Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-28 08:19 UTC

liu1700 / orlop

Multi-tenant, zero-trust durable POSIX disk for untrusted agents: per-agent mTLS, content-addressed chunk store, FUSE/NFS mount client.

Go · RustApache-2.0★ 1 estrella⑂ 0 forksdesde jun 2026Ver en GitHub ↗

liu1700/orlop tiene un índice de salud de 54 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es AI Readiness (75/100) y la más baja, Security (30/100). Se actualizó por última vez hace 2 días. Una sola persona concentra la mayor parte del trabajo reciente.

54
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

54
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

LiuCuenta personal
50 seguidores52 repositorios públicosdesde nov 2013

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/liu1700/orlopv0.4.5-14hace 2 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

70Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 2 días
2.8/36Cadencia de commits — 4/52 semanas con commits
16.7/18Volumen de commits — 71 commits en el último año
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Datos de entrada utilizados
commits_last_year71
human_commit_share1
days_since_last_push2
active_weeks_last_year4
Cómo se puntúa
27/27Publica versiones — 11 versiones publicadas
36/36Recencia de las versiones — última versión hace 2 días
27/27Cadencia de publicación — una versión cada ~3,1 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count11
latest_release_tagv0.4.5
releases_from_tagsno
days_since_latest_release2
mean_days_between_releases3,1

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

33En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 1 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (Apache-2.0)
18/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

59Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0.6/22.5Distribución de commits — el principal contribuyente firma el 97% de los commits
2.7/13.5Amplitud de contribuyentes — 2 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled2
top_contributor_share0,972
Cómo se puntúa
46.8/46.8Resolución de issues — 100% de issues cerradas
37.7/38.3Aceptación de PR — 64/65 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/29 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs64
open_issues0
closed_issues24
issue_closed_ratio1
closed_unmerged_prs1
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
12.3/25Alcance del propietario — 50 seguidores de liu1700
24.6/25Trayectoria — 52 repos públicos, cuenta de ~12 años
Datos de entrada utilizados
followers50
owner_typeUser
is_verified
owner_loginliu1700
public_repos52
account_age_days4624
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 2 días
20/20Historial de versiones — 14 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/liu1700/orlop
ecosystemsgo
any_deprecatedno
min_days_since_publish2

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

71Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 6 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

30En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — sin datos
2.5/2.5CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 25 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3
Excluidos de la puntuación (sin datos o no aplicable): branch_protection. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

75Bueno · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 71 de 71 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes2821
Cómo se puntúa
18/18Arranque con un solo comando — Makefile, third_party/fuser/Makefile
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — devcontainer, lockfile
10/10Práctica demostrada con agentes — 65 de los últimos 71 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilesCargo.lock, go.sum
has_dockerfileno
typed_language
bootstrap_filesMakefile, third_party/fuser/Makefile
has_devcontainer
has_linter_configno
typecheck_configs
agent_commit_share0,915
toolchain_manifestsCargo.toml, bench/Cargo.toml, go.mod, third_party/fuser/Cargo.toml
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.4/55Tamaños de archivo manejables — 3/291 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes102.445
source_files_sampled291
oversized_source_files3
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
0/20Servidor MCP
40/40Ejemplos ejecutables — examples
Datos de entrada utilizados
example_dirsexamples
has_mcp_signalno
api_schema_files

Datos clave

1estrellas de GitHub
2contribuidores
71commits en los últimos 12 meses
2días desde el último push
11versiones publicadas
1factor bus
0issues abiertas
crates.io, Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'orlop' from its registry
  • Could not fetch crates package 'orlop-bench' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 3.0 / 10
3.0agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-28 08:19 UTC

10Binary-Artifactsno binaries found in the repo
n/dBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities25 existing vulnerabilities detected
Dependencias directas 46
RegistroPaqueteRestricción de versiónManifiesto
crates.ioanyhow1Cargo.toml
crates.ioblake31Cargo.toml
crates.iochrono0.4Cargo.toml
crates.ioclap4Cargo.toml
crates.ioglobset0.4Cargo.toml
crates.iolibc0.2Cargo.toml
crates.iolru0.12Cargo.toml
crates.ioparking_lot0.12Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.iormp-serde1Cargo.toml
crates.ioquinn0.11Cargo.toml
crates.iorustls0.23Cargo.toml
crates.iorustls-pemfile2Cargo.toml
crates.iotokio1Cargo.toml
crates.iotokio-rustls0.26Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.ioserde_yaml0.9Cargo.toml
crates.iorusqlite0.31Cargo.toml
crates.iox509-parser0.16Cargo.toml
crates.iotempfile3Cargo.toml
crates.ioserde_bytes0.11.19Cargo.toml
crates.iofastcdc3Cargo.toml
crates.ionfsserve0.11Cargo.toml
crates.ioasync-trait0.1Cargo.toml
crates.iodaemonize0.5Cargo.toml
crates.ioos_pipe1.2Cargo.toml
crates.ioanyhow1bench/Cargo.toml
crates.iochrono0.4bench/Cargo.toml
crates.ioclap4bench/Cargo.toml
crates.iorand0.8bench/Cargo.toml
crates.ioserde1bench/Cargo.toml
crates.ioserde_json1bench/Cargo.toml
Gogithub.com/bmatcuk/doublestar/v4v4.10.0go.mod
Gogithub.com/go-chi/chi/v5v5.2.5go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogithub.com/jackc/pgx/v5v5.9.2go.mod
Gogithub.com/pressly/goose/v3v3.27.1go.mod
Gogithub.com/prometheus/client_golangv1.23.2go.mod
Gogithub.com/quic-go/quic-gov0.60.0go.mod
Gogithub.com/vmihailenco/msgpack/v5v5.4.1go.mod
Gogolang.org/x/timev0.14.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Golukechampine.com/blake3v1.4.1go.mod
Gomodernc.org/sqlitev1.49.1go.mod
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 5615,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1492330,
        "Rust": 710110,
        "Shell": 37497,
        "Makefile": 2984,
        "Dockerfile": 8567,
        "Go Template": 2270
      },
      "pushed_at": "2026-07-26T05:58:20Z",
      "created_at": "2026-06-26T05:23:59Z",
      "owner_type": "User",
      "updated_at": "2026-07-26T05:57:49Z",
      "description": "Multi-tenant, zero-trust durable POSIX disk for untrusted agents: per-agent mTLS, content-addressed chunk store, FUSE/NFS mount client.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Liu",
      "type": "User",
      "login": "liu1700",
      "company": null,
      "location": null,
      "followers": 50,
      "avatar_url": "https://avatars.githubusercontent.com/u/6064238?v=4",
      "created_at": "2013-11-29T06:10:07Z",
      "is_verified": null,
      "public_repos": 52,
      "account_age_days": 4624
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-07-26T06:01:48Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-07-16T15:53:09Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-07-05T18:18:49Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-07-05T08:32:50Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-05T06:28:25Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-07-03T20:16:20Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-07-02T15:18:02Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-06-28T05:25:31Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-06-28T03:07:14Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-06-27T23:40:47Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-06-27T21:16:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ed03ccff5c60cb5db1c1143116316f07ad171a46",
          "body": "* fix: make live handoff portable to musl\n\n* fix: explain libc-specific length conversions",
          "is_bot": false,
          "headline": "Fix live handoff on musl release targets (#89)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T05:57:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "414a3d4180686647f6575d2b23d2c22de39869c0",
          "body": null,
          "is_bot": false,
          "headline": "fix: stamp releases and configure mount paths (#88)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T05:37:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49741d22ae372a268f80ddb7af2f2f8daf0b9ecc",
          "body": null,
          "is_bot": false,
          "headline": "fix: add live FUSE mount handoff (#87)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T04:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bece032857ade7b4699489587d0c17d5e28b3dbb",
          "body": "* fix: harden infra lifecycle and POSIX semantics\n\n* ci: disable VCS stamping in FUSE rig",
          "is_bot": false,
          "headline": "Harden mount lifecycle, POSIX semantics, and infra observability (#86)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-26T03:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9dd90b6f529952db0f0e2a7f763bc2d6461937d",
          "body": "Refactor: shed datagateway-era residue, split worst-complexity paths",
          "is_bot": false,
          "headline": "Merge pull request #76 from liu1700/task/deep-refactor",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-16T15:46:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88e373c9653970f86789fc412c8640280502445b",
          "body": "- ORLOP_DATAGW_* env family renamed to ORLOP_* (old names remain accepted\n  fallbacks via envKeyWithLegacy); helm chart + docs on the new names.\n- manifests.go: renameOpt (cognitive 86) split into five phase helpers;\n  deleteSymlink/deleteSpecialNode clone collapsed. Rename/CAS/NOREPLACE\n  behavior \n[…]\neck code.\n- Shared startTestServer helper collapses the 3-way control test-setup clone.\n\ngo build/vet/test, cargo build/test, clippy: all clean.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: shed datagateway-era residue, split worst-complexity paths",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-07-16T06:35:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d44dd151cf2205251829b9a773b87ad2553609df",
          "body": "Rename overwrites a compatible destination, so a caller that needs a collision-\nsafe atomic move (e.g. a restore into an occupied path) had to fall back to a\nstat-then-rename TOCTOU. Add a real create-only mode.\n\n- Wire: ManifestRenameRequest gains an optional no_replace flag (Go\n  `,omitempty`; Rus\n[…]\ndataclient RenameNoReplace returns ErrExists over an existing dest;\nRust asserts no_replace=false is omitted and true round-trips.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dataplane): create-only rename (RENAME_NOREPLACE) (#75)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T17:31:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d97c3e1241d546724e61b2c00babd26ec0c87453",
          "body": "…(#74)\n\nhandleManifestPut attaches a recovery hint (with the server's current version)\non an ESTALE conflict, so the client's StaleError.CurrentVersion is populated.\nhandleManifestDelete/handleManifestRename went through manifestErrToWire, which\nmapped ErrVersionConflict to a bare ESTALE with no hin\n[…]\n\nhint (used by manifest_put); older clients ignore it. Tests assert Delete and\nRename-source conflicts return the current version.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dataplane): carry current version on Rename/Delete CAS conflicts …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T17:18:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65365caf04ec7c7c643eed8de4227fb9a576595f",
          "body": "WriteFile uploads all content chunks (chunk_put) and only then commits the\nmanifest (manifest_put). chunk_put wrote the blob to disk but inserted no row\ninto the `chunks` refcount table — that row was created solely by\napplyChunkRefDelta inside manifest Put/Delete/Rename. So whenever manifest_put\nfa\n[…]\nC candidate with its real size; once referenced, re-noting leaves refcount and\nadded_at untouched and it is no longer a candidate.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gc): reclaim chunks orphaned by an uncommitted WriteFile (#73)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T17:13:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4f85566a6f0e3631dc94e1a554322745744bafd",
          "body": "Two doc-accuracy fixes and one test-coverage gap from an adversarial review of\nthe whole-file object-ops surface. No behavior change.\n\n- ManifestRenameRequest.ExpectedVersionTo was documented \"0 = must-not-exist;\n  otherwise CAS replace\", and ErrAlreadyExists was documented as returned by\n  Rename o\n[…]\n tenant-only→\"\", and garbage/nil→\"\" fail-closed paths,\n  so SAN-parsing drift is caught in unit CI instead of as a scoping outage.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dataplane): correct Rename CAS docs; cover agentIDFromCertDER (#72)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T15:52:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8039c96429881d7fea565e02179262092b17d3be",
          "body": "…e (#71)\n\nDial presented only the leaf certificate. orlop-server's client-CA pool is\nthe org ROOT ALONE (cert_tenant_binding.go), so a leaf signed by a tenant\nintermediate can't be verified from the leaf alone: in TLS 1.3 the client's\nhandshake \"succeeds\" but the server closes the connection right a\n[…]\ned a single self-signed CA, so this class of bug only shows\nagainst a real intermediate chain — which the live test now exercises.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dataclient): present the tenant intermediate on Dial; add live e2…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T08:29:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2dd460641d13e25477f6764c9164959f17f73b35",
          "body": "…ount (#70)\n\nAdds github.com/liu1700/orlop/dataclient: a Go client that speaks\norlop-server's binary mTLS frame protocol directly to list/read/write/\ndelete/rename an agent's files with no FUSE mount and no mount lease.\nReads are lease-free; writes are guarded by manifest CAS (ErrStale).\n\n- Enroll()\n[…]\ntays\nstdlib-only). No server changes. Tested with an in-process frame server\nand a real mTLS Dial round-trip; go test -race clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dataclient): Go data-plane client for whole-file ops without a m…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-05T06:23:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3862d13e84e830958e50245261d30195e76ffd4d",
          "body": "…ecreate an orphan dir (#69)\n\nA data-plane connection resolves its *tenantState once at accept and reuses that\npointer for every frame (serveFrames -> identifyV2Peer -> goRequest). When\norlop-control purges a tenant (unregisterTenant: delete from map, db.Close,\nos.RemoveAll(tenantDir)), a chunk_put \n[…]\nstChunkPutOnClosedTenantReturnsESTALE — wire-level errno\n\n\nClaude-Session: https://claude.ai/code/session_01PHcvKCSt7VtJ9yJDADnXe1\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "server: gate tenant store writes on unregister so a dying pod can't r…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-03T20:06:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6192d82db97652f2c3f5e7b7da2c7093ceb3f289",
          "body": "…(#68)\n\nLinter-guided (deadcode, staticcheck, golangci-lint, clippy) plus a manual\nsweep of all three trees. Net -1,700 lines with no behavior change except\nthe listed fixes. All tests pass; clippy is warning-clean.\n\nControl plane (net -875):\n- Delete 17 dead sqlc queries (the whole anonymous-sessio\n[…]\nre and\n  .dockerignore; list advanced-usage.md in the README docs table.\n- Add CLAUDE.md (component map, build/test, invariants, docs pipeline).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: repo-wide dead-code purge, dedup, and doc/config alignment …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-02T16:02:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6561135bac1bacc6536524914e4e44d64e0bf9b5",
          "body": "…se (#67)\n\n* docs: fact-check and optimize all reference docs against the implementation\n\nSubstantive-editor pass over the README and every docs/ reference page,\nverifying each claim against the Go/Rust source and cutting or correcting\nanything unsupported.\n\nKey fact corrections:\n- container-images:\n[…]\nored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01PHcvKCSt7VtJ9yJDADnXe1\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "server: stale mount connection can no longer kill its successor's lea…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-07-02T15:00:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ef4295caee0731951bbddc8c0726a5ea3fbb877f",
          "body": "…tation (#66)\n\nSubstantive-editor pass over the README and every docs/ reference page,\nverifying each claim against the Go/Rust source and cutting or correcting\nanything unsupported.\n\nKey fact corrections:\n- container-images: document the real `orlop mount --from-env` env contract;\n  drop the non-ex\n[…]\nS (it's NFS there).\n\nAlso normalize doc link style and point repo-file links at absolute GitHub URLs\nso they resolve on orlop.dev.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: fact-check and optimize all reference docs against the implemen…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T20:17:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8ec8b1e1c0a6025b54bdc34c1200175bda89812",
          "body": "…panion (#65)\n\nCut the standalone quickstart to the first-integration essentials (install →\nup → see the disk → stop → verify persistence) for a shell-fluent ops/backend\nreader. Everything past that minimal path — the agent paste block, install\noverrides, build-from-source, what `dev up` does, prefl\n[…]\nta lives, and\n`doctor` troubleshooting — moves to a new advanced-usage.md companion, linked\nfrom the quickstart's \"Going further\".\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: slim the quickstart to its minimal path; add advanced-usage com…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T18:24:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "925e83db30f04bed146c5fc3db2e9feae88ad18d",
          "body": "Rewrite the agent-memory reference from a feature overview into a\npractical how-to: a local round-trip, then five abstracted steps for\ngiving an agent its own durable, isolated disk (allocate -> enroll ->\nmount -> read/write -> reattach), each with real commands and a verify.\n\nAdd a \"Where orlop sto\n[…]\nm) for positioning\nand SEO. The lead sentence is tuned so the auto-generated meta\ndescription leads with the keywords and JuiceFS.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reframe agent-memory as a how-to (per-agent disk, SEO peers) (#64)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T15:43:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4fb39ab4c03dd309b36cb4965897d1c1c9ea5867",
          "body": "Patch release consolidating the standalone dev-stack fixes (closes #51–#56):\nnon-interactive lifecycle (`dev up --detach` + `dev down`, #51), graceful\nshutdown exits 0 (#52), `status` liveness-probes UP/DEGRADED/DEAD (#53),\n`doctor --dev` + dev-up-aware warnings (#54), stable non-epoch directory mti\n[…]\n-compat — API major stays 1, no new migrations.\n\nBump version strings + the helm appVersion + the install/image examples to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.3.1 (#63)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T05:21:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e989d5d7319d498ae8e182f0f5451c9a89199e29",
          "body": "… commands (#56) (#62)\n\nThe standalone quickstart was effectively 4 mental steps (verify ports/mount →\ninstall → doctor → dev up). Fold the host checks into `dev up` itself so the\nhappy path is just install + run.\n\n- `dev up` preflight now runs the same checks as `orlop doctor --dev` (mount\n  suppor\n[…]\n busy port → fail-fast preflight with fix,\nexit 1; clean host → comes up; full install→up→write→down→up→file-survived\nwalkthrough.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dev): fold host preflight into `dev up`; shorten quickstart to 2…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:36:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8151a169f385bda6bc9b90a16b38346464bc763b",
          "body": "Directories carry no manifest (only files do), so the macOS NFSv3 server passed\nmtime_ns = 0 for every directory — surfacing as `Dec 31 1969` in `ls -l` and\nconfusing tools that sort/filter by mtime.\n\nSynthesise a sane, stable timestamp for directories: capture the mount time\nonce (`started_ns`) and\n[…]\nserts dir getattr/readdir/root mtimes are non-zero and\nstable; e2e `ls -laR` on a live mount shows real timestamps with no `1969`.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(nfs): give directories a stable non-epoch mtime over NFS (#55) (#61)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:31:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f1c7d590eb1b73238e304e3fbea2e74e6aedaf1",
          "body": "On a clean host, `orlop doctor` warned about a missing config + credentials —\nirrelevant to `orlop dev up`, which supplies them out of band — so a first-time\nuser read the standalone quickstart as \"your setup is incomplete.\"\n\nAddress both options from the issue:\n- `orlop doctor --dev`: checks exactl\n[…]\n, exit 0; with a\nstack holding the ports → port checks FAIL, exit 1 with actionable fixes;\nplain `doctor` warnings mention dev up.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(doctor): make doctor aware of the `dev up` flow (#54) (#60)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:22:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a4d7992ad98d72f0b4773f16a19c376a5ca50d6",
          "body": "…#53) (#59)\n\n`orlop status` printed a hardcoded `dev stack: UP` header straight from the\ncached `dev.json`, so a stack that died uncleanly (kill -9, OOM, crash) still\nread as a healthy UP — even though the per-component lines already probed\nliveness.\n\nDerive the overall state by probing the supervis\n[…]\n to component health.\n\nTested e2e (macOS): healthy → UP; `kill -9` supervisor → DEAD (not UP) with\nhint; `dev down` → not running.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(status): report DEAD/DEGRADED from live probes, not a cached UP (…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:16:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "baea0110aef5efeed7aa1de1bfc22e096643d187",
          "body": "A signal-initiated shutdown of `orlop dev up` is the documented, intended way\nto stop the stack, so it must be a success — a process supervisor or CI step\nshouldn't see a non-zero exit and mistake a normal stop for a crash.\n\nMake the exit status explicit and deterministic instead of always returning\n[…]\ntrol-plane child → tears the rest down and exits 1 naming the\ncrashed component. Unit tests cover the three shutdown_result cases.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dev): make `dev up` exit status reflect why it stopped (#52) (#58)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T04:11:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7db06aeee4e2249908ae72048a50110dfe2fbc2",
          "body": "…ecycle (#51) (#57)\n\n`orlop dev up` only ran in the foreground, stoppable solely by Ctrl-C, so CI,\nbackgrounded jobs, IDEs, and agents had to PID-hunt the supervisor to stop it\n(and the naive pgrep selects the wrapper shell, whose SIGINT is dropped).\n\n- `dev up --detach`/`-d`: re-exec the supervisor\n[…]\n up --detach → status → I/O → down; crash (kill -9) →\ndown reconcile frees ports; foreground up stopped via down; idempotent down.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dev): add `dev down` + `dev up --detach` for non-interactive lif…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T03:57:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f970c5e397a4f298a6813ec6a74a57c8b594f965",
          "body": "Feature release consolidating the consumer-feedback work: multi-arch GHCR\nimages (#47), a reference Helm chart (#48), control-plane API versioning +\nOpenAPI (#49), and upgrade-safety guards — CI in-place-upgrade test + boot\nschema self-check + migration policy (#46). All additive and back-compat\n(API major stays 1; no new migrations). Bump version strings + the helm\nappVersion + the install/image examples to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.3.0 (#50)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T03:02:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "04c96758e771a9b0023d51e940c97d58392d8d61",
          "body": "… detection (#42) (#49)\n\nThe Go SDK and orlop-control agreed on REST paths and bodies only implicitly: it\nhappened to be byte-identical across v0.1.0 and v0.2.0, but there was no\ndocumented contract and no way to detect version skew — a mismatched pair would\nsurface as an opaque 4xx, and other-langu\n[…]\nd\n  SDK/server (v0.1.0–v0.2.x) speaks major 1. Other-language clients implement\n  from the spec and check the header the same way.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "api: version the control-plane API — OpenAPI spec + SDK<->server skew…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T01:22:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "992b59577ef12d776e6a8f448f531ffd1698b0a8",
          "body": "… (#48)\n\nConsumers had to reverse-engineer the whole deployment from the binaries — the\nmigrate step, the CA/secrets topology, the mTLS self-provisioning, and a set of\ncross-component env constraints that are easy to get subtly wrong. This adds a\nreference chart (deploy/helm/orlop) that stands up a \n[…]\nallowed) and served mTLS on ops+data, both\nreached Ready, and `orlop-control server register` (the NOTES.txt next step)\nsucceeded.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "deploy: reference Helm chart for control + server on Kubernetes (#41)…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T01:11:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7e374f8d733c698a3b45208ea4782f436f18d1b2",
          "body": "Consumers running orlop on Kubernetes had to rebuild from source every release —\nthe Go binaries are cheap, but the Rust mount client (libfuse3 + a multi-minute\ncargo build) is the painful one. Publish prebuilt multi-arch images instead.\n\nThe release workflow gains an `images` job (tag-only, sibling\n[…]\n and a multi-arch\n(amd64+arm64) buildx of the TARGETARCH-staged Dockerfile succeeds. The GHCR\npublish itself runs on the next tag.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "images: publish multi-arch GHCR images per release (#40) (#47)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:59:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26974e8ba722703ceab8becb686c6cf0157a39c0",
          "body": "…(#39) (#46)\n\nIn-place upgrades had no guarantee: squashing already-released migrations\n(#23) reset goose numbering, so a deployed v0.1.0 database skipped the\nsquashed baseline and silently lacked access_tokens.consumed_at and the\ncert_revocations table. goose reported success; the gap only surfaced\n[…]\nnd a v0.1.0 database without the bridge fails boot with the exact\nincident (missing cert_revocations + access_tokens.consumed_at).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "upgrade safety: CI guard + boot schema self-check + migration policy …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:46:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f761e97f1410ef26a18903e9c7bbe12a86f9ceaa",
          "body": "These two are required status checks on main. With their `pull_request`\npath filters, a PR touching no Go/Rust files (docs, config) never triggered\nthem, leaving the required `go`/`build` checks stuck \"Expected\" and the PR\nunmergeable. Drop the pull_request path filters so both always run and\nreport on every PR; this is the prerequisite for enforce_admins=true gating.\nPush-to-main path filters are left as-is.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: run go and build checks on every PR (not path-filtered) (#44)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:21:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f65cc0aaba21cb9eb2dff53ce353a2383d0c1e0e",
          "body": "…l-bring-up (#43)\n\nThe quickstart still walked the six manual steps and ended with the fragile\n`kill %1 %2 %3` teardown, predating `orlop dev up`. Rewrite it around the\none-command path: install -> `orlop dev up` (+ `orlop status`) -> write a file,\nCtrl-C, bring it back up, watch it survive. Move th\n[…]\nthe\nrestart cycle preserves the file. Update README quickstart + docs table and the\ndatabase-backends cross-reference accordingly.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: make the quickstart `orlop dev up`-first; move by-hand to manua…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-28T00:15:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31f723fa57b7129aacf2e20df7ef5dc094a61049",
          "body": "Patch release: bridge migration (#38) so v0.2.0+ upgrades a database\nprovisioned by the pre-squash v0.1.x line. Update the install-version examples\nin the quickstart and the release workflow comment to match.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.2.1",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T23:37:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a6f99c9a658579bfc89d7130f5a7bef103290c62",
          "body": "…base (#38)\n\nThe squashed baseline (0001_init, #23) reset goose numbering to version 1, but a\ndatabase migrated by v0.1.0 is already at goose version 9 (from its original\n0001-0009 files). goose only applies versions greater than the current max, so on\nthose databases it skips the squashed baseline \n[…]\n010 and adds both objects; idempotent on re-run; a fresh DB applies\n0001+0010 to the same final schema. sqlc codegen is unchanged.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(db): bridge migration so v0.2.0 upgrades a pre-squash v0.1.x data…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T23:36:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a2131424eadf9acdd0a9914fb5f796c872538e84",
          "body": "… dev up + status (#37)\n\n* cli: stop orlop-control booting a server on unknown args; add --version\n\n`orlop-control <anything>` fell through a bare os.Args[1] switch to run(),\nso a typo or `--version` silently started a control plane on :8080 with no\ndatabase configured. Classify the arguments instea\n[…]\npatch) read, removing\n  the duplicated verb list.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CLI UX: kill the orlop-control footgun, fix macOS unmount zombie, add…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T23:18:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d795efd448ba33bc8feb54d4182442473cb896c4",
          "body": "Commit the standalone quickstart to a single SQLite happy path. Drop the\nPostgres/Docker branch (now a one-line pointer to database-backends.md),\nremove the optional `migrate up` step (SQLite applies its embedded schema\non open), and cut the duplicated gotchas and thrice-stated durability\nthesis. St\n[…]\nle blocks, the durability proof as the\npayoff. Net 126 lines removed.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: make the quickstart SQLite-only and tighter (#36)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T21:28:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b33819fc874e51177a4b13516791cd1f4fd34ccb",
          "body": "1.0.0-rc.17 overstated maturity for a project still at v0.1.0. Move to\n0.2.0 and update the install-version examples in the quickstart and the\nrelease workflow comment to match.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: set version to 0.2.0 (#35)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T21:12:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f0227bbc27a01e0a3273f3b63578ba51bb2cc819",
          "body": "GitHub's Intel macos-13 runners sat unassigned for hours and blocked the\nrelease. Build x86_64-apple-darwin on macos-14 instead (Go via GOARCH,\nRust via the x86_64-apple-darwin target), same runner as darwin/arm64.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: cross-compile darwin/amd64 on the Apple-Silicon runner (#34)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T21:04:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "eba5384c300065fa8071153e2f3a09fee6eb141d",
          "body": "…l-first quickstart (#33)\n\n* release: cross-platform binary builds and install.sh\n\nAdd .github/workflows/release.yml: on a v* tag, build orlop, orlop-control,\nand orlop-server for linux/darwin x amd64/arm64 and publish tarballs +\nsha256 to the GitHub Release. Go binaries are pure-Go (modernc sqlite \n[…]\n the agent\nfast-path prompt are updated to match.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "release: prebuilt binaries (release workflow + install.sh) and instal…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T18:28:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f376213bc59742cf0930cb5b144dae516c099bc8",
          "body": "…s (#32)\n\nRemoving the dead device-flow code (#31) left the two now-empty tables in the\nschema. Drop them from the Postgres squashed baseline and the SQLite schema, and\nregenerate sqlc so the dead DeviceAuthorization / RefreshToken models go away.\n\nNothing references these tables. go build/vet/test \n[…]\n(which applies schema.sql on open) and the sqlc-validated db package.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: drop the unused device_authorizations and refresh_tokens table…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T17:43:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "89ae5c0bd91a253470d347ca6cc3ff3c2545821d",
          "body": "The orlop binary has no `orlop login` command and nothing drives the\ncontrol-plane device-code flow, so remove it end to end and make the docs match.\n\nControl plane (Go):\n- Remove the device routes (/auth/device/code|token, /auth/token/refresh,\n  /device, /device/lookup, /device/approve) and their h\n[…]\nsurface.\n\nVerified: go build/vet/test and cargo build/test all green.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: remove the dead device-flow login subsystem (#31)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T17:34:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b5bbb9d7ef6e2ec00fd0565cec2bf0864d11fe56",
          "body": "… (#30)\n\nRewrite the README and every docs/ page against the actual implementation,\nfixing factual drift and turning the internal design RFCs into reader-facing\nreferences.\n\n- Fact-checked every command, flag, env var, route, field, and behavior against\n  the code. Corrected the major errors: design\n[…]\nark, light/dark wordmarks); the README now leads\n  with the wordmark.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: fact-check and reframe all viewer-facing docs; add brand assets…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T16:31:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25d7b705097358e97f5d053ebf783b2a93217c80",
          "body": "Our SQLite/Postgres choice was buried inside the standalone quickstart as\n\"Option A/B\" with no single home, no comparison, and the caveats (single-node,\nCA-secrets backend constraint) scattered across the quickstart and code.\n\nRestructure it the way established multi-backend projects do — a dedicate\n[…]\n and the runbook's\nDATABASE_URL example point at it too.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add a canonical \"Database backends\" reference page (#29)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:58:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b88757661de7a50cd0ca50197a3242dea79b0ef3",
          "body": "…(#28)\n\nWires the embedded SQLite backend in so the control plane actually runs on it.\nA storage.Store union interface (every role interface) lets runtimeDeps.store\nhold either backend; a DATABASE_URL \"sqlite:\" scheme selects SQLite (schema\napplied on open), anything else is Postgres. openStore() is\n[…]\nes not\neven Postgres is required for a single-node try).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: backend selection + quick-start on SQLite (stage 6d) …",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:49:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "472a9a412f38bbdb74e95dda5dd5412494d3ea77",
          "body": "Completes the SQLite adapter: the allocations subdomain (disk lifecycle, mount\nleases, purge CAS, placement + capacity reservations), the provisioning writes\n(idempotent tenant/user ensure + per-agent allocation upsert + reassign), and\ntransactions. *sqlite.Store now implements every storage role in\n[…]\nime). Still additive — wiring +\nquick-start docs are 6d.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: AllocationStore + Tx + provisioning (stage 6c) (#27)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:40:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bceaeec2ac8f5131e2631e8e03cc7455d1bb244",
          "body": "Implements the sessions subdomain (SessionOps) on the SQLite backend: device\nauthorizations, access tokens (incl. the single-use agent-enroll consume),\nrefresh tokens, and the user reads. The conditional updates preserve the\nPostgres semantics exactly — Approve/Deny match only a still-pending row\n(R\n[…]\n tests cover the flow\nagainst a real temp-file database.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: SessionStore — device flow + tokens (stage 6b) (#26)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:28:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b6e8d2ae9068f419e8ca7f380213c947d8e62564",
          "body": "…) (#25)\n\nFirst slice of an embedded, zero-external-dependency SQLite backend (issue #4's\n\"SQLite implementation\"), so the control plane can run for local quick-start\nwithout Postgres. Pure-Go driver (modernc.org/sqlite), hand-written database/sql\nadapter mirroring package postgres.\n\nThis slice land\n[…]\nemp-file\ndatabase (no external dependency — runs in CI).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage/sqlite: embedded backend foundation + simple stores (stage 6a…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T14:24:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa1b6cfb614724957ce62ffc084859aeded627df",
          "body": "…s (stage 5c) (#24)\n\nMove internal/db (the goose migration runner, sqlc query sources, generated\nsqlcdb, and squashed schema) under internal/storage/postgres/db, so everything\nPostgres-specific lives beneath the postgres adapter. The domain layer\n(internal/storage) and a future internal/storage/sqli\n[…]\nthe relocated goose embed applies\nthe baseline cleanly).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: relocate the Postgres backend under internal/storage/postgre…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:43:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "759fcf5f9acf7eeb88948c811d18080e76003ed1",
          "body": "The 12 incremental migrations (0001-0012) accreted real cruft — most visibly\nthe email-OTP self-service login added in 0009 and dropped in 0010 when #9\nremoved self-service signup. Pre-release, with no production schema history to\npreserve, collapse them into one 0001_init.sql baseline that reflects\n[…]\ne\nrecreated; there is no released deployment to migrate.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "db: squash migrations into a single clean baseline (stage 5b) (#23)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:36:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dfdb50a8fb8a30cb90f8db6397b65d3d5e17d7f2",
          "body": "With every consumer migrated onto the storage domain layer, the\nsqlc-generated db.Store alias (and db.ErrNotFound) has no users left — delete\ninternal/db/store.go. The runtimeDeps.queries field and its sqlcdb.New wiring go\nwith it; the DB-configured guards now key on deps.store. The internal/db pack\n[…]\nunner + sqlc query layer the Postgres adapter\nbuilds on.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: remove the db.Store god interface (stage 5a) (#22)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:25:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "548818ce2373a866578fed26ec22ee6d932f2b4c",
          "body": "Move the operator CLI commands (user seed/suspend, server register, token\nissue) and the serverapiMountLeaseFencer off direct sqlcdb.New(pool) usage onto\nthe storage domain layer, so sqlcdb is no longer touched outside the adapter\npackage.\n\nAdds storage.AdminStore — the privileged out-of-band operat\n[…]\n the runtimeDeps.queries field and its wiring (stage 5).\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate operator CLI + fencer off sqlcdb (stage 4e) (#21)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:18:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "077f758bc60de79254da348f2ee28763ba562e45",
          "body": "The journal HTTP handler carried a db.Store field that nothing read — drop it\n(and the constructor param). The serverapiJournalAdapter's inline placement\nquerier moves onto the storage domain layer: its queries field is now a\ntenantPlacementQuerier, and opsAddrFor delegates to the shared\nresolveTena\n[…]\nstill yields an empty\njournal page rather than an error.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate journal off db.Store (stage 4d) (#20)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:06:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ea1768eba0ba38d16d0ee603128837327609e63e",
          "body": "Move the entity provisioning handler — the control-plane→control-plane\n/v1/entities + /v1/agents/{id}/enroll-token surface — off the sqlc db.Store\ngod interface and onto the storage domain layer.\n\nAdds storage.ProvisioningStore (EnsureTenant, EnsureUserWithID,\nUpsertAgentAllocation, GetAllocationByA\n[…]\n; callers are the control-plane passing canonical UUIDs.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate /v1/entities provisioning off db.Store (stage 4c) (#19)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T08:01:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c361ba6fa3e8d0773dcc9aeaa4d6c25b9eaa5f3b",
          "body": "Move the five read-path handlers — agent enroll, mount-lease, dashboard,\ncontrol tenant-usage, and purge-sweep — off the sqlc-generated db.Store god\ninterface and onto the backend-agnostic storage layer.\n\nEach handler now depends on a narrow domain interface listing exactly the\nmethods it calls (age\n[…]\nreshes the stale WithTx note in the storage package doc.\n\n\nClaude-Session: https://claude.ai/code/session_017gGdJXoPSSjfnqd2yhYB9T\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate read handlers off db.Store (stage 4b) (#18)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T07:43:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac739bf5309b5b95664f64f2d73f640b500d910b",
          "body": "First slice of the handler migration. The api-token routes and the bearer\nmiddleware no longer use db.Store.\n\n- storage.APITokenStore: domain types (APIToken, NewAPIToken, APITokenAuth) and\n  the role interface; postgres adapter.\n- api_token_handlers + the requireBearer middleware (RequireBearer /\n \n[…]\nship 404,\nidempotent revoke) and the bearer-middleware suite (revoked/expired/suspended)\npass, plus the whole control-plane suite.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate API tokens off db.Store (stage 4a) (#17)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T07:19:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "08cd011dfe7d0a62ec729a7fa809fecce25b8fde",
          "body": "Stage 3. allocations.Service no longer holds *sqlcdb.Queries / *pgxpool.Pool;\nit depends on storage.AllocationStore.\n\n- storage.AllocationStore / AllocationOps: domain types (Allocation, AgentEnrollment,\n  ServerVM, Server, ChosenServer) and the ~22-method role interface for disks,\n  leases, placeme\n[…]\nns suite (lease takeover, quota, capacity race,\nplacement, resize compensation, purge CAS) and the whole control-plane suite pass.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate the allocations subdomain to the domain layer (#16)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T07:07:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "15cc9c6cfea2c6034316bc3cbe09f2c5640be527",
          "body": "… (#15)\n\nStage 2 of the data-layer redesign. The devauth service no longer holds\n*sqlcdb.Queries / *pgxpool.Pool; it depends on storage.SessionStore.\n\n- storage.SessionStore / SessionOps / SessionTx: domain types and a role\n  interface for the device-flow / token subdomain, with explicit\n  Begin/Com\n[…]\nily revocation, suspended user/tenant\nrejection) passes, plus the whole control-plane suite. uuid promoted to a\ndirect dependency.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: migrate the sessions subdomain (devauth) to the domain layer…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T06:46:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4f4c35e425483f6bc91e98a6d17ee12398ae2bcc",
          "body": "…#14)\n\nBegin redesigning the data layer from the sqlc-shaped db.Store (84\nmethods, returns pgtype) into small domain role interfaces with no\ndriver types crossing the boundary.\n\n- internal/storage: domain types + role interfaces + ErrNotFound. The\n  package doc states the conventions (intent-named m\n[…]\ned db.Store +\n  override 2\" to a clean 3-method implementation.\n\nOther subdomains still use db.Store; they migrate slice by slice.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "storage: introduce backend-agnostic domain layer (foundation slice) (…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T06:25:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "179044db8c95e22ed3752ff82f64c031a8f70893",
          "body": "…#13)\n\nSweep the docs against the code after the #4–#8 / email-OTP-removal work.\n\nRemoved-feature cleanup (#9 deleted self-service email-OTP; docs lagged):\n- SECURITY.md: drop the RESEND_API_KEY / ORLOP_DEV_LOG_OTP mailer bullet,\n  the \"Email OTPs lock out\" hardening clause, and \"OTP\" from the\n  rat\n[…]\numn is `data_addr`); also\n  corrected the testing note's client_ca_file (org root, not intermediate).\n\nDocs only; no code changes.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: match current architecture; drop removed-feature descriptions (…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T06:25:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9a464453b8a03f7efa460f3c1c22c24b60b5f18a",
          "body": "Post-merge quality pass over the #5-#8 / #4 changes.\n\nsimplify (efficiency): the cert-revocation deny-list pruned expired\nentries on every Add, so merging a full reconcile snapshot was O(n²).\nPrune once per push batch instead (Add is O(1) again).\n\nsecurity-review (medium): parseBoolEnv (was envBoolD\n[…]\niable.\n\nTested: go vet ./... clean; full suite green against a live Postgres\n(-p 1); the previously-flaky test now passes 100/100.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cleanup + security follow-ups from /simplify and /security-review (#12)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T05:14:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "57a9e602669a0358ea4f7b77082fbaae2fc4cf7f",
          "body": "The HTTP/business handlers held the concrete pgx-backed *sqlcdb.Queries and\nimported the pgx driver directly to interpret \"no rows\", coupling the\nconsumer layer to Postgres.\n\nIntroduce a storage seam in internal/db:\n  - db.Store: the sqlc-generated query interface under a domain name, so\n    handler\n[…]\n fake\ndb.Store to demonstrate the decoupling payoff.\n\nTested: go vet ./... clean; full suite green against a live Postgres (-p 1).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Hide Postgres behind a storage interface in the control plane (#4) (#11)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T04:41:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "97e8fb7dfbf67f60a8fbc302de30b152beb790a7",
          "body": "Addresses the four open security issues surfaced while reviewing the\nidentity design (docs/design-identity.md §6).\n\n#6 — Single-use agent enroll tokens. A per-pod agent_enroll token is now\nspent on a successful /agent/enroll (atomic UPDATE ... consumed_at), and\nauthenticateRaw rejects an already-con\n[…]\n.\n\nTested: go vet ./... clean; full suite green with a live Postgres\n(-p 1) including new unit + integration tests for each issue.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Harden agent identity and data plane (#5, #6, #7, #8) (#10)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T04:30:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ca6c8ad3cdd6086537dae0bfbeea36e7c473ed75",
          "body": "…fier (#9)\n\n* docs(identity): add identity & data-isolation design\n\nCapture the researched design basis for issue #4: separate the load-bearing\nauthorization subject (tenant/allocation/enrollment + mTLS SPIFFE) from the\nhuman account lifecycle; correct the \"passing an id is auth\" framing with the\ntw\n[…]\nroll seam,\nand re-sourcing /agent/enroll authorization from the verifier (issue #8).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove self-service email-OTP login; add pluggable host-identity veri…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-27T03:10:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6894e17f86335b21e7d388d29dfeb909e02cca14",
          "body": "Lead with a tight tagline, badges, and a quick-links nav row, then\nprogressively disclose detail: scannable Highlights, an early Quickstart,\nand deep prose (Why Go and Rust) folded into a <details> block. Convert\nthe doc list into an at-a-glance table and add Contributing/Security\nsections, mirroring the structure of well-organized project READMEs.\n\n\nClaude-Session: https://claude.ai/code/session_01WKCS21TsKzt66mEo2rra77\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reorganize README homepage for scannability (#3)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T14:52:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1aeff37acaf0e34aadd47900b84fb288ed89103e",
          "body": "…is-wymls5\n\ndocs: explain the Go/Rust split and add one-command onboarding",
          "is_bot": false,
          "headline": "Merge pull request #2 from liu1700/claude/language-unification-analys…",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T14:40:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cfe376fbeb13e38bc70b588d3fb618ad3865273",
          "body": "Provide one-command onboarding for the two-language layout:\n\n- Makefile `setup`/`setup-go`/`setup-rust` targets verify each toolchain,\n  install the Linux libfuse3 dev headers, and pre-fetch deps. The split\n  targets honor the \"you usually need only one side\" guidance — apt-get\n  update failures fro\n[…]\n Point CONTRIBUTING.md setup at the dev container and the make targets.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RpWseSPQhdBDmdoYk23RbH",
          "is_bot": false,
          "headline": "build: add `make setup` targets and a dev container",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-06-26T14:37:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e9dc55778295c58fb9299512920d8a7104ab66e6",
          "body": "Add docs/agent-memory.md describing what orlop's durable, isolated,\ncontent-addressed disk gives an agent-memory stack (persistence,\nfidelity-first raw storage, cheap incremental updates, overwritable\nversioned state, per-agent isolation, audit, portability) and the\nboundary where the cognitive memo\n[…]\nREADME with a new 'Why this matters for\nagent memory' section and a docs link.\n\n\nClaude-Session: https://claude.ai/code/session_01PFHaYAFUghmzjqfwt2rWQ2\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: explain orlop as the storage substrate for agent memory (#1)",
          "author_name": "Liu",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T14:32:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "105347e1ae68ef91464852a5e6469bf6549b7684",
          "body": "Add a CONTRIBUTING.md that lowers the onboarding bar for the two-language\nlayout: a per-module table showing contributors they almost always need\nonly one toolchain, exact Go/Rust build+test commands (including the\nLinux libfuse3 dependency and the macOS NFS path), and the cross-language\ncontract (w\n[…]\n (no cgo/FFI), with each\nside using the language strongest for its job.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01RpWseSPQhdBDmdoYk23RbH",
          "is_bot": false,
          "headline": "docs: add CONTRIBUTING guide and explain the Go/Rust split in README",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-06-26T14:32:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f1fa2c8213ea18eac31ad1f103ea2a4c24ba8ac6",
          "body": "A small, standard-library-only Go SDK for the orlop-control REST API: allocate\nand manage an agent's disk, set account budgets, reassign owners, mint the\nshort-lived per-agent enroll token, and read usage. Lifted from the proven\ncontrol-plane client; this is the canonical contract a host imports to \n[…]\nkflow (build + vet + test) — the Go control/data plane and\nthis SDK previously had no CI; only the Rust client and shellcheck did.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(client): add orlop/client Go SDK + Go CI",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T05:52:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac3a57b20fe4217e2de0af759179f3d5a8a8cd40",
          "body": "Three test initializers in the fh_tests module predated the uid/gid/atime_ns/\nrdev fields on Node and omitted them. A plain `cargo build`/`check` skips\n`#[cfg(test)]` modules so this stayed latent; CI compiling the lib tests on\nLinux surfaced E0063 (missing fields). Fill the four with their documented\nzero defaults, matching the canonical initializer.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(fs): complete Node initializers in fh_tests (uid/gid/atime_ns/rdev)",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T05:43:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "61f874fd001f1ab12abf3d524c9057d988742f35",
          "body": "Initial import. A multi-tenant file plane that gives each untrusted agent its\nown durable, auto-expanding POSIX disk over FUSE/NFS, without ever handing the\nagent a storage credential: per-agent short-lived mTLS identity (SPIFFE SAN),\ncontent-addressed chunk store with per-disk SQLite manifests, cap\n[…]\ncontrol plane that is the CA and allocator.\n\nComponents: orlop (Rust mount client), orlop-control + orlop-server (Go).\nApache-2.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "orlop: zero-trust durable POSIX disk for untrusted agents",
          "author_name": "liu1700",
          "author_login": "liu1700",
          "committed_at": "2026-06-26T05:23:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 11,
      "commits_last_year": 71,
      "latest_release_at": "2026-07-26T06:01:48Z",
      "latest_release_tag": "v0.4.5",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 2,
      "mean_days_between_releases": 3.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/liu1700/orlop",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/liu1700/orlop",
          "is_deprecated": false,
          "latest_version": "v0.4.5",
          "repository_url": "https://github.com/liu1700/orlop",
          "versions_count": 14,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-26T05:57:44Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 2
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "third_party/fuser/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "bench/Cargo.toml",
        "go.mod",
        "third_party/fuser/Cargo.toml"
      ],
      "largest_source_bytes": 102445,
      "source_files_sampled": 291,
      "oversized_source_files": 3,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 2821
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "bench/Cargo.toml",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "go"
      ],
      "dependencies": [
        {
          "name": "anyhow",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "blake3",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "chrono",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "clap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "globset",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "libc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "lru",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "parking_lot",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "rmp-serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "quinn",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "rustls-pemfile",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "tokio",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tokio-rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_yaml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "rusqlite",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.31"
        },
        {
          "name": "x509-parser",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.16"
        },
        {
          "name": "tempfile",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "serde_bytes",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11.19"
        },
        {
          "name": "fastcdc",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "nfsserve",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "async-trait",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "daemonize",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.5"
        },
        {
          "name": "os_pipe",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.2"
        },
        {
          "name": "anyhow",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "chrono",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "clap",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "rand",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "serde",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "bench/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "github.com/bmatcuk/doublestar/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.10.0"
        },
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.5"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.9.2"
        },
        {
          "name": "github.com/pressly/goose/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.27.1"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.23.2"
        },
        {
          "name": "github.com/quic-go/quic-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.60.0"
        },
        {
          "name": "github.com/vmihailenco/msgpack/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.4.1"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.14.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "lukechampine.com/blake3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.49.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 64,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 24,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "liu1700",
          "commits": 69,
          "avatar_url": "https://avatars.githubusercontent.com/u/6064238?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.972
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "go.yml",
        "orlop-cli.yml",
        "posix.yml",
        "release.yml",
        "shellcheck.yml",
        "upgrade.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "25 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ed03ccff5c60cb5db1c1143116316f07ad171a46",
        "ran_at": "2026-07-28T08:19:06Z",
        "aggregate_score": 3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T06:03:44Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T05:57:45Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/liu1700/orlop",
    "host": "github.com",
    "name": "orlop",
    "owner": "liu1700"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 54,
      "inputs": {
        "security": 30,
        "vitality": 70,
        "community": 33,
        "governance": 59,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 71,
              "human_commit_share": 1,
              "days_since_last_push": 2,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "71 commits in the last year",
                "points": 16.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 71
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 11,
              "latest_release_tag": "v0.4.5",
              "releases_from_tags": false,
              "days_since_latest_release": 2,
              "mean_days_between_releases": 3.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "11 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.972
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 97% of commits",
                "points": 0.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 64,
              "open_issues": 0,
              "closed_issues": 24,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "64/65 decided PRs merged",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 64,
                      "decided": 65
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "followers": 50,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "liu1700",
              "public_repos": 52,
              "account_age_days": 4624
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "50 followers of liu1700",
                "points": 12.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 50,
                      "login": "liu1700"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "52 public repos, account ~12 yr old",
                "points": 24.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 52
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 12
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/liu1700/orlop"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 2
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 2 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "14 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 30,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "25 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 75,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 2821
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "71 of 71 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 71,
                      "sampled": 71
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "third_party/fuser/Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.915,
              "toolchain_manifests": [
                "Cargo.toml",
                "bench/Cargo.toml",
                "go.mod",
                "third_party/fuser/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, third_party/fuser/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, third_party/fuser/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "65 of the last 71 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 65,
                      "sampled": 71
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 102445,
              "source_files_sampled": 291,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/291 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 291,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'orlop' from its registry",
    "Could not fetch crates package 'orlop-bench' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T08:19:22.659347Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/liu1700/orlop.svg",
  "full_name": "liu1700/orlop",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.