Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-29 16:43 UTC

gonest-dev / gonest

A NestJS-inspired dependency-injection and HTTP framework for Go

GoMIT★ 4 estrellas⑂ 1 forkdesde jul 2026Ver en GitHub ↗

gonest-dev/gonest tiene un índice de salud de 45 sobre 100, lo que lo sitúa en la banda En riesgo. Su puntuación más alta es Vitality (74/100) y la más baja, Community & Adoption (28/100). Se actualizó por última vez hace 4 días. Una sola persona concentra la mayor parte del trabajo reciente.

45
global / 100
En riesgo

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

45
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

gonest.devOrganización
0 seguidores3 repositorios públicosdesde mar 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogonest.dev/gonestv0.31.0-31hace 4 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

74Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 4 días
2.1/36Cadencia de commits — 3/52 semanas con commits
18/18Volumen de commits — 343 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year343
human_commit_share1
days_since_last_push4
active_weeks_last_year3
Cómo se puntúa
27/27Publica versiones — 31 versiones publicadas
36/36Recencia de las versiones — última versión hace 4 días
27/27Cadencia de publicación — una versión cada ~0,2 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count31
latest_release_tagv0.31.0
releases_from_tagsno
days_since_latest_release4
mean_days_between_releases0,2
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

28Crítico · 18% del índice global
Cómo se puntúa
7.7/60Estrellas — 4 estrellas
0/25Forks — 1 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks1
stars4
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

32En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
0/25Alcance del propietario — 0 seguidores de gonest-dev
5.2/25Trayectoria — 3 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers0
owner_typeOrganization
is_verified
owner_logingonest-dev
public_repos3
account_age_days145
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 4 días
20/20Historial de versiones — 31 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgonest.dev/gonest
ecosystemsgo
any_deprecatedno
min_days_since_publish4

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

56Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 1 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

50Moderado
Cómo se puntúa
30/30README
0/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

29Crítico · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — sin datos
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate2,9
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, packaging, signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

60Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 100 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Taskfile.yml
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfileno
typed_language
bootstrap_filesTaskfile.yml
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifests.examples/blog-api/go.mod, .examples/blog-graphql/go.mod, .examples/config-dotenv/go.mod, .examples/full-text-search/go.mod, .examples/lifecycle-hooks/go.mod, .examples/notification-driver/go.mod, .examples/simple-todo/go.mod, go.mod
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.2/55Tamaños de archivo manejables — 3/219 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes147.910
source_files_sampled219
oversized_source_files3

Datos clave

4estrellas de GitHub
1contribuidores
343commits en los últimos 12 meses
4días desde el último push
31versiones publicadas
1factor bus
0issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 2.9 / 10
2.9agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-29 16:43 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/dPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Dependencias directas 7
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/fasthttp/websocketv1.5.12go.mod
Gogithub.com/gofiber/contrib/v3/websocketv1.2.1go.mod
Gogithub.com/gofiber/fiber/v3v3.4.0go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/graphql-go/graphqlv0.8.1go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogolang.org/x/syncv0.22.0go.mod
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2981,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1756512
      },
      "pushed_at": "2026-07-25T15:10:27Z",
      "created_at": "2026-07-16T13:49:05Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T13:33:12Z",
      "description": "A NestJS-inspired dependency-injection and HTTP framework for Go",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://gonest.dev",
      "name": "gonest.dev",
      "type": "Organization",
      "login": "gonest-dev",
      "company": null,
      "location": "Brazil",
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/265890641?v=4",
      "created_at": "2026-03-05T19:13:28Z",
      "is_verified": null,
      "public_repos": 3,
      "account_age_days": 145
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-07-25T15:10:35Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-07-25T03:18:28Z"
        },
        {
          "tag": "v0.29.4",
          "kind": "patch",
          "published_at": "2026-07-25T02:12:13Z"
        },
        {
          "tag": "v0.29.3",
          "kind": "patch",
          "published_at": "2026-07-25T02:05:40Z"
        },
        {
          "tag": "v0.29.2",
          "kind": "patch",
          "published_at": "2026-07-24T19:43:10Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2026-07-24T19:33:50Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-07-24T18:57:24Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-07-24T14:16:56Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-07-23T17:41:23Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-07-23T17:41:20Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-07-23T17:41:20Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-07-22T19:59:20Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-07-21T22:27:15Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-21T21:03:06Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-21T16:41:44Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-07-21T02:15:07Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-07-20T20:35:09Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-20T18:29:42Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-07-20T17:55:21Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:56:28Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:56:29Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-19T22:30:17Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-19T20:20:06Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-18T21:54:32Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-18T03:02:18Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-18T02:38:12Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-18T00:57:35Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-17T19:09:02Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-07-16T21:53:26Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-16T20:54:29Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-16T20:44:04Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ea4e03179f40f7cc14adcaa9812343e8cfaf126b",
          "body": "Route gains an owner reference (set by Controller.Route) and implements\nResolveDirect/ResolveDirectAll by delegating to it, so MustInject[T](route)\nresolves from the same module scope MustInject[T](controller) does -- no\nmore forcing every per-route dependency up into the Controller's outer fn.\nroute.New takes owner as its new first param; existing internal callers pass\nnil (unchanged no-resolution behavior).",
          "is_bot": false,
          "headline": "feat(route): Route can MustInject inside its own callback",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T15:09:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f610fba1815857563c137d0a800fc479ed2b433f",
          "body": null,
          "is_bot": false,
          "headline": "docs(specs): mark http-context-unify traceability Verified (site done)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T03:27:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bb6739802fdaae07e5c8bb126c852df69ff6cec",
          "body": "Response (write-side) renamed to Reply (Fastify's own (request, reply)\nnaming for this exact role); RouteResponse (the OpenAPI per-status\ndocumentation builder) reclaims the Response name, matching OpenAPI 3.x's\nown vocabulary. New HttpContext type wraps Request/Reply behind exactly 2\nmethods, Reque\n[…]\nre changes from (req, res[, next/exc]) to (c, [next/exc]);\ngonest.Response is now the OpenAPI documentation builder (was\nRouteResponse); the HTTP write-side type is gonest.Reply (was\ngonest.Response).",
          "is_bot": false,
          "headline": "feat(execution)!: HttpContext unifies (req, res) into one parameter",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T03:17:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72160012f06b82e2d10e724a63c174ebcd914060",
          "body": "SetupSwagger was the last \"final\" bootstrap builder still returning a raw\nerror, forcing every call site to write its own\n`if err := ...; err != nil { panic(err) }` -- exactly the boilerplate\nevery other Must-prefixed API in the package already avoids. Migrates\nREADME's bootstrap example and .examples/{full-text-search,blog-api}.",
          "is_bot": false,
          "headline": "feat(openapi): add MustSetupSwagger, panic-on-error convenience wrapper",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T02:11:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1f551298fd8758e740d913ea026984ad970193",
          "body": "… addr\n\ndisplayAddr rewrote \":3000\" into \"0.0.0.0:3000\" for the \"Listening on\"\nbanner line. The actual bind is unaffected, but 0.0.0.0 is a wildcard\nbind address, not a real destination a browser can connect to on most\nOSes -- printing it produces a URL that fails to connect unless the dev\nalready knows to substitute localhost/127.0.0.1 themselves.\n\nFound via a real session: banner showed http://0.0.0.0:3000, only\n127.0.0.1/localhost actually worked.",
          "is_bot": false,
          "headline": "fix(app): startup banner prints localhost, not 0.0.0.0, for bare-port…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T02:04:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbbcbabae7662a9a6d83e71bd5e8c78960296039",
          "body": "NewBadRequestException/NewNotFoundException/etc (internal/exception/\nbuiltin.go) never call SetMessage, only SetDetails -- so Error() always\nreturned \"\" for every validation failure across internal/validate (env,\nquery, params, headers, form, body). A wrapped panic like \"gonest:\nprovider for type X \n[…]\ntails) when message was\nnever explicitly set; message still wins whenever it was set. MarshalJSON\n(the actual HTTP response body) is unchanged -- this only fixes the Go\nerror text used by panics/logs.",
          "is_bot": false,
          "headline": "fix(exception): Error() falls back to JSON of Details() when unset",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T19:42:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e09edc1ab331c3625d535217573f8c526d85dc8",
          "body": "OnModuleInit/OnApplicationBootstrap/OnModuleDestroy/BeforeApplicationShutdown/\nOnApplicationShutdown panicked with just \"gonest: invalid <Hook> signature\"\non a bad shape -- no hint of which provider, what was actually passed, or\nwhat shapes are accepted. Message now includes all three, e.g.:\n\n  gone\n[…]\none of: func(T, string), func(T,\n  string) error, func(T, context.Context, string), func(T, context.Context,\n  string) error\n\nFound debugging a real erc panic with no actionable detail in the message.",
          "is_bot": false,
          "headline": "fix(provider): name provider type + signature in lifecycle hook panics",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T19:33:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e4f27d2c75e564806221e169b208b8421129723",
          "body": "ExportableRef (AD-052) replaced by a broader TokenRef marker embedded by\nevery existing XxxRef interface. Imports/Providers/Controllers/Resolvers/\nUse/Filters/Listeners/Schedulers/Exports now all accept ...TokenRef,\nrouting internally via type-switch with a fail-fast panic on the wrong\nconcrete kind\n[…]\n be\ntype-asserted or spread into []gonest.ExportableRef (Go slices of\ninterface types are not covariant), panicking at runtime in erc's module\nfiles. See .specs/features/unified-token-ref/ and AD-056.",
          "is_bot": false,
          "headline": "feat(module): add TokenRef unifying all 9 Module builder methods",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T18:56:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ff3acc0f08070ca253be79bc7c1ee92b82a23cd",
          "body": "…truct field syncing",
          "is_bot": false,
          "headline": "feat(accessor): add SyncAccessorFields for automatic dirty Accessor s…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T14:14:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7723249804897b48b65307624ecbeb09ba45417d",
          "body": "…s, subagents)\n\nCodifies 6 process rules the user stated explicitly, previously followed\nonly informally this session: agent speech in pt-br (code/commits/README\nstay English); work always split by milestone with its own commit+push;\neach closed milestone gets its own version tag on its exact commit\n[…]\nthe version tags for v0.25.0-v0.27.0 only getting cut after\nthe user asked \"subiu as novas versões?\" -- makes the practice durable in\nPROJECT.md (base load every session) instead of relying on memory.",
          "is_bot": false,
          "headline": "docs(project): formalize workflow conventions (pt-br, milestones, tag…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T17:44:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "635ca0b4e0fe7a8a6299201d6de1a0de10ba411a",
          "body": "…xports\n\nMilestone 24 (module-lazy-loading). Replaces .examples/notification-driver's\nModuleForRoot free-function workaround (config picked outside the DI graph,\nin main()) with gonest.LazyModule: Module.Lazy(func(l *LazyModule) {...})\nruns synchronously during Stage 1 assembly, before Imports/Expor\n[…]\n now flows\nthrough a real Schema-validated notifier.Config_ provider instead of an\nad hoc env read in main.go. Verified live via curl for both drivers.\ngo test ./... -race -count=1 green, 24 packages.",
          "is_bot": false,
          "headline": "feat(module): add Module.Lazy for config-driven conditional Imports/E…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T17:19:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "328561cb1996a314c185d8a650a8265c0c57f1c7",
          "body": "Milestone 23 (provider-interface-export, P2). Every exported package-level\nvar produced by a gonest builder now carries a trailing underscore\nunconditionally (Provider_, Module_, Controller_) -- documented in README,\napplied across .examples/notification-driver (every builder var there was\nmissing i\n[…]\nmd\nremoved, PROVIDER.md status marked shipped). ROADMAP.md/STATE.md closed out\nfor Milestones 22-23 (AD-053). go test ./... -race -count=1 green, 25\npackages, zero regression from the example renames.",
          "is_bot": false,
          "headline": "docs(project): formalize Thing_ naming convention, close Milestone 22/23",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T16:35:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d58f4a3200d3985045057bffa6f1c0358790e782",
          "body": "Milestone 22 (provider-interface-export, P1). MustInject[T]/MustInjectAll[T]\nnow resolve an interface ONLY via an explicit gonest.ProviderAs[T](ref)\nregistration -- the implicit reflect.Type.Implements() structural fallback\nis removed entirely. Closes 3 real gaps from INSIGHT-PROVIDER.md: no\nmodule-\n[…]\ning another ProviderAs) is rejected outright.\n\n.examples/notification-driver migrated to ProviderAs[port.Notifier],\nverified live against both drivers. go test ./... -race -count=1 green,\n25 packages.",
          "is_bot": false,
          "headline": "feat(module): add ProviderAs[T] for explicit interface-export resolution",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T16:27:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a70cbee0241c8138f6cbc1870971625bb3ba551d",
          "body": "…leRef)\n\nReverses AD-051's separate ExportModules method: Exports(refs ...ExportableRef)\nnow takes both individual providers and whole modules to re-export in the same\ncall, mirroring NestJS's exports: [...] array. Nest-API-parity now documented\nas a fundamental project premise (PROJECT.md) that wins over Go-purity when\nthey conflict -- ExportModules removed, no deprecated alias.",
          "is_bot": false,
          "headline": "feat(module): unify Exports to accept providers and *Module (Exportab…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-22T19:58:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c8fac680f509c4673e5044abd5609ab694a8437",
          "body": "New example demonstrating gonest.Module's core value: injection across a\ndiffuse scope decided by config, not source code. NOTIFICATION_DRIVER\n(loaded via Dotenv, validated+defaulted via Schema.Enum+Default) picks,\nonce at bootstrap, whether notifier/impl/email or notifier/impl/sms wires\ninto AppMod\n[…]\n the notifier picker package\nitself, avoiding an import cycle -- their Providers return the concrete\n*Service type and gonest's resolver matches it against the interface via\nreflect.Type.Implements().",
          "is_bot": false,
          "headline": "docs(examples): add notification-driver -- env-driven Module swap",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-22T00:33:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddb112fe2b0b5ab912ed1e9f8c21b22ac7b2f385",
          "body": "…ld, runtime blocked by unrelated pre-existing bug)",
          "is_bot": false,
          "headline": "docs(specs): close module-reexport T3 (real consumer verified via bui…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T22:30:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9532de81bed49cdd7a2c047f17c58485ea80693",
          "body": "… (NestJS-style)\n\nModule.Exports only ever accepted individual providers -- NestJS's own\nexports: [...] also accepts a whole imported Module, re-exposing that\nmodule's own exports transitively to whoever imports the re-exporting\nmodule. gonest had no equivalent, confirmed by a real compile error in \n[…]\nntly gate-verified (go test ./... -race -count=1, no cache) before\napproval. Purely additive -- Exports/ExportedProviders unchanged, zero\nbehavior change for any module that never calls ExportModules.",
          "is_bot": false,
          "headline": "feat(module): add ExportModules for transitive whole-module re-export…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T22:26:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2abffe16fee2dd8978eabb23696e15d69d974251",
          "body": "…f/MiddlewareRef/FilterRef/ListenerRef/SchedulerRef\n\nModule.Providers/Controllers/Resolvers/Use/Filters/Listeners/Schedulers\nalready took these marker interfaces as their variadic parameter type\ninternally; without a root alias, hovering those methods from outside this\npackage showed the internal mo\n[…]\nf issue AD-046 already fixed elsewhere). Purely additive -- these methods\nalready accepted the same concrete values (*Provider, *Controller, etc.)\nbefore, only the visible parameter type name changes.",
          "is_bot": false,
          "headline": "feat(gonest): re-export Module's ProviderRef/ControllerRef/ResolverRe…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T21:02:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0582feedcf77e32123b6e7c0dd6698bdc328961",
          "body": "…gistered schema\n\nWraps internal/schema.Lookup (the registry NewSchema[T] already populates,\npreviously only consumed internally by the MustJsonBody family) so a\nProvider/Controller declared in a different file/package than an entity's\nown NewSchema[T] call can reach that schema without needing an e\n[…]\nal type->provider registry that conflicts with the DI graph's existing\nmodule-scoped semantics (2 unrelated modules can legitimately provide the\nsame concrete type today) -- deferred, not implemented.",
          "is_bot": false,
          "headline": "feat(gonest): add SchemaFor[T], a reflection lookup for an already-re…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T20:06:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cf8599f28bcf3009998c52cfd1fab5a93bfd44e",
          "body": "…sitive regex\n\nMatchString's LIKE/NLIKE operators did a case-SENSITIVE strings.Contains,\ninconsistent with query.text's own separate manual-lowercase substring\nsearch -- neither was a real regex match. Both now share one\nsearch.LikeMatch(value, pattern string) helper: compiles \"(?i)\" +\nregexp.QuoteM\n[…]\noth wrong matches and a\nReDoS-shaped footgun from compiling raw user input as a live pattern).\nVerified live: mixed-case search, and a name containing literal\nparentheses/period, both match correctly.",
          "is_bot": false,
          "headline": "fix(full-text-search): like/nlike and text search use real case-insen…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T17:02:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce7097cd385c4621b025e7d05856374353d87b6a",
          "body": "…heir parent, avoid OpenAPI title collisions\n\ninternal/openapi's registerSchema keys components.schemas purely by\nSchema.TitleText(), not by Go type -- search.QuerySchemaFor/FieldsSchemaFor/\nSortFieldSchemaFor/ResultSchemaFor were using a fixed \"search.Fields\"/\n\"search.SortField\"/\"search.Result\" tit\n[…]\nsSchemaFor/SortFieldSchemaFor fall back\nto a T-derived title (T's own type name + \"Fields\"/\"Sort\") the same way when\ncalled standalone, so nothing generated is ever left with an empty (invalid)\ntitle.",
          "is_bot": false,
          "headline": "docs(full-text-search): derive Fields/Sort/Where/Result titles from t…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:53:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f67ae3a8f1a6e4c5d38745d4b07d1dc895564685",
          "body": null,
          "is_bot": false,
          "headline": "chore: reorder routes",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:40:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8461a38ff7828e1f49c50100f1fc37368fb1ea93",
          "body": null,
          "is_bot": false,
          "headline": "docs(examples): reorder person.Controller routes (POST before _search)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:40:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4de2117330e7758ca27984254b72ddea000154f9",
          "body": "New standalone example (.examples/full-text-search, own go.mod) modeled after\na Search.ts gist: CRUD for Person plus POST /person/_search (text/where/\nfields/sort/offset/limit). Exercises gonest.Schema nested Object()/Array()\nrefs, gonest.Accessor dirty-tracking on both write DTOs and the Where filt\n[…]\nST /person/_search rather than the HTTP QUERY method: OpenAPI's Path\nItem Object has no representation for QUERY (still an IETF draft RFC), so a\nroute registered under it never surfaces in Swagger UI.",
          "is_bot": false,
          "headline": "docs(examples): add full-text-search (Person CRUD + generic search API)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:39:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29fe7d5458eb400c8761e8b3483029c11f0bf205",
          "body": "…set for nested embeds\n\nStringSchema.Enum(items ...string)/NumericSchema.Enum(items ...int64), chainable\nlike Min/Max/Pattern. internal/validate rejects out-of-list values (collected\nalongside other violations, never short-circuits); internal/openapi emits\n\"enum\":[...] when set. Motivated by a real \n[…]\n -- lets a long summary/description split across several Go string\nliterals without manual \"...\" + \"...\" concatenation, while still requiring at\nleast one word so an empty call can't compile silently.",
          "is_bot": false,
          "headline": "feat(schema): add Enum to String/Numeric branches; fix findFieldByOff…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a8fa1189c4ad177f4b4ac274f420c64323157e6",
          "body": "…OpenapiGenerate; root wrappers stop leaking internal types in autocomplete\n\nEvery root New*/etc that was a bare var-aliased func value (var NewX =\npkg.New) is now a real func with the signature spelled out using root\naliases -- var-aliasing copies pkg.New's literal signature verbatim, so\nIDE hover/\n[…]\nvel) and got renamed to\nLoggerLevel/LoggerLevel* alongside; GenerateOpenApiSchema renamed to\nOpenapiGenerate on request. Both are breaking, no deprecation path.\n\nSee AD-046 in .specs/project/STATE.md.",
          "is_bot": false,
          "headline": "refactor(gonest)!: LogLevel -> LoggerLevel, GenerateOpenApiSchema -> …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T02:12:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b5c2851f7f7c08886e939586937fe3ae3cf4c9a",
          "body": "…ruct\n\nParse[*Config]/MustParse[*Config] now allocates the pointee and returns\nthe populated pointer, instead of requiring the caller to Parse the\nstruct value and take its own address. Motivated by a real consumer\ncall site needing *T straight out of a DI provider constructor.\n\nSee AD-045 in .specs/project/STATE.md.",
          "is_bot": false,
          "headline": "feat(parse): Parse/MustParse accept T as a pointer to the schema's st…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T20:34:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee200f76b37f214577ebf393cb10126161b4a449",
          "body": "…or; drop ToDirtyMap/AccessorsToDirtyMap\n\nPackage name now matches the Accessor[T] type it defines. ToDirtyMap and its\npublic wrapper AccessorsToDirtyMap are removed -- unused, no known callers.\n\nBREAKING CHANGE: gonest.AccessorsToDirtyMap no longer exists.",
          "is_bot": false,
          "headline": "refactor(accessor)!: rename internal/value package to internal/access…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T18:28:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "046ac2b6a85ceb08ccdf677f6cc05211b9701d84",
          "body": "…Accessor\n\nApply writes into a raw *T target. Sync covers the DTO -> entity case where\nthe target is itself an Accessor[T], so the dirty flag propagates via Set\ninstead of being silently lost.",
          "is_bot": false,
          "headline": "feat(value): add Accessor.Sync to propagate dirty value into another …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T17:54:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3ae95c81bf4bd0ec2592eb4233b417ef419d528",
          "body": "…O.md\n\nManual dependency lookup already covered by MustInject. Module-level\nlazy loading has no Go equivalent (documented explicitly on the site,\nnot just silently absent) -- JS dynamic import() solves a runtime\nproblem Go's compiled binary doesn't have. Cycle detection already\nexists (DetectCycle); a real escape hatch for legitimate cycles\n(LazyInject[T]) and deferred-instantiation \"Lazy Providers\" are both\ngrounded in real NestJS examples but left speculative, no concrete use\ncase yet.",
          "is_bot": false,
          "headline": "docs: add INSIGHT-LAZY.md, split Module Reference/Lazy Loading in TOD…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T03:13:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14e80d40e5e008b8cb12444e69a20bb05f5b7186",
          "body": "No framework code needed -- Module is a plain Go value built by a\nbuilder function, so a dynamic module is just a function closing over\noptions and returning *Module. Documented on the site instead.",
          "is_bot": false,
          "headline": "docs: add INSIGHT-DYNAMIC.md, mark Dynamic Modules resolved in TODO.md",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T03:02:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff9fb9dac9474da6b81e1e7cfa984683155a205a",
          "body": "…no-error convenience form\n\nListener[EventType].On(func(ctx, event) error) -- a non-nil return is\nlogged by Emit the same way a recovered panic already is, never\npropagated to Emit's own caller. MustOn(func(ctx, event)) wraps a\nhandler that never fails, so simple listeners don't need \"return nil\".\nMustOn does not panic on anything despite the name -- deliberate choice\nto read naturally alongside On, confirmed with the user, a documented\nexception to this framework's usual Must=panics convention.",
          "is_bot": false,
          "headline": "feat(emitter): On returns error (logged like a panic); MustOn is the …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T00:31:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a59f509b0fa6254e7b3a4c7a28bf74664f7483d2",
          "body": "…places the return-a-handler builder\n\nNewListener(func(l *Listener[EventType]) { l.On(handler) }) -- Listener\nis now a genuinely generic struct (Go 1.24+ parameterized type alias),\nso On is a real method (uses the receiver's own type parameter, doesn't\nintroduce a new one, so L-001 doesn't block it)\n[…]\n\nuses, without the func-returning-func shape the previous iteration had.\n\nBreaking: Listener is now Listener[EventType] everywhere (call sites\ninferring it from NewListener's argument are unaffected).",
          "is_bot": false,
          "headline": "refactor(emitter)!: Listener[EventType] is a real generic type; On re…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T00:08:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6da8792244a0940b26173b43ab319dbaea29ddf6",
          "body": "Listener is now bound to its event type via NewListener's own generic\nparameter -- the builder receives *Listener (for MustInject) and returns\nthe per-event handler, resolving dependencies once instead of via a\nseparate MustOn call:\n\n  NewListener(func(l *Listener) func(context.Context, UserCreatedE\n[…]\nis removed -- the only real usage in the repo was always exactly\none event per Listener, so the split never bought anything. Breaking\nchange: internal/emitter.MustOn and gonest.MustOn no longer exist.",
          "is_bot": false,
          "headline": "refactor(emitter)!: NewListener[EventType] replaces NewListener+MustOn",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T22:29:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2ceff25fcce278294472f886c2dd4665456a042",
          "body": "…otstrap/OnModuleDestroy/BeforeApplicationShutdown/OnApplicationShutdown)\n\nProvider gains 5 lifecycle hooks matching NestJS's real hook set 1:1\n(confirmed via Context7, not assumed -- INSIGHT-ON.md's original sketch\nwas missing BeforeApplicationShutdown). OnModuleInit/OnApplicationBootstrap\nrun auto\n[…]\nire for scope.Singleton providers. HttpAdapter gains Shutdown(ctx),\nFiberApp implements it via Fiber v3's real ShutdownWithContext.\n\n.examples/lifecycle-hooks demonstrates the flow live. Milestone 20.",
          "is_bot": false,
          "headline": "feat(provider,app): add lifecycle hooks (OnModuleInit/OnApplicationBo…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T20:19:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a3d0fa9e78a0c8a33a18fc82a2520e8378399c5",
          "body": null,
          "is_bot": false,
          "headline": "chore: add config-dotenv to Taskfile's EXAMPLES list (missed in T12)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:32:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a63332cdd2ac9ff05ba2c180210453cb0c441d6",
          "body": "Update both spec.md's traceability tables (all DOTENV-0x/ENVCFG-0x ->\nVerified), ROADMAP.md (Milestone 19 -> COMPLETE), and STATE.md (AD-043\ndocumenting the T1-T12 execution: hand-rolled .env parser in distinct\npasses, PropertyBuilder.Default mirroring Custom exactly, envSource\nreusing the REST validation pipeline unchanged, real end-to-end evidence\nfrom .examples/config-dotenv).",
          "is_bot": false,
          "headline": "docs(specs): close Config Loading — Milestone 19 COMPLETE",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:31:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd8b96ddcdd5fbc8a971df1d4774f1b038ea509c",
          "body": "…se end-to-end",
          "is_bot": false,
          "headline": "docs(examples): add config-dotenv demonstrating Dotenv.Load + MustPar…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:28:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c24c8df3ad9508b42ab4248a15ca13eb17b34327",
          "body": "…se work end-to-end",
          "is_bot": false,
          "headline": "feat(dotenv): ParseInto satisfies execution.Parseable -- Load+MustPar…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:24:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0dadd89a8be4e8535efb3f822558e6b0a9a0e477",
          "body": "…lidateValue/populate unchanged",
          "is_bot": false,
          "headline": "feat(validate): envSource/ParseEnvInto -- reuses coerceParamString/va…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:21:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47fa731bf81760d0abc571896066b92ee41cbce3",
          "body": "…sent source data",
          "is_bot": false,
          "headline": "feat(schema): PropertyBuilder.Default/DefaultValue -- fallback for ab…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:18:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1129a4adc3ed7c38c27d143898f2c308dec8da8a",
          "body": "…bootstrap",
          "is_bot": false,
          "headline": "feat(gonest): export Dotenv() -- root re-export, callable before any …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:16:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a1f877d9fb4b0ec094940d3d2668f91f749e828",
          "body": "…ways wins",
          "is_bot": false,
          "headline": "feat(dotenv): first-path-wins precedence, pre-existing process env al…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:13:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23ceedb0b1db163b4ff8b382c99562b053077cb0",
          "body": "Extend the backtick branch so an unclosed backtick on the opening line\nfalls back to extractBacktickBlock, folding subsequent real file lines\ninto the value (joined with real \\n) until the closing backtick is\nfound. parseFile's line loop is now index-based (was range-based) so\nit can skip past all lines consumed by a multi-line backtick block.",
          "is_bot": false,
          "headline": "feat(dotenv): backtick multiline values preserve real newlines",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:10:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c61250bafdee0addd9be0152f81e031708f71951",
          "body": "…-close-rule)\n\nStrips inline \"# comment\" text per spec's 4 literal rules: bare values\nonly treat \" #\" (space then hash) as a comment start (glued \"#\" stays\npart of the value); quoted values (single/double) never treat a \"#\"\ninside the quotes as a comment (a natural consequence of the existing\nextrac\n[…]\nfault/alternate text is never mistaken for a real trailing comment.\n\nextractDelimited now also returns the text remaining after the closing\ndelimiter (rest) so callers can detect a post-quote comment.",
          "is_bot": false,
          "headline": "feat(dotenv): inline comment stripping (bare space-rule, quoted after…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:07:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d8903e018e93c6edd5f611dca71868b6b6487df",
          "body": "…me-type quotes\n\nextractDelimited now unescapes \\<delim> into a literal delimiter character\nwhile extracting (single/double/backtick), instead of leaving the backslash\nin the raw content. A new applyEscapes converts \\n/\\r/\\t/\\ to their real\nbyte values, wired only into parseValue's double-quote branch, running\nbefore resolveInterpolation on the escape-resolved content.",
          "is_bot": false,
          "headline": "feat(dotenv): double-quote escape sequences (\\n \\r \\t \\) + escaped sa…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28c8d30d6e42432b87b2599279557a052582d63f",
          "body": "…ors)",
          "is_bot": false,
          "headline": "feat(dotenv): interpolation (${VAR}/$VAR + 4 default/alternate operat…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:00:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaaa2be34147bfd655ec611fe30775d62b4e2b7c",
          "body": "…o interpolation yet)",
          "is_bot": false,
          "headline": "feat(dotenv): parseFile line classification + quote-style dispatch (n…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:56:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "842459eb3b1ff44f94d980008b2ec408708ed06a",
          "body": "…arser",
          "is_bot": false,
          "headline": "feat(dotenv): Dotenv singleton, Load/MustLoad skeleton over stubbed p…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6789dc3833b380ce4fb323c94be0f3e323ae685a",
          "body": "…racks",
          "is_bot": false,
          "headline": "docs(specs): tasks.md for Milestone 19 (Config Loading) — T1-T12, 2 t…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "305fadd5a7b660f4f4f969f01be53c30d541374b",
          "body": "Both features designed, mirroring existing internal/validate sources\nclosely (paramsSource.ParseInto's exact shape) rather than inventing new\npatterns.\n\ndotenv-loading: internal/dotenv (new leaf package), Dotenv.Load/MustLoad,\na hand-rolled line-by-line parser (classify -> dequote -> escape ->\ninter\n[…]\ne skips coercion entirely (assumed to already be the right Go\ntype). Dotenv.ParseInto is a one-line delegation to envSource, satisfying\nexecution.Parseable on the same singleton Load/MustLoad live on.",
          "is_bot": false,
          "headline": "docs(specs): design Milestone 19 (Config Loading)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:46:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11e270a2ede8d879ba49c8b378aea05cc46a0f80",
          "body": "… Env→Schema Binding\n\nTwo features, spec+context each, evolving INSIGHT-CONFIG.md's brainstorm\n(motivated by @nestjs/config's ConfigModule and the user's own gox/env\nmodel, which itself targets real dotenvx behavior — read live from\nhttps://dotenvx.com/docs/env-file via WebFetch, not assumed).\n\nKey \n[…]\ndefault/alternate operators, backtick\nmultiline, escapes) targeted for v1, not a smaller core first — explicit\nuser choice via AskUserQuestion.\n\nDesign/Tasks/Execute not started — no code written yet.",
          "is_bot": false,
          "headline": "docs(specs): specify Milestone 19 (Config Loading) — Dotenv Loading +…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:40:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66e8f30298290286bd78a09643ff07fd63f5faf9",
          "body": "Both still described the Milestone 17 ad-hoc SSE/WS transports\n(/graphql/stream/:name, /graphql/ws/:name) as current and, in\nINSIGHT-GRAPHQL.md's case, listed the real-protocol replacement as\n\"Design/Tasks/Execute ainda pendentes\" -- stale since Milestone 18\ncompleted. README.md's milestone checklis\n[…]\npen-items sections rewritten\nto match (Execute, WSProtocolHandler/SSEDistinctHandler/SSESingleXxxHandler,\nRequest.IsWebSocketUpgrade/Response.UpgradeWebSocket replacing\nHttpAdapter.RegisterWebSocket).",
          "is_bot": false,
          "headline": "docs: update README.md and INSIGHT-GRAPHQL.md for Milestone 18",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "95119371c3c1c4ee4745b12ed06a85e817bd75d9",
          "body": "…L tests\n\nlistenOnEphemeralPort's cleanup called fiber.App.Shutdown(), which waits\nfor every still-open connection to close gracefully -- an abandoned SSE\nstream (Distinct or Single connection mode) only notices its client is\ngone on the next heartbeat write attempt (sseHeartbeatInterval, 15s), so\nT\n[…]\non this test deliberately\nleft open), not asserted on.\n\ninternal/app package time: 31s -> ~1.9s. Full `task gate` (build, vet,\nrace test, examples) now completes in seconds instead of tens of seconds.",
          "is_bot": false,
          "headline": "fix(app): ShutdownWithTimeout instead of Shutdown in real-dial GraphQ…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:39:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abdaee02197b8a1bfb5187e45d53d8f324b46902",
          "body": null,
          "is_bot": false,
          "headline": "docs(specs): record AD-041 (internal/appoptions removal, test-cycle fix)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebab8928cad9ba98e6b13cdb66a00113c5c858ce",
          "body": "…-cycle it caused\n\ninternal/appoptions existed only to avoid an import cycle: FiberApp.Init\nneeded the config type, but internal/app already imported\ninternal/adapter/fiber (test_app.go's MustNewTestApp hardcoded\nfiber.FiberApp). internal/appoptions.AppOptions is now internal/app.Options\ndirectly --\n[…]\n}.go -> {ws_protocol,sse_distinct,sse_single}\n{,_test}.go.\n\ngo test ./... -race (25 packages) and .examples/* all green; test function\ncount in the migrated files verified identical before/after (66).",
          "is_bot": false,
          "headline": "refactor(app)!: move Options struct into internal/app, break the test…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:30:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fdd9ff77196d76e012bba3aa89877691f3c2d6dc",
          "body": "Update spec.md's traceability table (all GQLRT-0x -> Verified),\nROADMAP.md (Milestone 18 SPECIFIED -> COMPLETE), and STATE.md (AD-040\ndocumenting the T1-T18 execution, the Planner/Implementer/Evaluator\nsubagent run, and the 2 real bugs found running .examples/blog-graphql\nend-to-end).",
          "is_bot": false,
          "headline": "docs(specs): close graphql-realtime-protocols — Milestone 18 COMPLETE",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:17:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7432623d39ad3b7bef801d9d999620af28ccac8",
          "body": "…st stubs\n\napp_test.go's recordingFakeAdapter/listenSpyAdapter kept a RegisterWebSocket\nmethod after HttpAdapter dropped it (T4) -- dead code that still compiled\nsince Go allows extra methods on a type, cleaned up as part of the final\ngate pass. appoptions.go's GraphqlPath doc comment still described the\nremoved ad-hoc /graphql/stream/:name and /graphql/ws/:name paths -- updated\nto describe the real-protocol transports that replaced them.",
          "is_bot": false,
          "headline": "chore(graphql-realtime-protocols): drop orphaned RegisterWebSocket te…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:15:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c19d807a350931fc2ca4cea0ab5012d7224fc54",
          "body": "…otocol echoed back)\n\nfiberResponder.Upgrade called websocket.New(fn) with no Config, so\nSec-WebSocket-Protocol was never echoed back during the handshake even\nwhen a client offered graphql-transport-ws -- a spec-compliant IDE\n(Apollo Sandbox/GraphiQL) checks that response header and refuses the\ncon\n[…]\nket now\ntake a variadic subprotocols argument, forwarded to\nwebsocket.Config{Subprotocols: subprotocols} on the fiber adapter side;\nthe GraphQL GET dispatcher passes \"graphql-transport-ws\" explicitly.",
          "is_bot": false,
          "headline": "fix(adapter/fiber): negotiate WebSocket subprotocol (Sec-WebSocket-Pr…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:11:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aed1930f03f1f2f56524e293692863f03c9d8629",
          "body": "…aphql-sse (both modes)\n\nReplaces the removed ad-hoc /graphql/stream/:name and /graphql/ws/:name\nmentions in main.go's doc comment with a new README.md documenting the 3\nreal-protocol transports registerGraphql now exposes on /graphql\n(WebSocket graphql-transport-ws, SSE Distinct connections, SSE Si\n[…]\nand a streaming Subscription, a real curl -N SSE\nDistinct request for both a Query and a Subscription, and a full\nPUT->GET->POST->DELETE SSE Single connection flow -- captured output is\nin the README.",
          "is_bot": false,
          "headline": "docs(examples): blog-graphql demonstrates graphql-transport-ws and gr…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:04:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc4994288a81bdbe26d9f50d31ffea9681e4fcf1",
          "body": "…y real protocols)\n\nws.go/sse.go (Milestone 17's hand-rolled Subscription transports) had no\nconsumers left after registerGraphql was rewritten to use\nWSProtocolHandler/SSEDistinctHandler/SSESingleXxxHandler (real\ngraphql-transport-ws / graphql-sse protocols). Deletes ws.go, sse.go,\nws_test.go, sse_\n[…]\nnt through graphql-sse's Distinct\nconnections mode (SSEDistinctHandler), both subscribed to the same\nSubscription and fed by the same Emitter.Emit, proving disconnecting one\ndoes not affect the other.",
          "is_bot": false,
          "headline": "refactor(graphql)!: remove ad-hoc ws.go/sse.go transports (replaced b…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:58:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d90769e4fd5b335eda7f1714b07aa449741fb68",
          "body": "…ame /graphql path\n\nRewrites registerGraphql (internal/app/graphql.go) to register exactly 4\nRegisterRoute calls -- POST/PUT/GET/DELETE -- all on the same graphqlPath,\nreplacing the previous POST-only + ad-hoc WS/SSE-path registration:\n\n- POST dispatches to SSESingleOperationHandler when a graphql-s\n[…]\ndshake and\nreceives connection_ack, a real TCP dial reads an SSE Distinct next/complete\npair for a plain GET, and a PUT+GET+POST flow proves the Single connection\nmode token-based dispatch end to end.",
          "is_bot": false,
          "headline": "refactor(app)!: registerGraphql wires 4 real-protocol routes on the s…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:52:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1df9ac46180afaf9f62191efde83ec3dfbe6b2d0",
          "body": "SSESingleCancelHandler serves DELETE /graphql?operationId=X (token via\nheader or query) and delegates to ReservationRegistry.StopOperation,\nstopping only that operationId's Subscription without touching any other\noperation active on the same token. Unknown token/operationId responds\n404, never panics.",
          "is_bot": false,
          "headline": "feat(graphql): ssesingle DELETE cancels one streaming operation by id",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:35:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b567a8b0f796dc8578bdbd0353bd5a053ac1cff",
          "body": "…served token\n\nAdds SSESingleOperationHandler implementing graphql-sse's Single\nconnection mode operation start: POST /graphql decodes the standard\nGraphQL-over-HTTP body plus extensions.operationId, resolves the\nreservation token's write func via ReservationRegistry.Route (409 if\nno GET has attache\n[…]\nre\nDELETE handler (T14) can cancel one operationId's stream without\ntouching others on the same token; Release now also cancels any\noperations still registered under a token when its connection drops.",
          "is_bot": false,
          "headline": "feat(graphql): ssesingle POST executes operation, routes result to re…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:31:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce2f9175c7845ed735e1645393e77a8cadffb790",
          "body": null,
          "is_bot": false,
          "headline": "feat(graphql): ssesingle PUT (reservation) + GET (single SSE connection)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:23:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "162a7f8ddc1bd22ce792cf7e07419c641b365a65",
          "body": "Adds ReservationRegistry (Reserve/Attach/Route/Release), a thread-safe\ntoken -> connection registry used by graphql-sse's Single connection\nmode: PUT reserves a token, GET attaches the one SSE connection, and\nsubsequent POST/DELETE route by token via Route. Reuses google/uuid\n(already a direct dependency) for token generation.",
          "is_bot": false,
          "headline": "feat(graphql): reservation registry for SSE Single connection mode",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:09:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75bcf2fce3f702376762e8ad4a0f58f89fc148a9",
          "body": "…ections",
          "is_bot": false,
          "headline": "feat(graphql): ssedistinct handles Subscription via SSE Distinct conn…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:07:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94fcc60edde243f7ad2c3dcfa754fd3c2ad0a1d2",
          "body": "…r graphql-sse PROTOCOL.md\n\nPROTOCOL.md (github.com/enisdenjo/graphql-sse, line 52) requires an\nexplicit, empty `data: ` field on the complete event: EventSource never\nfires its listener for an event with no `data:` line at all. The\nprevious commit's SPEC_DEVIATION #1 omitted it, which was a real bug,\nnot a neutral protocol choice. writeSSEDistinctResult now writes\n`event: complete\\ndata: \\n\\n`.",
          "is_bot": false,
          "headline": "fix(graphql): ssedistinct complete event includes empty data field pe…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:03:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16ae41f1c8852d4574f8b75d7aa7fc5badd9154e",
          "body": "…TP SSE\n\nAdds SSEDistinctHandler (GET /graphql, graphql-sse Distinct connections\nmode): reads query/variables/operationName from the query string, reuses\nwsRootFieldName to resolve the root field and Execute to dispatch\nQuery/Mutation, then streams exactly one `event: next` frame (the\n{data,errors} \n[…]\never a bare HTTP\nerror status (EventSource can't read a non-2xx body). A root field that\nresolves to a registered Subscription gets a placeholder error frame --\nreal streaming dispatch is T10's scope.",
          "is_bot": false,
          "headline": "feat(graphql): ssedistinct handles Query/Mutation via GraphQL-over-HT…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:02:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b62c74c0ca89ee91b97f6710400cf6a7d2510047",
          "body": "T8: add a duplicate-id guard to handleSubscribe (checked via a new\nisOpActive closure over activeOps) that closes the connection with 4409\n(graphql-transport-ws's SubscriberAlreadyExists) when a Subscribe arrives\nfor an id whose earlier streaming Subscription hasn't completed yet. The\nQuery/Mutation\n[…]\nhere; documented inline.\n\nNew tests prove real multiplexing (a Query dispatched and fully answered\nwhile a Subscription is parked mid-stream on a different id, same\nconnection) and the new 4409 close.",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol multiplexing + 4409 on duplicate id",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:58:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc94d099e3064b39485ca8729c1808095576e962",
          "body": "Design phase (routing collision at /graphql resolved via a new\nResponse.UpgradeWebSocket capability instead of adapter-level\nRegisterWebSocket+app.Use) and Planner-generated task breakdown (T1-T18),\nboth already implemented up through T7 in prior commits this session.",
          "is_bot": false,
          "headline": "docs(specs): add design.md and tasks.md for graphql-realtime-protocols",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:54:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de2c24ce037ec7c3e029293d1b3ac7ef823fa785",
          "body": "…ing operation\n\nExtend WSProtocolHandler so a Subscribe whose root field matches a\nregistered Subscription runs HandlerFunc() in its own goroutine, emitting\none Next per emit(value) call instead of the T7-scope placeholder Error.\nWrites onto the connection are serialized through one writeMu (handsha\n[…]\nms are emitting share the same conn). A per-id\nid->done-channel registry lets a client's Complete for one id cancel only\nthat id's stream, and the connection dropping tears down every id still\nactive.",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol Subscribe dispatches Subscription as stream…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:53:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "86cb094104ec2fd6fe6128b33694b5433e5fce2f",
          "body": "…le-result operation\n\nExtends WSProtocolHandler's post-ack loop to handle graphql-transport-ws\nSubscribe messages: the root selection field is resolved via the\ngraphql-go parser (same AST parser Execute/gql.Do already uses) and\nlooked up in subs. When it isn't a registered Subscription (i.e. it's a\n\n[…]\nubscribe whose root field DOES match a registered\nSubscription gets a minimal Error response (\"not implemented yet\")\nrather than real streaming dispatch -- that's T7's scope, extending\nthis same loop.",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol Subscribe dispatches Query/Mutation as sing…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:48:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e296a8b49811170017cb834cc34c0949a980f4b",
          "body": "…00/4429)",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol handshake (ConnectionInit/Ack, timeouts, 44…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:40:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fa8ece27379000b3a9dbf48d3d7c6a6a8c74ed0",
          "body": "…terWebSocket\n\nReplace fiberResponder.IsUpgradeRequest/Upgrade stubs with real\nwebsocket.IsWebSocketUpgrade/websocket.New wiring, and give\nfiberWSConn.CloseWithCode a real close-frame implementation\n(WriteControl(CloseMessage, FormatCloseMessage(code, reason)) + Close),\nboth confirmed against github\n[…]\nRegisterWebSocket -- required so `go build ./...` (this repo's\npre-commit build gate builds the whole module) keeps passing; this is\nNOT the GraphQL WS path reorganization, that lands in a later task.",
          "is_bot": false,
          "headline": "refactor(adapter/fiber)!: real WS upgrade via Responder, remove Regis…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:37:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1bc06514da189db63349645ad5ccde28e0cd87d1",
          "body": "…, extend Responder\n\nAdds IsUpgradeRequest()/Upgrade(handler func(conn WSConn)) to the\nResponder contract so Request/Response can expose thin delegating\nwrappers (IsWebSocketUpgrade/UpgradeWebSocket) for the upcoming\nWebSocket transport (graphql-realtime-protocols, Milestone 18).\n\nEvery existing Responder fake across the repo gets minimal no-op\nimplementations to keep compiling. fiberResponder gets a temporary\npanicking stub -- the real Fiber-backed WS implementation lands in a\nlater task (T4).",
          "is_bot": false,
          "headline": "feat(execution): Request.IsWebSocketUpgrade/Response.UpgradeWebSocket…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:29:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cae5d81aa4d3dc3d9ce5d6d503086eb3ec0bb8a1",
          "body": "…Code\n\nMoves the WSConn interface to internal/execution/wsconn.go so it can be\nshared beyond internal/graphql, and adds CloseWithCode(code, reason) for\ngraphql-transport-ws's well-known close codes (4400/4401/4408/4409/4429).\ngraphql.WSConn becomes a type alias back to execution.WSConn so ws.go's\nWSHandler is unaffected. fakeWSConn (ws_test.go) and fiberWSConn\n(internal/adapter/fiber) get minimal CloseWithCode stubs that delegate to\nClose() -- real close-code behavior lands in a later task.",
          "is_bot": false,
          "headline": "refactor(execution): move WSConn from internal/graphql, add CloseWith…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:23:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7a50502f3779ae304359275c293e4a8a2fc632f",
          "body": "Move the gql.Do(gql.Params{...}) call plus the result.Errors ->\n[]map[string]any{\"message\": ...} mapping out of graphqlHandler into a\nnew internal/graphql.Execute(sch, query, variables, operationName)\nfunction, so upcoming WS/SSE transports can reuse the identical\ndispatch instead of copying it.",
          "is_bot": false,
          "headline": "refactor(graphql): extract Execute helper from POST /graphql handler",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:20:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a928cf3d42fbac091c92ed41447019920b9bb8ef",
          "body": null,
          "is_bot": false,
          "headline": "chore: change argument name on files",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:01:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d6fd98da79fbb2b2350f0d7086c9cfcfbf5bd2c",
          "body": null,
          "is_bot": false,
          "headline": "chore: change argument name on files",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T15:59:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae458408f42466aee3c581cdbd4446aaae823691",
          "body": "…ols, Design/Tasks/Execute pending\n\nMotivated by a real bug: a GraphQL IDE tried WebSocket directly on /graphql\nexpecting the graphql-transport-ws subprotocol and failed. The ad-hoc\nSubscription transports from Milestone 17 (/graphql/stream/:name,\n/graphql/ws/:name) never had a real consumer and don\n[…]\nely; WS modern subprotocol only (no legacy graphql-ws); multiplexing\nsupported from v1; full coverage of both graphql-sse modes.\n\nStopping here per explicit request — Design/Tasks/Execute not started.",
          "is_bot": false,
          "headline": "docs: specify graphql-realtime-protocols (Milestone 18) — real protoc…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:26:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91585f5b524e0f22f19b8ef7046828c579e08713",
          "body": null,
          "is_bot": false,
          "headline": "docs: mention AppOptions.GraphqlPath in README",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:15:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e26305239fda0fb34688be4c6c5d04cc57e06e2a",
          "body": null,
          "is_bot": false,
          "headline": "chore: untrack image.png (debug screenshot, not project content)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:15:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6f30121c82ffaefa8e540ee83cb348c7b7ccff3",
          "body": "…l endpoint\n\nSubscription's SSE/WS endpoints derive from the same path (<path>/stream/:name,\n<path>/ws/:name), so overriding it moves all three consistently.",
          "is_bot": false,
          "headline": "feat(app): add AppOptions.GraphqlPath to override the default /graphq…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:14:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd224e423240056fe3e15caa510190c3619515fa",
          "body": null,
          "is_bot": false,
          "headline": "docs: mention .examples/blog-graphql in README and Taskfile",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:01:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "916c86a1249c06e33db158e66a3e1e29d61efc36",
          "body": "… Returns\n\nThree real bugs found by actually running a GraphQL example end-to-end\n(not caught by any existing unit test, all of which used map[string]any\nHandler results and never a Query returning a list):\n\n1. Object fields never resolved when a Handler returned a real Go struct\n   (only a map[stri\n[…]\n Query/Mutation/Subscription\nend-to-end (verified via real dispatch: HTTP POST /graphql and a live SSE\nconnection actually receiving an emitted event), which is how all three\nbugs were actually found.",
          "is_bot": false,
          "headline": "fix(graphql): resolve struct fields, native int/float args, and array…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:57:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c50b995626fed42ebe9f9d462e9a0d2ed442377b",
          "body": null,
          "is_bot": false,
          "headline": "docs: update README for M16-M17 (Sanitize/Refine, GraphQL Support)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:37:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0898f8d98de615a2b3d5f1e9ca6e97178439f76e",
          "body": "…GHT-GRAPHQL, verify gate",
          "is_bot": false,
          "headline": "chore: finalize graphql-support feature — update STATE, ROADMAP, INSI…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4002ad68857863608baf098075349f04e81d8a17",
          "body": "…on/Subscription/Context, Subscribe[T])\n\nTasks.md's T1-T11 built the full internal/graphql plumbing (Resolver/\nQuery/Mutation/Subscription, Schema->SDL generation, real HTTP dispatch,\nSSE/WebSocket Subscription transports) but never exposed it through\ngonest.go -- a real gap: without this, the feature had no way to actually\nbe used. Verified end-to-end via a real scratch build + gonest_test.go's\nown dispatch test.",
          "is_bot": false,
          "headline": "feat(gonest): expose public GraphQL API (GraphqlResolver/Query/Mutati…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:32:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ffb8988e366e7ace363f38c46b2dfafa900285e",
          "body": "…gle internal/graphql package\n\nUser's call: 3 flat internal/* packages were unnecessary — the builder API,\nthe Schema->SDL generator, and the SSE/WS transports all belong to one\ncohesive concept. Package named 'graphql' (not nested under\ninternal/graphql/resolver, which would recreate the internal/r\n[…]\non AD-033 was written to avoid). Every reference to the\nEXTERNAL graphql-go/graphql package is import-aliased (gql \"github.com/\ngraphql-go/graphql\") wherever both packages are needed in the same file.",
          "is_bot": false,
          "headline": "refactor(graphql): merge gqlresolver/graphqlgen/gqltransport into sin…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:29:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1beb09910f60a3ca1cba80d8bbfca0d49c25ba3e",
          "body": "New HttpAdapter.RegisterWebSocket capability (confirmed real API via\nContext7: github.com/gofiber/contrib/v3/websocket's IsWebSocketUpgrade +\nwebsocket.New) -- a genuinely different connection shape than\nRegisterRoute's execution.Request/Response, so it gets its own method.\ngqltransport.WSConn keeps\n[…]\ns the spec's own P2 Independent Test: the same\nEmitter.Emit reaches an SSE client and a WebSocket client subscribed to\nthe same Subscription simultaneously; disconnecting one doesn't affect\nthe other.",
          "is_bot": false,
          "headline": "feat(gqltransport): add WebSocket transport for GraphQL Subscription",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:18:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0623354e119663da3ec474fb32e54586fe969b2",
          "body": "SPEC_DEVIATION (Args format not decided by design.md): GET has no body,\nso Args come from a single ?args=<JSON object> query param, reusing\nvalidate.NewGraphqlArgsSource unchanged rather than inventing a new\nper-field query tag/coercion path.\n\nDisconnect detection is write-failure-based (a closed connection only\nsurfaces on an actual write attempt) -- a periodic heartbeat frame\n(': ping') covers Subscriptions whose Handler doesn't emit often enough\non its own to notice quickly.",
          "is_bot": false,
          "headline": "feat(gqltransport): add SSE transport for GraphQL Subscription",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:10:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01773b93c663a706f1905133c908549d4c4dbc1c",
          "body": "…treaming responses\n\nPrerequisite for graphql-support's SSE transport (T9) -- neither Json/Html/\nText nor a single Response value can express \"keep this connection open,\nwrite more later\". Backed by fasthttp's real SetBodyStreamWriter (confirmed\nvia fasthttp@v1.72.0 source, stream.go/server.go).",
          "is_bot": false,
          "headline": "feat(execution): add Response.Stream/Responder.WriteStream for body-s…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:05:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab209ebea7308bb583d76e70fe0fd09a0dec3773",
          "body": null,
          "is_bot": false,
          "headline": "feat(emitter): add Subscribe[T] dynamic channel subscription",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:55:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "227f2879ce94946dd1a96c9803902fd5ab167091",
          "body": "SPEC_DEVIATION: graphql-go's own execution engine (graphql.Do) is what\ninvokes Resolve per field -- dispatch could not be wired from internal/app\nalone as tasks.md originally sketched. Resolve callbacks are built inside\ninternal/graphqlgen.Build itself (wrapping each Query/Mutation's own\nHandlerFunc\n[…]\nh jsonBodySource.ParseInto) so GraphqlContext.Args()\nreuses the exact same validate/populate/Refine pipeline REST already has,\nover graphql-go's own already-decoded args map instead of raw JSON bytes.",
          "is_bot": false,
          "headline": "feat(app): wire real GraphQL Query/Mutation dispatch over POST /graphql",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:52:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cbbf6239416bcbf53f6fd8faffc04af0c86e9e9",
          "body": "Dispatch (Resolve/Subscribe) intentionally left nil -- Query/Mutation\ndispatch is wired directly against gqlresolver's own HandlerFunc by\ninternal/app (T7), Subscription transport bypasses graphql-go's execution\nengine entirely (T9/T10), per design.md's Architecture Overview.\n\nSPEC_DEVIATION: no Pri\n[…]\nper found in graphql-go/graphql\n(confirmed via Context7 docs search) -- tests assert against the built\n*graphql.Schema's own structure (QueryType().Fields(), TypeMap()) instead\nof a golden SDL string.",
          "is_bot": false,
          "headline": "feat(graphqlgen): build graphql.Schema from gonest Schema declarations",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:44:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55a5c73034e506b3963f6c1777946126e44f9025",
          "body": null,
          "is_bot": false,
          "headline": "feat(schema): add GraphqlScalar(name) modifier for Custom(fn) fields",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "036743457e9ed6ef9dc52e6c037572711785cb1a",
          "body": "…apping",
          "is_bot": false,
          "headline": "feat(graphqlgen): add graphql-go/graphql dependency + native scalar m…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:38:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e81fb90eae8ab3e28c84ed4769d76802bbdc51",
          "body": "…eclaration API\n\nAdds internal/gqlresolver (T1, T3) mirroring Controller/Route's builder\nshape, plus Module.Resolvers/OwnResolvers (T2) mirroring Controllers.\nGraphqlContext is stubbed for now (real Args()/Done() wiring lands in T7).",
          "is_bot": false,
          "headline": "feat(gqlresolver): add Resolver shell + Query/Mutation/Subscription d…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:36:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0e8da2399dfcf945382e07b20b975923b3109c7",
          "body": "…Refine)",
          "is_bot": false,
          "headline": "docs: update README for M13-M16 (Accessor rename, NewValue, Sanitize/…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T00:57:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 31,
      "commits_last_year": 343,
      "latest_release_at": "2026-07-25T15:10:35Z",
      "latest_release_tag": "v0.31.0",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "gonest.dev/gonest",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": null,
          "registry_url": "https://pkg.go.dev/gonest.dev/gonest",
          "is_deprecated": false,
          "latest_version": "v0.31.0",
          "repository_url": null,
          "versions_count": 31,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-25T15:09:39Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 4,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Taskfile.yml"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        ".examples/blog-api/go.mod",
        ".examples/blog-graphql/go.mod",
        ".examples/config-dotenv/go.mod",
        ".examples/full-text-search/go.mod",
        ".examples/lifecycle-hooks/go.mod",
        ".examples/notification-driver/go.mod",
        ".examples/simple-todo/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 147910,
      "source_files_sampled": 219,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/fasthttp/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.12"
        },
        {
          "name": "github.com/gofiber/contrib/v3/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.1"
        },
        {
          "name": "github.com/gofiber/fiber/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.4.0"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/graphql-go/graphql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.8.1"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "leandroluk",
          "commits": 343,
          "avatar_url": "https://avatars.githubusercontent.com/u/8602982?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ea4e03179f40f7cc14adcaa9812343e8cfaf126b",
        "ran_at": "2026-07-29T16:43:24Z",
        "aggregate_score": 2.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T15:10:38Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/gonest-dev/gonest",
    "host": "github.com",
    "name": "gonest",
    "owner": "gonest-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 45,
      "inputs": {
        "security": 29,
        "vitality": 74,
        "community": 28,
        "governance": 32,
        "engineering": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 343,
              "human_commit_share": 1,
              "days_since_last_push": 4,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "343 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 343
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 31,
              "latest_release_tag": "v0.31.0",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "31 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 28,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 8,
            "inputs": {
              "forks": 1,
              "stars": 4,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "4 stars",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 32,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "gonest-dev",
              "public_repos": 3,
              "account_age_days": 145
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of gonest-dev",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "gonest-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "3 public repos, account ~0 yr old",
                "points": 5.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 3
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "gonest.dev/gonest"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "31 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 56,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 29,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 29,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 2.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Taskfile.yml"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                ".examples/blog-api/go.mod",
                ".examples/blog-graphql/go.mod",
                ".examples/config-dotenv/go.mod",
                ".examples/full-text-search/go.mod",
                ".examples/lifecycle-hooks/go.mod",
                ".examples/notification-driver/go.mod",
                ".examples/simple-todo/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Taskfile.yml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Taskfile.yml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 147910,
              "source_files_sampled": 219,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/219 source files over 60KB",
                "points": 54.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 219,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T16:43:29.647887Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/gonest-dev/gonest.svg",
  "full_name": "gonest-dev/gonest",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.