Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"background-jobs",
"durable-execution",
"go",
"golang",
"gorm",
"job-queue",
"mysql",
"postgres",
"sqlite",
"task-queue",
"workflow-engine"
],
"is_fork": false,
"size_kb": 14499,
"has_wiki": true,
"homepage": "https://jdziat.github.io/simple-durable-jobs/",
"languages": {
"Go": 3005955,
"CSS": 4196,
"HTML": 851,
"Shell": 15052,
"Svelte": 218063,
"Makefile": 3093,
"Dockerfile": 1670,
"JavaScript": 114,
"TypeScript": 209717
},
"pushed_at": "2026-07-27T14:46:45Z",
"created_at": "2026-02-09T13:36:10Z",
"owner_type": "User",
"updated_at": "2026-07-27T07:04:35Z",
"description": "Durable jobs and checkpointed workflows on the SQL database you already have — Postgres, MySQL, or SQLite. Embedded dashboard, signals, timers, transactional enqueue.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": "Jordan Dziat",
"type": "User",
"login": "jdziat",
"company": "Lifetime Value Co",
"location": null,
"followers": 12,
"avatar_url": "https://avatars.githubusercontent.com/u/1184714?v=4",
"created_at": "2011-11-09T22:07:28Z",
"is_verified": null,
"public_repos": 146,
"account_age_days": 5374
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v4.7.0",
"kind": "minor",
"published_at": "2026-07-26T05:57:05Z"
},
{
"tag": "v4.6.0",
"kind": "minor",
"published_at": "2026-07-25T23:13:26Z"
},
{
"tag": "v4.5.1",
"kind": "patch",
"published_at": "2026-07-18T18:29:05Z"
},
{
"tag": "v4.5.0",
"kind": "minor",
"published_at": "2026-07-10T05:56:03Z"
},
{
"tag": "v4.4.3",
"kind": "patch",
"published_at": "2026-07-10T04:44:08Z"
},
{
"tag": "v4.4.2",
"kind": "patch",
"published_at": "2026-07-10T03:20:55Z"
},
{
"tag": "v4.4.1",
"kind": "patch",
"published_at": "2026-07-10T00:51:24Z"
},
{
"tag": "v4.4.0",
"kind": "minor",
"published_at": "2026-07-10T00:24:22Z"
},
{
"tag": "v4.3.1",
"kind": "patch",
"published_at": "2026-07-09T23:08:05Z"
},
{
"tag": "v4.3.0",
"kind": "minor",
"published_at": "2026-07-09T16:34:23Z"
},
{
"tag": "v4.2.0",
"kind": "minor",
"published_at": "2026-07-09T16:09:30Z"
},
{
"tag": "v4.1.2",
"kind": "patch",
"published_at": "2026-07-09T15:08:56Z"
},
{
"tag": "v4.1.1",
"kind": "patch",
"published_at": "2026-06-26T17:53:43Z"
},
{
"tag": "v4.1.0",
"kind": "minor",
"published_at": "2026-06-26T15:42:37Z"
},
{
"tag": "v4.0.1",
"kind": "patch",
"published_at": "2026-06-23T03:58:00Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2026-06-23T02:37:32Z"
},
{
"tag": "v3.10.2",
"kind": "patch",
"published_at": "2026-06-19T21:06:36Z"
},
{
"tag": "v3.10.1",
"kind": "patch",
"published_at": "2026-06-19T19:15:20Z"
},
{
"tag": "v3.10.0",
"kind": "minor",
"published_at": "2026-06-19T17:00:46Z"
},
{
"tag": "v3.9.2",
"kind": "patch",
"published_at": "2026-06-17T23:10:32Z"
},
{
"tag": "v3.9.1",
"kind": "patch",
"published_at": "2026-06-17T21:03:24Z"
},
{
"tag": "v3.9.0",
"kind": "minor",
"published_at": "2026-06-17T18:19:29Z"
},
{
"tag": "v3.8.0",
"kind": "minor",
"published_at": "2026-06-17T13:51:02Z"
},
{
"tag": "v3.7.0",
"kind": "minor",
"published_at": "2026-06-16T22:40:32Z"
},
{
"tag": "v3.6.0",
"kind": "minor",
"published_at": "2026-06-16T13:59:24Z"
},
{
"tag": "v3.5.3",
"kind": "patch",
"published_at": "2026-06-16T05:24:07Z"
},
{
"tag": "v3.5.2",
"kind": "patch",
"published_at": "2026-06-16T05:02:50Z"
},
{
"tag": "v3.5.1",
"kind": "patch",
"published_at": "2026-06-16T04:44:54Z"
},
{
"tag": "v3.5.0",
"kind": "minor",
"published_at": "2026-06-16T02:02:06Z"
},
{
"tag": "v3.4.7",
"kind": "patch",
"published_at": "2026-06-16T00:27:38Z"
},
{
"tag": "v3.4.6",
"kind": "patch",
"published_at": "2026-06-16T00:03:30Z"
},
{
"tag": "v3.4.5",
"kind": "patch",
"published_at": "2026-06-15T23:44:07Z"
},
{
"tag": "v3.4.4",
"kind": "patch",
"published_at": "2026-06-15T14:12:29Z"
},
{
"tag": "v3.4.3",
"kind": "patch",
"published_at": "2026-06-15T13:45:08Z"
},
{
"tag": "v3.4.2",
"kind": "patch",
"published_at": "2026-06-15T13:23:58Z"
},
{
"tag": "v3.4.1",
"kind": "patch",
"published_at": "2026-06-15T06:13:29Z"
},
{
"tag": "v3.4.0",
"kind": "minor",
"published_at": "2026-06-15T02:35:47Z"
},
{
"tag": "v3.3.0",
"kind": "minor",
"published_at": "2026-06-15T01:32:28Z"
},
{
"tag": "v3.2.1",
"kind": "patch",
"published_at": "2026-06-15T00:54:58Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2026-06-14T23:23:32Z"
},
{
"tag": "v3.1.5",
"kind": "patch",
"published_at": "2026-06-14T21:32:14Z"
},
{
"tag": "v3.1.4",
"kind": "patch",
"published_at": "2026-06-14T19:14:30Z"
},
{
"tag": "v3.1.3",
"kind": "patch",
"published_at": "2026-06-14T17:58:58Z"
},
{
"tag": "v3.1.2",
"kind": "patch",
"published_at": "2026-06-14T17:09:38Z"
},
{
"tag": "v3.1.1",
"kind": "patch",
"published_at": "2026-06-14T14:59:33Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2026-06-14T14:31:08Z"
},
{
"tag": "v3.0.1",
"kind": "patch",
"published_at": "2026-06-14T04:52:39Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2026-06-14T04:21:11Z"
},
{
"tag": "v2.7.1",
"kind": "patch",
"published_at": "2026-06-13T21:12:00Z"
},
{
"tag": "v2.7.0",
"kind": "minor",
"published_at": "2026-06-13T17:43:08Z"
},
{
"tag": "v2.6.1",
"kind": "patch",
"published_at": "2026-06-12T12:38:24Z"
},
{
"tag": "v2.6.0",
"kind": "minor",
"published_at": "2026-06-10T14:47:06Z"
},
{
"tag": "v2.5.1",
"kind": "patch",
"published_at": "2026-06-10T13:25:36Z"
},
{
"tag": "v2.5.0",
"kind": "minor",
"published_at": "2026-06-10T05:25:20Z"
},
{
"tag": "v2.4.0",
"kind": "minor",
"published_at": "2026-06-10T03:44:46Z"
},
{
"tag": "v2.3.0",
"kind": "minor",
"published_at": "2026-06-10T01:10:09Z"
},
{
"tag": "v2.2.0",
"kind": "minor",
"published_at": "2026-06-09T22:25:33Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2026-06-09T18:59:45Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2026-06-09T13:12:45Z"
},
{
"tag": "v1.11.0",
"kind": "minor",
"published_at": "2026-06-09T12:03:34Z"
},
{
"tag": "v1.10.0",
"kind": "minor",
"published_at": "2026-06-09T04:57:23Z"
},
{
"tag": "v1.9.0",
"kind": "minor",
"published_at": "2026-06-09T02:05:51Z"
},
{
"tag": "v1.8.0",
"kind": "minor",
"published_at": "2026-06-08T13:19:26Z"
},
{
"tag": "v1.7.0",
"kind": "minor",
"published_at": "2026-06-07T19:57:06Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2026-06-07T14:23:54Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-06-06T23:13:35Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-06-06T16:19:35Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2026-06-04T13:00:38Z"
},
{
"tag": "v1.2.4",
"kind": "patch",
"published_at": "2026-06-02T16:53:24Z"
},
{
"tag": "v1.2.3",
"kind": "patch",
"published_at": "2026-06-01T03:47:44Z"
},
{
"tag": "v1.2.2",
"kind": "patch",
"published_at": "2026-05-31T01:56:21Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2026-05-30T16:22:00Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2026-05-01T17:07:55Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-03-09T01:48:28Z"
},
{
"tag": "v1.0.2",
"kind": "patch",
"published_at": "2026-02-28T19:07:09Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2026-02-28T19:00:59Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2026-02-19T05:57:56Z"
}
],
"recent_commits": [
{
"oid": "24c904c9682de40fa1aaafe7a6f907968ed5d85f",
"body": "…ns, backlog age, MySQL charset, slot ownership (#115)\n\n* fix(storage): release committed claims when a dequeue aborts after claiming\n\nA claim is durably COMMITTED before the payload is decoded and before the batch\nis re-fetched. Every error exit after that point returned without undoing it,\nleaving\n[…]\nh said \"three presets\" where four are exported.\n\n6. Markdown log fences carry a language.\n\nGate: golangci-lint 0 issues; pkg/worker green with -race; the corrected\nexamples.md block compiled verbatim.",
"is_bot": false,
"headline": "feat: wave 3 durability train — stranded claims, unwritten dispositio…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-26T05:44:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad7b9665fced825e4fdc59c23b263137f9a74ce5",
"body": "…d unblock releases (#113)\n\n* fix(deps): bump x/text and otel to clear the release-blocking vulnerability gate\n\ngovulncheck is release-blocking (ci.yml's release job lists it in `needs`), and\nit was red on two reachable advisories, so merges to main were building green\nand minting no tag — a SKIPPED\n[…]\nthat also left the new option undocumented.\n\nGate: golangci-lint 0 issues; full suite 23 packages green with -race -p=1;\ncheckpoint upsert and nested-call replay tests re-run green after the refactor.",
"is_bot": false,
"headline": "feat: close the nested-Call replay corruption and h2c auth bypass, an…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-25T23:00:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "205e2bcf0bc465eb79ac3af3ca7e90100984ce44",
"body": "…omplete, batch dequeue, stats leak) (#112)\n\n* fix(storage): guard PurgeJobs/DeleteJob against stranding a live fan-out child\n\nPurgeJobs excluded only fan-out PARENTS, so a routine PurgeJobs(queue,\nStatusCompleted) (also the dashboard PurgeQueue RPC) deleted a completed LEAF\nsub-job whose parent was\n[…]\n + a\n spurious server log. Map it to FailedPrecondition with a friendly bulk reason,\n mirroring ErrJobHasChildren.\n\nAdded a >1-batch PurgeJobs test. Verified on sqlite + live PG + MySQL; lint clean.",
"is_bot": false,
"headline": "fix: five review-found bugs (fan-out purge, concurrency slot, pause-c…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-18T18:17:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a51cef8ff8596b42a025fa0ca0c2a84ba8e1aaaa",
"body": "* feat(ui): compute schedule overdue/health in ListScheduledJobs\n\nFold missed-fire detection into the NextRun forward-walk: a schedule is\noverdue when its most recent real fire is behind wall-clock by more than a\nconfigurable grace threshold, i.e. one or more boundaries that should have\nfired have n\n[…]\nscheduler/worker may not be running\" — a\n paused queue keeps advancing last_fired_at, so it does not flag overdue); make\n the mock overdue sample internally coherent (last fire older than expected).",
"is_bot": false,
"headline": "feat(ui): schedule health/overdue indicator on the Scheduled page (#111)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T05:43:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc3d14079bfa833f46be5d45a31b85bbacad09b0",
"body": "…undaries (#110)\n\nC-03 (#106) anchored the dashboard NextRun on the persisted last run but took a\nsingle Schedule.Next(lastRun) step. When the last run is more than one interval\nbehind now (worker down / schedule paused), that step returns a boundary already\nin the PAST, so the dashboard labels a st\n[…]\nRun, now)). Both fail on the old\none-step code and pass on the walk.\n\nFound by an adversarial codex-dispatch teardown of #103-#109; CTO-validated\n(CONFIRMED, low severity, display-only, self-healing).",
"is_bot": false,
"headline": "fix(ui): walk NextRun forward to the next future fire after missed bo…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T04:31:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "324c76f056c5f1a5bcf5816274f6b184f7e71d4d",
"body": "…bogus cross-major tags (#109)\n\nAdds a 'Detect a superseded Release run' step that gates go-semantic-release on HEAD == origin/main tip, so re-running an old Release job can't re-scan history and mint a bogus cross-major tag (the v5.0.0/v5.0.1 incident).",
"is_bot": false,
"headline": "ci(release): skip release on a superseded (re-run) commit to prevent …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T03:36:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a70cb9ae7796adecbddff99835c03b4d6e68f66",
"body": "… (#108)\n\ndrainDequeuedJobs re-checks IsPaused() after the dequeue round-trip and releases the just-claimed batch instead of dispatching it, so a Pause() landing mid-dequeue no longer lets a graceful-paused worker run jobs enqueued after the pause. Fixes the PG-only TestPauseIntegration flake (39/100→0/100). Deterministic fail-first test + a 'paused' bounce metric. Gated concurrency/10x/CTO A/A-/A-.",
"is_bot": false,
"headline": "fix(worker): don't dispatch jobs claimed while a graceful pause lands…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T02:49:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e86f7cd5947e241c4e30420b86f7c3a69f78221",
"body": "… (#107)\n\nReframe the migration guide as v2->v4 (fix the impossible go get .../v4@v3.0.0, attribute terminal CancelJob to v4.0.0, document the CancelJob v2->v4 behavior break), retitle README links, and document that UniqueFor dedup is fleet-wide and tenant-excluded. Docs/godoc only. Gated accuracy/CTO A/A.",
"is_bot": false,
"headline": "docs: v4-consistent v2 migration guide + UniqueFor tenant-scope godoc…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T00:40:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "164ad3af4e204747cd841776aead9af8ad554b04",
"body": "…y workflows (#106)\n\nC-03: ListScheduledJobs NextRun now anchors on the persisted last run (Schedule.Next(lastRun)) matching the scheduler, not Next(now). C-04: ListWorkflows aggregates fan-out strategies to a display-only 'mixed' when they differ instead of reporting only the first. Read-only UI honesty fixes. Gated scheduler/10x/CTO A/A-/A.",
"is_bot": false,
"headline": "fix(ui): anchor scheduled NextRun on last run and label mixed-strateg…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T00:37:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d755f25bc428dee717091d40120560df2292df5",
"body": "…105)\n\nAdditive TryConsumeRateWindow + ReleaseRateAt refund the exact committed (limit_name, window_start) row instead of now.Truncate(window), fixing the off-by-one where a refund after a window rollover drained the wrong window. TryConsumeRate/ReleaseRate signatures unchanged; new windowedRateLimiter capability added to the compile-time guard wall. Gated DBA/10x/CTO A-/A-/A-.",
"is_bot": false,
"headline": "feat(ratelimit): refund the exact consume window across a rollover (#…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-10T00:11:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "25929fe5db9f1647ec8b043c961ce012c05e2940",
"body": "…(#104)\n\nMake the dq_ready dequeue predicate MySQL-only. On PG/SQLite it was a redundant filter imposing a promoter-latency floor; the partial idx_jobs_dequeue_eligible is priority-first and doesn't contain dq_ready. Gated DBA/10x/CTO A/A-/A-. D2a index-drop deferred on live-EXPLAIN filesort evidence.",
"is_bot": false,
"headline": "perf(dequeue): drop the dq_ready visibility floor on Postgres/SQLite …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-09T23:46:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84f3dfd65e53f0c00f2d7d9fbb54ccf399c26d90",
"body": "…over-dispatches (#103)\n\nPG re-evaluates a bare `FOR UPDATE SKIP LOCKED ... LIMIT n` subquery embedded in an UPDATE, ignoring the limit and over-dispatching (got=10 for limit=5). Fence it in a MATERIALIZED CTE. Gated DBA/10x/CTO A/A-/A; 3-backend -race green; regression guards added.",
"is_bot": false,
"headline": "fix(dequeue): materialize the locking subquery so DequeueBatch never …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-09T22:55:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5a19f6d8303e52da199a2f683967e877bb3e8bd",
"body": "Wave C — PKT-11..14: GetWorkflow truncation honesty + fail-loud deleteFanOutSubtree; custom-storage durability-capability startup warnings; worker re-entry guard + bounded drain + shutdown-release ordering (also stabilizes the flaky drain test); OTel span-error redaction + double-instrument guard + \n[…]\nket gated DBA/10x/CTO unanimous >=A-; 3-backend -race + chaos-smoke green. The two dequeue-hot-path D2 items + E6/C-03/C-04/docs are deferred to a dedicated live-EXPLAIN follow-up (see PKT-14 commit).",
"is_bot": false,
"headline": "feat(wave-c): P2 hardening/honesty from the 2026-07-05 teardown (#102)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-09T16:22:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "31c4f710a6bb778c1c505709ab8c9a32c924be4e",
"body": "…6-07-05 teardown (#101)\n\nWave B — PKT-06..10: fan-out count persistence + cross-API cancel resume; aggressive-pause locked_by + serialized terminal cancel; signal-consume ownership gate; v1.x->v4 boot fix; hot-path stat cache + purge unique_locks + growth-cardinality metrics + paused-read surfacing\n[…]\ny/RateLimitWindowCardinality, ConsumeSignalTxOwned/DrainSignalsTxOwned, SupportsAtomicScheduledFire) -> minor. Each packet gated DBA/10x/CTO unanimous >=A-; 3-backend -race + full chaos harness green.",
"is_bot": false,
"headline": "feat(wave-b): P1 durability/ops edges + hot-path caching from the 202…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-09T15:56:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6949f7dc5d4141c2fb5b27cfd86065b56224f8b5",
"body": "Wave A — 5 P0 launch-blockers + shared-DB test-isolation flake fix + go1.25.12 toolchain (CVE GO-2026-5856). Each packet gated DBA/10x/CTO unanimous >=A-; 3-backend -race + chaos green.",
"is_bot": false,
"headline": "fix(wave-a): P0 launch-blockers from the 2026-07-05 dual teardown (#100)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-07-09T14:22:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7640254d463ba8374f8359266139c250c332bd98",
"body": "A worker killed mid-fan-out could leave the parent stranded in 'waiting' with a\npending fan_out and ZERO persisted children — unrecovered for 37+ minutes in a\ndownstream incident. Root cause: the fan-out first-execution suspend was four\nseparate transactions (CreateFanOut -> SaveCheckpoint -> MarkWa\n[…]\n on all three backends; chaos harness (worker kills, 12 invariants) green on\nPostgres; gorelease: additive, no API break. Reviewed DBA + 10x + CTO.\n\nRefs hivemind incident (pod recreated mid-fan-out).",
"is_bot": false,
"headline": "fix(fanout): atomic fan-out suspend + graceful shutdown release (#99)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-26T17:41:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27637ddf94a54a500b3f43c3ac6e9dd9b826782e",
"body": "Extends the chaostest crash/recovery harness into a configurable torture mode\nthat drives thousands of complex durable jobs locally via docker compose, with\na clean high-volume drain by default and opt-in worker-kill chaos. Reuses the\nexisting complex job types, the chaos_effects exactly-once ledger\n[…]\non Postgres: clean smoke (40 roots) and --chaos smoke (59 roots under\nworker kills) both drain with all 12 invariants PASS; baseline chaos-test.sh\nregression stays green (now also exercises megaflow).",
"is_bot": false,
"headline": "feat(chaostest): local torture test for thousands of complex jobs (#98)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-26T15:30:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44b97297f2c4ac2e7abdaaf3b93939c0df4e8e98",
"body": "…tx (#96)\n\n* test(resume): add unit tests across resume logic\n\nCover previously-untested resume paths at the storage and queue layers.\nAll storage tests are backend-parametrized via openTestDB and run on\nsqlite, Postgres, and MySQL in CI (the existing 3-backend matrix).\n\nStorage (pkg/storage/resume_\n[…]\n 5s-ticker\nwrapper over the already-tested pollWaitingJobsOnce and is not unit-testable\nwithout refactoring production code.\n\n* test(queue): drop redundant BackoffPolicy assertion (staticcheck QF1011)",
"is_bot": false,
"headline": "test: raise unit coverage across resume, queue, storage, worker, jobc…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-26T15:01:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab58ab83ffb54f44676ac06ddcb90a412fd50c09",
"body": "GO-2026-5004 (SQL injection via placeholder confusion with dollar-quoted\nstring literals) affects github.com/jackc/pgx/v5 < v5.9.2 and was reachable\nfrom GormStorage.GetCompletablePendingFanOuts, failing the govulncheck CI gate\non main. Bump the (indirect) pgx dependency to the latest v5.10.0.\n\nVerified: govulncheck reports 0 affected vulnerabilities; full pkg/storage\nsuite passes against Postgres with -race.",
"is_bot": false,
"headline": "chore(deps): bump jackc/pgx/v5 to v5.10.0 (fixes GO-2026-5004) (#97)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-26T14:49:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "920e556e61307a3a8a99e3522766c27c40980144",
"body": "…ot-found race (#95)\n\nThe three non-blocking follow-ups flagged by the v4.0.0 terminal-cancel gate,\nall using existing core.Storage methods (no interface additions).\n\n- Fan-out first-execution cancel race (pkg/fanout): after EnqueueBatch, re-read\n the fan-out and CancelSubJobs the children if it wa\n[…]\nancel.\n\nAdds MIGRATION-v4.md (v3 -> v4 upgrade guide).\n\nGated DBA + 10x + CTO (A-/A/A, GO). golangci-lint clean; SQLite + live PG/MySQL\nstorage cancel and tests/ fan-out integration green under -race.",
"is_bot": false,
"headline": "fix(cancel): fan-out cancel-race guard, fail-loud deep subtrees, UI n…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-23T03:46:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "715c18806afbf9444f20f0fcf6a5ead24bdbae51",
"body": "Bumps the Go module path github.com/jdziat/simple-durable-jobs/v3 -> /v4 and\nrewrites every internal import, the proto go_package, and the README/docs\nsnippets, so semantic-release can cut v4.0.0. Companion to #93 (the feat!\nterminal-cancel change). With the path at /v4, the api-compat (gorelease) g\n[…]\ncut branch and passes, unblocking the Release job.\n\nBREAKING CHANGE: the Go module path is now github.com/jdziat/simple-durable-jobs/v4.\nImporters must update their import paths from .../v3 to .../v4.",
"is_bot": false,
"headline": "build!: migrate Go module path to /v4 for the v4.0.0 major release (#94)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-23T02:25:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4dba05dcb6d1abe6178fb01cf290a45cd62f9296",
"body": "…ion (#93)\n\nCancelJob was a thin alias for aggressive pause: a job that self-suspended to\n`waiting` just before cancel ended up paused and recoverable, not cancelled. It\nnow performs true terminal cancellation via a new Storage.CancelJobTerminal\nprimitive, recursively cancelling the whole descendant\n[…]\nble aggressive pause, so a `waiting` job ended up paused; it\nis now cancelled. The core.Storage interface also gains a required\nCancelJobTerminal method, which breaks external Storage implementations.",
"is_bot": false,
"headline": "feat(cancel)!: make CancelJob terminal with fan-out subtree cancellat…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-23T01:46:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b7b75cac1b994935826c44c8acf002721bf78f78",
"body": "…aper-anchor timestamp precision\n\nCloses the two deferred follow-ups from PRs #89/#90.\n\n- Fan-out count reconcile (CancelOnFail=false): accountTerminalWithFanOut now\n reconciles the frozen, under-counted fan_outs persisted snapshot in its\n already-terminal branch once every child has settled (acco\n[…]\nhe DBA's #1 PR #89\n chaos-kill residual.\n\nNo migration. Verified: mutation-proven 3-backend -race; full pkg/storage PG+MySQL\n+ tests/ -race green; golangci-lint 0 issues; gate DBA A / 10x A / CTO GO.",
"is_bot": false,
"headline": "fix(storage): reconcile fan-out counts on natural completion + pin re…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-19T20:54:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "19e5ff3af867ab020b5b5d0f8569460561b223f0",
"body": "…WAL file DB\n\nMigrates two recurring -race CI flakes off shared-cache in-memory SQLite onto a\nWAL file DB. TestWorker_SubJobTimeoutCancelsHandlerContext (~7.5%) and\nTestInstrumentedWorkerEndsProcessSpanOnWaiting (~1.25%) stalled because the\nshared-cache global writer lock made a fan-out/waiting writ\n[…]\n0/100. A doc comment on\nnewSQLiteQueue records this so the busy_timeout footgun is not re-tried.\n\nVerified: 10x-reviewer grade A; full pkg/worker + pkg/otel suites green -race;\ngolangci-lint 0 issues.",
"is_bot": false,
"headline": "test(worker,otel): de-flake shared-cache SQLite contention tests via …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-19T20:00:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "823199233e221491d3433841bf323cef65a48979",
"body": "…os-gate trust\n\nFixes the nightly Stress & Chaos workflow, red since 2026-06-18 for three causes.\n\n- Fan-out count durability bug: CancelSubJobs now reconciles fan_outs persisted\n counts (completed+failed+cancelled) atomically with the sibling cancellation,\n ungated by status, so a fail_fast termi\n[…]\nMySQL 8.0.42; gated GO (DBA/10x/skeptic -> CTO). Known residual documented:\nfail_fast with CancelOnFail=false does not reconcile (un-exercised by chaos,\nmasked at the API by GetFanOut's live overlay).",
"is_bot": false,
"headline": "fix(storage,chaostest): repair fan-out count divergence + restore cha…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-19T19:03:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "880050daddff16b4c18bcc90433b73feedb513e2",
"body": "…BatchCompletion\n\nAdds one-transaction batched leaf-job completion (GormStorage.BatchComplete,\n3 dialects) behind a default-off opt-in WithBatchCompletion(maxBatch, maxDelay),\nre-exported as jobs.WithBatchCompletion. A worker accumulates successful leaf\ncompletions and group-commits them in a single\n[…]\nce on SQLite/Postgres/MySQL; mutation-tested for non-vacuity.\n\nContract: at-least-once — handlers must be idempotent under batched completion.\nDefault-off; promote to default-on only after field bake.",
"is_bot": false,
"headline": "feat(worker): group-committed leaf completion behind default-off With…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-19T16:39:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21a5546a637e4dfb3bb152f33b94405bc60ad1e3",
"body": "… batch (throughput #1+#2)\n\nThroughput levers #1+#2: single-statement dequeue claim (PG/SQLite) + larger default batch.\n\n- #2: replace the candidate-SELECT/per-candidate-paused-loop/UPDATE/re-fetch with one UPDATE...WHERE id IN (SELECT...FOR UPDATE SKIP LOCKED LIMIT n) RETURNING * per queue; claim i\n[…]\n-queue race under READ COMMITTED - no regression, identical residual to the old path; comment corrected). SKIP-LOCKED partitioning, index usage, budget exactness, #1 slot-bounding all verified intact.",
"is_bot": false,
"headline": "perf(storage,worker): single-statement dequeue claim + larger default…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-18T02:53:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c080b11965732263584ab0a9e340d306f508e79e",
"body": "… g7/g1)\n\nGodoc-only clarifications for the g7/g1 documented-footgun findings: Unique/IdempotencyKey are fleet-global (namespace per tenant for isolation), WithTenant is length-validated only and does not scope dedup, EnqueueBatch in-slice dedup precedes middleware. No code/behavior/API change. Closes the FEATURE-TEARDOWN-2026-06-16 backlog in full.",
"is_bot": false,
"headline": "docs(queue): document tenant-scoping + batch-dedup footguns (teardown…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-17T23:13:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27fb68541c263292c2284c2062b1f9ea7c2962d7",
"body": "…docs (teardown g8/g4/g11/g7 L4)\n\nCloses the final g8 finding + documents the g4/g11/g7 dialect/semantics findings (no exported API change):\n\n- schedule: Every(d<=0) now panics at construction (idiomatic, like time.NewTicker) instead of building a schedule whose Next busy-loops the scheduler; Next h\n[…]\nding ./tests/, golangci-lint 0, gofmt clean. gorelease no API change -> v3.9.2. Gate DBA/10x/CTO: design + all defer decisions verified sound; caught and fixed a missed tests/ caller of jobs.Every(0).",
"is_bot": false,
"headline": "fix(schedule,core,storage): scheduler robustness + dialect/semantics …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-17T22:58:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9188c8fd8fa04d26b678166a80dbec015c2b5a56",
"body": "… (teardown g9/g10 L3)\n\nCloses four g9/g10 LOW findings + documents one (no exported API change):\n\n- storage: GetWaitingJobsToResume + GetStalledFanOutParents select DISTINCT j.id (caller uses only job.ID); the signal-resume sibling stays on j.* (its caller reads job.RunAt).\n- storage: UpdateFanOutS\n[…]\ncancel-semantics change is tracked separately.\n\nVerified sqlite+PG+MySQL -race, golangci-lint 0, gofmt clean. gorelease: no exported API change -> v3.9.1. Gate DBA/10x/CTO unanimous A, GO, 0 blocking.",
"is_bot": false,
"headline": "fix(storage,worker,queue): recovery/fan-out efficiency + signal edges…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-17T20:51:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "65a9da9e526698fb7475a9bfc1f30d8a2673c6ee",
"body": "…g (teardown g2 L2)\n\nCloses three g2 LOW findings from FEATURE-TEARDOWN-2026-06-16:\n\n- jobctx: SavePhaseCheckpoint now write-backs to the in-memory call state (mirroring GetVersion) so a same-run LoadPhaseCheckpoint returns the value instead of (zero,false); SavePhaseCheckpointTx intentionally does \n[…]\ne untouched).\n\nVerified sqlite+PG+MySQL -race, golangci-lint 0, gofmt clean. gorelease additive -> v3.9.0. Gate DBA/10x/CTO unanimous A, CTO GO, 0 blocking; all 3 tests verified to fail when reverted.",
"is_bot": false,
"headline": "feat(jobctx,call,storage): typed/Call/checkpoint correctness hardenin…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-17T18:07:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "08f09d5fcb341e6c8bf6b2288d1ff426d829bcb0",
"body": "…(teardown g12 L1)\n\nCloses the three g12 LOW findings from FEATURE-TEARDOWN-2026-06-16, migration-free:\n\n- storage/codec: decodeErrorText corrupted plaintext containing \"sdjenc:<valid-base64>\" under the identity codec; new codecIsIdentity() helper gates the tag scan (argsSearchable reuses it).\n- ui/\n[…]\n regressions. Gate DBA/10x/CTO unanimous A, CTO GO, 0 blocking. CI green (PG flake in unrelated pkg/otel cleared on rerun). Tracked follow-up: registerBacklogOldestAgeGauge same silent-drop bug class.",
"is_bot": false,
"headline": "fix(storage,ui,metrics): codec/redaction/observability LOW hardening …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-17T14:49:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "082bcf113738344e55c73c6280add13f6c9fb38a",
"body": "…ive recovery/rate-limit/scheduler API (migration v33)\n\nRemediates the FEATURE-TEARDOWN-2026-06-16 adversarial review: closes every actionable HIGH (11/11) and every MEDIUM (~25/25) plus all 5 cross-cutting themes. Migration head v33.\n\nAdditive API (backward-compatible) introduced by the fixes:\n- pk\n[…]\nma-assertions + concurrent-safe PASS; sqlite full PASS; golangci-lint 0 issues; gorelease vs v3.7.0 all-compatible -> v3.8.0. CI: all 11 checks green. Per-commit coverage ledger in the PR description.",
"is_bot": false,
"headline": "feat: remediate FEATURE-TEARDOWN-2026-06-16 HIGH+MED findings + addit…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-17T13:39:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bf5d2c0863f1fe4e8889f26bb973f51a08e7cc5e",
"body": "…to-F2 v2 P1c) (#81)\n\nFinal Phase-1 packet: makes the per-key cooldown (P1b) observable so the keyed\nchurn behavior is diagnosable in production (the CTO-flagged prerequisite before\nkeyed coverage is 'done').\n\n- A pre-tx cooldown skip is now attributed to released{reason=fleet_rate_cached}\n (distin\n[…]\nd (live numbers\nfleet_rate=1, fleet_rate_cached=191, cacheSize=1); metrics tests assert the new\nlabel + gauge via ManualReader; full pkg/worker (incl -race x3 on the subset) +\npkg/metrics suites pass.",
"is_bot": false,
"headline": "feat(metrics): attribute keyed cooldown bounces + cache-size gauge (c…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T22:28:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3f6c6f89e792500eb748f95b8ca31680dac4a5b",
"body": "…for keyed configs (cto-F2 v2 P1b) (#80)\n\nv1 (#77) throttles only all-unkeyed configs; with a keyed RateLimit the throttle\nwas disabled and the keyed claim->bounce churn paid a full locked TryConsumeRate\ntransaction on every bounce (the saturation scaling bottleneck — every worker\ncontending the sam\n[…]\nLen<=1, over-cap key degrades to paying the DB tx).\nAll v1 unkeyed tests unchanged. Verified: go vet + golangci-lint 0 issues, gofmt\nclean; full pkg/worker passes incl. -race; gorelease + chaos below.",
"is_bot": false,
"headline": "perf(worker): per-key cooldown collapses the contended rate-limit tx …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T22:04:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d8b8869d388146e5052d613d52075ac19064cac8",
"body": "…(#79)\n\nExtends the cto-F2 soak harness to a KEYED fleet-limit scenario (the gap v1\nleaves: a keyed RateLimit disables the unkeyed throttle, so the claim->release\nchurn persists for keyed/mixed configs). Test-only; no production change.\n\n- soakStorage gains a per-effective-name keyDeny verdict + new\n[…]\nhecks=190) — full churn, confirming v1 is disabled for keyed configs.\n\nVerified: go vet + golangci-lint 0 issues, gofmt clean; full pkg/worker suite\npasses; keyed baseline recorded on live PG + MySQL.",
"is_bot": false,
"headline": "test(perf): keyed-saturation soak harness + baseline (cto-F2 v2 P1a) …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T21:35:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bfbd2b2b7b97273f0b13ff09e2dff75a81206606",
"body": "Makes the rate-limit saturation throttle (PR #77) visible in production, the\ndocumented Packet-3 fast-follow. The worker now counts, with atomic counters:\n- dispatch bounces by reason (queue_cap/queue_rate/concurrency/fleet_rate/\n shutdown) — jobs claimed then released back to pending without runni\n[…]\necorded (fleet_rate=one batch,\nsuppressedTicks rising) + keyed config records zero; OTel export asserted by\nTestInstrumentWorkerDequeue_RecordsChurnCounters; full pkg/worker + pkg/metrics\nsuites pass.",
"is_bot": false,
"headline": "feat(metrics): dequeue churn observability for the cto-F2 throttle (#78)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T13:47:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "61599f5fd1f1742afc0fed49b550ae1367c26131",
"body": "…it claim->release churn (cto-F2) (#77)\n\nWhen a fleet RateLimit is saturated but concurrency is free, the dispatch loop\npreviously CLAIMED jobs (status->running) every poll tick only to have the last\ngate (tryConsumeRateLimits) bounce them and RELEASE them back to pending — pure\nwrite amplification \n[…]\nmt clean; full pkg/worker suite\npasses (incl. -race; rate-limit/saturation subset x3 under -race); gorelease\ncompatible (v3.5.4, no API break); scripts/chaos-test.sh postgres ALL invariants\nHARD PASS.",
"is_bot": false,
"headline": "perf(worker): saturation-feedback dequeue throttle collapses rate-lim…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T10:27:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb7b37b798653001a88cad578957cccdd85cf8b5",
"body": "…ase churn (#76)\n\nAdds the durable harness that QUANTIFIES the cto-F2 write amplification (the\ndispatch loop claims jobs then bounces them back to pending while a fleet rate\nlimit is saturated but concurrency is free) so the upcoming fix is proven, not\nasserted. No production code change.\n\nTwo layer\n[…]\nle holding completed at the fleet ceiling.\n\nVerified: go vet + golangci-lint 0 issues, gofmt clean; deterministic harness\npasses under -race on sqlite; real-DB benchmark recorded on live PG and MySQL.",
"is_bot": false,
"headline": "test(perf): cto-F2 load/soak harness measuring rate-limit claim->rele…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T09:54:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6fa3ce9e2728831c4438d8f76e9c8a8146a5529",
"body": "…s through a Postgres-pinned helper (conv F1 / codex F-005) (#75)\n\nconv F1: seven worker tests shared one process-global\n'file::memory:?cache=shared' SQLite database, so they could read each other's\nrows. A new newInMemoryDB(t) helper gives each test a UNIQUELY-named\nshared-cache instance (pooled co\n[…]\ncuous' worker tests) is NOT addressed: the review\nsynthesis names no specific tests and a scan found no assertion-free test funcs,\nso fixing would be guessing -- deferred pending the detailed finding.",
"is_bot": false,
"headline": "test: isolate per-test SQLite DBs in worker tests; route PG-only test…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T05:33:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c360f9715c0dde200105dfc0845ccce5c7e79178",
"body": "…earer search placeholder (UI §2.1/UI-03) (#74)\n\nThe Jobs table always sent sort_key=created_at, overriding the server's\nper-view default so the dead-letter view showed created_at DESC instead of\ndead_lettered_at DESC (most-recently-dead first). Now a userSorted flag gates\nthe send: until the user c\n[…]\npayloads) -> 'Search by job ID or arguments…'.\n\nVerified: svelte-check 0 errors; vitest 25/25 (incl. new mock-client sort\ndefaults test); full Playwright e2e 150/150; go build ./ui/... re-embeds dist.",
"is_bot": false,
"headline": "fix(ui): dead-letter view keeps its dead_lettered_at default sort; cl…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T05:12:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c9fdd17b1c8457f83251c156ae615bf23ea5cd5",
"body": "…e bulk skips (F-002/SEC-3/F-003) (#73)\n\nerrToConnect funnels every dashboard handler's storage/queue errors:\n- An existing *connect.Error passes through unchanged, so codes set by inner\n helpers (CodeInvalidArgument for a bad UUID, CodeUnimplemented for non-UI\n storage) survive instead of collaps\n[…]\nted tests that codified the old behavior\n(RetryJob/DeleteJob fallback now assert Unimplemented; *_PartialFailure assert\nskipped entries) + added malformed-id, workflow-parent, and SEC-3 message tests.",
"is_bot": false,
"headline": "fix(ui): preserve RPC error codes, stop leaking raw DB errors, surfac…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T04:51:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e130787c2e9766a0b5b172ce904d681d5ba02c59",
"body": "…wed-dedup, write consumed_at on DB clock (ST-02/F2/ST-03) (#72)\n\n- ST-02: pauseJobAggressive (running->cancelled) and CancelSubJob (singular)\n now delete the job's ConcurrencySlot rows in the terminal tx, mirroring\n CancelSubJobs and terminal completion. A worker's deferred slot release never\n r\n[…]\n'd consumed signals early/late. On SQLite the\n value is normalized to UTC so it is lexically comparable with the UTC cutoff\n (SQLite compares timestamps as strings; a local-offset value mis-sorted).",
"is_bot": false,
"headline": "fix(storage): release concurrency slots on cancel, reject batch windo…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T04:33:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3de9d26c0c30c45b71e5418a981afb96c089592",
"body": "…te_subtree (F-001b) (#71)\n\nF-001 made DeleteJob refuse a workflow parent (ErrJobHasChildren → \"delete the\nworkflow subtree instead\") and added the storage-level DeleteWorkflowSubtree, but\nthat remediation was unreachable from the dashboard. Wire it through WITHOUT a new\nRPC (a new RPC adds a method\n[…]\nests green; frontend\nbuilds (dist rebuilt); buf regen drift-free; full playwright e2e 150/150;\ngorelease all-compatible (additive proto field + capability assertion, no exported\ninterface/RPC change).",
"is_bot": false,
"headline": "feat(ui): workflow-aware delete from the dashboard via DeleteJob dele…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T01:50:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b1726584248e73403147ab55ef0ed2acb38e3f5e",
"body": "UI-01 — the Jobs table presented full-dataset sort affordances on its column\nheaders but sorted only the current page in the browser, so triage like \"oldest\npending\" / \"highest priority\" was wrong across a multi-page result set. Make sort\nserver-side: ListJobsRequest gains sort_key/sort_dir; JobFilt\n[…]\n pkg/storage suite green on live PG + MySQL; frontend builds (embedded\ndist rebuilt); buf regen drift-free; playwright e2e green. proto fields additive\n(non-comparable) so api-compat stays compatible.",
"is_bot": false,
"headline": "feat(ui): server-side job sort + chart a11y legend (UI-01, UI-02) (#70)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T01:09:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f18e97106177cefc6962f7cd36ff112a6a4ca739",
"body": "…ing retention (F-004) (#69)\n\nFan-out creation is four non-atomic durable writes (CreateFanOut → SaveCheckpoint →\nMarkWaiting → EnqueueBatch). A crash after CreateFanOut but before EnqueueBatch leaves\na PENDING fan_outs row with ZERO sub-jobs; on replay the parent re-runs and creates a\nfresh fan-out\n[…]\nleanup live in the recovery loop. No\nmigration/schema change; core.Storage interface unchanged (concrete *GormStorage method\n+ optional worker capability interface, like GetCompletablePendingFanOuts).",
"is_bot": false,
"headline": "fix(storage): reconcile abandoned pending fan-outs so they stop block…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-16T00:15:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "988e2d7370559569bbb0d6aa14322b0c4ef8d0de",
"body": "…res (arch-10x/F3) (#68)\n\nThe cron scheduler built a FIXED allowlist of queue.Options when enqueueing a\nscheduled fire (queue/priority/retries/unique/delay/runAt/timeout/determinism) and\nsilently dropped every other configured field — so a schedule registered with a\ntenant, metadata tags, an explici\n[…]\nrgsOptionsAndUserUniqueKey\nstill passes.\n\nVerified: build/vet/golangci-lint/gofmt clean; pkg/worker -race full suite green;\ntests/ scheduler integration green. No migration/schema/exported-API change.",
"is_bot": false,
"headline": "fix(worker): scheduler forwards tenant/metadata/dedup to scheduled fi…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T23:52:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "82e86f5469d7357f565deb12e93ac7ca7094efcb",
"body": "…ST-01) (#67)\n\napplyJobSearch (used by both dashboard SearchJobs and dead-letter search) did a\nsubstring LIKE over a text-cast of the args column. Under an encrypting codec\n(secretbox), args holds non-UTF8 ciphertext, so the cast in argsTextExpression\nbreaks: convert_from(args,'UTF8') ERRORS on Post\n[…]\nunchanged\n(TestSearchJobs_EscapesLikeMetacharacters).\n\nVerified: build/vet/golangci-lint/gofmt clean; pkg/storage full suite green on\nsqlite + live PG + MySQL. No migration/schema/exported-API change.",
"is_bot": false,
"headline": "fix(storage): don't run free-text args search on encrypted payloads (…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T23:32:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d9451701de98afc6c516c1862513533b7856979f",
"body": "…er tick (cto-ship/F1 follow-up) (#66)\n\nPromoteReadyJobs ran one unbounded UPDATE over every eligible-but-unready pending\njob. Under a thundering-herd schedule (many jobs sharing a run_at that passes at the\nsame instant) every worker's promoter loop + every dequeue self-heal would rewrite the\nwhole \n[…]\ne self-heal tests still pass.\n\nVerified: build/vet/golangci-lint/gofmt clean; pkg/storage full suite green on sqlite +\nlive PG + MySQL; pkg/worker -race green. No migration/schema/exported-API change.",
"is_bot": false,
"headline": "perf(storage): bound the dq_ready promoter pass + jitter the per-work…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T23:18:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "59fa29d66038cc4c7baf40fbd7a0dc155667d1d4",
"body": "…ready-backlog filesort (cto-ship/F1) (#65)\n\nOn MySQL a large steady-state READY backlog filesorted ~50k rows on every dequeue\npoll: no index can both range-prune `dq_eligible_at <= now` AND provide the\n`priority DESC` order, and the optimizer even abandoned idx_jobs_dequeue_eligible for\nidx_jobs_re\n[…]\nsts/ integration suite green on sqlite; live\nEXPLAIN confirms no filesort; chaos PG all invariants HARD PASS. Gated 10x/DBA/CTO\nunanimous SHIP; DBA independently re-EXPLAINed the fix on live PG+MySQL.",
"is_bot": false,
"headline": "perf(storage): dq_ready dequeue hint + promoter eliminates the MySQL …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T15:59:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78d90acef517d074ade3b840144543d88e7135b1",
"body": "…t orphan fan-out children (F-001) (#64)\n\nDeleteJob/PurgeJobs were not workflow-aware. Deleting a fan-out parent removed only\nthe parent row + its checkpoints (+signals for delete), stranding every sub-job with\ndangling parent_job_id/root_job_id/fan_out_id — the FK cascade only covers\nfan_outs.paren\n[…]\n storage suite green on\nsqlite + live PG + MySQL. No migration/schema change; core.Storage interface\nunchanged (ErrJobHasChildren is additive; DeleteWorkflowSubtree is a concrete\n*GormStorage method).",
"is_bot": false,
"headline": "fix(storage): make dashboard delete/purge workflow-aware so they can'…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T13:59:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d7f072742b2f03cc2fde1ee150d7cc035ac0faa",
"body": "…ryable instead of a clear error (arch-10x/F1) (#63)\n\nExecuteCall built the arg Value with `argsVal := reflect.ValueOf(args)` then\nbranched on `argsVal.Type()`. When a Call passed nil for a handler whose ArgsType\nis non-nil, reflect.ValueOf(nil) is the zero Value and .Type() PANICS (\"reflect:\ncall o\n[…]\nnce). A shared-policy comment\non acceptsEmptyArgs guards the symmetry.\n\nVerified: build/vet/golangci-lint clean (0 issues); -race green on\nhandler+call+typed. No storage/migration/exported-API change.",
"is_bot": false,
"headline": "fix(handler): nested Call with nil typed args returned a panic-as-ret…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T13:33:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aa4593af2aea9592244c5bb1d15fec63c21faac4",
"body": "…eaper double-executed re-dequeued jobs (CD-01, exactly-once) (#62)\n\nThe stale-lock reaper anchors a running job's freshness on\nCOALESCE(last_heartbeat_at, started_at, locked_until) and reclaims it once that\nanchor is older than StaleLockAge. But the dequeue claim set started_at without\nclearing las\n[…]\nclean (0 issues); -race sqlite (storage+worker) +\nfull storage suite green on live PG + MySQL; chaos-test.sh postgres all 11\ninvariants HARD PASS incl INV-EXACTLY-ONCE; no migration/schema/API change.",
"is_bot": false,
"headline": "fix(storage): clear last_heartbeat_at on dequeue claim — stale-lock r…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T13:12:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f12ce230daa31b02e242f5c88b757bad1223b164",
"body": "…v31) + document the metadata-GIN/status-index decisions (N03/N06) (#61)\n\nSchema-review N08 (LOW, defense-in-depth): jobs.fan_out_index and\nfan_outs.completed_count/failed_count/cancelled_count were int DEFAULT 0 but NULLABLE,\nand the existing non-negative CHECK permits NULL (NULL >= 0 is unknown), \n[…]\ngreen on live PG + MySQL; the two\nCHECKs exist after Migrate and reject a NULL counter insert on both engines while 0/\npositive inserts succeed; migration idempotent. Migration head v31; ledger 1..31.",
"is_bot": false,
"headline": "fix(storage): forbid NULL fan-out counters via CHECK (N08, migration …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T06:01:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "934b99c1af72ef86d3b9856adedc23d542acabc8",
"body": "…irst index (N01) + real plan-test guard (N02), migration v30 (#60)\n\nSchema-review finding N01 (HIGH): on MySQL the dequeue index idx_jobs_dequeue_eligible\nwas (status, priority DESC, dq_eligible_at, queue). Because dq_eligible_at sits AFTER\npriority, MySQL walked the entire priority-ordered pending\n[…]\nrate (idempotent; 2nd Migrate no-op); v30 is a no-op\non PG and the PG plan test still passes. Index-reorder only — no claim/recovery/dequeue\nlogic change. Migration head v30; ledger expectation 1..30.",
"is_bot": false,
"headline": "perf(storage): fix MySQL dequeue future-backlog cliff — eligibility-f…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T04:19:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7eaf1a2574ec75b2477697f2ce6c85b327da2b9e",
"body": "The dashboard's nine status cards (Failed/Pending/Running/Completed/Retrying/\nWaiting/Paused/Cancelled/Active workers) were a flat, equally-weighted 3x3 grid —\na number dump. Group them by job lifecycle so the eye parses them, closing the\ndesign-visionary's non-blocking nit from the CODEX-08 review:\n[…]\nnly — no Go/proto/schema/version change.\n\nVerified: svelte-check 0 errors; pnpm test:unit green; deterministic pnpm build\n(rebuilt embedded dist, zero drift on a second build); go build clean (embed).",
"is_bot": false,
"headline": "feat(ui): group dashboard status cards by job lifecycle (#59)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T02:24:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eaa2317ae1bfc8fbb87ad305be16402c3de86047",
"body": "…xed-metadata-key lifecycle (DBA-07, CODEX-08 follow-up) (#58)\n\nTwo operator-facing caveats from the v3 review's deferred list — godoc + the\nconcurrency-caps guide. No code behavior change.\n\n- DBA-07: ConcurrencyCapConfig.Key must return values from a BOUNDED, enumerable\n set. Each distinct effecti\n[…]\nex per declared key and never drops them; removing a key later leaves\n the inert meta_<key> column + idx_jobs_meta_<key> index in place (drop manually if\n desired). Documented on the option's godoc.",
"is_bot": false,
"headline": "docs: document the concurrency-cap slot-name cardinality bound + inde…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T02:11:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6b84348a1a2e8a2aa10cb5757c9b9b41855bf48d",
"body": "…Go + dashboard) (CODEX-08) (#57)\n\nThe dashboard under-reported active/terminal work: the DB aggregation buckets every\njob status, but the proto/UI only carried pending/running/completed/failed/paused, so\nretrying (in-flight), waiting (fan-out/signals/durable-sleep park here), and cancelled\n(termina\n[…]\nats_IncludesRetryingWaitingCancelled per-queue +\nTestGetStats_TotalsAggregatedAcrossQueues) pass on sqlite + live PG + MySQL; pnpm build +\ntest:unit (22/22) green; e2e dashboard/queues specs extended.",
"is_bot": false,
"headline": "feat(ui): surface retrying/waiting/cancelled in queue stats (proto + …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T01:20:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7993f6480126e45c996f8f14a48df56b7408073b",
"body": "…gn queue_states.queue collation (DBA-05, migration v29) (#56)\n\nEvery dequeue poll did a separate GetPausedQueues read (SELECT FROM queue_states)\nthen filtered the queue list in Go (activeQueuesExcludingPaused) before the shared\ndequeue predicate. At high worker counts that doubles the idle query ra\n[…]\ne_states.\nqueue is utf8mb4_0900_as_cs after Migrate (idempotent); full storage + worker suites\ngreen on both backends; chaos on Postgres HARD PASS on all invariants under SIGKILL +\nconcurrent dequeue.",
"is_bot": false,
"headline": "fix(storage): fold paused-queue check into the dequeue predicate; ali…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-15T00:43:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f342f9095b02bb2524a24b6710108e63ecd0758b",
"body": "…erated columns for MySQL tag-filter acceleration (DBA-02) (#55)\n\nThe dashboard/DLQ metadata tag filter is arbitrary key=value JSON object containment.\nPostgres serves it from the idx_jobs_metadata_gin GIN index (all keys); MySQL's\nJSON_CONTAINS over the longtext metadata column cannot use any gener\n[…]\nn (gencol resolves NULL, no 3141), mixed filter correct, invalid\nkey fails Migrate; LIVE PG — query no-op (@>), no meta_*/idx_jobs_meta_* created;\nmetadata/search/UI regression green on both backends.",
"is_bot": false,
"headline": "feat(storage): operator-declared indexed metadata keys via STORED gen…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T23:12:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8711b6d2915cda73334b166c98e6c9a49e6d5ec6",
"body": "…before AutoMigrate enforces NOT NULL (v3 boot failure) (#54)\n\nA pre-v3 baseline can hold rows with NULL jobs.timeout and NULL jobs.determinism.\nBoth columns shipped originally WITHOUT a gorm tag (a genuinely nullable era) and\nwere tightened to `not null;default:0` in the same commit, so the same le\n[…]\ns and both are NOT NULL\nagain. Both would fail without the heal (PG 23502 / MySQL 1265). Verified:\nbuild/vet/golangci-lint clean (0 issues); full storage suite green on live PG +\nMySQL + sqlite -race.",
"is_bot": false,
"headline": "fix(storage): backfill legacy NULL jobs.timeout AND jobs.determinism …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T21:21:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "de56c109521a86dd960bf89c774e7b6ec76bc232",
"body": "…nversion convergence test, ScheduledFire field docs (DBA-08/DBA-03/DBA-04) (#53)\n\nThree non-breaking v3.2 storage-hardening items. No migration, no schema change,\nno migration-version bump (head stays v28), no behavior change.\n\nDBA-08 — single source of truth for the terminal-status set:\nadd core.T\n[…]\nnvergence test passes on live MySQL (both\nsubtests, ~26s); retention/orphan/workflow/deadletter/terminal green on live PG +\nMySQL (no regression). Gate: 10x/DBA/CTO unanimous SHIP (A/A/A, 0 blocking).",
"is_bot": false,
"headline": "test(storage): terminal-status source-of-truth + drift test, MySQL co…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T20:34:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6b04a38dab531cdf7a4f640e4d5598eace2c75a3",
"body": "…cument it (CODEX-01) (#52)\n\nThe 2026-06-14 review flagged the worker dispatch accounting as fragility (the\nbound lives in three structures — runningJobs, queueRunning, and the buffered\njobsChan — so a future change could silently break it), not a reproduced bug.\nAnalysis confirmed it is bounded-cor\n[…]\nssues); -race ./pkg/worker -count=3\ngreen (new + sibling test, non-flaky — all bounds are <=); worker.go diff is\ncomment-only; pkg/core untouched. Gate: 10x/DBA/CTO unanimous SHIP (A/A/A, 0 blocking).",
"is_bot": false,
"headline": "test(worker): lock the multi-queue dispatch-accounting invariant + do…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T19:31:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c0e3fda4cc282b3049d6a70b9fe7a97aa2cd88e",
"body": "…e validation, nil schedule, secretbox zero key (CODEX-03/04/05/07) (#51)\n\nFour small, independent API-hardening fixes from the 2026-06-14 review. All\nadditive (new error returns on already-error-returning paths); no exported\nsignature, core.Storage, or schema change.\n\n- CODEX-03 (typed.DefineE): wa\n[…]\n Gate:\n10x/DBA/CTO unanimous SHIP (A/A/A, 0 blocking).\n\nNote: CODEX-07 turns a previously-accepted all-zero Secretbox key into a construction\nerror (correct — a zero key is never a legitimate secret).",
"is_bot": false,
"headline": "fix: v3.1 API-hardening guards — typed register-rollback, enqueue nam…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T19:03:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9f5f042f6bb6feece3ac666e919952710432c6f2",
"body": "…rkflow ref (DBA-01, CODEX-06) (#50)\n\ncore.UUID.Scan rejects invalid non-empty text (CODEX-06). Migration v28 adds CHECK constraints forbidding the zero-UUID on jobs.parent_job_id/root_job_id/fan_out_id (NULL + valid uuids allowed), with a pre-clean that heals a v3.0.x Value(\"\") orphan — closing DBA\n[…]\n's silent-orphan vector cross-dialect. Self-FKs were infeasible on MySQL (Error 1215 vs the generated columns); CHECK chosen. Additive (core.Storage/job.go unchanged). Gate 10x/DBA/CTO unanimous SHIP.",
"is_bot": false,
"headline": "fix(core,storage): reject invalid UUID text + forbid the zero-UUID wo…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T17:47:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02f3e180ac4632d0a7bac4693312e1ad59406059",
"body": "…V1c) (#49)\n\nFixes a prod-down blocker upgrading a real v1.x baseline (no signals table, no child FKs) to v3: the pre-AutoMigrate UUID->binary conversion crashlooped (PG 42P01 / MySQL 1146) and orphan child rows aborted FK re-add (23503/1452). Every child-table-touching conversion step (PG drop/add \n[…]\n composite-index recreate, FK re-add) is now HasTable-guarded with an in-tx orphan-prune. Verified live on PG+MySQL; committed PG regression test in an isolated schema. Gate 10x/DBA/CTO SHIP (A/A/A-).",
"is_bot": false,
"headline": "fix(storage): v3 UUID conversion survives legacy (pre-v3) baselines (…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T16:58:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b7d2c121a37620aedfff0469083f24523291019",
"body": "…) (#48)\n\nCloses the graceful-pause TOCTOU race that could silently cancel a running job. Additive fix (core.Storage unchanged): new concrete (*GormStorage).PauseJobWithMode — graceful pauses only pending/waiting via an atomic conditional UPDATE with no cancel branch (running → ErrCannotPauseStatus); aggressive unchanged. Queue threads mode via an optional-capability assertion. Race structurally closed; proven on live PG+MySQL. Gate 10x/DBA/CTO unanimous SHIP.",
"is_bot": false,
"headline": "fix(storage): graceful PauseJob never cancels a running job (CODEX-02…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T14:48:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02581c17dbf49ec3c8d3763db1ff0dbe28ed4687",
"body": "… (closes DBA-03) (#47)\n\nAdds a schema_pre_migrations ledger giving pre-AutoMigrate one-shot migrations (the UUID conversion) a START-fence + DONE-marker run-once contract: crash-resumable, can't double-execute, in-progress distinguishable from never-started. Wrap-not-gut (conversion body unchanged). Migration head stays v27. Gate 10x/DBA/CTO unanimous SHIP.",
"is_bot": false,
"headline": "feat(storage): run-once fence for pre-AutoMigrate one-shot migrations…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T14:19:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b530a187a1344449d7e6ab677b9609130304799a",
"body": "… flap, typed.Signal dedup (#46)\n\nNon-breaking v3 follow-ups (migration v27):\n- checkpoints.call_index bigint->integer (R52 follow-up); in-place narrowing\n preserves the composite UNIQUE idx_checkpoints_job_call on both engines.\n- fan_outs.threshold gorm tag default 1.0->1 stops the per-Migrate\n \"\n[…]\nQueue).\n\nVerified on live Postgres + MySQL (fresh + simulated-v3.0.0 narrowing with the\nunique index intact, the flap gone via general_log) and chaos on both engines;\ngated 10x/DBA/CTO unanimous SHIP.",
"is_bot": false,
"headline": "fix(storage): v3 follow-ups — call_index width, threshold AutoMigrate…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T04:41:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d34a71ce1696acd17d0e66a2fad18b7467e0634",
"body": "… (#45)\n\nv3 breaking major: /v3 module path, binary/uuid primary keys (R29) with an in-place\nvarchar(36)->binary conversion, integer right-sizing (R52, migration v26), and Go API\ncoherence (R36/R37/R38). Every wave gated 10x/DBA/CTO unanimous; verified on live\nPostgres + MySQL incl. a populated-v2 c\n[…]\nto typed.DeclareUnchecked; typed.Define/DefineE now\nvalidate the result type R; Queue.Schedule now returns error and rejects unregistered/\nduplicate names; Queue.EnqueueRemote rejects malformed names.",
"is_bot": false,
"headline": "feat!: v3.0.0 — binary/uuid PK, int right-sizing, coherent *Queue API…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-14T04:09:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "279b4d559a20ad41096a837c7957aadda0fa123f",
"body": "…O index + schema v25 (#44)\n\nAddresses the codex code review, live-DB DBA schema review, and counsel docs review run against v2.7.0. Non-breaking to the Go API (additive only); migration head v24 -> v25.\n\n- Reaper false-reclaim race fixed (FOR UPDATE SKIP LOCKED + staleness re-check); terminal-write\n[…]\nQL and fixing a latent silently-merged-queue bug. MySQL-only deployments relying on case-insensitive queue/tenant names should normalize them before upgrading; see docs/content/docs/production-ops.md.",
"is_bot": false,
"headline": "fix: post-merge hardening — recovery/signal/storage races, signal FIF…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-13T21:01:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "66372f3b95acfa98de2e4f1a623c1ddce85d78f7",
"body": "Non-breaking hardening campaign: security C-→A, scale/indexing/schema/code-quality/API/concurrency/testing C+/B-→A-, durability A- held. 17 gated packets (each verified across sqlite/PG/MySQL + chaos on hot paths). Additive API only: ErrJobArgsMismatch, GormStorage.WithSerializationRetry, core.AllJo\n[…]\negies/AllFanOutStatuses, compile-time capability guards + startup self-check. A new chaos invariant caught and fixed a real crash-window concurrency-slot leak (in-tx slot release). Migration head v24.",
"is_bot": false,
"headline": "feat: whole-repo hardening — drive all 9 review dimensions to ≥A- (#43)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-13T17:32:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ebda065418bdd2b93ac2aeb3bd5715aadac6b50",
"body": "…on/UTC/fan-out/UUIDv7 (v11–v18) + closure fixes (#42)\n\n* fix(storage): make versioned migrations source of truth — partial dead-letter index + datetime(6) + DDL-assertion CI guard (S02)\n\n* fix(storage): drop dead/redundant jobs indexes (idx_jobs_priority/queue/locked_until/dequeue; unique_key PG-on\n[…]\n + migrations.go (index defs, v14 FK + TRUNCATE\nerror, v15 collation, CONCURRENTLY absence); hugo builds clean; no remaining stale\nschema refs. Gate: DBA A / 10x A / CTO A, unanimous SHIP, 0 blocking.",
"is_bot": false,
"headline": "fix(storage): schema-teardown hardening — dequeue/indexes/FKs/collati…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-12T12:27:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1ce28e4ea529fcff6a3496f07f23bc2b2729cabf",
"body": "Adds a 30-day window to the throughput selector (1h/24h/7d/30d): parsePeriod + 12h periodBucket, frontend Period/selector/AreaChart, default stats retention 7d->31d so the data survives, and an interval-proportional 31-day demo seed. Verified live across all four ranges; service test + dashboard e2e cover 30d.",
"is_bot": false,
"headline": "feat(ui): add 30d throughput range (#41)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-10T14:36:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8fa12304acaeb70dbc351bbfbff55c8bc5d10186",
"body": "Server-side bucketing in GetStatsHistory (1h->1m, 24h->30m, 7d->3h, window-spanning + bounded) so the chart actually changes per range; demo seed extended to 7 days with a diurnal wave. Adds a service test + dashboard e2e. Two CI flakes (docker registry timeout; pre-existing TestWorker_PauseJobAggressivePreservesCancelledStatus) cleared on re-run.",
"is_bot": false,
"headline": "fix(ui): throughput chart now reflects the 1h/24h/7d window (#40)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-10T13:14:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28621632486084f91f90a49362a9ad0f2f9696dc",
"body": "Lift the Workflow Timeline from the cramped ~300px sidebar to a full-width section; single title, untruncated single-line job rows, responsive gutter, ongoing-marker on running bars so long jobs no longer swamp the plot. design+10x+CTO consensus A; 146 e2e pass.",
"is_bot": false,
"headline": "feat(ui): full-width Workflow Timeline on JobDetail (#39)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-10T05:14:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0cbc54ec53c6251dc7fd8e37d0782365216aebe",
"body": "Additive windowed enqueue dedup: IdempotencyKey(key,ttl) + UniqueFor(ttl), new unique_locks table (migration v10), canonical-plaintext hash pre-codec, atomic dialect-split upsert, DB-clock windows, separate self-bounding sweep. Active-unique path + fan-out replay guard untouched. Gated A-/A/A; 3-backend + chaos PG+MySQL green.",
"is_bot": false,
"headline": "feat: v2.4.0 — idempotency-key / unique-by-period enqueue dedup (#19)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-10T03:33:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53e44412c5748d963152921992cb801bd9a47697",
"body": "Final-signoff polish nit: corrected three stale worker.md deep-link fragments in rate-limiting.md to the authoritative Hugo heading IDs.",
"is_bot": false,
"headline": "docs: fix stale rate-limit cross-link anchors (#37)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-10T01:28:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "456ed24d1a464c7e990209940206b607bf03b2f0",
"body": "…e + filtering, ops docs (#36)\n\nAdditive operator surface: proto Job.tenant=22/metadata=23 + ListJobsRequest filters, dashboard tenant filter + metadata display, DLQ requeue affordance (honest checkpoint-preserving dialog) + DeadLetterFilter tenant/meta/search with correct totals, sdj dlq --tenant/--metadata + bulk requeue, ops-docs cleanup. No migration. Gated A-/A/A; 3-backend + chaos PG+MySQL + e2e green.",
"is_bot": false,
"headline": "feat: v2.3.0 — surface tenant/metadata in dashboard + CLI, DLQ requeu…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-10T00:59:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "524cfee30ee8363c5fed7ad99daaacc6e2e2c499",
"body": "…), deprecation annotations, docs truth pass (#35)\n\nAdditive. Completes the typed API headline with package-level generic FanOut/Signal/WaitForSignal/WaitForSignalTimeout/SubJobOf wrappers (pkg/typed/workflow.go, no root import), comment-only deprecation markers (Clamp*/Sanitize*/Validate*/NopCodec/Timezone → v3 removal), and a docs truth pass. Gated design+10x+CTO unanimous (A-/A/A); 3-backend matrix + chaos smoke green.",
"is_bot": false,
"headline": "feat: v2.2.0 — typed workflow primitives (FanOut/Signal/WaitForSignal…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T22:15:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45e5f36c21238821fa0f94ca9fa2429a86515867",
"body": "…igration guide + tenant/metadata (#34)\n\nDocs+README only. Fixes the 28 bare-root /v2 import paths the v2.0.0 cut broke, surfaces the typed API (new api-reference/typed-api.md), MIGRATION-v2 guide, and tenant/metadata docs. Gated design-visionary+10x+CTO unanimous (A-/A/A).",
"is_bot": false,
"headline": "feat: v2.1.0 — docs-true: fix /v2 import paths, surface typed API + m…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T18:48:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18114f1c3d95525ff840396be7f3366d6990f4ca",
"body": "…aliases (#33)\n\nDeliberate break-only major: /v2 module path, core.Storage.SuspendJob->MarkWaiting (and SuspendJobWithDeadline->MarkWaitingWithDeadline), removal of the deprecated IsSuspendError/SuspendError aliases. No features, no schema change. See MIGRATION-v2.md.\n\nBREAKING CHANGE: module import\n[…]\njdziat/simple-durable-jobs/v2; core.Storage.SuspendJob/SuspendJobWithDeadline renamed to MarkWaiting/MarkWaitingWithDeadline; IsSuspendError and SuspendError removed (use IsWaitingError/WaitingError).",
"is_bot": false,
"headline": "feat!: v2.0.0 — /v2 module path, MarkWaiting rename, drop deprecated …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T13:01:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7ce2ef4d298be1ab1a760852b552e004d53f14f9",
"body": "…bridge, #20)\n\nfeat(core): add job metadata/tags + tenant foundation (multi-tenancy bridge, #20)",
"is_bot": false,
"headline": "feat(core): add job metadata/tags + tenant foundation (multi-tenancy …",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T11:52:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fbfadda9500e29778e631d81206a75b5feab014a",
"body": null,
"is_bot": false,
"headline": "feat(core): add job metadata/tags + tenant foundation",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T06:02:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e12e9678162cd1758991766a916622793e4030a",
"body": null,
"is_bot": false,
"headline": "feat(typed): add typed Define[Args,Result] front door (#31)",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T04:46:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d905e1b33afa0be97bd2ed30a0dae1c8f1b5b276",
"body": "…s, sdj CLI, health probes, depth metrics (#5,#7,#9,#16,#22,#23,#43)\n\nfeat: v1.9.0 OPENLINE — work-conserving dispatcher, per-queue fairness, sdj CLI, health probes, depth metrics (#5,#7,#9,#16,#22,#23,#43)",
"is_bot": false,
"headline": "feat: v1.9.0 OPENLINE — work-conserving dispatcher, per-queue fairnes…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T01:55:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b89fe8a39abd8f63de226a0bc6ceda0258cd0729",
"body": "CI golangci-lint (v2.8.0, no .golangci.yml so v2 defaults) flagged unchecked\nfmt.Fprint* returns in cmd/sdj, rows/resp Close() in tests, and QF1008\nDialector embedded-field selectors. go vet (the per-packet gate) does not\ncover these. No behavior change.",
"is_bot": false,
"headline": "style: satisfy golangci-lint errcheck/staticcheck on OPENLINE additions",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T01:41:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fbc443e2bd4f509c30dc16529aae1a57a86367a",
"body": null,
"is_bot": false,
"headline": "docs(ops): production operations guide + docs refresh [OPENLINE P8]",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T01:23:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73caf6213b6c80cbebec073a0fda662b1d150b3a",
"body": null,
"is_bot": false,
"headline": "feat(cli): add sdj command-line interface [OPENLINE P7]",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T01:08:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a08d95be8fe82854f83059c869e6fd5d3d93fb65",
"body": null,
"is_bot": false,
"headline": "chore: gitignore the sdj CLI binary [OPENLINE]",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T00:55:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d547abc9c21c133ae58abae1b355432d4974fa55",
"body": "… [OPENLINE P6]",
"is_bot": false,
"headline": "feat(worker): add liveness/readiness probes and local health snapshot…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T00:18:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c81814c1420568d435494e45f9eae0ed24c3a4a",
"body": "…NE P5]",
"is_bot": false,
"headline": "feat(worker): per-queue fair-share batch dequeue with budgets [OPENLI…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-09T00:04:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f724bc9b5ab3fe2ba843f1ced5540e23ebbefe4",
"body": "…ll interval [OPENLINE P4]",
"is_bot": false,
"headline": "feat(worker): work-conserving dispatcher drains available work per po…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-08T23:43:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "faa84caf0e4f99980aa4204ff2f9bc42c90272a9",
"body": "… checks [OPENLINE P3]",
"is_bot": false,
"headline": "feat(storage): add Healther Ping capability for database connectivity…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-08T22:51:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0a3755bbd2172f160242f7658d0a03b2a14071ce",
"body": null,
"is_bot": false,
"headline": "feat(metrics): add storage-backed job count metrics [OPENLINE P2]",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-08T22:41:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe3d7061376046d6f02486c8888f6419b86942f1",
"body": "… scans [OPENLINE P1]",
"is_bot": false,
"headline": "perf(storage): add order-first dequeue index for multi-queue priority…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-08T22:31:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4db972bce3a0e063cc712257bab1928922b0eb16",
"body": "…e CI (#28)\n\nFixes the non-reproducible-CI / supply-chain finding (#30) that cost the v1.8.0\nrelease a Lint rerun (transient sum.golang.org Go-toolchain download).\n\n- setup-go pinned to go-version: '1.25.11' (matches go.mod's toolchain directive)\n so the patched toolchain installs directly from set\n[…]\nn every GitHub Action (# vX.Y.Z); pin govulncheck v1.3.0, gocovmerge and\n benchstat pseudo-versions, hugo 0.162.1.\n- Add .github/dependabot.yml (github-actions, weekly, grouped) to keep pins current.",
"is_bot": false,
"headline": "ci: SHA-pin Actions, pin Go 1.25.11 and tool versions for reproducibl…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-08T21:42:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c181cc3a51f5f1c1f763075127e13a89e154efc",
"body": "… gate, bounded growth (#1–#48) (#27)\n\n* fix(signal): consume signals and persist replay checkpoints atomically [DEADBOLT P1]\n\nReplace the ConsumeSignal/DrainSignals + separate writeCheckpoint pair with\nConsumeSignalTx/DrainSignalsTx, which take the pending signal(s) and persist the\nreplay checkpoin\n[…]\nct last-contact reclaim model (replaces stale lock-expiry framing)\n- P9: document default pool behavior\n- P11: document error encryption\n- P12: document error sentinels\n- P2: document fan-out recovery",
"is_bot": false,
"headline": "feat: v1.8.0 DEADBOLT — durability-seam fixes, release-blocking chaos…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-08T13:05:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f1f8e264e176d416d935db6353e7419fd6b1dcb3",
"body": "…uled/queue/worker data, signals events & GC, chaos invariant fix) (#26)\n\n* feat: transactional phase checkpoints — jobs.SavePhaseCheckpointTx\n\nCloses the documented at-least-once window for phase checkpoints: a new\noptional storage.TxCheckpointer capability (mirroring TxEnqueuer; core\nStorage byte-\n[…]\nthe window\npipeline's intentional terminal-failure outcome documented.\n\nHolistic wave gate: 10x-reviewer A + CTO A + design-visionary A-\n(sole blocker: the events-test omission — fixed as prescribed).",
"is_bot": false,
"headline": "feat: transactional phase checkpoints + the polish wave (honest sched…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-07T19:47:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fbaca484d51a88b52fa1d3afcaf008e8abd5bb35",
"body": "…sign system, every view rebuilt, -39% bundle) (#25)\n\n* feat(ui): BLACKBOX foundation — design tokens, dark-hero theming, instrument chrome\n\nIncrement 1 of the gated dashboard revamp (direction: BLACKBOX, the\noperator's instrument). Adds the token system in src/app.css (dark hero +\nlight peer palett\n[…]\nkActiveWorkersStorage embeds the existing mockStorage\nper the package's capability-mock convention; test-only diff.\n\nGate: 10x-reviewer A + CTO A unanimous (1 iteration); ui package green\nunder -race.",
"is_bot": false,
"headline": "feat(ui): BLACKBOX — next-generation embedded dashboard (dark-hero de…",
"author_name": "Jordan Dziat",
"author_login": "jdziat",
"committed_at": "2026-06-07T14:14:19Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 77,
"commits_last_year": 210,
"latest_release_at": "2026-07-26T05:57:05Z",
"latest_release_tag": "v4.7.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 15,
"days_since_latest_release": 2,
"mean_days_between_releases": 1.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/jdziat/simple-durable-jobs/v4",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/jdziat/simple-durable-jobs/v4",
"is_deprecated": false,
"latest_version": "v4.7.0",
"repository_url": "https://github.com/jdziat/simple-durable-jobs",
"versions_count": 16,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-26T05:44:10Z",
"latest_version_yanked": null,
"days_since_latest_publish": 2
}
]
},
"popularity": {
"forks": 0,
"stars": 3,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 3
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [
"ui/proto/jobs/v1/jobs.proto"
],
"has_devcontainer": false,
"typecheck_configs": [
"ui/frontend/tsconfig.json"
],
"toolchain_manifests": [
"docs/go.mod",
"go.mod"
],
"largest_source_bytes": 194138,
"source_files_sampled": 338,
"oversized_source_files": 8,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 5424
},
"dependencies": {
"manifests": [
"docs/go.mod",
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/crypto",
"direct": true,
"version": "v0.50.0",
"severity": "critical",
"ecosystem": "go",
"cvss_score": 10,
"advisory_ids": [
"GHSA-45gg-vh54-h5m9",
"GHSA-5cgq-3rg8-m6cv",
"GHSA-78mq-xcr3-xm33",
"GHSA-89gr-r52h-f8rx",
"GHSA-9m57-25v3-79x9",
"GHSA-f5wc-c3c7-36mc",
"GHSA-jppx-rxg9-jmrx",
"GHSA-q4h4-gmj2-qvw2",
"GHSA-qpw4-5x99-6vjp",
"GHSA-rm3j-f69w-wqmq"
],
"fixed_version": "0.52.0",
"advisory_count": 27,
"oldest_advisory_days": 67
},
{
"name": "rollup",
"direct": false,
"version": "4.57.1",
"severity": "critical",
"ecosystem": "npm",
"cvss_score": 9.1,
"advisory_ids": [
"GHSA-mw96-cpmx-2vgc"
],
"fixed_version": "4.59.0",
"advisory_count": 1,
"oldest_advisory_days": 152
},
{
"name": "vitest",
"direct": false,
"version": "2.1.9",
"severity": "critical",
"ecosystem": "npm",
"cvss_score": 9.8,
"advisory_ids": [
"GHSA-5xrq-8626-4rwp"
],
"fixed_version": "4.1.0",
"advisory_count": 1,
"oldest_advisory_days": 56
},
{
"name": "go.opentelemetry.io/otel/sdk",
"direct": true,
"version": "v1.40.0",
"severity": "high",
"ecosystem": "go",
"cvss_score": 7,
"advisory_ids": [
"GHSA-hfvc-g4fc-pqhx",
"GO-2026-5426"
],
"fixed_version": "1.43.0",
"advisory_count": 2,
"oldest_advisory_days": 110
},
{
"name": "postcss",
"direct": false,
"version": "8.5.15",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-r28c-9q8g-f849"
],
"fixed_version": "8.5.18",
"advisory_count": 1,
"oldest_advisory_days": 3
},
{
"name": "postcss",
"direct": false,
"version": "8.5.6",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-6g55-p6wh-862q",
"GHSA-qx2v-qp2m-jg93",
"GHSA-r28c-9q8g-f849"
],
"fixed_version": "8.5.18",
"advisory_count": 3,
"oldest_advisory_days": 94
},
{
"name": "vite",
"direct": false,
"version": "5.4.21",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-4w7w-66w2-5vf9",
"GHSA-fx2h-pf6j-xcff",
"GHSA-v6wh-96g9-6wx3"
],
"fixed_version": "8.0.16",
"advisory_count": 3,
"oldest_advisory_days": 112
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.53.0",
"severity": "moderate",
"ecosystem": "go",
"cvss_score": 6.5,
"advisory_ids": [
"GHSA-5cv4-jp36-h3mw",
"GO-2026-5025",
"GO-2026-5026",
"GO-2026-5027",
"GO-2026-5028",
"GO-2026-5029",
"GO-2026-5030",
"GO-2026-5942"
],
"fixed_version": "0.56.0",
"advisory_count": 8,
"oldest_advisory_days": 67
},
{
"name": "devalue",
"direct": false,
"version": "5.6.2",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.3,
"advisory_ids": [
"GHSA-33hq-fvwr-56pm",
"GHSA-8qm3-746x-r74r",
"GHSA-cfw5-2vxh-hr84",
"GHSA-mwv9-gp5h-frr4"
],
"fixed_version": "5.6.4",
"advisory_count": 4,
"oldest_advisory_days": 158
},
{
"name": "esbuild",
"direct": false,
"version": "0.21.5",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.3,
"advisory_ids": [
"GHSA-67mh-4wv8-2f99"
],
"fixed_version": "0.25.0",
"advisory_count": 1,
"oldest_advisory_days": 532
},
{
"name": "svelte",
"direct": false,
"version": "5.51.3",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 4.2,
"advisory_ids": [
"GHSA-crpf-4hrx-3jrp",
"GHSA-f3cj-j4f6-wq85",
"GHSA-f7gr-6p89-r883",
"GHSA-h7h7-mm68-gmrc",
"GHSA-m56q-vw4c-c2cp",
"GHSA-phwv-c562-gvmh",
"GHSA-pr6f-5x2q-rwfp",
"GHSA-rcqx-6q8c-2c42"
],
"fixed_version": "5.55.7",
"advisory_count": 8,
"oldest_advisory_days": 158
},
{
"name": "filippo.io/edwards25519",
"direct": false,
"version": "v1.1.0",
"severity": "low",
"ecosystem": "go",
"cvss_score": 3.7,
"advisory_ids": [
"GHSA-fw7p-63qq-7hpr",
"GO-2026-4503"
],
"fixed_version": "1.1.1",
"advisory_count": 2,
"oldest_advisory_days": 160
},
{
"name": "go.opentelemetry.io/otel",
"direct": true,
"version": "v1.41.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5158"
],
"fixed_version": "1.44.0",
"advisory_count": 1,
"oldest_advisory_days": 3
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.43.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5024"
],
"fixed_version": "0.44.0",
"advisory_count": 1,
"oldest_advisory_days": 66
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"low": 1,
"high": 4,
"unknown": 2,
"critical": 3,
"moderate": 4
},
"advisory_count": 63,
"affected_count": 14,
"assessed_count": 219,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 4
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "connectrpc.com/connect",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.19.1"
},
{
"name": "github.com/go-sql-driver/mysql",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.1"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.23.2"
},
{
"name": "github.com/robfig/cron/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.41.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/prometheus",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.61.0"
},
{
"name": "go.opentelemetry.io/otel/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.41.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.40.0"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.40.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.41.0"
},
{
"name": "golang.org/x/crypto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.50.0"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.53.0"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "gorm.io/driver/mysql",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "gorm.io/driver/postgres",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "gorm.io/driver/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "gorm.io/gorm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.31.1"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "connectrpc.com/connect",
"direct": true,
"version": "v1.19.1",
"ecosystem": "go"
},
{
"name": "github.com/go-sql-driver/mysql",
"direct": true,
"version": "v1.8.1",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": true,
"version": "v1.23.2",
"ecosystem": "go"
},
{
"name": "github.com/robfig/cron/v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel",
"direct": true,
"version": "v1.41.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/prometheus",
"direct": true,
"version": "v0.61.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/metric",
"direct": true,
"version": "v1.41.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"direct": true,
"version": "v1.40.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"direct": true,
"version": "v1.40.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/trace",
"direct": true,
"version": "v1.41.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": true,
"version": "v0.50.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.53.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": true,
"version": "v1.36.11",
"ecosystem": "go"
},
{
"name": "gorm.io/driver/mysql",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "gorm.io/driver/postgres",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "gorm.io/driver/sqlite",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "gorm.io/gorm",
"direct": true,
"version": "v1.31.1",
"ecosystem": "go"
},
{
"name": "filippo.io/edwards25519",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/logr",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/stdr",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/imfing/hextra",
"direct": false,
"version": "v0.12.3",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgpassfile",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgservicefile",
"direct": false,
"version": "v0.0.0-20240606120523-5a60cdf6a761",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgx/v5",
"direct": false,
"version": "v5.10.0",
"ecosystem": "go"
},
{
"name": "github.com/jackc/puddle/v2",
"direct": false,
"version": "v2.2.2",
"ecosystem": "go"
},
{
"name": "github.com/jinzhu/inflection",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/jinzhu/now",
"direct": false,
"version": "v1.1.5",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-sqlite3",
"direct": false,
"version": "v1.14.22",
"ecosystem": "go"
},
{
"name": "github.com/munnerz/goautoneg",
"direct": false,
"version": "v0.0.0-20191010083416-a7dc8b61c822",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "v0.67.5",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/otlptranslator",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.20.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/auto/sdk",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v2",
"direct": false,
"version": "v2.4.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.43.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.39.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": false,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "@bufbuild/protobuf",
"direct": false,
"version": "1.10.1",
"ecosystem": "npm"
},
{
"name": "@connectrpc/connect",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "@connectrpc/connect-web",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/gen-mapping",
"direct": false,
"version": "0.3.13",
"ecosystem": "npm"
},
{
"name": "@jridgewell/remapping",
"direct": false,
"version": "2.3.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.5.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.31",
"ecosystem": "npm"
},
{
"name": "@playwright/test",
"direct": false,
"version": "1.58.2",
"ecosystem": "npm"
},
{
"name": "@playwright/test",
"direct": false,
"version": "1.60.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-android-arm-eabi",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-android-arm-eabi",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-android-arm64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-android-arm64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-darwin-arm64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-darwin-arm64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-darwin-x64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-darwin-x64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-freebsd-arm64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-freebsd-arm64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-freebsd-x64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-freebsd-x64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm-gnueabihf",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm-gnueabihf",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm-musleabihf",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm-musleabihf",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm64-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm64-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm64-musl",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm64-musl",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-loong64-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-loong64-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-loong64-musl",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-loong64-musl",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-ppc64-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-ppc64-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-ppc64-musl",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-ppc64-musl",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-riscv64-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-riscv64-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-riscv64-musl",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-riscv64-musl",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-s390x-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-s390x-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-x64-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-x64-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-x64-musl",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-x64-musl",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-openbsd-x64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-openbsd-x64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-openharmony-arm64",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-openharmony-arm64",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-arm64-msvc",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-arm64-msvc",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-ia32-msvc",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-ia32-msvc",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-x64-gnu",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-x64-gnu",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-x64-msvc",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-x64-msvc",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "@sveltejs/acorn-typescript",
"direct": false,
"version": "1.0.10",
"ecosystem": "npm"
},
{
"name": "@sveltejs/acorn-typescript",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@sveltejs/load-config",
"direct": false,
"version": "0.1.1",
"ecosystem": "npm"
},
{
"name": "@sveltejs/vite-plugin-svelte",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "@sveltejs/vite-plugin-svelte-inspector",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "@tsconfig/svelte",
"direct": false,
"version": "5.0.8",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "25.3.5",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "25.9.2",
"ecosystem": "npm"
},
{
"name": "@types/trusted-types",
"direct": false,
"version": "2.0.7",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.15.0",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.16.0",
"ecosystem": "npm"
},
{
"name": "aria-query",
"direct": false,
"version": "5.3.1",
"ecosystem": "npm"
},
{
"name": "aria-query",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "assertion-error",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "axobject-query",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "cac",
"direct": false,
"version": "6.7.14",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "5.3.3",
"ecosystem": "npm"
},
{
"name": "check-error",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "chokidar",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "clsx",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "deep-eql",
"direct": false,
"version": "5.0.2",
"ecosystem": "npm"
},
{
"name": "deepmerge",
"direct": false,
"version": "4.3.1",
"ecosystem": "npm"
},
{
"name": "devalue",
"direct": false,
"version": "5.6.2",
"ecosystem": "npm"
},
{
"name": "devalue",
"direct": false,
"version": "5.8.1",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "0.21.5",
"ecosystem": "npm"
},
{
"name": "esm-env",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "esrap",
"direct": false,
"version": "2.2.11",
"ecosystem": "npm"
},
{
"name": "esrap",
"direct": false,
"version": "2.2.3",
"ecosystem": "npm"
},
{
"name": "estree-walker",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "expect-type",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.2",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "is-reference",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "kleur",
"direct": false,
"version": "4.1.5",
"ecosystem": "npm"
},
{
"name": "locate-character",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "loupe",
"direct": false,
"version": "3.2.1",
"ecosystem": "npm"
},
{
"name": "magic-string",
"direct": false,
"version": "0.30.21",
"ecosystem": "npm"
},
{
"name": "mri",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.11",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.12",
"ecosystem": "npm"
},
{
"name": "pathe",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "pathval",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "playwright",
"direct": false,
"version": "1.58.2",
"ecosystem": "npm"
},
{
"name": "playwright",
"direct": false,
"version": "1.60.0",
"ecosystem": "npm"
},
{
"name": "playwright-core",
"direct": false,
"version": "1.58.2",
"ecosystem": "npm"
},
{
"name": "playwright-core",
"direct": false,
"version": "1.60.0",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.15",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.6",
"ecosystem": "npm"
},
{
"name": "readdirp",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "rollup",
"direct": false,
"version": "4.57.1",
"ecosystem": "npm"
},
{
"name": "rollup",
"direct": false,
"version": "4.61.1",
"ecosystem": "npm"
},
{
"name": "sade",
"direct": false,
"version": "1.8.1",
"ecosystem": "npm"
},
{
"name": "siginfo",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "source-map-js",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "stackback",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "3.10.0",
"ecosystem": "npm"
},
{
"name": "svelte",
"direct": false,
"version": "5.51.3",
"ecosystem": "npm"
},
{
"name": "svelte",
"direct": false,
"version": "5.56.2",
"ecosystem": "npm"
},
{
"name": "svelte-check",
"direct": false,
"version": "4.4.0",
"ecosystem": "npm"
},
{
"name": "svelte-check",
"direct": false,
"version": "4.6.0",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "0.3.2",
"ecosystem": "npm"
},
{
"name": "tinypool",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "tinyspy",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.9.3",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "7.18.2",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "7.24.6",
"ecosystem": "npm"
},
{
"name": "uuid",
"direct": false,
"version": "14.0.0",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "5.4.21",
"ecosystem": "npm"
},
{
"name": "vite-node",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "vitefu",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "vitefu",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "2.1.9",
"ecosystem": "npm"
},
{
"name": "why-is-node-running",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "zimmerframe",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 219,
"direct_count": 19,
"indirect_count": 200
}
},
"maintainership": {
"issues": {
"open_prs": 3,
"merged_prs": 113,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "jdziat",
"commits": 207,
"avatar_url": "https://avatars.githubusercontent.com/u/1184714?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"bench.yml",
"ci.yml",
"govulncheck-scheduled.yml",
"pages.yml",
"stress.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json",
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 9,
"reason": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 6,
"reason": "dependency not pinned by hash detected -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "46 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "24c904c9682de40fa1aaafe7a6f907968ed5d85f",
"ran_at": "2026-07-28T12:01:33Z",
"aggregate_score": 5.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-28T08:10:11Z",
"oldest_open_prs": [
{
"number": 29,
"created_at": "2026-06-08T21:43:51Z",
"last_comment_at": "2026-06-09T13:18:06Z",
"last_comment_author": "codecov-commenter"
},
{
"number": 114,
"created_at": "2026-07-25T23:02:15Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 116,
"created_at": "2026-07-26T20:57:50Z",
"last_comment_at": "2026-07-27T02:16:14Z",
"last_comment_author": "coderabbitai"
}
],
"last_merged_pr_at": "2026-07-26T05:44:10Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/jdziat/simple-durable-jobs",
"host": "github.com",
"name": "simple-durable-jobs",
"owner": "jdziat"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"security": 54,
"vitality": 84,
"community": 46,
"governance": 55,
"engineering": 80
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 84,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"commits_last_year": 210,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 15
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "15/52 weeks with commits",
"points": 10.4,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 15
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "210 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 210
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 77,
"latest_release_tag": "v4.7.0",
"releases_from_tags": false,
"days_since_latest_release": 2,
"mean_days_between_releases": 1.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "77 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 77
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 2 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 2
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 46,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 5,
"inputs": {
"forks": 0,
"stars": 3,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "3 stars",
"points": 4.9,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 3
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 55,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 72,
"inputs": {
"merged_prs": 113,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "113/113 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 113,
"decided": 113
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 54,
"inputs": {
"followers": 12,
"owner_type": "User",
"is_verified": null,
"owner_login": "jdziat",
"public_repos": 146,
"account_age_days": 5374
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "12 followers of jdziat",
"points": 8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 12,
"login": "jdziat"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "146 public repos, account ~14 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 146
}
},
{
"code": "account_age_years",
"params": {
"years": 14
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/jdziat/simple-durable-jobs/v4"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 2
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 2 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 2
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "16 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 16
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 80,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
"points": 18,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"background-jobs",
"durable-execution",
"go",
"golang",
"gorm",
"job-queue",
"mysql",
"postgres",
"sqlite",
"task-queue",
"workflow-engine"
],
"has_wiki": true,
"homepage": "https://jdziat.github.io/simple-durable-jobs/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://jdziat.github.io/simple-durable-jobs/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "11 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 11
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 54,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 55,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 5.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 3,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "46 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "moderate",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 219 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 219
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 52,
"inputs": {
"source": "osv",
"advisories": 63,
"affected_packages": 14,
"assessed_packages": 219,
"unassessed_packages": 0,
"affected_by_severity": "critical 3, high 4, moderate 4, low 1, unknown 2",
"direct_affected_packages": 4
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "4 affected: golang.org/x/crypto v0.50.0 (critical 10.0), go.opentelemetry.io/otel/sdk v1.40.0 (high 7.0), golang.org/x/net v0.53.0 (moderate 6.5), +1 more",
"points": 5,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 4,
"packages": "golang.org/x/crypto v0.50.0 (critical 10.0), go.opentelemetry.io/otel/sdk v1.40.0 (high 7.0), golang.org/x/net v0.53.0 (moderate 6.5)"
}
},
{
"code": "advisories_affected_more",
"params": {
"count": 1
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 110 days ago",
"points": 34,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 1,
"oldest": 110
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 219,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 81,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 5424
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 72,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json",
"pnpm-lock.yaml"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"ui/frontend/tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [
"docs/go.mod",
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "ui/frontend/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "ui/frontend/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "dependency automation configured, none observed in the sampled commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "dependency_bot_config_only",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 194138,
"source_files_sampled": 338,
"oversized_source_files": 8
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "8/338 source files over 60KB",
"points": 53.7,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 338,
"oversized": 8
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": [
"ui/proto/jobs/v1/jobs.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "ui/proto/jobs/v1/jobs.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "ui/proto/jobs/v1/jobs.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-28T12:01:49.906373Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/jdziat/simple-durable-jobs.svg",
"full_name": "jdziat/simple-durable-jobs",
"license_state": "standard",
"license_spdx": "MIT"
}