting.",
          "is_bot": false,
          "headline": "chore(deps): bun update; biome 2.5.4 migration; typescript 7 held",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:18:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53ed7cd01b96c3d45a6b9c81f4a0d6dd53f4009d",
          "body": "…l-defs-analysis 1.4\n\ngit-wrapup: tag-annotation format overhauled to a flat-bullet headline\ndigest — no Keep-a-Changelog section headers, no gates line, deps\ncapped at one line naming only what earns it; notable changes get\ntheir own bullet, minor/internal items share one grouped bullet.\norchestrat\n[…]\ns (naming taxonomy, parameter vocabulary, tool overlap,\ninstructions drift, length outliers).\n\nfield-test-fix.md, fix-wrapup-release.md, maintenance-release.md updated\nto reference the new tag format.",
          "is_bot": false,
          "headline": "docs(skills): field-test 2.7, git-wrapup 1.8, orchestrations 1.7, too…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c00f24e7bb63d33f562e0d701faacb162badcdb",
          "body": "The 0.10.13 agent-notes told downstream maintenance agents to add a\ntrustedDependencies entry alongside the @socketsecurity/bun-security-scanner\ndevDependency. No such entry exists in that release — the instruction\nwould send an adopting agent looking for something that isn't there.",
          "is_bot": false,
          "headline": "docs(changelog): drop trustedDependencies from 0.10.13 notes (#281)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "685203b8c8ab1c8be4e4df458fc9001295924de9",
          "body": "…ror fields (#256, #279)\n\nfetchWithTimeout gains options.expectedStatuses: number[] — a listed\nnon-2xx status logs at debug instead of error; the thrown, status-mapped\nMcpError is unchanged. Also stops double-logging: the catch block now\nre-throws a FetchHttpError-tagged McpError as-is instead of re\n[…]\nside the\npre-existing statusCode/responseBody aliases (kept, identical values) so\na consumer can read either helper's error the same way.\n\nskills/api-utils/SKILL.md documents both changes (2.4 → 2.5).",
          "is_bot": false,
          "headline": "feat(network): expectedStatuses log opt-out; canonical status/body er…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:17:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d6143cc8c91701025dbe292b8521de24244b1fd",
          "body": "Parses an upstream Retry-After hint (RFC 9110 §10.2.3 delta-seconds\nor HTTP-date) off McpError.data.retryAfter and waits that long instead\nof blind exponential backoff. The honored delay is not jittered. When\nthe requested wait exceeds maxDelayMs, the error is treated as\nnon-transient and fails fast with the original error rather than\nburning an attempt that can't succeed in time.",
          "is_bot": false,
          "headline": "feat(network): withRetry honors Retry-After (#285)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-19T12:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "352addd4d50a55cd73c04c64e7a86bad0fa0c671",
          "body": "Split the dense post-snippet block into shorter paragraphs, cut a redundant sentence, and tighten wording. Facts and code samples unchanged.",
          "is_bot": false,
          "headline": "docs: condense README intro prose",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T09:26:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6a6235c923aaabfd4b172cad81a919a38e6b482",
          "body": "…oc fixes\n\nVersion bumps across package.json, server.json, README, CLAUDE.md, AGENTS.md; changelog 0.10.14; regenerated CHANGELOG.md rollup and docs/tree.md.",
          "is_bot": false,
          "headline": "chore(release): 0.10.14 — Docker build, linter null guard, canvas + d…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "738a6bb9bd6431b49f012ddc504f7b23332011db",
          "body": "…262)\n\nA bare-token curl 404s on the multi-arch OCI indexes docker buildx pushes; the manifest-list Accept header is missing. docker manifest inspect resolves them and exits non-zero when the tag is genuinely absent.",
          "is_bot": false,
          "headline": "docs(release-and-publish): verify GHCR via docker manifest inspect (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f40d4383847f5ce21f3f9e67ee0a95b9c8bbbbe",
          "body": "…minated union (#249)\n\nOUTLINE_VARIANT and outlineOnOverflow JSDoc and the techniques, add-tool, and design-mcp-server skills advertised a z.discriminatedUnion output that tool() rejects (schema-is-object lint and enrichment .extend() are ZodObject-only). Document the flat z.object with a kind discriminator and presence-based optional arms, rendered per field presence in format(). Docs and JSDoc only; no runtime change.",
          "is_bot": false,
          "headline": "docs(overflow): correct outline output to a flat object, not a discri…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb9a6321d856dac49592da1511695db6f22eba19",
          "body": "…overy (#264)\n\nMirror the missing_table precedent from query(): the source-table-not-found throw in DuckdbProvider.importFrom now sets reason missing_table plus a recovery hint. The sibling import_same_canvas and import_view_clash throws gain recovery hints too.",
          "is_bot": false,
          "headline": "fix(canvas): importFrom missing-table NotFound carries reason and rec…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13dbdbdbefa7b7a87ec76640a328c5eb4787f58e",
          "body": "… entry (#265)\n\nA null or undefined entry in a tools/resources/prompts array threw a TypeError and aborted validateDefinitions; only the prompts path survived. Harden the three shared sub-linters (lintEnrichmentContract, lintCappedListTruncation, lintHandlerBody) to early-return on a non-object def, and guard each per-definition loop before dispatch, emitting one definition-invalid error per bad entry. Adds src/linter/rules/definition-rules.ts.",
          "is_bot": false,
          "headline": "fix(linter): surface definition-invalid instead of crashing on a null…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:05:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a546e8e4db6d71236bce5049dd938ebc38f5f13",
          "body": "The build stage ran every dependency lifecycle script; better-sqlite3 prebuild-install falls back to node-gyp (absent in oven/bun) and exits 127, failing the build. Match the production stage with --ignore-scripts: the build only runs tsc, which needs type declarations, not native bindings. templates/Dockerfile mirrors it.",
          "is_bot": false,
          "headline": "fix(build): install with --ignore-scripts in Docker build stage (#267)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-06T08:04:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e82602fdbf699318a63a740bca990d3ca0061e92",
          "body": "…ization",
          "is_bot": false,
          "headline": "chore(release): 0.10.13 — supply-chain guard, coverage, config modern…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:01:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29e3ceb99a7453a83f620f5e08e8f0e617566ed8",
          "body": "AGENTS.md and CLAUDE.md note that init now scaffolds bunfig.toml, LICENSE, and .gitattributes. .github/FUNDING.yml trims to the active github and buy_me_a_coffee entries; LICENSE copyright year 2025 → 2026 (still Apache-2.0).",
          "is_bot": false,
          "headline": "docs: sync consumer-path list; trim FUNDING; LICENSE year 2026",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "53aca5fc19253a53c30aa365e3bac7c591b6f8c3",
          "body": "…lish-docs-meta 2.11\n\napi-workers documents the @duckdb/node-api Worker stub alias. git-wrapup and orchestrations add the changelog-link final line to tag bodies. polish-docs-meta covers manifest.json author identity plus author/packageManager/engines metadata guidance.",
          "is_bot": false,
          "headline": "docs(skills): api-workers 1.6, git-wrapup 1.7, orchestrations 1.6, po…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7940d011996224e29aaf1dc506352cbfb0cb9d87",
          "body": "init now copies an Apache-2.0 LICENSE and a .gitattributes (LF normalization, binary-asset and machine-generated markers) into newly scaffolded servers.",
          "is_bot": false,
          "headline": "feat(templates): scaffold LICENSE and .gitattributes",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5f5027b6404f6ef5fa4d3d16f2b36b73f8d34b2",
          "body": "tsconfig.json extends a deduped tsconfig.base.json; the base moves target/lib ESNext → ES2025 (plus ESNext.TypedArrays). Dockerfile and templates/Dockerfile pin oven/bun:1.3.14 and add BuildKit install-cache mounts. .gitattributes overhauls the lockfile and linguist-generated markers and the git-arc\n[…]\nommit gains a POSIX shebang. Stricter-tsconfig script fixes: devdocs.ts explicit return, lint-mcp.ts conditional packageJson spread, tree.ts entries() iteration. typedoc drops the scripts entry point.",
          "is_bot": false,
          "headline": "build: modernize tsconfig, Dockerfile, and tooling config",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T18:00:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e0fbfd49e4365027c17e8ae8e8623e47bddb49b",
          "body": null,
          "is_bot": false,
          "headline": "chore: drop Smithery deployment config",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69433f431c6e695df623a831b57561d1f34d1821",
          "body": "wrangler.toml becomes wrangler.jsonc (schema-referenced, inline comments). An alias maps @duckdb/node-api to examples/duckdb-stub.ts so wrangler's esbuild step stops failing on DuckDB's native bindings — the DataCanvas provider's lazy import() is statically reachable from the Worker entry but never executes there.",
          "is_bot": false,
          "headline": "build(workers): migrate wrangler config to JSONC; stub @duckdb/node-api",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "114edd0339601adcc4294ffab99e024c7ce236c0",
          "body": "bunfig.toml adds a 3-day minimumReleaseAge hold on fresh publishes and an [install.security] Socket scanner; package.json declares the @socketsecurity/bun-security-scanner devDependency and trusts it. devcheck's Outdated gate now skips versions bun holds by release age (Update == Current, marked *),\n[…]\n .github/SECURITY.md adds a disclosure policy.\n\npackage.json also drops the unused main/types fields, adds a prepare hook-path script, bumps packageManager to bun@1.3.14, and sets the author identity.",
          "is_bot": false,
          "headline": "chore(security): minimumReleaseAge hold + Socket install scanner",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:59:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e301d1fe4e54c48702db126410acbeedbcb99554",
          "body": "…/services",
          "is_bot": false,
          "headline": "test: expand unit coverage; move DuckDB smoke suite under tests/smoke…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T17:58:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebbb12bfe2a8e37cbbccface856c59a9ae758c98",
          "body": "…separator",
          "is_bot": false,
          "headline": "chore(release): 0.10.12 — canvas error contracts, enrichment trailer …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c415f70563ad2bef2ae6eda735f136151f24269",
          "body": "…h (#261, #254)\n\nCanvasRegistry's not-found throws (acquire, touchOrThrow, touchWithTable, touchWithSqlTables) and DuckdbProvider.requireCanvas() now carry data.reason 'canvas_not_found', the canvasId, and a default recovery.hint, so consumer-declared canvas_not_found error contracts populate on the\n[…]\ny-structured McpError unchanged instead of reclassifying it to DatabaseError, preserving register_as_clash and export_path_* ValidationError codes and data across all four provider catch sites (#254).",
          "is_bot": false,
          "headline": "fix(canvas): structured canvas_not_found errors, McpError pass-throug…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07928d739c5ab069b8ca38c5339a2517bb0906c3",
          "body": "Clients that concatenate adjacent content[] text blocks with no join (Claude Desktop, claude.ai) rendered the trailer glued onto the last domain line. Markdown collapses consecutive blank lines, so clients that insert their own separator render at most one blank line either way.",
          "is_bot": false,
          "headline": "fix(tools): lead enrichment trailer with a blank-line separator (#257)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T08:44:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0c35f0558e3375079acc9212ffb7937b7ece8c9",
          "body": "…ics, dep refresh",
          "is_bot": false,
          "headline": "chore(release): 0.10.11 — scaffold devcheck fix, security-flag semant…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:56:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf33b280dfaf83378157eafb3961dfbb3cfea0a3",
          "body": "…overy discipline\n\nAdds the Reference tool shape to the taxonomy (decoder ring for opaque domain vocabulary — codes, enums, identifier formats; the standing target of recovery routing; implement first) with its own subsection. API probing gains unknown-param and omission-semantics probes, and the st\n[…]\nfalse, guidance } instead of throwing, zero-hit behavior is specced at design time, and design docs settle verbatim recovery strings under a no-dead-ends rule (each names the concrete next tool call).",
          "is_bot": false,
          "headline": "docs(skills): design-mcp-server 2.19 — reference tools, probe and rec…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:51:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8199830341c44d465e6c02bbd98e7224ae512d2e",
          "body": "@biomejs/biome 2.5.1 → 2.5.2 (biome.json $schema follows), @cloudflare/vitest-pool-workers ^0.16.20 → ^0.18.0, @cloudflare/workers-types 4.20260630.1 → 5.20260705.1, @opentelemetry/* 0.219→0.220 and 2.8→2.9 sets, @opentelemetry/instrumentation-pino ^0.65.0 → ^0.66.0, @supabase/supabase-js ^2.109.0 →\n[…]\nte 8.1.0 → 8.1.3.\ntemplates/package.json pins @biomejs/biome 2.5.2 and @types/node 26.1.0 so a fresh scaffold's Biome CLI matches the shared config's $schema and devcheck passes out of the box (#260).",
          "is_bot": false,
          "headline": "chore(deps): bun update --latest; align template biome/types pins (#260)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:46:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8ff580bcbf7110eb5539d859339c768a02a657c",
          "body": "…263)\n\n0.9.0 removed the startup lint gate — createApp() no longer invokes validateDefinitions — but three comment sites still described it: the errors-contract and format-parity JSDoc in toolDefinition.ts and the startup-fatal error comment in app.ts. All three now state the current mechanism (bun run lint:mcp, gated in devcheck). These ship in the published .d.ts, so hover docs previously contradicted actual behavior.",
          "is_bot": false,
          "headline": "docs(src): stale startup-linter JSDoc corrected to build-time lint (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:46:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4fc2f05c948da905d86127aceadc95e6046ba11",
          "body": "… as-built\n\nRoot protocol: definition linting described as build-time (bun run lint:mcp / devcheck), not startup — schema-serializable and format-parity notes corrected; init copy list completed (devcheck.config.json, tests, scripts/, skills/, never-overwrite + in-place upgrade); ContentCollect/Cont\n[…]\n(devcheck removed; techniques and api-mirror added; bun run list-skills), commands table moved npm→bun and gains lint:mcp / lint:packaging / list-skills rows, security frontmatter scoped the same way.",
          "is_bot": false,
          "headline": "docs(protocol): sync CLAUDE.md/AGENTS.md and template counterparts to…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0736c339d407ed94df2c285971e2049f2da1260",
          "body": "git-wrapup 1.6: create annotated tags with --cleanup=whitespace (default strip deletes #-leading markdown lines; verbatim breaks SSH signature parsing and leaks the signature block into the release body), verify the tag reads as signed in the end-state check, and scope the changelog security flag to\n[…]\nruns the project gates, and three transformation rows corrected (TS 5.5 inferred type predicates, enum-value serialization caveat, walrus example).\napi-utils 2.4, polish-docs-meta 2.10: version bumps.",
          "is_bot": false,
          "headline": "docs(skills): tag-signature safeguards, code-simplifier corrections",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18abb9cd5b3312619179ee6186cb4d303b091b77",
          "body": "The security frontmatter field flags a vulnerability or hardening fix in this project's own code. A dependency or transitive CVE bump is routine maintenance: it stays under ## Dependencies with the flag false, so the Security badge answers \"does the shipped code have a vuln\" rather than tripping on every dep refresh. Tightened in both changelog templates and the build-changelog JSDoc.",
          "is_bot": false,
          "headline": "docs(changelog): scope security flag to source-code fixes only",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-07-05T05:45:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8373752be1f3395fb2f05c224bbd512b88b4165",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.10.10 — js-yaml v5 migration, dependency refresh",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-30T09:16:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c34bf3dc3b3dd43cfc68fc94448df9dc96eefc2",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): remove Contributing from readme reference",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-30T09:16:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a95a408dd2a77eff8501f3e4952bc65bcc1bae3d",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): remove Contributing section",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-28T08:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c5b9ccb6e01cc88a0064b2e94f5ab9b669bee85",
          "body": "…uards\n\n@cloudflare/workers-types 4.20260619.1 → 4.20260620.1",
          "is_bot": false,
          "headline": "chore(release): 0.10.9 — devcheck dep-specifier and plugin-manifest g…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-20T07:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af5d2643d70b08990fb3f292c74b579663da67ad",
          "body": "…manifests (#246, #240)\n\ncheck-dependency-specifiers (new ALL_CHECKS step, --no-dep-specifiers): hard-fails on latest/*/dist-tag specifiers in package.json's four dep sections and bun.lock's workspaces map, never the packages section. latest fails everywhere; */next/beta/canary/rc fail in dependenci\n[…]\nnstall arg (an unscoped arg for a scoped package 404s). Gated by devcheck.config.json packaging.pluginManifests (default on); the Packaging gate now also runs when a plugin manifest is present. (#240)",
          "is_bot": false,
          "headline": "feat(devcheck): guard floating dep specifiers and plugin marketplace …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-20T07:46:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3de075e7b090a669334e8e4378de9e5fcb20f98",
          "body": "…assification",
          "is_bot": false,
          "headline": "chore(release): 0.10.8 — ctx.content collector, canvas invalid_sql cl…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "669ae01e52082d23bf3417f2756b83d8aff9324d",
          "body": "…(#239)",
          "is_bot": false,
          "headline": "feat(context): add ctx.content collector for non-text content blocks …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1761990cd6080eab5d4c62421c9e6999b69953d2",
          "body": "…ith binder detail (#236)",
          "is_bot": false,
          "headline": "fix(canvas): classify SELECT-shaped prepare failures as invalid_sql w…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267e6da839c3b7dddd0e50463019ada1a106a1c1",
          "body": "…eeds it (#233)",
          "is_bot": false,
          "headline": "docs(telemetry): correct OTEL_SERVICE_NAME default — createApp name s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T23:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa1faca2c84607ea2e53887a4cdee69c5f6dec49",
          "body": "…x, dep refresh\n\nFresh-scaffold devcheck fixes (#242 #243), check-skill-versions worktree-deletion guard (#237), and the DuckdbProvider.describe() Binder Error fix (#235); seven skill version bumps (#238). Dependency refresh: biome 2.4.16 -> 2.5.0 (biome migrate applied to biome.json), node-cron 4.2\n[…]\nuler test moved to vi.mock for the frozen ESM namespace), and the resolutions block trimmed to one js-yaml pin (bun audit clean). Version bumped across package.json, server.json, CLAUDE.md, AGENTS.md.",
          "is_bot": false,
          "headline": "chore(release): 0.10.7 — devcheck scaffold guards, canvas describe fi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7d73e49c18598a3db6a72d60d141a17c9a06edb",
          "body": "…244)\n\nThe #157 body-size tests assert only an eventual 413, which passes even when the whole over-limit body is buffered via arrayBuffer() first. This adds an instrumented-stream test asserting the cap bounds buffering — cancels the stream shortly after the limit on a no-Content-Length body. Marked test.fails: the current buffer-then-check code does not satisfy it, so the suite stays green while #244 is open; implementing the streaming cap flips it red as the signal to restore test.",
          "is_bot": false,
          "headline": "test(transport): stage streaming body-cap regression as test.fails (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5e164216ada101b985998c12fae3d023ca20079",
          "body": "…ver isolation note\n\ngit-wrapup v1.4: tag annotations may carry one concise context line under the subject (one or two lines, never paragraph blocks); restate the Bash-git rule without the obsolete git-mcp-server rationale. orchestrations v1.4: parallel sub-agents drive git through the shell against their own working directory.",
          "is_bot": false,
          "headline": "docs(skills): allow one tag-annotation context line; drop git-mcp-ser…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:24:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe9e8b48439374b5c9fc551eb8872009fc20e900",
          "body": "…y drift (#238)\n\nSeven external skills carried body changes that shipped pre-0.9.18 with no metadata.version bump, so the version-gated maintenance Phase A sync never propagated them to consumers. Bumped: api-auth 1.1->1.2, api-errors 1.6->1.7, api-services 1.3->1.4, api-telemetry 1.0->1.1, field-test 2.5->2.6, report-issue-local 1.5->1.6, tool-defs-analysis 1.2->1.3. Mirrors in .claude/skills and .agents/skills already match.",
          "is_bot": false,
          "headline": "chore(skills): bump metadata.version on seven skills with shipped bod…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "200454465ad226087acd70a71a5de9621a5ae2bf",
          "body": "…oin (#235)\n\ndescribe({ tableName }) pushed an unqualified table_name predicate into a query joining information_schema.tables t with duckdb_tables(), both exposing table_name — DuckDB raised a Binder Error (ambiguous column) on every filtered call. Qualified the pushed filters with the t alias (t.table_name, t.table_type, t.table_schema); the table_type arm was latent but qualified for consistency.",
          "is_bot": false,
          "headline": "fix(canvas): qualify describe() filters against the duckdb_tables() j…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecccb7e85cfe939574346987b110a8e4ae5f5de0",
          "body": "git diff --name-only HEAD lists a deleted skill and git show HEAD:<path> still returns the blob, so the loop reached readFileSync on a path no longer on disk and crashed with ENOENT — hit on every maintenance pass that prunes an upstream-removed skill. Added an existsSync guard before the read; a deleted file has no body to compare and cannot violate the policy.",
          "is_bot": false,
          "headline": "fix(scripts): skip worktree-deleted SKILL.md in the version gate (#237)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71f4c5818d574962a6f0c0a91273509cfa79dd69",
          "body": "TODOs/FIXMEs, Tracked Secrets, and Framework Antipatterns shell out to git grep / git ls-files, which exit 128 (not a finding) on a fresh scaffold before git init — devcheck reported it as a failure. Added a shared isGitRepo() helper that returns null from those getCommand()s when .git is absent; check-framework-antipatterns.ts also self-guards for direct invocation.",
          "is_bot": false,
          "headline": "fix(scripts): guard git-dependent devcheck checks outside a repo (#243)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9b8a17d22f9a44bfe1a4207d077df4cc4179e2",
          "body": "build-changelog.ts --check exited via a thrown buildRollup() when changelog/ held only template.md and no <major.minor>.x/ version files — a fresh scaffold's own shipped state, surfacing as a stack trace on the first devcheck. Now exits 0 under --check when collectVersionFiles() is empty; a manual changelog:build still throws on an empty tree.",
          "is_bot": false,
          "headline": "fix(scripts): skip changelog sync cleanly on a fresh scaffold (#242)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-19T21:23:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d491a2789a3f20d0e3ea5496a8a84c53081f3da",
          "body": "…e preamble (git-wrapup v1.3)",
          "is_bot": false,
          "headline": "docs(skills): tag annotations are sections+bullets only — no narrativ…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78d58aaafb9cacd17323633f93c09a1ea72f43f",
          "body": "…lated to #230; clean-mcpb ships by init copy/script sync, not node_modules reference",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.6 entry — orchestrations bullet is unre…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:30:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65ce31ab46f45575c2f09358acfe32f99bbbb1a8",
          "body": "…ity lint (#230, #231)",
          "is_bot": false,
          "headline": "feat(packaging): 0.10.6 — bundle cleaner, post-bundle content + ident…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:24:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3e3c7551f0f00e43f79e55272fe69989b23ae76",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): orchestrations v1.3 — Phase 4 close-loop wording",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T20:24:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b8955b8164ca51b09b787b79f5cde879ac6eb5a",
          "body": "…ndings attribution, linter-claim wording",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.5 entry — skill version 1.5, fixture/bi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:56:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f4222e37bd18d26b2f37c187a2e2d5f24c46e3a",
          "body": "New ./testing/vitest subpath exports mcpTest (test.extend with ctx + storage fixtures) and McpTestFixtures interface. vitest >=4.0.0 added as an optional peer dependency. packaging guards updated: export-map allowlist gains ./testing/vitest; optional-peer-deps test adds an integration-entrypoint exe\n[…]\nino ^0.64.0 → ^0.65.0; @opentelemetry/resources ^2.7.1 → ^2.8.0; @opentelemetry/sdk-metrics ^2.7.1 → ^2.8.0; @opentelemetry/sdk-node ^0.218.0 → ^0.219.0; @opentelemetry/sdk-trace-node ^2.7.1 → ^2.8.0.",
          "is_bot": false,
          "headline": "feat(testing): 0.10.5 — mcpTest fixture-based Vitest subpath (#227)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:50:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1362c22cc9038c1e1aef17c9d262ef6b7765cb2",
          "body": "lintCappedListTruncation checked allowlist.includes(name) without guarding against non-array truncationAllowlist values; guard added.",
          "is_bot": false,
          "headline": "chore(linter): Array.isArray guard for the truncation allowlist check",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d44bee496c12fdfdaa011f1efbcfd0fb5fe2c8e2",
          "body": "… cases (#229)\n\nFifth vitest project 'typecheck' over tests/types/**/*.test-d.ts, using tsc checker with ignoreSourceErrors. maxWorkers: 4 required by vitest's uniform-sequence-group rule. New test:typecheck script. Three .test-d.ts files: error-contract (ReasonOf, TypedFail, TypedRecoveryFor, createFail, createRecoveryFor, HandlerContext), handler-context (HandlerContext inference), and tool-builder (output type inference).",
          "is_bot": false,
          "headline": "chore(tests): vitest typecheck project with @ts-expect-error negative…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbbec769c5bd2baa13452419568870b3028458cd",
          "body": "r2Buckets and d1Databases miniflare bindings added to the worker-runtime fixture. Per-provider test files exercise set/get/delete/list/TTL through the worker handler. skills/api-workers v1.3 documents the binding pattern.",
          "is_bot": false,
          "headline": "chore(tests): R2/D1 emulated workerd storage suites (#228)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0760ea0a627008344836ffad7a27e185bfff40da",
          "body": "R2 rejects list() limits above 1000; limit+1 now clamped to R2_MAX_LIST_LIMIT=1000. At the cap, the response's truncated flag covers has-more detection instead of the +1 probe.",
          "is_bot": false,
          "headline": "fix(storage): clamp R2 list +1 page probe at the 1000-key cap (#228)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:49:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54fd2e650dbde7474c170947873d503376cb2619",
          "body": "….3 floors (#216)\n\nAbortSignal.any for fetchWithTimeout external-signal composition and retry sleep cancellation. Uint8Array.toBase64/fromBase64 replaces chunked string-based encoding in the workerd/browser branch; Buffer fast-path stays primary. globalThis.performance.now direct delegation in nowMs\n[…]\nre extends AsyncDisposable — custom backend implementations must add [Symbol.asyncDispose]. TextToSpeechResult.audio and SpeechToTextOptions.audio type changed from Buffer|string to Uint8Array|string.",
          "is_bot": false,
          "headline": "refactor(utils,services): platform-native sweep under Node>=24/Bun>=1…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T16:48:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffa740dda1ec7f793efe305e9cad953ae50b15d2",
          "body": "…rom peers",
          "is_bot": false,
          "headline": "docs(changelog): fast-check was added to devDependencies, not moved f…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:22:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95c4927058f500771a797617abf425b3193c824c",
          "body": "…ync (#217)\n\nPackaging (#217):\n\n- exports map: default condition added to all 18 JS entries\n\n- HEALTHCHECK in Dockerfile and templates/Dockerfile (bun-native fetch, no curl dep)\n\n- tsconfig.base.json, tsconfig.json: importHelpers removed (no-op at ESNext, tslib never declared)\n\n- tsconfig.test.json \n[…]\nerage thresholds raised (stmts 88->91, branches 79->83, fns 90->92, lines 89->92)\n\nSkills:\n\n- api-testing v1.4: output schema assertions via expect.schemaMatching\n\n- api-canvas v1.6: see canvas commit",
          "is_bot": false,
          "headline": "chore(build,test): 0.10.4 — packaging hygiene, test infra, template s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:19:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0ad33f93e4241bf5a3f14da20b131f3f6b6000c",
          "body": "…Found, catalog deny layer, approxSizeBytes (#221, #222, #223, #224, #226)\n\n- inferSchemaFromRows: all inferred columns now nullable: true; sample cannot prove NOT NULL (#221)\n\n- query() non-registerAs path: streamAndReadUntil(rowLimit+1) replaces runAndReadAll+slice; adds truncated flag to QueryRes\n[…]\nSystemCatalogs: new export; opt-in QueryOptions/RegisterViewOptions.denySystemCatalogs flag (#224)\n\n- describe(): LEFT JOIN duckdb_tables() to populate TableInfo.approxSizeBytes for base tables (#226)",
          "is_bot": false,
          "headline": "feat(canvas): inferred-nullable fix, streaming cap, missing-table Not…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-11T01:18:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfeb9ff6de473a04837319999a718e7676b2a8bd",
          "body": "…on, sampling removed, server identity, completable args\n\nVersion: 0.10.2 → 0.10.3\nDependency: @types/node ^25.9.2 → 25.9.3 (pinned to patch)",
          "is_bot": false,
          "headline": "chore(release): 0.10.3 — elicit wired on the wire, URL-mode elicitati…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:12:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07d71331263b1db5ade50df0608912df8a83c110",
          "body": "…tures\n\ngit ls-files lists files deleted from the worktree but not yet staged. The audit\ncrashed when trying to read those paths. Added existsSync() filter so uncommitted\ndeletions don't break the audit during development.",
          "is_bot": false,
          "headline": "chore(scripts): skip worktree-deleted files in audit-open-index-signa…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44d6bda1e971ed14e89ddba0719f3137d0144e96",
          "body": "…#213, #218)\n\nCreateAppOptions gains optional title, websiteUrl, description, icons (typed against\nImplementation['icons']). All four are forwarded to the McpServer constructor's\nserverInfo and to buildServerManifest so initialize and /.well-known/mcp.json stay\nconsistent. Explicit description wins \n[…]\nervices and createMcpServerInstance\nbut the registerAll() call was a no-op. The roots/ directory and its test are gone.\nRoots is also deprecated by SEP-2577. RootsRegistry was never publicly exported.",
          "is_bot": false,
          "headline": "feat(app): server identity fields, remove RootsRegistry placeholder (…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc7e7b02e607eb1c7694fc8c049d5371e353dc71",
          "body": "…mpt title (#214)\n\nprompt() args fields may be wrapped with completable() — re-exported from the main\nentry so consumers don't need a direct SDK import. The SDK auto-installs\ncompletion/complete handling and advertises the completions capability when any\nregistered prompt has a completable argument.\n[…]\nResourceTemplate constructor second argument; triggers the\nsame automatic completions capability advertisement.\n\nresource-registration.ts also carries the #211 elicit notifier wiring (file atomicity).",
          "is_bot": false,
          "headline": "feat(prompts,resources): completable args, resource complete map, pro…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:11:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee720eb0c63cb25938796bf1dee3da15bc54521f",
          "body": "…, #212, #220)\n\nctx.elicit was never defined at runtime — the extra-sniffing approach misread the\nSDK's RequestHandlerExtra shape. Now wired via registration-time notifier closures:\nelicitInput and getClientCapabilities bound to the per-server Server instance in\nboth tool-registration.ts and resourc\n[…]\nicitFn with a default no-op .url()\nstub so tests exercising form-mode elicitation don't need to supply .url explicitly.\n\nsrc/core/index.ts also carries the #214 completion re-exports (file atomicity).",
          "is_bot": false,
          "headline": "feat(context): wire ctx.elicit, add URL-mode, remove ctx.sample (#211…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T23:10:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43b072e45ea9344b4a4dcf6de720959d8935a36e",
          "body": "…irror-CLI recipe description, cap-field list",
          "is_bot": false,
          "headline": "docs(changelog): correct 0.10.2 entry — scaffold stanza paths/user, m…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:50:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75c2b0bc10d1f7efb44f40565d2ed14074864518",
          "body": "… rules, scaffold data dirs\n\nhono ^4.12.24 → ^4.12.25\n@cloudflare/vitest-pool-workers ^0.16.13 → ^0.16.14\n@cloudflare/workers-types 4.20260608.1 → 4.20260610.1\n@supabase/supabase-js ^2.108.0 → ^2.108.1\nsanitize-html ^2.17.4 → ^2.17.5",
          "is_bot": false,
          "headline": "chore(release): 0.10.2 — per-table canvas TTL, canvas/truncation lint…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6aa8b05262127d4b7ca429eb37307e447b780a96",
          "body": "…rror-CLI Docker recipe (#199, #195)",
          "is_bot": false,
          "headline": "feat(templates): writable SQLite data dirs in scaffold Dockerfile, mi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "772939b251f95fa23ddf4de2aef52d198b334eec",
          "body": "…rich.truncated (#209, #197)",
          "is_bot": false,
          "headline": "feat(linter): canvas-consumer and truncation-disclosure rules, ctx.en…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a058c5efbad6b7e63779510ad706434f987a8d5a",
          "body": "…pillover (#140)",
          "is_bot": false,
          "headline": "feat(canvas): per-table TTL on registerTable, query registerAs, and s…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-10T17:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "158747a30ee6c82246925f2c55190e8223d2d8fc",
          "body": "…scaffold/packaging fixes",
          "is_bot": false,
          "headline": "chore(release): 0.10.1 — canvas SQL gate fail-closed, pragma_* deny, …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a641fe30dec6ebfb21cd919d74968e1ce2bf3dbc",
          "body": "…ons (#210)",
          "is_bot": false,
          "headline": "fix(canvas): fail closed on non-SELECT and deny pragma_* table functi…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4fe4cc7ec1b5ef3b974f7c8418c867b860ee8d3",
          "body": null,
          "is_bot": false,
          "headline": "fix(scheduling): actionable error when node-cron peer is missing (#200)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:45:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bc402edbe765de8bdae29594baff47eb892e0cd",
          "body": "…uard (#207)",
          "is_bot": false,
          "headline": "fix(packaging): anchor .mcpbignore dev patterns, add bundle-content g…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2a055524862a95b1f015ecb05c9ba4db0dbfea2",
          "body": null,
          "is_bot": false,
          "headline": "fix(templates): ship repository object in manifest (#206)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a59dea547837af557f39d34a5b9c1b6e3741b951",
          "body": null,
          "is_bot": false,
          "headline": "fix(templates): run scaffold scripts via Bun, drop tsx (#205)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-08T14:44:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e6cd672ee25a8f9e24234b4bfb3dc93fd919e73",
          "body": "@cloudflare/vitest-pool-workers ^0.16.11 → ^0.16.13\n@cloudflare/workers-types 4.20260602.1 → 4.20260605.1\n@supabase/supabase-js ^2.106.2 → ^2.107.0\nopenai ^6.41.0 → ^6.42.0",
          "is_bot": false,
          "headline": "chore(release): 0.10.0 — outline-on-overflow, stringbool env booleans",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ac4cc9089157bdfb7f1065ca2994160e59e316d",
          "body": "…202)\n\ntemplates/Dockerfile now accepts an APP_VERSION build arg and stamps\norg.opencontainers.image.version in the OCI label block; also declares\norg.opencontainers.image.source (filled with the repo URL at scaffold\ntime). release-and-publish skill updated to pass --build-arg APP_VERSION\nto docker buildx for both amd64/arm64 platforms. Scaffolded servers only\n— existing servers pick this up on re-scaffold.",
          "is_bot": false,
          "headline": "fix(templates): stamp OCI image.version and source on built images (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15d8d2b7eea4e77301d5737d4b84e4ecd9f02b7d",
          "body": "New /utils exports: outlineOnOverflow(), OUTLINE_VARIANT, selectSections(),\nformatOutline(), DEFAULT_OUTLINE_BUDGET_BYTES. When a document-shaped\npayload exceeds a serialized-byte budget, returns a section outline\n(top-level keys + per-section size) and a re-call notice instead of\ntruncating. Agent \n[…]\nte cache, when to choose\nit over spillover() or capped-list disclosure).\n\ndesign-mcp-server and add-tool skills updated with overflow guidance.\nCLAUDE.md, AGENTS.md, docs/tree.md updated for new dirs.",
          "is_bot": false,
          "headline": "feat(utils): outline-on-overflow for oversized document payloads (#204)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63655562b73a7694d85c5cb6ce2564b40195453f",
          "body": "Replaces the hand-rolled envBoolean preprocess in src/config/index.ts\nwith Zod z.stringbool(). Accepts true/false/1/0/yes/no/on/off\n(case-insensitive); rejects unrecognized values at startup instead of\nsilently coercing them to false. Real booleans pass through (Workers\n[vars]). yes/on/y/enabled now\n[…]\nin src/, which coerces \"false\" to true. Scanner now\nskips comment lines to avoid false-positives on doc mentions. Server-\nconfig docs (api-config skill, templates) updated to recommend\nz.stringbool().",
          "is_bot": false,
          "headline": "feat(config): parse env booleans via Zod stringbool (#201)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-05T12:12:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db1bc01d26a51e50bd2a27342ccc7a695f85c110",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.9.21 — HTTP transport per-request log context fix",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18ddb7eb9322592f8af3d01f893e28b0d06cf3ee",
          "body": "…ions skill",
          "is_bot": false,
          "headline": "docs(templates): expand First Session onboarding, document orchestrat…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a367b9c7edfff97e419f834335912ed63eca6284",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): mark orchestrations workflows as audience: external",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fd7c11e126b727e120a847383015725f0ceb2c3",
          "body": null,
          "is_bot": false,
          "headline": "fix(transport): derive per-request context in HTTP handlers (#194)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T09:04:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b24ebb00efd4d556a310236a7631483c1c9d5408",
          "body": "…ication routing",
          "is_bot": false,
          "headline": "chore(release): 0.9.20 — query-string redaction, lint fix, HTTP notif…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "908cadf8a147f5a11c86abdf7134a1d3befb71cd",
          "body": "…anvas, design-mcp-server",
          "is_bot": false,
          "headline": "docs(skills): add MCP-side list-filtering guidance to add-tool, api-c…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "664e10f2bbd43d26535f305162b92940abc5fbde",
          "body": "…135)",
          "is_bot": false,
          "headline": "fix: route list-changed notifications via request scope under HTTP (#…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:42:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4ab379de4de2acfe1c4d30c4fd417f60afcce41",
          "body": "…ns (#191)",
          "is_bot": false,
          "headline": "fix(linter): scope error-contract rules to throw sites, not compariso…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:41:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3109bb5993ff1eb7d7627b4814bf086a4e7ff577",
          "body": "… and logs (#190)",
          "is_bot": false,
          "headline": "fix(security): redact query-string secrets in fetchWithTimeout errors…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-06-02T03:41:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f72213a81ba556d899d3ab112c99a537028ecad",
          "body": "…orkflow gate markers\n\nAdds scripts/release-github.ts (bun run release:github): reads package.json version, derives tag subject, runs gh release create with --verify-tag --notes-from-tag --title 'v<VERSION>: <subject>', attaches dist/*.mcpb when manifest.json exists, and handles the release-already-\n[…]\ny fail-fast on data.retryable === false (#174), ctx.fail auto-populates data.retryable from contract entry, Gate after column in workflow phase tables (#183), MirrorService design-mcp-server guidance.",
          "is_bot": false,
          "headline": "feat(scripts): 0.9.19 — release:github script, withRetry fail-fast, w…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:07:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa7601461e0ea4543c0b5fe8db5c5c8970a61b54",
          "body": "New bullet in the output-design section of design-mcp-server/SKILL.md: when to mirror a bulk upstream instead of paginating it live, with corpus-size thresholds (in-memory / MirrorService / external store) and a pointer to api-mirror.",
          "is_bot": false,
          "headline": "docs(design-mcp-server): add MirrorService bulk-upstream design guidance",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:07:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f625b576d2d0f79cd41dfabadb141559548fbf3",
          "body": "Every phase row in skills/orchestrations/workflows/*.md now has a Gate after column: barrier (with a terse reason) or gate-free. The orchestrator can derive spawn/round structure directly from the table without re-deriving the barrier positions each run.\n\nskills/orchestrations/SKILL.md adds a one-line pointer tying the new column back to the 'Barriers only where gates sit' principle.",
          "is_bot": false,
          "headline": "feat(orchestrations): Gate after column in workflow phase tables (#183)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:06:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f825f53b7b2f58d39bea80315c3b1a54c88a77b7",
          "body": "defaultIsTransient now checks error.data.retryable === false and returns non-transient immediately, even when the error code is in the transient set (Timeout, ServiceUnavailable, RateLimited). This closes the gap for deterministic upstream failures surfaced as HTTP 200 with an error body — they no l\n[…]\ncontract entry's retryable field as a base default. Caller-supplied data.retryable overrides per-occurrence; reason is always forced last. Contract entries that omit retryable inject no key onto data.",
          "is_bot": false,
          "headline": "feat(utils): withRetry fail-fast on data.retryable === false (#174)",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T11:06:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a458781a006bf8d1909704cd504740c46fc972b9",
          "body": "… gate (#123)",
          "is_bot": false,
          "headline": "feat(devcheck): 0.9.18 — skill-version gate (#99), open-indexed-named…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T10:17:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72ec04223613586ac432f68c99947a6075725538",
          "body": "…e3 peer dep\n\nNew Tier 3 primitive: `defineMirror()` + `sqliteMirrorStore()` under\n`@cyanheads/mcp-ts-core/mirror`. Provides the source-agnostic machinery\nfor a persistent, self-refreshing local mirror of a bulk upstream dataset\n(embedded SQLite + FTS5): cross-runtime store, volatile cursor / durabl\n[…]\npply only the ingester (sync generator) and schema. Node/Bun only;\n`bun:sqlite` built-in on Bun, `better-sqlite3` optional peer on Node.\n\n`@cloudflare/workers-types` 4.20260530.1 → 4.20260531.1 (dev).",
          "is_bot": false,
          "headline": "feat(services): 0.9.17 — MirrorService, /mirror subpath, better-sqlit…",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-31T05:41:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52a7122c5ba6def233f6e71900537e886a9d9c09",
          "body": "The httpError test built a Response with status 204 and an empty-string body; 204 is a null-body status that rejects any body, so the suite failed under current runtimes. Default the helper body to null.\n\nAdd behavior coverage for untested paths: a new resource-rules suite, landing-rules validation \n[…]\nraversal, sanitization security edge cases, scheduler lifecycle (listJobs/destroyAll/not-found), error factories, tokenCounter, and JSON/YAML error truncation. Branches 83.0% to 83.9%; no src changes.",
          "is_bot": false,
          "headline": "test: fix null-body httpError helper, expand suite coverage",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-30T14:16:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6002abf68947d859e1523e607fae3f6084e416bf",
          "body": "…tools\n\nenrichmentTrailer.render was an arrow property, so its parameter was\nvariance-strict under strictFunctionTypes — a concrete tool's narrow\nrender value no longer assigned to the type-erased AnyToolDefinition,\nbreaking createApp({ tools }) typecheck for every tool declaring an\nenrichment block (even with no trailer literal). Switch to method\nsyntax for bivariant params, matching format and handler.\n\nType-only; no runtime change. (#180)",
          "is_bot": false,
          "headline": "fix: 0.9.16 — restore AnyToolDefinition assignability for enrichment …",
          "author_name": "cyanheads",
          "author_login": "cyanheads",
          "committed_at": "2026-05-30T03:27:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 33,
      "commits_last_year": 1289,
      "latest_release_at": "2026-07-19T12:24:31Z",
      "latest_release_tag": "v0.10.15",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 34,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 4.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@cyanheads/mcp-ts-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "agent",
            "agent-native",
            "ai",
            "ai-agent",
            "bun",
            "cloudflare-workers",
            "declarative",
            "framework",
            "mcp",
            "mcp-server",
            "mcp-framework",
            "model-context-protocol",
            "observability",
            "opentelemetry",
            "tools",
            "typescript"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
          "is_deprecated": false,
          "latest_version": "0.10.15",
          "repository_url": "https://github.com/cyanheads/mcp-ts-core",
          "versions_count": 142,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 44618,
          "first_published_at": "2026-03-12T12:17:08.098000Z",
          "latest_published_at": "2026-07-19T12:24:09.144000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 29,
      "stars": 147,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-04-27",
            "count": 1
          },
          {
            "date": "2025-05-12",
            "count": 1
          },
          {
            "date": "2025-05-14",
            "count": 2
          },
          {
            "date": "2025-05-17",
            "count": 1
          },
          {
            "date": "2025-07-09",
            "count": 1
          },
          {
            "date": "2025-07-23",
            "count": 1
          },
          {
            "date": "2025-09-03",
            "count": 1
          },
          {
            "date": "2025-10-02",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-10-16",
            "count": 1
          },
          {
            "date": "2025-10-30",
            "count": 1
          },
          {
            "date": "2025-11-17",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 1
          },
          {
            "date": "2025-12-24",
            "count": 1
          },
          {
            "date": "2026-01-02",
            "count": 1
          },
          {
            "date": "2026-01-04",
            "count": 1
          },
          {
            "date": "2026-01-14",
            "count": 1
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 2
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-28",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 29,
        "total_forks": 29
      },
      "star_history": null,
      "open_issues_and_prs": 59
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 54037,
      "source_files_sampled": 445,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "templates/AGENTS.md",
        "templates/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 39823
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "templates/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 115,
        "malicious_count": 0,
        "assessed_package": "npm:@cyanheads/mcp-ts-core@0.10.15",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@hono/mcp",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.1"
        },
        {
          "name": "@hono/node-server",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.10"
        },
        {
          "name": "@modelcontextprotocol/ext-apps",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.4"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@opentelemetry/api",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.1"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^17.4.2"
        },
        {
          "name": "hono",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.30"
        },
        {
          "name": "jose",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.3"
        },
        {
          "name": "pino",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.3.1"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@cyanheads/mcp-ts-core",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "^{{FRAMEWORK_VERSION}}"
        },
        {
          "name": "pino-pretty",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.1.3"
        },
        {
          "name": "zod",
          "manifest": "templates/package.json",
          "ecosystem": "npm",
          "version_constraint": "{{ZOD_VERSION}}"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@cyanheads/mcp-ts-core",
            "direct": true,
            "version": "^{{FRAMEWORK_VERSION}}",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/mcp",
            "direct": true,
            "version": "^0.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": true,
            "version": "^2.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/ext-apps",
            "direct": true,
            "version": "^1.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "^1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": true,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "^17.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": true,
            "version": "^4.12.30",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": true,
            "version": "^6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": true,
            "version": "^10.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pino-pretty",
            "direct": true,
            "version": "^13.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "{{ZOD_VERSION}}",
            "ecosystem": "npm"
          },
          {
            "name": "@biomejs/biome",
            "direct": false,
            "version": "2.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "@cloudflare/vitest-pool-workers",
            "direct": false,
            "version": "^0.18.4",
            "ecosystem": "npm"
          },
          {
            "name": "@cloudflare/workers-types",
            "direct": false,
            "version": "5.20260706.1",
            "ecosystem": "npm"
          },
          {
            "name": "@duckdb/node-api",
            "direct": false,
            "version": "^1.5.4-r.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/otel",
            "direct": false,
            "version": "^1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-http",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-pino",
            "direct": false,
            "version": "^0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resources",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-metrics",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-node",
            "direct": false,
            "version": "^0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace-node",
            "direct": false,
            "version": "^2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": false,
            "version": "^1.43.0",
            "ecosystem": "npm"
          },
          {
            "name": "@socketsecurity/bun-security-scanner",
            "direct": false,
            "version": "^1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@supabase/supabase-js",
            "direct": false,
            "version": "^2.110.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bun",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/papaparse",
            "direct": false,
            "version": "^5.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/sanitize-html",
            "direct": false,
            "version": "^2.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/validator",
            "direct": false,
            "version": "^13.15.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-istanbul",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/ui",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "better-sqlite3",
            "direct": false,
            "version": "^12.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "bun-types",
            "direct": false,
            "version": "^1.3.14",
            "ecosystem": "npm"
          },
          {
            "name": "chrono-node",
            "direct": false,
            "version": "^2.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "clipboardy",
            "direct": false,
            "version": "^5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "defuddle",
            "direct": false,
            "version": "^0.19.1",
            "ecosystem": "npm"
          },
          {
            "name": "depcheck",
            "direct": false,
            "version": "^1.4.7",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "^9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "^4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": false,
            "version": "^5.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "^7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "^7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "^5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "linkedom",
            "direct": false,
            "version": "^0.18.13",
            "ecosystem": "npm"
          },
          {
            "name": "node-cron",
            "direct": false,
            "version": "^4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "openai",
            "direct": false,
            "version": "^6.46.0",
            "ecosystem": "npm"
          },
          {
            "name": "papaparse",
            "direct": false,
            "version": "^5.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "partial-json",
            "direct": false,
            "version": "^0.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "pdf-lib",
            "direct": false,
            "version": "^1.17.1",
            "ecosystem": "npm"
          },
          {
            "name": "repomix",
            "direct": false,
            "version": "^1.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "sanitize-html",
            "direct": false,
            "version": "^2.17.6",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "^1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsc-alias",
            "direct": false,
            "version": "^1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "typedoc",
            "direct": false,
            "version": "^0.28.20",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "unpdf",
            "direct": false,
            "version": "^1.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "validator",
            "direct": false,
            "version": "^13.15.35",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "8.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.9",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 66,
        "direct_count": 13,
        "indirect_count": 53
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 13,
        "open_issues": 59,
        "closed_ratio": 0.768,
        "closed_issues": 195,
        "closed_unmerged_prs": 13
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "cyanheads",
          "commits": 1544,
          "avatar_url": "https://avatars.githubusercontent.com/u/10339515?v=4"
        },
        {
          "type": "User",
          "login": "caseybreen",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/26234849?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.995
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "296d43ab89d1af77807f0e7cee7dc46e10d42ae3",
        "ran_at": "2026-07-25T09:49:09Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T12:23:34Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-05-23T02:12:04Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 66,
          "created_at": "2026-04-24T21:00:39Z",
          "last_comment_at": "2026-05-22T00:35:02Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 75,
          "created_at": "2026-04-28T04:08:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 77,
          "created_at": "2026-04-28T23:53:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 78,
          "created_at": "2026-04-28T23:53:33Z",
          "last_comment_at": "2026-06-07T18:16:07Z",
          "last_comment_author": "xlyoung"
        },
        {
          "number": 79,
          "created_at": "2026-04-28T23:53:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 94,
          "created_at": "2026-05-01T23:25:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 106,
          "created_at": "2026-05-03T07:02:02Z",
          "last_comment_at": "2026-05-03T08:11:29Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 107,
          "created_at": "2026-05-03T07:39:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 110,
          "created_at": "2026-05-03T22:45:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 139,
          "created_at": "2026-05-17T18:23:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 142,
          "created_at": "2026-05-21T15:01:15Z",
          "last_comment_at": "2026-06-11T22:37:44Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 151,
          "created_at": "2026-05-23T16:12:48Z",
          "last_comment_at": "2026-06-02T10:26:46Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 152,
          "created_at": "2026-05-23T18:12:07Z",
          "last_comment_at": "2026-05-23T18:18:18Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 162,
          "created_at": "2026-05-28T09:05:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 163,
          "created_at": "2026-05-28T10:14:45Z",
          "last_comment_at": "2026-05-28T12:41:51Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 164,
          "created_at": "2026-05-28T23:27:45Z",
          "last_comment_at": "2026-05-31T05:42:50Z",
          "last_comment_author": "cyanheads"
        },
        {
          "number": 187,
          "created_at": "2026-06-01T06:12:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 188,
          "created_at": "2026-06-01T06:13:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 193,
          "created_at": "2026-06-02T03:33:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 196,
          "created_at": "2026-06-02T10:26:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cyanheads/mcp-ts-core",
    "host": "github.com",
    "name": "mcp-ts-core",
    "owner": "cyanheads"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 47,
        "vitality": 93,
        "community": 56,
        "governance": 55,
        "engineering": 70
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 93,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "commits_last_year": 1289,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 34
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "34/52 weeks with commits",
                "points": 23.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 34
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1289 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1289
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 33,
              "latest_release_tag": "v0.10.15",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 4.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "33 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 33
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "forks": 29,
              "stars": 147,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "147 stars",
                "points": 35.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 147
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "29 forks",
                "points": 12.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 78,
            "inputs": {
              "packages": [
                "@cyanheads/mcp-ts-core"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 44618
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "44,618 downloads/month across npm",
                "points": 62,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 44618,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.995
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "merged_prs": 13,
              "open_issues": 59,
              "closed_issues": 195,
              "issue_closed_ratio": 0.768,
              "closed_unmerged_prs": 13
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "77% of issues closed",
                "points": 35.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 77
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "13/26 decided PRs merged",
                "points": 19.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 13,
                      "decided": 26
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "followers": 175,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "cyanheads",
              "public_repos": 146,
              "account_age_days": 4225
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "175 followers of cyanheads",
                "points": 16.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 175,
                      "login": "cyanheads"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "146 public repos, account ~11 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 146
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@cyanheads/mcp-ts-core"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "142 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 142
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "mcp",
                "mcp-server",
                "model-context-protocol",
                "ai",
                "opentelemetry",
                "cloudflare-workers",
                "agent-native",
                "framework",
                "typescript",
                "cyanheads"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@cyanheads/mcp-ts-core",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@cyanheads/mcp-ts-core@0.10.15 runtime dependency closure — what installing the published package pulls in — 115 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@cyanheads/mcp-ts-core@0.10.15",
                  "assessed": 115
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 115,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 115,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "templates/AGENTS.md",
                "templates/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 39823
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, templates/AGENTS.md, templates/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 54037,
              "source_files_sampled": 445,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/445 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 445,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package '{{PACKAGE_NAME}}' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T09:49:14.556607Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cyanheads/mcp-ts-core.svg",
  "full_name": "cyanheads/mcp-ts-core",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.