Registro público
Informe de salud del softwareesquema 0.31.0 · métricas 2.5.0 · 2026-08-05 09:31 UTC

iotserver24 / Xibecode

a autonomous open-source coding tool

TypeScriptApache-2.0★ 12 estrellas⑂ 2 forksdesde feb 2026Ver en GitHub ↗
TipoHerramienta de línea de comandosAplicación de escritorioServidor MCPBibliotecaInterfaz webInterfaz de terminalcómo se determina

iotserver24/Xibecode tiene un índice de salud de 67 sobre 100, lo que lo sitúa en la banda Bueno. Su puntuación más alta es Vitality (80/100) y la más baja, Sustainability & Governance (47/100). Se actualizó por última vez hace 3 días. Una sola persona concentra la mayor parte del trabajo reciente.

67
global / 100
Bueno

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala estandarizada de 1 a 100. El resultado global parte de su media ponderada, calibrada contra la distribución del registro público para que las bandas tengan significado percentil; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe un límite «En riesgo» de 34.

67
Excepcional93-100El nivel más alto del registro (≈ el 5% superior); cumple prácticamente todos los criterios evaluados
Excelente80-92Sólido en todos los frentes; carencias menores
Bueno65-79Saludable; carencias limitadas y manejables
Moderado50-64Aceptable con carencias notables; se recomienda revisión
Débil35-49Debilidades sustanciales en varias áreas
En riesgo20-34Debilidades significativas; su adopción exige cautela
Crítico1-19Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

El resultado global ponderado 61 se calibra a 67 en la escala publicada del índice (calibración del registro 2026-08-02).

Titularidad

R3AP3R editCuenta personal
73 seguidores205 repositorios públicosdesde oct 2023MegaVault

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npmxibecode1.17.4351284hace 11 díascliaicodingassistantautonomousagentautomationtest-generation
npmxibecode-core1.17.4295042hace 11 díasaiagentcodingautonomousmcptools

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

80Excelente · 21% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 3 días
10.4/36Cadencia de commits — 15/52 semanas con commits
18/18Volumen de commits — 389 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year389
human_commit_share1
days_since_last_push3
active_weeks_last_year15
Cómo se puntúa
27/27Publica versiones — 6 versiones publicadas
36/36Recencia de las versiones — última versión hace 11 días
27/27Cadencia de publicación — una versión cada ~33 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count6
latest_release_tagv1.17.0
releases_from_tagsno
days_since_latest_release11
mean_days_between_releases33

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

50Moderado · 17% del índice global
Cómo se puntúa
16.9/60Estrellas — 12 estrellas
0/25Forks — 2 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks2
stars12
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
readme_badges5
has_contributing
has_issue_templateno
has_code_of_conductno
readme_badge_servicesshields.io
has_pull_request_template
Cómo se puntúa
50.8/80Descargas mensuales — 6462 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesxibecode, xibecode-core
dependents
ecosystemsnpm
total_downloads
monthly_downloads6462
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

47Débil · 23% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0.1/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
2.7/13.5Amplitud de contribuyentes — 2 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations
Datos de entrada utilizados
bus_factor1
contributors_sampled2
top_contributor_share0,997
Cómo se puntúa
0/42Resolución de issues — sin issues o sin datos
13.2/30Aceptación de PR — 49/111 PR decididos fusionados
0/13Newcomer PR acceptance — ningún PR de un contribuyente primerizo decidido en 30 d
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs49
open_issues0
closed_issues0
prs_merged_7d0
prs_decided_7d5
prs_merged_30d0
prs_decided_30d5
issue_closed_ratio
closed_unmerged_prs62
first_time_authors_30d0
first_time_prs_merged_30d0
first_time_prs_decided_30d0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, newcomer_pr_acceptance. Los pesos restantes se han renormalizado.
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
13.4/25Alcance del propietario — 73 seguidores de iotserver24
18.6/25Trayectoria — 205 repos públicos, cuenta de ~2 años
Datos de entrada utilizados
followers73
owner_typeUser
is_verified
owner_loginiotserver24
public_repos205
account_age_days1025
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 2 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 11 días
20/20Historial de versiones — 84 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesxibecode, xibecode-core
ecosystemsnpm
any_deprecatedno
min_days_since_publish11

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

76Bueno · 19% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 1 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

100Excepcional
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://xibeai.in
10/10Descripción del repositorio
10/10Topics — 5 topics
10/10Wiki
Datos de entrada utilizados
topicsai, claude-code-alternative, cli-coding, tool, xibecode
has_wiki
homepagehttps://xibeai.in
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

51Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 4 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — sin datos
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 71 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,1
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, packaging. Los pesos restantes se han renormalizado.
Cómo se puntúa
35/35Dependencias directas libres de avisos conocidos — ninguna dependencia directa tiene un aviso conocido
14.4/25Dependencias indirectas libres de avisos conocidos — 1 afectados: hono 4.12.33 (moderate 5.3)
40/40Sin avisos pendientes — ningún aviso lleva público más de 90 días
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages299
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Se cotejó el cierre de dependencias en tiempo de ejecución de npm:xibecode@1.17.4 —lo que arrastra la instalación del paquete publicado—: 299 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Tiene un peso deliberadamente pequeño (4%): las herramientas para agentes son una señal real de mantenimiento, pero un repositorio sin ninguna puede alcanzar igualmente 100/100.

67Bueno · 4% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — AGENTS.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 97 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,97
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes7978
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/desktop/tsconfig.json, packages/e2b-gateway/tsconfig.json, packages/ext/tsconfig.json, packages/hosting/tsconfig.json, tsconfig.json
10/10Entorno reproducible — Dockerfile, lockfile
10/10Práctica demostrada con agentes — 10 de los últimos 100 commits con autoría o crédito de agente
5/8Mantenimiento automatizado — automatización de dependencias configurada, no observada en los commits muestreados
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilespnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configspackages/cli/tsconfig.json, packages/core/tsconfig.json, packages/desktop/tsconfig.json, packages/e2b-gateway/tsconfig.json, packages/ext/tsconfig.json, packages/hosting/tsconfig.json, tsconfig.json
agent_commit_share0,1
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
53.9/55Tamaños de archivo manejables — 5/247 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes170.806
source_files_sampled247
oversized_source_files5
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
0/40Ejemplos ejecutables
Datos de entrada utilizados
example_dirs
has_mcp_signal
api_schema_files

Datos clave

12estrellas de GitHub
2contribuidores
389commits en los últimos 12 meses
3días desde el último push
6versiones publicadas
1factor bus
0issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package 'xibecode-vscode' from its registry
  • Could not fetch npm package 'xibecode-desktop' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

Historial de estrellas y forks 0 ★ / 2 ⇿
0Estrellas
2Forks
2Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

111222212026-022026-032026-03
Mayor 0Menor 0Parche 2
OpenSSF Scorecard 4.1 / 10
4.1agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-08-05 09:30 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 4 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/dPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities71 existing vulnerabilities detected
Dependencias directas 47
RegistroPaqueteRestricción de versiónManifiesto
npmxibecode-core^1.17.4packages/cli/package.json
npm@anthropic-ai/sdk^0.78.0packages/cli/package.json
npmchalk^4.1.2packages/cli/package.json
npmcommander^12.0.0packages/cli/package.json
npmconf^15.1.0packages/cli/package.json
npmdotenv^16.3.1packages/cli/package.json
npmink^6.7.0packages/cli/package.json
npmink-select-input^6.2.0packages/cli/package.json
npmink-text-input^6.0.0packages/cli/package.json
npminquirer^13.4.1packages/cli/package.json
npmmarked^11.2.0packages/cli/package.json
npmmarked-terminal^7.3.0packages/cli/package.json
npmnode-fetch^3.3.2packages/cli/package.json
npmopen^10.0.0packages/cli/package.json
npmora^5.4.1packages/cli/package.json
npmreact^19.2.4packages/cli/package.json
npmws^8.18.0packages/cli/package.json
npm@anthropic-ai/sdk^0.78.0packages/core/package.json
npm@modelcontextprotocol/sdk^1.29.0packages/core/package.json
npmdiff^5.1.0packages/core/package.json
npmdotenv^16.3.1packages/core/package.json
npmfast-glob^3.3.3packages/core/package.json
npmgray-matter^4.0.3packages/core/package.json
npmnode-fetch^3.3.2packages/core/package.json
npmopen^10.0.0packages/core/package.json
npmpicomatch^4.0.2packages/core/package.json
npmstrip-ansi^7.1.0packages/core/package.json
npmts-morph^27.0.2packages/core/package.json
npmtypescript^5.3.3packages/core/package.json
npmzod^4.3.6packages/core/package.json
npmclsx^2.1.1packages/desktop/package.json
npmconf^15.1.0packages/desktop/package.json
npmframer-motion^12.38.0packages/desktop/package.json
npmhighlight.js^11.11.1packages/desktop/package.json
npmlucide-react^1.14.0packages/desktop/package.json
npmreact^19.2.4packages/desktop/package.json
npmreact-dom^19.2.4packages/desktop/package.json
npmreact-markdown^9.0.3packages/desktop/package.json
npmremark-gfm^4.0.0packages/desktop/package.json
npmtailwind-merge^3.5.0packages/desktop/package.json
npmxibecode-coreworkspace:*packages/desktop/package.json
npme2b^2.19.4packages/e2b-gateway/package.json
npm@types/marked^6.0.0packages/ext/package.json
npmmarked^11.2.0packages/ext/package.json
npmxibecode-coreworkspace:*packages/ext/package.json
npmjsonwebtoken^9.0.2packages/hosting/package.json
npmnanoid^5.1.5packages/hosting/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Avisos de dependencias 1

Instalar npm:xibecode@1.17.4 arrastra 299 paquetes, directos y transitivos: 1 tienen avisos conocidos, de los cuales 0 son dependencias directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
hono4.12.33indirectamoderada14.12.34

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "icon": {
      "bytes": 9061,
      "width": 256,
      "height": 256,
      "rejected": [
        {
          "url": "https://www.xibeai.in/favicon.ico",
          "reason": "HTTP 404",
          "source_type": "homepage"
        }
      ],
      "collected": true,
      "media_type": "image/jpeg",
      "source_url": "https://avatars.githubusercontent.com/u/147928812?v=4&s=256",
      "source_type": "avatar",
      "content_hash": "5a3643b9933a513141325095fa53a86755018afdb05cf5d919fce896106b6743",
      "candidates_considered": 2
    },
    "repo": {
      "topics": [
        "ai",
        "claude-code-alternative",
        "cli-coding",
        "tool",
        "xibecode"
      ],
      "is_fork": false,
      "size_kb": 12932,
      "has_wiki": true,
      "homepage": "https://xibeai.in",
      "languages": {
        "CSS": 2282,
        "HTML": 26160,
        "Shell": 3478,
        "Python": 11943,
        "Dockerfile": 4247,
        "JavaScript": 26399,
        "TypeScript": 2235382
      },
      "pushed_at": "2026-08-01T14:21:55Z",
      "created_at": "2026-02-08T13:24:52Z",
      "owner_type": "User",
      "updated_at": "2026-07-25T07:02:44Z",
      "description": "a autonomous open-source coding tool",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://anishkumar.tech",
      "name": "R3AP3R edit",
      "type": "User",
      "login": "iotserver24",
      "company": "MegaVault",
      "location": "karnataka",
      "followers": 73,
      "avatar_url": "https://avatars.githubusercontent.com/u/147928812?v=4",
      "created_at": "2023-10-14T13:44:37Z",
      "is_verified": null,
      "public_repos": 205,
      "account_age_days": 1025
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2026-07-24T12:58:57Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-04-12T07:03:03Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-02-16T02:27:39Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-02-16T02:13:36Z"
        },
        {
          "tag": "v0.0.7",
          "kind": "patch",
          "published_at": "2026-02-10T07:50:36Z"
        },
        {
          "tag": "1.0.0",
          "kind": "major",
          "published_at": "2026-02-09T08:34:30Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e6cd6c4c6b05f14089db771d6a5d0b9bd348ae2e",
          "body": "Register curated_memory, session_search, save_skill, list_skills, and\nview_skill in TOOL_CATEGORIES so daemon/Telegram memory saves are not\nrejected as Unknown tool.",
          "is_bot": false,
          "headline": "fix: allow curated_memory in mode permissions (1.17.4)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T07:01:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97802990cccd7bcea5dbc5890d9c471c697d19e7",
          "body": null,
          "is_bot": false,
          "headline": "chore(e2b-template): ship 1.17.3 soft-wake",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T04:05:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00707a36011ddb0a962e6a29e89af23b04069d81",
          "body": null,
          "is_bot": false,
          "headline": "chore: pin xibecode-core ^1.17.3",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T04:05:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb44d029380e4857fda6bc19d270333608ac3c81",
          "body": "Prefer SIGUSR1 + pending queue when daemon still lives after E2B memory\nresume; avoid cold Node restart. Fast cold-start fallback with short polls.",
          "is_bot": false,
          "headline": "feat: soft-wake Telegram path for ~1–2s resume (1.17.3)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T04:05:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5d61b9a776d7769c51c5c009e4eef3ad54c598b",
          "body": null,
          "is_bot": false,
          "headline": "chore(e2b-template): pin CLI 1.17.2 (auto-replay wake DM)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T04:01:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01aa3cd9bfea73d8b55b614688d95ce153d7e2cc",
          "body": null,
          "is_bot": false,
          "headline": "chore: pin xibecode-core ^1.17.2 for npm publish",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T04:00:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e01924ab88ca06b2c138b8dc4f0687268fa7b030",
          "body": "wake-http queues the webhook update; daemon drains pending-telegram-updates\non start so users do not need to resend after pause resume.",
          "is_bot": false,
          "headline": "feat: auto-replay first Telegram DM after E2B wake (1.17.2)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T04:00:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a00a7591f92b82c2e42e05a58a413e909185ab45",
          "body": "Same bash -c / pkill -f pitfall as hosting restart.",
          "is_bot": false,
          "headline": "fix(wake-http): do not pkill self when restarting daemon",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T03:05:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a97ad08639aa7d006ce75fac10d34996a6e425c",
          "body": "Add safe-fetch wrapper and process guards so /stop and auto-stop\naborting node-fetch streams no longer kill the 24/7 gateway process.",
          "is_bot": false,
          "headline": "fix(daemon): survive AbortError on stop without process crash",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T02:59:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69259acab7d9f426f59c303f86a9a5cd233d935f",
          "body": "Pin Dockerfile packs to 1.17.1 (wake-http template + latest CLI).",
          "is_bot": false,
          "headline": "chore(e2b-template): ship xibecode 1.17.1 tarballs",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T02:45:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c362ab4e464a070269b9d0b31307f4d0abcb2ea",
          "body": "Patch release for E2B template rebuild with wake-http and aligned npm packages.",
          "is_bot": false,
          "headline": "chore: release 1.17.1",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T02:45:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3941e69472248f632f6e58da1709ad471d97c26b",
          "body": "Add /opt/vectra/wake-http on port 8788 in the custom sandbox template.\nTelegram (or host) can hit the public URL so E2B resumes a paused VM;\nthe coding bot stays long-poll. Reverts embedding webhook in TelegramEngine.",
          "is_bot": false,
          "headline": "feat(e2b-template): wake HTTP doorbell for auto-resume (not the bot)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T02:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7d8a299fa0fbf6068964083e116f0d2537ef542",
          "body": "This reverts commit 366e46e7bb233a69f5fa9c4dd8628dd40102b950.",
          "is_bot": false,
          "headline": "Revert \"feat(telegram): webhook mode for E2B auto-resume on public URL\"",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T02:38:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "366e46e7bb233a69f5fa9c4dd8628dd40102b950",
          "body": "When TELEGRAM_WEBHOOK_PORT / TELEGRAM_WEBHOOK_URL are set, listen on HTTP\nand setWebhook instead of getUpdates long-poll. Telegram traffic to\nhttps://{port}-{sandboxId}.e2b.app/telegram wakes a paused sandbox\n(E2B auto-resume on request) then dispatches the update.",
          "is_bot": false,
          "headline": "feat(telegram): webhook mode for E2B auto-resume on public URL",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-25T02:28:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "509576e27e83337d5662e04ee516fa40a17f7311",
          "body": "- Bump vitest to ^3.2.6 (GHSA-5xrq-8626-4rwp UI server RCE)\n- Override shell-quote >=1.8.4 (via concurrently)\n- Override tar >=7.5.19 (via electron-builder / e2b)",
          "is_bot": false,
          "headline": "fix(security): clear critical audit findings (vitest, shell-quote, tar)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T13:59:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09f5334b094366f511f51185480ea4b5a9da81da",
          "body": "…irst\n\nCLI used a npm semver range (^1.17.0), so turbo treated core as external\nand ran xibecode#build in parallel with xibecode-core#build. Without\npackages/core/dist, tsc failed with TS2307 on every CI run since 1.5.5.\nMatch desktop/ext: workspace:* (pnpm publish rewrites for npm consumers).",
          "is_bot": false,
          "headline": "fix(ci): restore workspace:* for xibecode-core so turbo builds core f…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T13:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e8d0472625e4677b6afdbc97b89de199827a149",
          "body": "Add Telegram /cmd shell, curated memory with Write saved feedback,\nand production-style auto-compact (preflight + token-budget tail).\nBump xibecode and xibecode-core to 1.17.0.",
          "is_bot": false,
          "headline": "feat: release 1.17.0 — /cmd, memory saves, auto-compact",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T12:58:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09b59fa4c919aecd9d847b97c221725d8bdf0a81",
          "body": "E2B serves apps as {port}-{sandboxId}.e2b.dev; Vite blocks unknown hosts\nunless server.allowedHosts is set. Inject that into e2b system context.",
          "is_bot": false,
          "headline": "fix(e2b): teach agent Vite allowedHosts for preview URLs",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T12:30:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14fdff0f2cddc773a3a50b1f1cbbcadfebfb0467",
          "body": "Root-owned /usr/lib/node_modules/xibecode needs passwordless sudo; try\nsudo -n before plain npm, then local prefix fallback.",
          "is_bot": false,
          "headline": "fix(e2b): self-update uses sudo -n first to avoid EACCES on global npm",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T12:17:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14f3f72299919a1092e6f100bbbb10cf57f9c296",
          "body": "Ship e2b auto-detect, sandbox id in agent context, sudo -n, /update restart.",
          "is_bot": false,
          "headline": "chore: release xibecode@1.6.5 and xibecode-core@1.6.5",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T12:12:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a8e57756448e41d15834853e8d0667cb2053d77",
          "body": "Resolve E2B_SANDBOX_ID (or /run/e2b/) into the coding system prompt and\n/status. In e2b mode, strip sudo -n for risk scoring so package installs\ndo not stall on approval while still blocking catastrophic commands.",
          "is_bot": false,
          "headline": "feat(e2b): agent knows sandbox id; allow passwordless sudo -n",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T12:08:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "477a41765d894cdf2a401f38f14a16fbd3d7bd6f",
          "body": "Keep XibeCode branding only in help, changelog, and source commentary.",
          "is_bot": false,
          "headline": "chore: drop third-party product names from public copy and comments",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T11:57:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaeaf791ba9a659ccdcb4ad98f745fd1569a085a",
          "body": "E2B mode enables npm self-update (sudo fallback) + daemon relaunch while\npreserving ~/.xibecode/daemon/sessions chat memory. /mode surfaces current mode.",
          "is_bot": false,
          "headline": "feat(daemon): default vs e2b runtime modes with /update restart",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T11:54:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fb0d2022ee6e3aeebccd326a17b0c500e61d0ea",
          "body": "Default XIBECODE_BUSY_INPUT_MODE=steer injects follow-ups into the active\nagent after tools / before the next model call. queue and interrupt modes\nmatch Hermes; /queue <prompt> forces FIFO without interrupting.",
          "is_bot": false,
          "headline": "feat(daemon): Hermes-style mid-run steer (busy messages not only queue)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T11:45:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68ea1112184174fdf1831f8092784a7d78faf248",
          "body": "Relative MEDIA: paths resolve to the session workdir; photos/videos/audio/docs\nupload via the Bot API. Successful take_screenshot results are auto-attached\nwhen the model forgets MEDIA tags so Telegram users actually receive images.",
          "is_bot": false,
          "headline": "feat(telegram): deliver any file + auto-send screenshots (1.6.3)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T11:36:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99d2c2df777367141a8c4f5427a5e9a6d739804c",
          "body": "After /stop, clear the busy slot so a hung LLM cannot block new messages\nuntil restart. Telegram .txt/.md/code documents are downloaded and\nincluded in the agent prompt (512KB cap).",
          "is_bot": false,
          "headline": "fix(daemon): /stop frees chat immediately; inline text file attachments",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T10:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0eeab7f73f917781f0d4d5c81c0e3ec97e4b680f",
          "body": "Template installs CLI from local tarballs + agent-browser/Chrome.\nAgents get explicit tool-failure recovery instead of silent stuck runs.",
          "is_bot": false,
          "headline": "feat: ship 1.6.0 with agent-browser default and failure recovery",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T09:49:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6119f2b14d9c0810450149c0fc34fb690613cee",
          "body": null,
          "is_bot": false,
          "headline": "chore: publish xibecode@1.5.5 with xibecode-core@^1.5.3",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T09:37:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d485c7fb5f152a7c383d45f709bcdfe99dcafdb",
          "body": "- Prefer agent-browser for take_screenshot; pack it in E2B template\n  with Chrome for Testing (xibecode@1.5.5 pin)\n- On tool failure inject SYSTEM recovery (retry differently / alt tool /\n  report fail + TASK_COMPLETE) so agents do not silent-loop\n- Daemon: always log fails, longer error in progress, heartbeats show\n  last tool failed instead of only \"still checking\"",
          "is_bot": false,
          "headline": "feat: agent-browser default + anti-stuck tool failure recovery",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T09:37:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b5e794fc2124d1ccb9703dbf38320ff52fcad44",
          "body": "Absolute /tmp and other paths outside the working directory caused\n\"Path escapes working directory\" on hosted sandboxes. Remap them to\nscreenshots/<basename>, update tool/docs prompts, ship CLI 1.5.4 /\ncore 1.5.2.",
          "is_bot": false,
          "headline": "fix: remap take_screenshot paths into workspace screenshots/",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T09:29:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddff286443a2b35ef7fd46972a45a390d631a87f",
          "body": "Rebuild xibecode-full-sandbox (4c/8G) so new sandboxes ship the\nTelegram/verbose/daemon fixes from the 1.5.3 release.",
          "is_bot": false,
          "headline": "chore(sandbox): pin template CLI to xibecode@1.5.3",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T09:04:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31d1912d7ea9b703c384638ff620bf5eeaff7868",
          "body": "Create with { onTimeout: pause, autoResume: true }, wake via SDK activity\nfirst then connect, setTimeout only when running, retry exec after resume,\ndefault idle timeout 30m.",
          "is_bot": false,
          "headline": "fix(e2b-gateway): match E2B auto-resume docs",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T08:57:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b9ed7f540fc36107140836555225564199b4aeb",
          "body": "Poll until daemon process is up, clear leftover Telegram webhook, and\nsource both daemon.env and gateway.env before relaunch.",
          "is_bot": false,
          "headline": "fix(e2b-gateway): more reliable daemon restart on wake",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T08:51:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "603a32d69dda2f3e97dc9b8d3e71430d88f95465",
          "body": "… (v1.5.3)\n\nLoad daemon-<profile>.env over gateway.env, make xibecode-gateway a oneshot\nalias, log pid/profile (+ per-profile log file), and enable headless tool\ntracing via XIBECODE_DAEMON_VERBOSE. CLI update uses --to instead of --version.",
          "is_bot": false,
          "headline": "fix(daemon): multi-profile secrets, dual-unit 409, verbose agent logs…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-24T05:18:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9d6d9b9c2f1f42a6b19e4ba290274a7b4ebedd5",
          "body": "…Done footer\n\n- Tool progress sends new messages (separate grouping) instead of one edited bubble\n- Approval/ask callbacks edit the same message and remove inline keyboards\n- Strip [[TASK_COMPLETE]] from chat replies into a plain ✅ Done footer\n- Disable progressive draft edits by default; final answer is a new message",
          "is_bot": false,
          "headline": "fix(gateway): Hermes Telegram UX — separate progress, clear buttons, …",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T22:29:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d26557a086f2c6a95cd42fdba12b215365ced60",
          "body": "Send agent MEDIA:/path tags as native Telegram photos/videos/documents\n(multipart sendPhoto/sendVideo/sendDocument/sendVoice per Bot API).\nImplement take_screenshot via agent-browser or headless Chrome (localhost\nOK) and document the build→screenshot→MEDIA chat flow for generated sites.",
          "is_bot": false,
          "headline": "feat: Telegram media delivery + site screenshots (v1.5.1)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T22:14:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1545836934fe42e893d67a75fdc4960197fb353b",
          "body": "Use workspace:* for core deps so turbo ^build runs core before\ncli/desktop/vscode (esbuild could not resolve npm semver links).\nHarden CI: pin pnpm 9.15.0, checkout/setup-node v4, timeouts, and\ntreat critical audit as non-blocking. Override axios/ws for audit noise.",
          "is_bot": false,
          "headline": "fix(ci): restore turbo workspace build order for xibecode-core",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T16:43:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "664f3b0faeb523f9c8d4d88a80dcd7709fe1c7f4",
          "body": "Short status phrases, no Got it/starting spam; heartbeat every 30s with\nelapsed time while agent is busy; /clear alias; ship 1.5.0.",
          "is_bot": false,
          "headline": "feat: v1.5.0 Hermes openers + 30s busy heartbeat on Telegram",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T16:31:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c61d485c8606a5de6fb5d89e7791b7f486ac7d57",
          "body": "Drop \"Got it — On it in workspace\" and \"Coding… dir · default / starting\".\nUse one progress bubble with short phrases like \"on it\" / \"one sec\".",
          "is_bot": false,
          "headline": "fix(gateway): Hermes-style Telegram openers (short status phrases)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T16:20:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "075aa2f5b9f948668d4ee168eb27b410feaf1fdb",
          "body": "- Tool-result budget + batch summary after tool turns (Claude-style)\n- ACP: balanced harness defaults, session/permission for dangerous tools\n- xibecode acp alias; docs/acp.md for IDE hosts\n- VS Code: AcpClient spawn of CLI --acp (useAcp default true)\n- Desktop note for shared ACP path",
          "is_bot": false,
          "headline": "feat: tool budget, ACP permissions, VS Code ACP client, docs",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T16:15:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b540a009b6c3860cb37574480c06846cc89636fb",
          "body": "- evaluateStopHooks blocks false \"done\"/unverified edits (XIBECODE_STOP_HOOKS=0 to disable)\n- Gateway default rigor now post-edit verifies (balanced); yolo stays off\n- GatewayStreamConsumer: progressive tool edits, stream_text draft, tool-boundary\n- Telegram chunk/fence hygiene for multi-part replies",
          "is_bot": false,
          "headline": "feat: Claude-style stop-hooks + Hermes stream progress for gateway",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T16:09:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2c17dc846e926364ce33f3f3b3ecce1a2e44879",
          "body": "Improve E2B gateway lifecycle (default template, auto-resume, continuous-run\ncycle), allow ~/.xibecode paths for hosting config writes, and harden the\npackages/hosting stack (native auth cookies, richer gateway client + UI).",
          "is_bot": false,
          "headline": "feat(e2b): gateway pause/resume, path allowlist, hosting daemon config",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T15:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bcc34d2a35d1fffa1216204134500341857ef054",
          "body": "- xibecode update --check/--apply with E2B auto-restart; /update yes in chat\n- models.dev catalog + expanded providers; live /models with curated fallback\n- daemon env load, skills progressive tools, secret redaction",
          "is_bot": false,
          "headline": "feat: v1.4.30 E2B opt-in CLI update, providers/models.dev, daemon skills",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T15:29:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "707d5720d7a8c449b7b8af31f1ebdaea0830f625",
          "body": "Add packages/hosting (login, create infra, AI+Telegram setup via gateway\nexec). Fix sandbox Dockerfile for E2B default user; rebuild template at\n4 vCPU / 8 GB with xibecode@1.4.2.",
          "is_bot": false,
          "headline": "feat(hosting): dashboard for managed E2B instances + 4c/8G template",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T03:28:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fee904b31ca9537b50e9cb5668c6dc319a2edc91",
          "body": "Ship Hermes-style Telegram gateway (slash menu, model pickers, rigor,\nprocess registry), E2B auto-pause and 23h continuous cycle, and pin the\ncustom sandbox template to 4 vCPU / 8GB with xibecode@1.4.2.",
          "is_bot": false,
          "headline": "feat: v1.4.2 gateway Telegram UX, E2B pause/resume, hosting sandbox",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-20T03:23:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1669719cb7e8675af71930e3f35143ea27057168",
          "body": "Default maxIterations is unlimited (0). Expand the provider catalog and\nsetup surfaces. Neutralize third-party naming in user-facing copy.\nShip aligned xibecode-core and xibecode 1.4.0.",
          "is_bot": false,
          "headline": "feat: v1.4.0 unlimited agent loops, providers, setup docs",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-19T17:29:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f4296580b2e96532e911c6800c3fb4e39ab54bb",
          "body": "Ship xibecode-core and xibecode at 1.3.22: messaging gateway (Telegram,\nDiscord, Slack), cron, delivery ledger, circuit breakers, DM pairing,\nprovider pool failover, and Hermes-style learning loop (curated memory,\nsession FTS, skill learner, write-approval).",
          "is_bot": false,
          "headline": "feat: 24/7 gateway, learning loop, provider failover (v1.3.22)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-07-19T16:43:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea5de4c0abf5ed634d3c5d987cda0f0f6e3e421c",
          "body": "Replaced `fs.existsSync` with asynchronous file operations (`fs.promises.readFile`, `fs.promises.access`, `fs.promises.mkdir`) wrapped in `try/catch` blocks across the `packages/core` package.\n\nThis change prevents blocking the Node.js event loop during initialization or loading operations, improving overall application concurrency and responsiveness.",
          "is_bot": false,
          "headline": "⚡ Bolt: Replace synchronous fs operations with async alternatives (#102)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-24T17:28:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e25b3b0cfcf95f9a09f9e968ad0de84ddc328abc",
          "body": null,
          "is_bot": false,
          "headline": "fix(core): register stream error handler early to prevent abort crash",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-24T10:44:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cd8756ad7326ec49bb257508a16c7bf5f39e53f",
          "body": "…and, and refactor CLI structure",
          "is_bot": false,
          "headline": "feat: implement asynchronous MCP connection handling, add models comm…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-24T10:39:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6767decf65779164691c4879c27760bca2676399",
          "body": null,
          "is_bot": false,
          "headline": "chore: update cli core dependency lockfile",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-24T04:45:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "034a477fc2d74185979d7dd54a5c012599714e87",
          "body": null,
          "is_bot": false,
          "headline": "feat: add zed acp support and bump packages to 1.3.15",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-24T04:41:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa6d06c8b4e4e8e9b194981b2d9f7b4418fcdf49",
          "body": null,
          "is_bot": false,
          "headline": "chore: configure electron-builder files and package metadata",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T23:47:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8a5ab9b8f6b8f0bfbc62b0d1d025f0128c774c3",
          "body": "…, and button sizes for better spacing",
          "is_bot": false,
          "headline": "style(desktop): adjust Settings panel layout height, padding, margins…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T23:38:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "604ea49e1b2d7d56f306053d4d15868c34e598a4",
          "body": "…e spacing",
          "is_bot": false,
          "headline": "feat(desktop): redesign settings panel layout and improve sidebar tre…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T23:37:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ea850d015bc831d5815840aa0e552dd4daa02d3",
          "body": null,
          "is_bot": false,
          "headline": "chore: update xibecode-core dependency range to ^1.3.13",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T23:16:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1452638245c0ebf0d5fb62d94a2537ea7b06f51c",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump versions to 1.3.13",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T23:02:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf50915582f6c5597cd92d78e83fb58f8e05d7a2",
          "body": null,
          "is_bot": false,
          "headline": "chore: disable automatic workspace package linking in pnpm",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T22:59:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5c23970f060c33495f5bd953b053a5d9c3f2cf0",
          "body": null,
          "is_bot": false,
          "headline": "fix: intercept natural language mode switching in chat UI",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T22:13:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "998683c4533a35099d3cbb53ca16101dbb90f49e",
          "body": null,
          "is_bot": false,
          "headline": "feat: color code CLI output based on active agent mode",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T21:08:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ceebbc9bf04b426053f31c0fbcf73680aca212c0",
          "body": "…renders (#98)\n\nExtracted the inline button map in `ChatHistory.tsx` into a separate `ChatHistoryItem` component wrapped in `React.memo()`.\n\nInstead of causing O(N) re-renders for the entire list when a single chat is selected, we now pass a computed boolean flag (`isActive={activeSessionId === s.id\n[…]\nmance when navigating history.\n\nThe `handleDelete` function in `ChatHistory` was also wrapped in a `useCallback` to prevent breaking the referential equality of props passed down to `ChatHistoryItem`.",
          "is_bot": false,
          "headline": "⚡ Bolt: Extract React.memo component for chat history to fix O(N) re-…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T16:50:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82b58b51796745d8d5635ac1524574af2b4345f9",
          "body": "- Updated global.css to use zinc-based neutral hex codes for background and surfaces\n- Refined App.tsx layout to remove shadows and flatten sidebars\n- Repositioned model selector directly into the top header bar\n- Redesigned ChatPanel.tsx empty state with minimalist buttons and clean heading\n- Rebuilt chat input as a floating, rounded-3xl pill design\n- Adjusted ChatHistory padding and hover states for a flatter, modern look",
          "is_bot": false,
          "headline": "✨ Refine desktop UI to match Claude Code / Cursor aesthetic (#97)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-21T12:17:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5252104415f2fe06104d48c29b70c7088a407a1a",
          "body": "- Set desktop global background strictly to `#09090b` and removed unnecessary elevations.\n- Updated user message bubbles to use soft `rounded-2xl` pills without borders.\n- Flattened the chat prompt input to use `bg-xibe-surface-raised` matching the borderless look.\n- Adjusted sidebar active items to replace heavy left borders with soft raised backgrounds.\n- Preserved existing semantic colors (info/error/success) and optimized `group-hover` components.",
          "is_bot": false,
          "headline": "🎨 [desktop] Update UI to flat, minimalist grayscale aesthetic (#96)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-20T15:47:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf8dac8f2a336629d189a6cb01d1ddbaf9f717eb",
          "body": "Refined the desktop React UI in `packages/desktop` to align with the\nsleek, minimalist, grayscale aesthetic requested by the user, comparable\nto tools like Claude Desktop and Cursor.\n\nChanges:\n- **App Header:** Softened title color and added subtle panel dividers\n  for a cleaner shell layout.\n- **Ch\n[…]\nilwind configuration in `global.css` to use\n  slightly darker, zinc-like tones for `--color-xibe-surface-raised`\n  and `--color-xibe-border-subtle`, establishing better depth without\n  heavy contrast.",
          "is_bot": false,
          "headline": "feat(desktop): polish UI to match modern dark-mode AI aesthetic (#94)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-19T06:23:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92c2ff698bbb656613a82c36d4d108d97ebbc779",
          "body": "…n listing (#93)",
          "is_bot": false,
          "headline": "perf(core): Replace O(N²) array search with O(N) Set lookup in sessio…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-17T18:23:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "950b4629d52aa53cfbb7fb9fd16a20fa602d055f",
          "body": "… (#91)",
          "is_bot": false,
          "headline": "⚡ Bolt: Chunked concurrency for file history to prevent EMFILE errors…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-17T06:19:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "035dbac815cf2478d8163c844a0971e49aa00451",
          "body": "…#92)\n\n- Replaced outlined borders with filled surfaces across main sections (headers, sidebars, panels).\n- Updated ChatPanel components (action buttons, chat input container, mode selectors) to use `bg-xibe-surface-raised` borderless styles.\n- Updated user message bubbles and inline code blocks in MessageBubble.tsx to use borderless flatter backgrounds.\n- Updated Tailwind config variables in `global.css` to blend sub-surfaces better for a seamless look.",
          "is_bot": false,
          "headline": "feat(desktop): update UI for a modern flat and borderless aesthetic (…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-17T06:19:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "151c75e4e5439bddcd82bc2d64848a36047e1d6d",
          "body": "…s (#89)",
          "is_bot": false,
          "headline": "⚡ Bolt: [performance improvement] Async preview server file operation…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-16T01:40:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bb1903f7f8b870fa53df141881dc52a73c0f119",
          "body": "- Updated global CSS variables for a softer surface and border focus.\n- Added subtle borders to cleanly separate header, sidebar, and right panels.\n- Tightened sidebar session item padding and reduced hover prominence.\n- Redesigned chat input to a floating pill format with focus rings.\n- Refined message bubble borders, spacing, and typography margins.",
          "is_bot": false,
          "headline": "Refine desktop UI for a flatter, minimalist aesthetic (#88)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-15T06:21:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f40794501b37ec7e6998fcebf49329649dc3005",
          "body": "Introduced new functions to manage tagged file mentions, allowing for better integration of file paths in chat inputs. Implemented mechanisms to reconcile and flatten tagged mentions, ensuring only valid tokens are retained. Updated the file picker to improve user experience when inserting file paths. Adjusted input handling to maintain caret position and manage state effectively during interactions.",
          "is_bot": false,
          "headline": "feat(cli): enhance file mention handling and input management in chat",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-14T04:11:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93a4c2ea439da684fef35b604a92fd69c187ef5c",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(cli): 1.3.11 — depend on xibecode-core ^1.3.10",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-14T04:10:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "280325f0ce268247ad243a28e62fd83738772b85",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(core): release 1.3.10 with package README",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-14T04:10:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9c09125f1c7c794fdf1026688d7dcab1df737f82",
          "body": "Updated `xibecode resume` to explicitly handle local sessions, allowing users to resume host-stored sessions without inheriting global E2B behavior. Introduced `xibecode resume cloud <sandbox-id>` for attaching to existing E2B sandboxes. Added a file picker feature for easier file navigation during chat sessions, improving user experience and interaction with workspace files. Bumped version to 1.3.9 and updated CHANGELOG accordingly.",
          "is_bot": false,
          "headline": "feat(cli): enhance session management and file picker functionality",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-14T04:10:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4f5c29304380b1bf20ca008ac72138c283636b",
          "body": "Added functionality to save prompt history and navigate through it using UP/DOWN arrow keys. This enhancement allows users to easily access previous inputs while chatting, improving the overall user experience.",
          "is_bot": false,
          "headline": "feat(cli): implement prompt history and navigation in chat input",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-14T04:10:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "960a0c570e60bdf21587fe46b8d255ad1e9f63be",
          "body": null,
          "is_bot": false,
          "headline": "extract spinnerVerb from App.tsx to prevent global O(N) re-renders (#86)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-13T14:08:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3f02261602042e37a886f77d6b5382054957ede",
          "body": "- Updated `global.css` with a darker `#09090b` zinc background palette.\n- Removed drop shadows (`shadow-sm`, `shadow-lg`, `shadow-inner`) across components:\n  - `ChatPanel.tsx`\n  - `CommandPalette.tsx`\n  - `SettingsPanel.tsx`\n  - `SetupWizard.tsx`\n  - `ToolCallCard.tsx`\n- Refined `MessageBubble.tsx`\n[…]\nibe-surface-raised`) instead of border effects.\n- Maintained exact semantic status colors (`success`, `warning`, `error`, `info`) as requested.\n- Visually verified via Playwright screenshot recording.",
          "is_bot": false,
          "headline": "update desktop UI to modern flat zinc theme (#87)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-13T14:08:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1968ed83335682a2815e88da4a18f75fd44fe242",
          "body": "- Removed borders from ChatPanel input field and suggestion chips\n- Replaced backgrounds with flat surface colors\n- Cleaned up keyboard shortcut displays\n- Rounded MessageBubble user messages more smoothly (rounded-2xl)\n- Simplified assistant message blockquotes to align with flat design\n- Visually verified via screenshots",
          "is_bot": false,
          "headline": "feat(desktop): modernize UI with flat design aesthetic (#85)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-11T17:39:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a728b8b9a6598f1ea655f226439616beb45aee14",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(cli): bump to 1.3.8 and xibecode-core ^1.3.8",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T12:10:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc99cf260ce0faac71ae7ab2803d9f4c5e63bccd",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(core): bump xibecode-core to 1.3.8",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T12:08:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b2273dabd0eb5210dfaa8afe2a8681fc06be1ff4",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(cli): merge sandbox files on cloud pull --apply",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T12:08:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "78246cbee072bf604abed408c15d3eae8888500e",
          "body": "Switch to e2b SDK v2 and pass lifecycle onTimeout pause + autoResume.\nDefault idle window 15m via XIBECODE_E2B_SANDBOX_TIMEOUT_MS (avoids 5m SDK default).\nDocument gateway env in .env.example.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(e2b-gateway): pause on idle timeout with auto-resume",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:55:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9ae9d9a0a43553dde6fe832b95a5c0e1741782c6",
          "body": "Pre-install matches published CLI; rebuild/publish via E2B CLI (same template id).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(e2b): pin xibecode@1.3.7 in sandbox template and rebuild",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:41:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5f3bd30c8d0da16e298428d0edf471401a0c8913",
          "body": "npm blocks re-publishing the same version; document republish in CHANGELOG and README.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(cli): publish 1.3.7 after npm unpublish of 1.3.6",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:36:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "50a87f09c7c13b799d40c3897b5c0a93b553009a",
          "body": "…lated package resolutions\n\nUpdated the xibecode-core dependency across CLI, desktop, and extension packages to version 1.3.6, replacing workspace links with semver ranges. Adjusted pnpm-lock.yaml to reflect the new version and updated zod dependency to 4.4.3. Modified tsconfig.json to exclude test files from compilation.",
          "is_bot": false,
          "headline": "chore: update xibecode-core dependency to version 1.3.6 and adjust re…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:35:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a33bd7f0ed0247b723b1ca4775667b4bcec908b0",
          "body": "Released version 1.3.6 for both CLI and core packages, introducing an optional update awareness feature in the CLI, allowing users to be notified of newer versions. Added `whats-new` and `changelog` commands for version comparison and documentation enhancements. Updated CHANGELOG to reflect these changes and ensure consistency across releases.",
          "is_bot": false,
          "headline": "chore(release): bump version to 1.3.6 and update changelog",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:33:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e44237150340f6060336347e9365d47cb37f328",
          "body": "Revised documentation to clarify release visibility practices, emphasizing the importance of keeping the CHANGELOG updated and directing users to the npm package page for release notes. Updated the `whats-new` command to reflect these changes, replacing references to the CHANGELOG with the npm package page for a more streamlined user experience.",
          "is_bot": false,
          "headline": "refactor(cli): update release visibility and changelog references",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:31:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b66fa08b61ad6c09691890e9929ca92996fe3f0",
          "body": "Added a new `whats-new` command (alias `changelog`) to the CLI for users to compare their installed version with the latest on npm and access the CHANGELOG. Enhanced the `xibecode` and `xibecode chat` commands to print a notice if a newer version is available, with an option to disable this check. Updated documentation to reflect these new features.",
          "is_bot": false,
          "headline": "feat(cli): introduce version check and changelog command",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:30:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db86e7443d7ca83d3d27b3ec482152d13365e2a0",
          "body": "…lated package resolutions",
          "is_bot": false,
          "headline": "chore: update xibecode-core dependency to version 1.3.5 and adjust re…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:11:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "088e81ac1b6c50b6b62aa3af977c6150122e94ef",
          "body": null,
          "is_bot": false,
          "headline": "fix(cli): update xibecode-core dependency version to 1.3.5",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:10:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4f5828d080761e0c71202237672c3856d6bd380",
          "body": "Updated package versions for xibecode and xibecode-core to 1.3.5. Introduced an `onStatus` callback to the `cloudPullCommand` for improved logging flexibility. Enhanced the CLI with new commands `/cpull` for pulling cloud sandbox changes and `/commit` for staging and committing changes, improving user interaction and functionality. Updated default sandbox gateway URL and auth token for better configuration defaults.",
          "is_bot": false,
          "headline": "feat(cli): bump version to 1.3.5 and enhance cloud pull command",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T11:06:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8166fe25dc5c027bcfbe08539dd3389b3270add",
          "body": "Introduced a new `resume` command to the CLI, allowing users to resume chat on existing cloud sandboxes using a sandbox ID. Enhanced error handling for session management and updated the remote execution configuration to utilize the session ID from the environment. Improved synchronization logic to accommodate skipping initial sync when resuming sessions. This update enhances user experience by providing seamless access to ongoing cloud interactions.",
          "is_bot": false,
          "headline": "feat(cli): add resume command for cloud sandbox sessions",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T10:42:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6fb178330d2e7896080c6eeff09c2d1266cf7fb",
          "body": "…ures\n\nAdded support for recording the active `sandboxId` in `sandbox_full` mode, enabling queries for preview hosts and improved user experience with the new `xc cloud pull` command to retrieve sandbox edits. Introduced an export endpoint for compressed workspace archives, enhancing the CLI's capabilities for managing sandbox sessions. Updated documentation to reflect these changes and ensure clarity on new features.",
          "is_bot": false,
          "headline": "feat(cli): enhance cloud functionality with sandboxId and export feat…",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T10:33:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51aa6443482de434cb2c5bbc9a492f22b0589a50",
          "body": "Updated the CLI commands to include a loading spinner during workspace synchronization for the `sandbox_full` strategy. Improved user experience by providing visual feedback while syncing projects to the E2B cloud. Additionally, refined the description for the `cloud` command to clarify its functionality.",
          "is_bot": false,
          "headline": "feat(cli): enhance cloud execution sync with spinner feedback",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T09:58:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42ab0a037d8c22bae3ed1bd6cf230c9915dcbe89",
          "body": "Updated package versions for xibecode and xibecode-core to 1.3.4. Introduced a new CLI option `--set-sandbox-sync-respect-gitignore` to allow users to control whether the sandbox sync honors .gitignore files. Enhanced the sandbox sync functionality to improve user experience and flexibility in managing workspace synchronization.",
          "is_bot": false,
          "headline": "feat(cli): bump version to 1.3.4 and enhance sandbox sync options",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T09:24:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ef9ce3e3977ed2b28c71b93cb62d6b780f3050c",
          "body": "- Updated global CSS to use a refined, flatter neutral palette with darker backgrounds (`#0A0A0A`, `#171717`) and reduced contrast borders.\n- Refined `ChatPanel` UI by replacing the heavy floating pill input with a clean border, flattening suggestion and mode buttons, and removing unnecessary drop shadows and heavy backgrounds from the welcome screen.\n- Updated `MessageBubble` styling to replace `rounded-2xl` with `rounded-lg` and use flatter backgrounds, reducing overall visual weight.",
          "is_bot": false,
          "headline": "feat: Update desktop UI to a flatter, minimalist aesthetic (#84)",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T09:10:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b99ebfba9b7712df25c3ff52e1ceb0d0205758b4",
          "body": "Added support for a new sandbox session strategy, `sandbox_full`, allowing for remote execution with workspace synchronization. Updated CLI options to configure maximum sync size and exclude patterns for file synchronization. Enhanced documentation to reflect these changes and ensure clarity on sandbox operation modes. Improved command execution to handle file operations in both `host_only` and `sandbox_full` modes, ensuring a seamless user experience.",
          "is_bot": false,
          "headline": "feat(cli): enhance E2B sandbox integration with new sync features",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T08:48:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61670244bd1d4f0ce6b28142402ea23e5379279d",
          "body": "Introduced a new configuration for team-hosted E2B gateway integration, allowing command execution in a remote sandbox environment. Added CLI options for setting sandbox mode, gateway URL, auth token, and session strategy. Updated documentation to reflect these changes and ensure secure handling of sensitive keys. Enhanced command execution to support remote execution configurations.",
          "is_bot": false,
          "headline": "feat(cli): add E2B gateway support for team sandboxing",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T04:38:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c7472b9998248bef7c165d7cacf9010a8707193",
          "body": "Changed the chat status from \"◈ cloud\" to \"◈ local\" and adjusted the prompt text for improved readability and user experience.",
          "is_bot": false,
          "headline": "fix(cli): update chat status text for clarity",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T04:03:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cc11e1e61023b75da7d522b1743a8254d6207f3",
          "body": "Published core is consumed via registry instead of workspace link for the CLI package.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(cli): depend on xibecode-core@^1.3.3 from npm",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T03:55:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc4ff68b4209cf2918452572b6972f54c993a0ed",
          "body": "- Bump root/core/cli to 1.3.3; desktop/ext depend on workspace xibecode-core\n- Chat: implicit image paths + @ refs for vision; Esc/queue fixes; help text\n- Core: Anthropic multimodal normalization tests; read_file skips raster bytes\n- Agent prompt: images/vision and filename-is-not-content guidance\n- Remove stale packages/cli/bun.lock (xibecode-core 1.2.2); use pnpm at repo root\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): xibecode 1.3.3 and vision UX fixes",
          "author_name": "R3AP3R edit",
          "author_login": "iotserver24",
          "committed_at": "2026-05-10T03:54:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 6,
      "commits_last_year": 389,
      "latest_release_at": "2026-07-24T12:58:57Z",
      "latest_release_tag": "v1.17.0",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 15,
      "days_since_latest_release": 11,
      "mean_days_between_releases": 33
    },
    "artifacts": {
      "collected": true,
      "structure": [
        "tree.dockerfile",
        "tree.electron"
      ],
      "declarations": [
        {
          "name": null,
          "path": "package.json",
          "tokens": [
            "npm.private"
          ],
          "ecosystem": "npm"
        },
        {
          "name": "xibecode",
          "path": "packages/cli/package.json",
          "tokens": [
            "npm.bin",
            "npm.entry"
          ],
          "ecosystem": "npm"
        },
        {
          "name": "xibecode-core",
          "path": "packages/core/package.json",
          "tokens": [
            "npm.entry"
          ],
          "ecosystem": "npm"
        },
        {
          "name": "xibecode-desktop",
          "path": "packages/desktop/package.json",
          "tokens": [
            "npm.entry"
          ],
          "ecosystem": "npm"
        },
        {
          "name": null,
          "path": "packages/e2b-gateway/package.json",
          "tokens": [
            "npm.private"
          ],
          "ecosystem": "npm"
        },
        {
          "name": "xibecode-vscode",
          "path": "packages/ext/package.json",
          "tokens": [
            "npm.entry"
          ],
          "ecosystem": "npm"
        },
        {
          "name": null,
          "path": "packages/hosting/package.json",
          "tokens": [
            "npm.private"
          ],
          "ecosystem": "npm"
        }
      ]
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "readme_badges": {
        "hosts": [
          "shields.io"
        ],
        "total": 5,
        "header": 5,
        "collected": true,
        "has_inspect_badge": false
      },
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 85,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "xibecode",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "cli",
            "ai",
            "coding",
            "assistant",
            "autonomous",
            "agent",
            "automation",
            "test-generation"
          ],
          "ecosystem": "npm",
          "categories": [],
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/xibecode",
          "declared_type": null,
          "is_deprecated": false,
          "latest_version": "1.17.4",
          "repository_url": "https://github.com/iotserver24/Xibecode",
          "versions_count": 84,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3512,
          "first_published_at": "2026-02-09T08:45:51.034000Z",
          "latest_published_at": "2026-07-25T07:02:15.276000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 11
        },
        {
          "name": "xibecode-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai",
            "agent",
            "coding",
            "autonomous",
            "mcp",
            "tools"
          ],
          "ecosystem": "npm",
          "categories": [],
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/xibecode-core",
          "declared_type": null,
          "is_deprecated": false,
          "latest_version": "1.17.4",
          "repository_url": "https://github.com/iotserver24/Xibecode",
          "versions_count": 42,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2950,
          "first_published_at": "2026-05-01T11:08:12.375000Z",
          "latest_published_at": "2026-07-25T07:02:07.176000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 11
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 12,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 50
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/cli/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/desktop/tsconfig.json",
        "packages/e2b-gateway/tsconfig.json",
        "packages/ext/tsconfig.json",
        "packages/hosting/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 170806,
      "source_files_sampled": 247,
      "oversized_source_files": 5,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 7978
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.33",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-8j4g-w8fx-2239"
            ],
            "fixed_version": "4.12.34",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 299,
        "malicious_count": 0,
        "assessed_package": "npm:xibecode@1.17.4",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "xibecode-core",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.17.4"
        },
        {
          "name": "@anthropic-ai/sdk",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.78.0"
        },
        {
          "name": "chalk",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.2"
        },
        {
          "name": "commander",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.0.0"
        },
        {
          "name": "conf",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.0"
        },
        {
          "name": "dotenv",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.3.1"
        },
        {
          "name": "ink",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.7.0"
        },
        {
          "name": "ink-select-input",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.0"
        },
        {
          "name": "ink-text-input",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "inquirer",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.4.1"
        },
        {
          "name": "marked",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.2.0"
        },
        {
          "name": "marked-terminal",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.3.0"
        },
        {
          "name": "node-fetch",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.2"
        },
        {
          "name": "open",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.0.0"
        },
        {
          "name": "ora",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.1"
        },
        {
          "name": "react",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "ws",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.18.0"
        },
        {
          "name": "@anthropic-ai/sdk",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.78.0"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "diff",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.0"
        },
        {
          "name": "dotenv",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.3.1"
        },
        {
          "name": "fast-glob",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.3"
        },
        {
          "name": "gray-matter",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.3"
        },
        {
          "name": "node-fetch",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.2"
        },
        {
          "name": "open",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.0.0"
        },
        {
          "name": "picomatch",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.2"
        },
        {
          "name": "strip-ansi",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.1.0"
        },
        {
          "name": "ts-morph",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^27.0.2"
        },
        {
          "name": "typescript",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.3.3"
        },
        {
          "name": "zod",
          "manifest": "packages/core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "clsx",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "conf",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.0"
        },
        {
          "name": "framer-motion",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.38.0"
        },
        {
          "name": "highlight.js",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.11.1"
        },
        {
          "name": "lucide-react",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.14.0"
        },
        {
          "name": "react",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "react-dom",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "react-markdown",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.3"
        },
        {
          "name": "remark-gfm",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.0"
        },
        {
          "name": "tailwind-merge",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.5.0"
        },
        {
          "name": "xibecode-core",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "e2b",
          "manifest": "packages/e2b-gateway/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.19.4"
        },
        {
          "name": "@types/marked",
          "manifest": "packages/ext/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "marked",
          "manifest": "packages/ext/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.2.0"
        },
        {
          "name": "xibecode-core",
          "manifest": "packages/ext/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "jsonwebtoken",
          "manifest": "packages/hosting/package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.2"
        },
        {
          "name": "nanoid",
          "manifest": "packages/hosting/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.1.5"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 50,
        "merged_prs": 49,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 62
      },
      "bus_factor": 1,
      "bot_contributors": 4,
      "top_contributors": [
        {
          "type": "User",
          "login": "iotserver24",
          "commits": 372,
          "avatar_url": "https://avatars.githubusercontent.com/u/147928812?v=4"
        },
        {
          "type": "User",
          "login": "snyk-bot",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/19733683?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.997
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 4 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "71 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e6cd6c4c6b05f14089db771d6a5d0b9bd348ae2e",
        "ran_at": "2026-08-05T09:30:55Z",
        "aggregate_score": 4.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "recent_prs": {
        "merged_7d": 0,
        "decided_7d": 5,
        "merged_30d": 0,
        "authors_30d": 1,
        "decided_30d": 5,
        "sample_size": 60,
        "window_days": 30,
        "sample_exhausted": false,
        "authors_probed_30d": 1,
        "newcomer_merged_30d": 0,
        "bot_prs_excluded_30d": 5,
        "newcomer_authors_30d": 0,
        "newcomer_decided_30d": 0
      },
      "ci_last_run_at": "2026-08-01T14:21:57Z",
      "oldest_open_prs": [
        {
          "number": 99,
          "created_at": "2026-05-22T06:24:30Z",
          "last_comment_at": "2026-05-22T06:24:38Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 100,
          "created_at": "2026-05-23T06:01:07Z",
          "last_comment_at": "2026-05-23T06:02:27Z",
          "last_comment_author": "xibe-review"
        },
        {
          "number": 101,
          "created_at": "2026-05-24T05:50:36Z",
          "last_comment_at": "2026-05-24T05:50:42Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 103,
          "created_at": "2026-05-26T06:14:59Z",
          "last_comment_at": "2026-05-26T06:24:09Z",
          "last_comment_author": "xibe-review"
        },
        {
          "number": 104,
          "created_at": "2026-05-27T05:56:05Z",
          "last_comment_at": "2026-05-27T05:56:12Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 105,
          "created_at": "2026-05-28T06:04:57Z",
          "last_comment_at": "2026-05-28T06:06:19Z",
          "last_comment_author": "xibe-review"
        },
        {
          "number": 106,
          "created_at": "2026-05-28T16:58:35Z",
          "last_comment_at": "2026-05-28T16:58:42Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 107,
          "created_at": "2026-05-29T05:53:16Z",
          "last_comment_at": "2026-05-29T05:53:23Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 108,
          "created_at": "2026-05-29T16:45:47Z",
          "last_comment_at": "2026-05-29T16:45:58Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 109,
          "created_at": "2026-05-30T05:54:56Z",
          "last_comment_at": "2026-05-30T05:55:03Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 110,
          "created_at": "2026-05-30T17:11:17Z",
          "last_comment_at": "2026-05-30T17:11:26Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 111,
          "created_at": "2026-05-31T05:47:37Z",
          "last_comment_at": "2026-05-31T05:47:44Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 112,
          "created_at": "2026-05-31T16:44:32Z",
          "last_comment_at": "2026-05-31T16:44:38Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 113,
          "created_at": "2026-06-01T05:55:41Z",
          "last_comment_at": "2026-06-01T05:55:48Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 114,
          "created_at": "2026-06-01T17:07:13Z",
          "last_comment_at": "2026-06-01T17:07:22Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 115,
          "created_at": "2026-06-02T05:55:20Z",
          "last_comment_at": "2026-06-02T06:02:15Z",
          "last_comment_author": "xibe-review"
        },
        {
          "number": 116,
          "created_at": "2026-06-02T17:19:14Z",
          "last_comment_at": "2026-06-02T17:19:24Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 119,
          "created_at": "2026-06-02T18:56:21Z",
          "last_comment_at": "2026-06-02T18:56:22Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 121,
          "created_at": "2026-06-03T06:08:59Z",
          "last_comment_at": "2026-06-03T06:09:06Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 122,
          "created_at": "2026-06-03T17:15:01Z",
          "last_comment_at": "2026-06-03T17:15:10Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-05-24T17:28:03Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/iotserver24/Xibecode",
    "host": "github.com",
    "name": "Xibecode",
    "owner": "iotserver24"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": "The weighted overall 61 is calibrated to 67 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 61,
            "calibrated": 67,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 67,
      "inputs": {
        "security": 51,
        "vitality": 80,
        "community": 50,
        "governance": 47,
        "calibration": "2026-08-02",
        "engineering": 76,
        "ai_readiness": 67,
        "weighted_overall_raw": 61
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 80,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 389,
              "human_commit_share": 1,
              "days_since_last_push": 3,
              "active_weeks_last_year": 15
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "15/52 weeks with commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 15
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "389 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 389
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 6,
              "latest_release_tag": "v1.17.0",
              "releases_from_tags": false,
              "days_since_latest_release": 11,
              "mean_days_between_releases": 33
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "6 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 11 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~33 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 33
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 17,
            "inputs": {
              "forks": 2,
              "stars": 12,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "12 stars",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": 5,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [
                "shields.io"
              ],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "xibecode",
                "xibecode-core"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 6462
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "6,462 downloads/month across npm",
                "points": 50.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 6462,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 47,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.997
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 29,
            "inputs": {
              "merged_prs": 49,
              "open_issues": 0,
              "closed_issues": 0,
              "prs_merged_7d": 0,
              "prs_decided_7d": 5,
              "prs_merged_30d": 0,
              "prs_decided_30d": 5,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 62,
              "first_time_authors_30d": 0,
              "first_time_prs_merged_30d": 0,
              "first_time_prs_decided_30d": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "49/111 decided PRs merged",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 49,
                      "decided": 111
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "followers": 73,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "iotserver24",
              "public_repos": 205,
              "account_age_days": 1025
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "73 followers of iotserver24",
                "points": 13.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 73,
                      "login": "iotserver24"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "205 public repos, account ~2 yr old",
                "points": 18.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 205
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "xibecode",
                "xibecode-core"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 11
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 11 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 11
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "84 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 84
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 76,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "exceptional",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "ai",
                "claude-code-alternative",
                "cli-coding",
                "tool",
                "xibecode"
              ],
              "has_wiki": true,
              "homepage": "https://xibeai.in",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://xibeai.in",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "5 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 51,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "71 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:xibecode@1.17.4 runtime dependency closure — what installing the published package pulls in — 299 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:xibecode@1.17.4",
                  "assessed": 299
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 89,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 299,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: hono 4.12.33 (moderate 5.3)",
                "points": 14.4,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "hono 4.12.33 (moderate 5.3)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 299,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 67,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.97,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 7978
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/cli/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/desktop/tsconfig.json",
                "packages/e2b-gateway/tsconfig.json",
                "packages/ext/tsconfig.json",
                "packages/hosting/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.1,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/desktop/tsconfig.json, packages/e2b-gateway/tsconfig.json, packages/ext/tsconfig.json, packages/hosting/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/desktop/tsconfig.json, packages/e2b-gateway/tsconfig.json, packages/ext/tsconfig.json, packages/hosting/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "10 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 10,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 170806,
              "source_files_sampled": 247,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/247 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 247,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "library",
        "application"
      ],
      "labels": [
        "cli",
        "desktop",
        "mcp-server",
        "library",
        "web-ui",
        "tui"
      ],
      "scores": {
        "cli": 12,
        "tui": 4,
        "web-ui": 4,
        "desktop": 8,
        "library": 4.8,
        "mcp-server": 7
      },
      "primary": "cli",
      "evidence": [
        {
          "tier": "structure",
          "label": "desktop",
          "source": "tree.electron",
          "weight": 8
        },
        {
          "tier": "declared",
          "label": "cli",
          "source": "npm.bin",
          "weight": 6
        },
        {
          "tier": "declared",
          "label": "library",
          "source": "npm.private",
          "weight": -6
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:npm",
          "weight": 6
        },
        {
          "tier": "declared",
          "label": "library",
          "source": "npm.entry",
          "weight": 4.8
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:commander",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "mcp-server",
          "source": "dep:@modelcontextprotocol/sdk",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "tui",
          "source": "dep:ink",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "web-ui",
          "source": "dep:react-dom",
          "weight": 4
        },
        {
          "tier": "structure",
          "label": "mcp-server",
          "source": "mcp_signal",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "cli",
          "source": "tag:cli",
          "weight": 2
        }
      ],
      "artifacts": [
        {
          "path": "package.json",
          "labels": [],
          "ecosystem": "npm"
        },
        {
          "path": "packages/cli/package.json",
          "labels": [
            "cli",
            "library"
          ],
          "ecosystem": "npm"
        },
        {
          "path": "packages/core/package.json",
          "labels": [
            "library"
          ],
          "ecosystem": "npm"
        },
        {
          "path": "packages/desktop/package.json",
          "labels": [
            "library"
          ],
          "ecosystem": "npm"
        },
        {
          "path": "packages/e2b-gateway/package.json",
          "labels": [],
          "ecosystem": "npm"
        },
        {
          "path": "packages/ext/package.json",
          "labels": [
            "library"
          ],
          "ecosystem": "npm"
        },
        {
          "path": "packages/hosting/package.json",
          "labels": [],
          "ecosystem": "npm"
        }
      ],
      "confidence": "high",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package 'xibecode-vscode' from its registry",
    "Could not fetch npm package 'xibecode-desktop' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-05T09:31:01.350256Z",
  "schema_version": "0.31.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/iotserver24/Xibecode.svg",
  "full_name": "iotserver24/Xibecode",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v2.5.0, esquema v0.31.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.