Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [
"advertising",
"ai-agents",
"cli",
"google-ads",
"marketing",
"mcp",
"model-context-protocol",
"python",
"agentic-ai",
"claude-code",
"codex",
"cursor",
"gemini-cli",
"marketing-automation",
"search-console",
"meta-ads",
"facebook-ads"
],
"is_fork": false,
"size_kb": 5725,
"has_wiki": false,
"homepage": "https://mureo.io",
"languages": {
"CSS": 46444,
"HTML": 26823,
"Jinja": 8967,
"Shell": 10757,
"Python": 7477049,
"Dockerfile": 1998,
"JavaScript": 270785
},
"pushed_at": "2026-08-01T13:05:52Z",
"created_at": "2026-03-30T22:25:22Z",
"owner_type": "Organization",
"updated_at": "2026-08-01T13:05:57Z",
"description": "Your local-first AI ad ops crew. Works with Claude Code, Cursor, Codex & Gemini.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": "https://corp.logly.co.jp/",
"name": "LOGLY, Inc.",
"type": "Organization",
"login": "logly",
"company": null,
"location": "Japan",
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/2733811?v=4",
"created_at": "2012-11-06T09:30:12Z",
"is_verified": null,
"public_repos": 7,
"account_age_days": 5016
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.10.38",
"kind": "patch",
"published_at": "2026-08-01T13:05:52Z"
},
{
"tag": "v0.10.37",
"kind": "patch",
"published_at": "2026-07-31T09:22:06Z"
},
{
"tag": "v0.10.36",
"kind": "patch",
"published_at": "2026-07-31T02:47:29Z"
},
{
"tag": "v0.10.35",
"kind": "patch",
"published_at": "2026-07-30T06:49:20Z"
},
{
"tag": "v0.10.34",
"kind": "patch",
"published_at": "2026-07-30T02:15:41Z"
},
{
"tag": "v0.10.33",
"kind": "patch",
"published_at": "2026-07-29T12:31:16Z"
},
{
"tag": "v0.10.32",
"kind": "patch",
"published_at": "2026-07-29T05:00:24Z"
},
{
"tag": "v0.10.31",
"kind": "patch",
"published_at": "2026-07-27T23:03:33Z"
},
{
"tag": "v0.10.30",
"kind": "patch",
"published_at": "2026-07-27T07:30:57Z"
},
{
"tag": "v0.10.29",
"kind": "patch",
"published_at": "2026-07-18T23:27:24Z"
},
{
"tag": "v0.10.28",
"kind": "patch",
"published_at": "2026-07-18T01:25:25Z"
},
{
"tag": "v0.10.27",
"kind": "patch",
"published_at": "2026-07-15T22:50:38Z"
},
{
"tag": "v0.10.26",
"kind": "patch",
"published_at": "2026-07-15T01:30:25Z"
},
{
"tag": "v0.10.25",
"kind": "patch",
"published_at": "2026-07-14T20:01:39Z"
},
{
"tag": "v0.10.24",
"kind": "patch",
"published_at": "2026-07-14T06:29:21Z"
},
{
"tag": "v0.10.23",
"kind": "patch",
"published_at": "2026-07-13T02:53:08Z"
},
{
"tag": "v0.10.22",
"kind": "patch",
"published_at": "2026-07-12T09:24:56Z"
},
{
"tag": "v0.10.21",
"kind": "patch",
"published_at": "2026-07-12T07:48:46Z"
},
{
"tag": "v0.10.20",
"kind": "patch",
"published_at": "2026-07-11T23:51:01Z"
},
{
"tag": "v0.10.19",
"kind": "patch",
"published_at": "2026-07-09T02:29:19Z"
},
{
"tag": "v0.10.18",
"kind": "patch",
"published_at": "2026-07-07T02:56:16Z"
},
{
"tag": "v0.10.17",
"kind": "patch",
"published_at": "2026-07-06T10:46:57Z"
},
{
"tag": "v0.10.16",
"kind": "patch",
"published_at": "2026-07-03T05:44:56Z"
},
{
"tag": "v0.10.14",
"kind": "patch",
"published_at": "2026-06-24T10:44:16Z"
},
{
"tag": "v0.10.13",
"kind": "patch",
"published_at": "2026-06-24T09:01:17Z"
},
{
"tag": "v0.10.12",
"kind": "patch",
"published_at": "2026-06-23T05:52:39Z"
},
{
"tag": "v0.10.11",
"kind": "patch",
"published_at": "2026-06-22T13:21:40Z"
},
{
"tag": "v0.10.10",
"kind": "patch",
"published_at": "2026-06-22T10:21:59Z"
},
{
"tag": "v0.10.9",
"kind": "patch",
"published_at": "2026-06-20T21:30:34Z"
},
{
"tag": "v0.10.8",
"kind": "patch",
"published_at": "2026-06-20T06:17:38Z"
},
{
"tag": "v0.10.7",
"kind": "patch",
"published_at": "2026-06-17T23:28:54Z"
},
{
"tag": "v0.10.6",
"kind": "patch",
"published_at": "2026-06-16T22:52:54Z"
},
{
"tag": "v0.10.5",
"kind": "patch",
"published_at": "2026-06-16T00:59:18Z"
},
{
"tag": "v0.10.4",
"kind": "patch",
"published_at": "2026-06-14T05:35:55Z"
},
{
"tag": "v0.10.3",
"kind": "patch",
"published_at": "2026-06-14T05:00:00Z"
},
{
"tag": "v0.10.2",
"kind": "patch",
"published_at": "2026-06-14T03:50:05Z"
},
{
"tag": "v0.10.1",
"kind": "patch",
"published_at": "2026-06-14T01:18:00Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-06-13T23:42:16Z"
},
{
"tag": "v0.9.33",
"kind": "patch",
"published_at": "2026-06-13T11:42:01Z"
},
{
"tag": "v0.9.32",
"kind": "patch",
"published_at": "2026-06-12T23:42:10Z"
},
{
"tag": "v0.9.31",
"kind": "patch",
"published_at": "2026-06-12T11:49:27Z"
},
{
"tag": "v0.9.30",
"kind": "patch",
"published_at": "2026-06-12T04:42:32Z"
},
{
"tag": "v0.9.29",
"kind": "patch",
"published_at": "2026-06-10T17:42:34Z"
},
{
"tag": "v0.9.28",
"kind": "patch",
"published_at": "2026-06-10T08:01:47Z"
},
{
"tag": "v0.9.27",
"kind": "patch",
"published_at": "2026-06-09T10:30:47Z"
},
{
"tag": "v0.9.26",
"kind": "patch",
"published_at": "2026-06-09T03:39:26Z"
},
{
"tag": "v0.9.25",
"kind": "patch",
"published_at": "2026-06-05T23:27:04Z"
},
{
"tag": "v0.9.23",
"kind": "patch",
"published_at": "2026-05-31T11:08:55Z"
},
{
"tag": "v0.9.21",
"kind": "patch",
"published_at": "2026-05-30T03:17:53Z"
},
{
"tag": "v0.9.19",
"kind": "patch",
"published_at": "2026-05-29T23:45:43Z"
},
{
"tag": "v0.9.17",
"kind": "patch",
"published_at": "2026-05-29T03:04:54Z"
},
{
"tag": "v0.9.13",
"kind": "patch",
"published_at": "2026-05-27T08:05:00Z"
},
{
"tag": "v0.9.12",
"kind": "patch",
"published_at": "2026-05-26T02:33:35Z"
},
{
"tag": "v0.9.11",
"kind": "patch",
"published_at": "2026-05-26T01:35:24Z"
},
{
"tag": "v0.9.10",
"kind": "patch",
"published_at": "2026-05-25T11:27:57Z"
},
{
"tag": "v0.9.9",
"kind": "patch",
"published_at": "2026-05-23T08:23:11Z"
},
{
"tag": "v0.9.8",
"kind": "patch",
"published_at": "2026-05-22T07:28:34Z"
},
{
"tag": "v0.9.7",
"kind": "patch",
"published_at": "2026-05-22T06:09:41Z"
},
{
"tag": "v0.9.6",
"kind": "patch",
"published_at": "2026-05-22T02:29:20Z"
},
{
"tag": "v0.9.5",
"kind": "patch",
"published_at": "2026-05-21T10:58:54Z"
},
{
"tag": "v0.9.4",
"kind": "patch",
"published_at": "2026-05-21T07:02:53Z"
},
{
"tag": "v0.9.3",
"kind": "patch",
"published_at": "2026-05-19T05:31:34Z"
},
{
"tag": "v0.9.2",
"kind": "patch",
"published_at": "2026-05-18T03:55:28Z"
},
{
"tag": "v0.9.1",
"kind": "patch",
"published_at": "2026-05-18T00:51:29Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-05-16T10:09:50Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-05-02T01:28:57Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-04-29T09:15:36Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-04-20T12:06:32Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2026-04-10T07:34:31Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2026-04-10T05:56:05Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-04-09T04:50:36Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-03-31T07:24:45Z"
}
],
"recent_commits": [
{
"oid": "fa9bcf2df1d5ce4786425cced4e8ed3ef6e34968",
"body": null,
"is_bot": false,
"headline": "chore: release 0.10.38 (#519)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-08-01T13:05:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84cd24159873741def84c35d4be6a117dccb5a85",
"body": "…gainst the real tool surface (#518)\n\nThe first live end-to-end Amazon setup produced a real 85-tool manifest,\nand checking the shipped behaviour against it exposed three defects that\nno amount of reasoning from documentation had caught.\n\nManifest location (closes #516)\n- The configure UI wrote the \n[…]\nacross all 85 tools, and\nwhite-box order and fail-closed assertions that fail against the\npre-fix code. Full suite 6940 passed with only the known\nenvironment-only failures; ruff / black / mypy clean.",
"is_bot": false,
"headline": "fix(amazon): correct the manifest location and the money guardrails a…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-08-01T12:55:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21146a3b9145fff6bbe8f6f430166f8f3278e2aa",
"body": "Document the SecretStore runtime-capability family in\ndocs/plugin-authoring.md (new section 15): the\nmureo.runtime_context_factory entry point, resolution and caching\nrules, and each store capability (credentials_write_path,\nmulti_account_auth, ui_plugin_credential_fields, the per-client\naccount allow-lists, amazon_token_saver) with their defensive-getattr\nsemantics, including the fail-closed behavior of the allow-lists on\nmulti-account backends. Adds a minimal example store and factory.",
"is_bot": false,
"headline": "docs: add multi-tenant backend authoring guide (#515)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T14:58:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a03084956766a6afc60c537ae42c1f665670efb",
"body": "…ts (#514)\n\nCloses #511. AmazonAdsBridge's default token persistence can now be\nbound by the active runtime context: a secret store may declare an\n`amazon_token_saver: Callable[[str, str | None], None]` capability\n(access_token, refresh_token), resolved at persist time by the new\n`runtime_amazon_tok\n[…]\neives the refreshed tokens with the legacy writer\nuntouched, injected-saver precedence, failure-surface parity). Full\nsuite green except the known environment-only failures; ruff / black /\nmypy clean.",
"is_bot": false,
"headline": "feat(amazon): runtime-bindable token persistence for multi-tenant hos…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T10:51:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f3afb5224231c43828c50b4b6099ea5740809dae",
"body": null,
"is_bot": false,
"headline": "chore: release 0.10.37 (#513)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T09:08:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5416d4c91069464806e566ebbd8c65109466fc96",
"body": "…path (#512)\n\nIn a multi-tenant runtime context the credentials location is\nruntime-resolved, and every loader reads through the secret-store seam —\nbut three writers still resolved path=None to the legacy per-user file,\nso their writes landed where no reader looks (silent read/write\ndivergence; a r\n[…]\nrough the runtime store,\nno-override unchanged, explicit path wins), RED-verified against the\nold code. Full suite 6741 passed with only the known environment-only\nfailures; ruff / black / mypy clean.",
"is_bot": false,
"headline": "fix(auth): route all credential writers through the runtime-resolved …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T08:54:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1abe137814d2c36f3263b1512e8ca3332e44c750",
"body": "…e.atomic_json (#507)\n\n* refactor: extract atomic-JSON helpers into mureo.core.atomic_json\n\nmureo/providers/config_writer.py is documented and default-pathed for\nClaude Code MCP settings, but ten unrelated writers had come to depend\non its private atomic-write internals. Pure move, no behavior chang\n[…]\nmove to mureo.core.atomic_json; pin the\n ConfigWriteError re-export identity.\n\nTests: 6614 passed with only the known environment-only failures;\nruff / black / mypy introduce no new findings vs HEAD.",
"is_bot": false,
"headline": "refactor: consolidate remaining atomic-JSON duplicates onto mureo.cor…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T04:22:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a84f9967fcb3972a53528a8f87b6867681bd9024",
"body": null,
"is_bot": false,
"headline": "chore: release 0.10.36 (#509)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T02:47:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "275fd2becc8454897fdd9ec32dd7feb93e712ac4",
"body": "…n expiry signal (#121) (#508)\n\nAmazon setup previously ended with \"obtain a refresh token yourself and\npaste it\". This adds the guided flow, built on the documented\ndirect-advertiser pattern (an allowed return URL like https://amazon.com\nplus manual code copy — no loopback callback, whose support L\n[…]\nmatrix, scrubber redaction and\nfalse-positive suites, asset/i18n contracts). Full suite 6728 passed\nwith only the known environment-only failures; ruff / black / mypy /\nnode --check clean.\n\nRefs #121.",
"is_bot": false,
"headline": "feat(amazon): guided paste-code authorization wizard and refresh-toke…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-31T01:05:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8273da3096e7ebb120c1000d2806d972498dc75c",
"body": "…s) (#506)\n\nOpenAI and Codex providers advertised max_size [1536, 1536], but GPT\nImage cannot generate a 1536x1536 square — the real menu is 1024x1024 /\n1536x1024 / 1024x1536. No downstream code computed with max_size, so\nthis is an honesty fix:\n\n- capabilities() gains an optional supported_sizes ke\n[…]\nt max_size\nequals the per-axis maxima, clamp targets subset of the advertised\nmenu, providers_list passthrough). Full suite green except the known\nenvironment-only failures; ruff / black / mypy clean.",
"is_bot": false,
"headline": "fix(creative-studio): report honest size capabilities (supported_size…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T22:04:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "05f7db40290aa1590a2c804cc7f3029116530ab5",
"body": "mureo/providers/config_writer.py is documented and default-pathed for\nClaude Code MCP settings, but ten unrelated writers had come to depend\non its private atomic-write internals. Pure move, no behavior change:\n\n- New mureo/core/atomic_json.py with the public trio\n load_existing_json / atomic_write\n[…]\nng, failure leaves the original intact,\n malformed raises) and pins the re-export identity.\n\nCloses #500.\n\nTests: 6613 passed with only the known environment-only failures;\nruff / black / mypy clean.",
"is_bot": false,
"headline": "refactor: extract atomic-JSON helpers into mureo.core.atomic_json (#505)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T21:55:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "277b34932321e946db98106ca6fdcf99093e7d68",
"body": "…(#504)\n\nAmazon Ads shipped as a mureo-mediated official-MCP bridge, but the\ndocumentation still presented it as absent or \"Planned\". This sweep\nbrings every doc and skill surface in line with the code:\n\n- README(.ja): Amazon in every platform enumeration, a connection\n section, and honest notes (m\n[…]\ntics/BYOD overclaims; en/ja parity; skills mirrors byte-identical.\nSkill contract suites pass.\n\nRefs #121. Depends on the safety-core branch (pattern fallback,\nMUREO_DISABLE_AMAZON_ADS) landing first.",
"is_bot": false,
"headline": "docs: present Amazon Ads as a first-class platform everywhere (#121) …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T12:17:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "18644d8cdb14014e007dc8307994f846582305de",
"body": "…I (#121) (#503)\n\nGives Amazon the same operator-facing surfaces Google/Meta have:\n\n- Setup wizard: amazon_ads is a selectable platform. Its credential\n step is a new generic pluginProvider slot that fetches the\n server-declared account_credential_fields at runtime and saves\n through the existing\n[…]\nsts: +35 (handler security, env mapping, asset/i18n contracts, CLI).\nFull suite green except the known environment-only failures;\nruff / black / mypy clean; node --check on all touched JS.\n\nRefs #121.",
"is_bot": false,
"headline": "feat(ux): Amazon Ads operator parity in the wizard, dashboard, and CL…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T12:08:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f281792dbf0ed0144522eb24fba7bbf2030009c",
"body": "…azon core parity (#121) (#502)\n\nAmazon rides the plugin dispatch path with a manifest that cannot carry\nmureo _meta declarations, which left several safety surfaces silently\nuncovered. This closes the code-side gaps from the first-class parity\naudit:\n\n- Budget/bid guardrail pattern fallback: mutati\n[…]\nern fallback, staleness, rollback matching,\nbridge scrubbing, wiring, CLI, status, reports. Full suite 6567 passed\nwith only the known environment-only failures; ruff / black / mypy\nclean.\n\nRefs #121.",
"is_bot": false,
"headline": "feat(safety): budget/bid pattern fallback, manifest staleness, and Am…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T11:59:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d5f8306f83a7cb15c424a12dd67d2aac069f41b",
"body": "…en mint (#121) (#501)\n\nAmazon Ads previously required hand-editing the credentials file with a\nself-obtained short-lived access token. This closes the setup-UX gap\n(issue #121 item 3, phase A — the browser OAuth wizard is a later\nchange):\n\n- The Amazon bridge now declares account_credential_fields \n[…]\nadowing, secret non-leak through the UI\nlisting, loader/env matrix, proactive mint bounds, status row). Full\nsuite 6417 passed with only the known environment-only failures;\nruff / black / mypy clean.",
"is_bot": false,
"headline": "feat(amazon): configure-UI setup, env-var fallback, and first-use tok…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T10:25:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f9ee84f8d30315d1feb6cd0431443cfea49b5956",
"body": "…(#113) (#499)\n\n* feat(amazon): Phase 1 — Amazon Ads via official MCP, mureo-mediated bridge (#113)\n\nmureo sits in the request path (Claude → local mureo → Amazon hosted\nMCP), like mureo-native Google/Meta: credentials in\n~/.mureo/credentials.json (Claude never sees them), and Amazon calls\ninherit t\n[…]\nurrency: 4 passed; full suite\ngreen except the known environment-only failures. black / ruff / mypy\nclean on the CI gates.\n\n* test(amazon): skip POSIX 0600 mode assertions on Windows (repo convention)",
"is_bot": false,
"headline": "feat(amazon): Amazon Ads via the official MCP, mureo-mediated bridge …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T09:12:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4a22df56e38567adbcd7ce1bc8b07795acf94d11",
"body": "* feat: Codex CLI image provider for Creative Studio (no API key)\n\nCreative Studio assumed a hosted-API key for every provider. Teams that\ngenerate images through the locally-installed Codex CLI (ChatGPT login,\nno API key) had no way to point Creative Studio at it. New built-in\nprovider \"codex\" clos\n[…]\negression test proves a metacharacter-laden prompt\n (\" & % ^ |) arrives as one byte-identical argv element.\n\n34 tests in the provider file (169 -> 175 in creative_studio/);\nblack / ruff / mypy clean.",
"is_bot": false,
"headline": "feat: Codex CLI image provider for Creative Studio (no API key) (#497)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T08:51:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed27dc273ffba2c8fc980a1fbf1b7631516496c6",
"body": "Bump the version on all 55 surfaces and cut the 0.10.35 CHANGELOG\nsection.\n\nHighlights:\n- /daily-check is incremental by default: analytics-first gathering,\n scoped action_log reads, diff-first reporting with the Action-needed\n safety rule, deep mode on demand with a weekly recommendation, and\n evaluation records that close pending observations (#495)",
"is_bot": false,
"headline": "chore: release 0.10.35 (#496)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T06:49:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45855569ca103b81bd9847ceccc2629bde6513b1",
"body": "Field feedback: /daily-check burned too much context (raw pulls from\nevery platform every run) and its report repeated unchanged items\ndaily. The previous run's summary was already persisted to\nreports.daily — this turns it into the diff anchor.\n\nTwo modes\n- Incremental (default): analytics-first da\n[…]\nat the fields carry behavioral weight.\n\nTests: 6270 passed with no new failures; legacy STATE.json entries\nload unchanged; default mureo_state_get output pinned byte-identical;\nmirrors byte-identical.",
"is_bot": false,
"headline": "feat: make /daily-check incremental by default (#495)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T04:50:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c36690da202c07ddef312afb57d156ca2a3eda39",
"body": "Bump the version on all 55 surfaces and cut the 0.10.34 CHANGELOG\nsection.\n\nHighlights:\n- mureo --version and a version subcommand, with a drift guard pinning\n __version__ to pyproject (#490, fixes #487)\n- Google SDKs no longer imported eagerly by the CLI: zero\n FutureWarnings on py3.10 for every \n[…]\n3, fixes #486)\n- No-credentials quickstart smoke: shared script + CI workflow with a\n weekly from-PyPI variant (#493, fixes #488)\n- README: TikTok Ads connector and configure-first quick start (#489)",
"is_bot": false,
"headline": "chore: release 0.10.34 (#494)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T02:15:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6e09bfb4ed4bf5ab2c42d405feb8df436df1e670",
"body": "…ke (#493)\n\nEvery CLI command on Python 3.10 printed two google FutureWarnings at\nimport time, and nothing guarded the README's no-credentials\nquickstart against regressions.\n\nLazy Google SDK imports (#486) — root fix, no warnings filter\n- Two eager chains removed: mureo/auth.py imported the Google \n[…]\n-to-end (both pythons, including a claude-off-PATH run\n exercising the hand-merge fallback).\n\nTests: 6240 passed with no new failures; black / ruff / mypy at the\nmain baseline.\n\nFixes #486\nFixes #488",
"is_bot": false,
"headline": "fix: stop the CLI importing Google SDKs eagerly, add a quickstart smo…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-30T01:56:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0774e37711573b1e397e862db04240baacf08acf",
"body": "…#492)\n\n* docs: quick start now says to pick the demo scenario and skip OAuth\n\nThe quick start opened with \"no credentials, no OAuth\" but then sent\nthe reader into mureo configure, whose UI also shows a platform-\nconnection (OAuth) step — an apparent contradiction. Both READMEs now\nsay explicitly: c\n[…]\n Japanese-site note and the redundant free-to-use line\n\nmureo.jp is getting an English version, and open-source in the\nheadline plus the license badge already say what Apache 2.0 / free\nwas repeating.",
"is_bot": false,
"headline": "docs: quick start now says to pick the demo scenario and skip OAuth (…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T23:16:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ded46317635cad6d50fa96bebea610d13a74fdd1",
"body": "… (#491)\n\nThe Japanese README read like machine translation in places. Applied\nthe house style guide across the whole file:\n\n- Removed every em dash: term-definition bullets now use a full-width\n colon, inline dashes became punctuation\n- Removed interpunct-joined lists (A・B・C) in favor of commas or\n[…]\n-> 制御基盤, aligned the tagline\n with the wording already used on mureo.jp\n- Rewrote image alt texts as full sentences\n\nStructure, headings used as anchors, links, tables, and code blocks\nare unchanged.",
"is_bot": false,
"headline": "docs: rewrite README.ja.md to follow the Japanese writing style guide…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T21:57:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f45e25887be125394598b93c1789bd1eb8a0ca4a",
"body": "Checking the version is the first command a developer runs after\ninstalling, and what bug reports ask for — yet mureo --version errored\nwith \"No such option\".\n\n- Standard Typer eager --version option on the root app and a\n `mureo version` subcommand alias, both printing `mureo <version>`\n (one pla\n[…]\n1 new CliRunner tests (exit codes, exact patched output for\nboth surfaces, fallback path, bare-invocation regression, tagline).\nFull suite unchanged apart from the known env-only failures.\n\nFixes #487",
"is_bot": false,
"headline": "feat: add mureo --version and a version subcommand (#490)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T21:29:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3a571b6f78000e54249cff52b5708e6afb8bb6a",
"body": "* docs: mention TikTok Ads support in both READMEs\n\nTikTok Ads has shipped as the tiktok-ads-official provider (TikTok's\nofficial hosted MCP, added via mureo configure / mureo providers add,\nfirst-class tiktok_ads platform key in workflows and reports) but the\nREADMEs never mentioned it. Add it to t\n[…]\nAPI, and hosts sections led with raw commands.\nReorder so configure is the primary path everywhere it applies, with the\nterminal command kept as a one-line scriptable equivalent. English and\nJapanese.",
"is_bot": false,
"headline": "docs: mention TikTok Ads and lead setup with mureo configure (#489)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T14:29:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bf31ebe533917187dacfef5d41e1ec0fc9c42cac",
"body": "…#485)\n\n* docs: restructure README around a single no-credentials quick start\n\nThe README had grown to 1,261 lines with setup instructions repeated in\nfour different forms and a 500-line tool table duplicating docs/mcp-server.md.\nA first-time visitor faced three mode/host decisions before seeing wha\n[…]\nhost table, and a reference section linking to the docs/ guides.\n708 -> 355 lines; reuses the existing Japanese translations for the\nretained sections (Features, Workflow Commands, samples, security).",
"is_bot": false,
"headline": "docs: restructure README around a single no-credentials quick start (…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T14:13:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c850a1bd794eac82153f7d2863e03b0a870b779b",
"body": "Bump the version on all 55 surfaces and cut the 0.10.33 CHANGELOG\nsection.\n\nHighlights:\n- Advice gated on delivery state: /daily-check delivery-state guard,\n platform-independent not-running exclusion in /ad-fatigue-check\n (#482, fixes #479)\n- External-change diff hardened: campaign-status diff, c\n[…]\nred-vs-stored comparison, Status vocabulary contract, reported\n skips (#482, fixes #480)\n- plugin:<dist> as the one canonical plugin platform key, single-sourced\n and hijack-proof (#483, fixes #481)",
"is_bot": false,
"headline": "chore: release 0.10.33 (#484)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T12:31:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cdf40178193763ffa3aa9c39a1d285d6b3de3031",
"body": "…(#483)\n\nA plugin platform's data could be written into STATE.json under one\nkey and read back under another: STATE.json, action_log, and the\ndashboard agreed on plugin:<dist>, while the analytics registry\nreported the entry-point name. The two identifiers never reconciled,\nso persisted state and an\n[…]\nately; no bridge code change needed.)\n\nTests: 6210 passed, no new failures; hijack, reserved-prefix, and\nduplicate-distribution cases pinned. black / ruff clean; mypy at the\nmain baseline.\n\nFixes #481",
"is_bot": false,
"headline": "fix: make plugin:<dist> the one canonical plugin platform key (#481) …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T10:18:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d44f5056b31ee68a75296ba48a0c7e7e2fed55f",
"body": "…reliable (#482)\n\nSkills-and-tests-only follow-up to #468, closing #479 and #480.\n\nDelivery-state guard (#479)\n- /daily-check gains a Delivery-state guard next to the Learning-state\n guard: an entity that was not delivering for part of the period is\n Watch at most, never Action needed on efficienc\n[…]\n to report.\n\nTests: 10 new skill-contract tests (mutation-verified: all fail\nagainst the pre-fix wording). Full suite 6179 passed with no new\nfailures; mirrors byte-identical.\n\nCloses #479\nCloses #480",
"is_bot": false,
"headline": "fix: gate advice on delivery state and make the external-change diff …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T09:28:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d02337299e1758e5543e07165e02016eee3f7084",
"body": "Bump the version on all 55 surfaces and cut the 0.10.32 CHANGELOG\nsection.\n\nHighlights:\n- Two-tier /learn completed: workspace-tier insights are read by\n mureo_learning_insights_get, new mureo learn tiers subcommand,\n /learn scope selection (#475)\n- Ad-level delivery status in the standard flows: Meta status fields\n actually requested, STATE.json AdState audit trail, /sync-state and\n /daily-check ad-level diffs, BYOD freshness envelope, untrue\n description claims removed (#477, fixes #468)",
"is_bot": false,
"headline": "chore: release 0.10.32 (#478)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T05:00:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "324ac37a92f18a2035e58731936fa6f717b17f38",
"body": "Manual changes made in the platform UI were invisible to mureo: the\nstandard flows never fetched ad-level (creative-level) delivery state,\nso an ad paused by hand kept being treated as delivering — and advice\nbuilt on that state could mislead. Manual operation and mureo-driven\noperation coexist, esp\n[…]\n the 800-line guideline).\n\nTests: 6169 passed (+13 in the review round; 502 targeted), legacy\nbyte-identity pinned, JST frozen-clock coverage for as_of stamping.\nblack / ruff / mypy clean.\n\nFixes #468",
"is_bot": false,
"headline": "fix: surface ad-level delivery status in standard flows (#468) (#477)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-29T01:50:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d452f70d584af0475b58fb2ec4ea21f4c1290d20",
"body": "The KnowledgeStore Protocol has had a workspace tier on the write side\n(mureo learn add --scope workspace) with no production reader, so\nworkspace-scoped insights were invisible to every diagnostic workflow.\nClose the loop on both sides:\n\n- mureo_learning_insights_get now reads BOTH tiers. When the \n[…]\ne per-call; both are\nnow pinned by dedicated tests. Tool schema unchanged (still zero\narguments).\n\nTests: 38 targeted (+15 new), full suite 6108 passed with no new\nfailures. ruff / black / mypy clean.",
"is_bot": false,
"headline": "feat: complete the two-tier /learn loop with workspace-tier reads (#475)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-28T04:20:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f18f42bfc83f30d0fb0815ceabb2ce02552fd358",
"body": "Bump 0.10.30 -> 0.10.31 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nallocation and learning-state diagnostic discipline (#465), end-to-end Meta\nvideo creatives (#467), the server-clock injection that stops daily checks\nrunning on \n[…]\nin extraction with streaming video upload (#472) changes merged since\n0.10.30.\n\nNo entry text was changed: the [Unreleased] body moved verbatim into\n[0.10.31], leaving the empty [Unreleased] skeleton.",
"is_bot": false,
"headline": "chore(release): 0.10.31 (#474)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T23:03:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d42e9ddfabd5e127afb459b331df2b36d3803a6f",
"body": "Splits the /advideos machinery out of _creatives.py (939 -> 789 lines;\nnew _videos.py 208, mixin count 16 -> 17 in docs) with zero\ncross-imports. Behavioral part: upload_ad_video_file no longer\nmaterializes up to 1 GB in memory — the open file handle streams\nthrough the shared request machinery, and\n[…]\n attempt so retries resend identical bytes; an unseekable\npart now fails loud with RuntimeError instead of risking a silently\ntruncated retry body. Wire shape, timeout and size-cap behavior\nunchanged.",
"is_bot": false,
"headline": "refactor(meta): extract VideosMixin and stream video uploads (#472)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T22:10:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2030f3e0a61237bc9bcbd423435d4f0c3091e63c",
"body": "…Slot (#473)\n\nThe host check is done inline where needed (state.host comparisons in\nauth_wizards_meta.js and the codex branches); this binding was never read.",
"is_bot": false,
"headline": "refactor: remove unused onDesktop declaration in buildProviderInstall…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T21:42:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "abb26d6aac7229d8ce1bac93c8f9ff2425af334c",
"body": "auth_wizards.js exceeded the 800-line budget (1248). The Meta-specific\nregions (hosted-connector setup card, connection-method chooser,\nsystem-user token card) move verbatim to auth_wizards_meta.js (539\nlines; main file now 734), published via the established\nwindow.MUREO_AUTH_META namespace pattern\n[…]\nsure and now takes (wrap, state, providerId), plus the call sites.\nStatic allowlist gains the new filename; wheel packaging verified.\nAsset tests read the concatenated pair; no assertion text changed.",
"is_bot": false,
"headline": "refactor(web): split the Meta auth step into auth_wizards_meta.js (#471)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T21:25:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2d0f5b3335a0b0d010af4360cab39bb65c0dfe33",
"body": "…itive skills (#470)\n\nCompletes the #460 follow-up: the step-0 \"establish the current date\nfrom server_now\" discipline added to daily-check, sync-state and\nbudget-pacing in #469 now covers every skill that computes a date\nwindow or writes observation_due — weekly-report, monthly-report,\ngoal-review,\n[…]\n the two remaining creative-studio manifest created_at\nsites onto mureo.core.clock (display-only field; verified no consumer\nparses it), with a guard test asserting the module carries no second\nclock.",
"is_bot": false,
"headline": "fix(skills): roll the server_now date discipline across all date-sens…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T21:17:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9ba62322bb53ab0495ba255d8cc6c4f8e906c695",
"body": "… stale date (#469)\n\nAgents running /daily-check could adopt a days-old notion of \"today\"\nfrom the dates already sitting in STATE.json (reports.*.period,\nlast_synced_at, action_log timestamps) and short-circuit with a\nre-display of an old report instead of fetching fresh data. Nothing in\nmureo injec\n[…]\nls\n- Two observation-window tests that compared against the real UTC\n wall clock are frozen onto the injected clock (they failed\n deterministically on positive-offset hosts during local small hours)",
"is_bot": false,
"headline": "fix(context): inject the server clock so daily checks cannot run on a…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T20:08:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6e1facb49b8beaba1ec96168646a6878a42ba9ee",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\ny: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Hirokazu Yoshinaga <4027404+hyoshi@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#466)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T12:07:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6e2484a44dd975c35f3ae9780824b48935151fe5",
"body": "Video was half-built: uploads existed but only Lead Ads could build a\nvideo creative, videos could not be status-polled or thumbnailed, and\nthe local-file upload path predated the shared client machinery. A\nfield report confirmed video creative submission was impossible for\nstandard objectives.\n\n- c\n[…]\np-by-step video\n creative flow (upload -> poll -> thumbnail -> creative -> ad), and\n the tool-summary table completed to all 88 tools (five pre-existing\n tools were missing from the numbered table)",
"is_bot": false,
"headline": "feat(meta): end-to-end video creative support (#467)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T11:39:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a96ae7d243c36407876090605cafabcc88da7349",
"body": "Add three cross-platform principles to the pro-diagnosis framework\ncatalogue, grounded in documented Meta and Google Ads delivery\nmechanics:\n\n- Judge by marginal efficiency, not averages: automated delivery\n spends the cheapest inventory first, so average-CPA rankings misfire\n in both directions; \n[…]\nll's routing description; the audience-review worked\nexample is updated to match the new discipline. Mirrors kept\nbyte-identical; pro-diagnosis stays canonical-only per the /learn\nwrite-path contract.",
"is_bot": false,
"headline": "docs(skills): allocation and learning-state diagnostic discipline (#465)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T08:26:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8faa542fca427145144ae3d9716f138c9b4b3c0e",
"body": "Bump 0.10.29 -> 0.10.30 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nMeta pixels_create (#451), bidding controls and pages_list (#452), targeting\ndiscovery (#453), strict input schemas (#454), bid-cap guardrails (#455),\nplugin bid \n[…]\nder Added (a later PR's section header orphaned it into Changed), and\nthe adimages fix (#463), which was written into the already-released [0.10.29]\nsection, into [0.10.30]. No entry text was changed.",
"is_bot": false,
"headline": "chore(release): 0.10.30 (#464)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T07:30:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21a9ffc8cafd7d667c4400816e6eabf38ad38a9c",
"body": "…(#463)\n\nmeta_ads_images_upload_file returned 400 for every file. Even a\nprovably well-formed multipart request (correct boundary, image/* part\nContent-Type, raw binary) was rejected by Graph /adimages with\nFileTypeNotSupported (subcode 1487411), so the multipart approach was\nabandoned in favor of t\n[…]\ness_token form\n field)\n- Tests pin the bytes wire shape, Bearer-only auth, 60s timeout,\n identical body on retry, non-ASCII path handling, and the Meta error\n round-trip with the real-world subcode",
"is_bot": false,
"headline": "fix(meta): switch adimages file upload to the base64 bytes form body …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T07:13:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "73b0dca776f3351f4eb1801150025071fe1f916c",
"body": "…(#462)\n\nField feedback: the Meta auth step showed the prominent Login with\nFacebook button with the token card collapsed below, so operators who\nmust use a system-user token (Live apps, where OAuth can never\ncomplete) clicked OAuth anyway. The two paths are mutually exclusive\nalternatives and the U\n[…]\n keys are unchanged (stable contract\n for downstream extensions); the OAuth timeout hint wording follows\n the new layout\n- Card construction decomposed into helpers within the function-size\n budget",
"is_bot": false,
"headline": "feat(web): present Meta auth as an explicit either/or method chooser …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T07:01:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1280ece096e769bc9c4236fc5496ee00131be9c9",
"body": "…optional (#461)\n\nAfter Validate, the account select was populated with probed accounts\nonly — no placeholder — so the browser silently pre-selected the first\naccount and Save persisted it even if the operator never opened the\ndropdown. The picker now defaults to a \"Select an ad account (optional)\"\n\n[…]\n so tokens that reach\nzero ad accounts failed Save with a spurious 400 account_not_accessible.\n\nTests: placeholder/default pinning, absent/null/blank account_id save\npaths, prior-selection carry-over.",
"is_bot": false,
"headline": "fix(web): make the Meta token card's ad-account selection explicitly …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-27T05:46:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b1967e76d55b1c267a7037af3b011a3b8b5332aa",
"body": "…I (#459)\n\nLive-mode Meta apps cannot complete OAuth from the localhost configure\nUI (Facebook rejects the localhost redirect on Facebook's own page, so\nthe callback never fires), while dev-mode apps cannot create ad\ncreatives (Marketing API subcode 1885183) — a dead end either way.\nThe escape is a \n[…]\nirement,\n BM guide, configure-UI path)\n\nSecurity review: no CRITICAL/HIGH; token never echoed in any response,\nnever logged, redacted from error strings; multipart/DOM insertion via\ntextContent only.",
"is_bot": false,
"headline": "feat(web): first-class Meta system-user token path in the configure U…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-24T20:05:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "34c0a8bf651212c0b2424414ad0e581f065f04a6",
"body": "…larations.py (#457)\n\nPure move, zero behavior change: BudgetDeclaration, BidDeclaration,\ntheir registries and register/lookup/reset helpers, and the shared\ndeclared-key readers (_Unreadable, _saturate, _declared_amount) move to\na new sibling module, bringing strategy_gate.py from 877 back under the\n[…]\nry dicts stay identical objects across both module paths.\nInternal callers (plugin_semantics, server registration) repoint at the\ncanonical module. Existing gate and declaration test files unmodified.",
"is_bot": false,
"headline": "refactor(policy): extract declaration machinery into mureo/policy/dec…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T10:55:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bea7b4c0e1b3a8041bc1911954feb97f27b1a22d",
"body": "…ardrails (#456)\n\nThe bid-cap guardrails (#455) scan only the builtin keys (bid_amount,\ncpc_bid_micros), so a plugin bid tool using different argument\nvocabulary was silently unenforced — the same gap BudgetDeclaration\n(#414) closed for budgets.\n\n- BidDeclaration(bid_amount_key, cpc_bid_key, micros)\n[…]\ns a bid-declaration subsection\n\nNote: strategy_gate.py now exceeds the 800-line budget; extracting the\ndeclaration machinery (budget + bid) into a sibling module is planned\nas a follow-up refactor PR.",
"is_bot": false,
"headline": "feat(policy): plugin bid declarations so custom bid keys reach the gu…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T10:18:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df8053a6118c5f585b5b1cede31b18dd7148bd74",
"body": "…id_micros (#455)\n\nThe bidding controls added in #452 exposed bid_amount (Meta ad sets)\nand the pre-existing cpc_bid_micros (Google ad groups) with no\nSTRATEGY.md guardrail — an agent could set an arbitrarily high bid cap\nwithout any policy check, unlike budgets.\n\n- New optional Guardrails fields: m\n[…]\n2\n wire-reachability tests (json.loads-constructed args) across all four\n capped channels\n- STRATEGY.md skill docs updated with currency-annotated examples\n demonstrating the minor-units convention",
"is_bot": false,
"headline": "feat(policy): bid-cap guardrails for Meta bid_amount and Google cpc_b…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T09:35:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "16b91400ad49889c1403e61f7fa2cd330d83e49e",
"body": "…hemas (#454)\n\nUnknown parameters used to pass schema validation and be silently\ndiscarded by handler whitelists — a field-reported footgun where a\ncaller's misspelled or unsupported argument produced no error and no\neffect. Every builtin tool schema (203 across 9 registries; 197 fixed\nhere, 6 alrea\n[…]\nink_text, RSA campaign_id, landing-page\n url, creatives image_url, and the create_dynamic required set;\n mirrored into mureo/_data/skills/\n- CHANGELOG: breaking for callers relying on typo-tolerance",
"is_bot": false,
"headline": "feat(mcp): enforce additionalProperties: false on all builtin tool sc…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T08:55:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "65a23e4add7260c21c857e3cb5f60644c5f6850d",
"body": "…talogues (#453)\n\nAgents could not resolve Meta's internal targeting IDs (interests,\nbehaviors such as \"Facebook Page admins\") needed to build ad-set\ntargeting specs. Adds two read-only tools backed by the Graph API\nroot /search endpoint via a new TargetingMixin:\n\n- meta_ads_targeting_search: keywor\n[…]\n and limit; inputs validated at the\n boundary (empty query / unknown class fail fast); schemas declare\n additionalProperties: false\n- Tool counts 201 -> 203 (Meta Ads 84 -> 86) across tests and docs",
"is_bot": false,
"headline": "feat(mcp): Meta targeting discovery — interest search and category ca…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T07:12:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41d67db8f2893c6d011e5a86054680e77e7686c6",
"body": "…oted_object, pages_list (#452)\n\nAnswers a field report where automated bidding could not be configured\nand non-CBO (ad-set-level budget) campaigns could not be created.\n\n- bid_strategy (LOWEST_COST_WITHOUT_CAP / LOWEST_COST_WITH_BID_CAP /\n COST_CAP / LOWEST_COST_WITH_MIN_ROAS) on campaigns create/\n[…]\n silently\n dropped\n- Read side: campaigns list/get return is_adset_budget_sharing_enabled;\n ad_sets list/get return promoted_object\n- Tool counts 200 -> 201 (Meta Ads 83 -> 84) across tests and docs",
"is_bot": false,
"headline": "feat(mcp): Meta bidding controls — bid_strategy, ad-set budgets, prom…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T06:02:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ec3c0fbc9dbb2269eb9ed73547ee1bf30f85eeaa",
"body": "…451)\n\nAdd a mutating MCP tool that creates a Meta Pixel on an ad account via\nGraph API POST /act_{ad_account_id}/adspixels.\n\n- PixelsMixin gains create_ad_pixel(name) with non-empty-name validation\n (the mixin is no longer read-only; _post stub added)\n- New handler handle_pixels_create following t\n[…]\n: client path/body assertions, empty-name rejection, handler\n success / missing-name / missing-credentials / API-error round-trip\n- Tool counts bumped 199 -> 200 (Meta Ads 82 -> 83) in tests and docs",
"is_bot": false,
"headline": "feat(mcp): add meta_ads_pixels_create tool for Meta Pixel creation (#…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-23T01:51:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "527bf0308c32d4493959fb4dba5ef0e10cf8a23b",
"body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.3.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b\n[…]\ny: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Hirokazu Yoshinaga <4027404+hyoshi@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-python from 6.3.0 to 7.0.0 (#450)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-21T22:05:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "35c916d5b530c0a07d64a036b11dbe53638e315b",
"body": "…#449)\n\nBumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.14.0 to 1.14.1.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-21T06:29:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8e15a3431834714c4a0556e4033786e14b1d5339",
"body": "Bump 0.10.28 -> 0.10.29 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nSearch Console site_url schema fix (#447/H1) and the full documentation refresh\n(#446) merged since 0.10.28.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "chore(release): 0.10.29 (#448)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T23:23:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5678dd8002dabb5014090a72f9ad916e94baff55",
"body": "…e works (H1) (#447)\n\nEvery Search Console tool declared `site_url` in its inputSchema `required`, so\n`server.handle_call_tool` rejected an omitted `site_url` at `_validate_tool_input`\nbefore the handler ran — making `_resolve_site_url`'s single-property\nauto-resolution (for a tenant-scoped multi-ac\n[…]\na that was the actual bug), updates the\n`test_required_fields` expectations, and syncs the docs/mcp-server.md required\ncolumns.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "fix(mcp): make Search Console site_url optional so tenant auto-resolv…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T23:10:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b162065b1eebee5266d72ca6b65cb8e423d99776",
"body": "…tool counts) (#446)\n\nBring the documentation back in line with the code after 0.10.28. Audited every\ndoc against the codebase; the notable drift fixed:\n\n- README / mcp-server / architecture: tool inventory corrected to 199 (Google\n Ads 86, Meta 82, SC 10, Rollback 2, Analysis 1, mureo-context 9, a\n[…]\n-web`), native\n tool counts, Codex parity, bundled foundation-skill count, skills paths.\n\nDocs only — no code or test changes.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "docs: refresh docs for 0.10.28 (native skills, analytics dispatcher, …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T22:28:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "25b1a487807b6fafcfa074220cb684f6f5ca8bea",
"body": "Bump 0.10.27 -> 0.10.28 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nplugin native-skills (#439), analytics dispatcher (#440), onboard guardrails\n(#364), GA4 multi-account gate (#442), analytics account_id scoping\n(#413/#435), atomic host snapshot (#407), and full-codebase security review\n(#441) changes merged since 0.10.27.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "chore(release): 0.10.28 (#445)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T01:24:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "13750078e69258d5df34881a3700ceec9e899968",
"body": "Address findings from a full-codebase review, spanning CRITICAL–LOW severity.\n\nSecurity\n- google_ads: validate ad_group_id in update_ad_group before it reaches the\n GAQL pre-check and resource path (C1); validate campaign/geo/criterion IDs\n in location & schedule targeting updates (H4); restrict t\n[…]\n safe fix needs a dedicated design (the\nattempted lock-across-await fix could deadlock the concurrently-dispatched\nMCP server).\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "fix: security and correctness fixes from full-codebase review (#441)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T01:12:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a1cedb6dc541713c1d0b7e9e590131742bca4e59",
"body": "…#444)\n\n* fix(#442): gate GA4 credential wizard under a multi-account backend\n\nGA4 auth is a single service account. Under a multi-account backend (a\nSecretStore declaring credentials_write_path), the Setup-tab GA4 wizard\nwrote that one SA into the shared credentials.json `ga4` section, so it\nreache\n[…]\ntAuth.\n\nThe server-side 403 (_post_env_var) is unchanged and remains the\nauthoritative boundary. Adds static-asset guard tests.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "fix(#442): gate GA4 credential wizard under a multi-account backend (…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T00:53:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a42c7b41ea2d39e7a94672e90f2e8b7392f92962",
"body": "… (#443)\n\n* feat: plugin native slash skills (#439) + analytics dispatcher (#440)\n\nTwo plugin-extension surfaces requested by the mureo-logly-bridge plugin.\n\n#439 — Deploy plugin native slash skills\n- New entry-point group `mureo.native_skills` (constant in\n core/providers/registry.py): a plugin re\n[…]\ner-module TOOLS lists. This CI failure was masked locally because the dev\nenv's agency plugin inflates the count independently.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
"is_bot": false,
"headline": "feat: plugin native slash skills (#439) + analytics dispatcher (#440)…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-18T00:04:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8f855536006500560f2ec3e7d1d66b2ddcbc495",
"body": "…64) (#438)\n\nv0.10.18's hard budget-guardrail enforcement (StrategyPolicyGate) is fail-open\nand had no onboarding prompt, so it stayed dormant for operators who didn't know\nto ask. onboard now offers to seed the machine-readable ## Guardrails keys from\nthe operator's inputs, confirms every number, writes the section, and is\nskippable — with an honest note that hard enforcement covers only mureo-\ndispatched native google_ads/meta_ads (hosted/official MCPs bypass; #359).",
"is_bot": false,
"headline": "feat(onboard): proactively offer to set STRATEGY.md ## Guardrails (#3…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-16T01:37:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a54b204c0baa494129f92675854f5ad5d6eb4fe1",
"body": "…path (#435) (#437)\n\nFollow-up to #435. _open_meta_ads_client resolved account_id via the #411\nresolver, but the non-tenant-scoped path returned it verbatim — a bare\n(non-act_) id then raised a raw ValueError from MetaAdsApiClient, escaping the\nadapters' graceful except-NoCredentialsError handler. Apply the idempotent\n_canonical_meta_account_id after resolution so both paths pass (and thread\ndownstream) the act_-prefixed id.",
"is_bot": false,
"headline": "fix(analytics): canonicalize Meta account_id to act_ on the unscoped …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-16T01:13:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "742fb69fad7b897401edf61791c184fc6afc718f",
"body": "…#435) (#436)\n\nFollow-up to #413. (1) A workspace-scope refusal from the #411 resolver now\nraises AccountNotAvailableError (a NoCredentialsError subclass), so the\nAnalyticsModule adapters' existing `except NoCredentialsError` renders the\ngraceful empty sentinel instead of letting a raw ValueError es\n[…]\n (client,\nresolved_id) and all 8 fetch call sites rebind account_id, so aggregation /\nlabeling / conversion-override lookup use the same (canonicalized) id the\nclient was opened with — no format skew.",
"is_bot": false,
"headline": "fix(analytics): graceful scope refusal + thread resolved account_id (…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-16T00:49:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d00860d7e80d247d972a3202487febfb9a7f48d2",
"body": "…ist (#413) (#434)\n\nThe built-in analytics live-client helpers passed the caller account_id\nverbatim to the client factory, bypassing the workspace allow-list the MCP\nhandlers enforce. Route _open_google_ads_client / _open_meta_ads_client through\n_resolve_customer_id / _resolve_account_id: non-tenant-scoped passes through;\ntenant-scoped refuses an out-of-set id (fail-closed), so a future tool wiring a\ncaller-supplied id into the AnalyticsModule Protocol can't silently escape #411\nscoping.",
"is_bot": false,
"headline": "fix(analytics): scope live-client account_id through the #411 allow-l…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-16T00:02:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98e6dbd34082120007b52e75421df576f440a611",
"body": "Reading session.host and host_paths as two separate accesses let a\nconcurrent set_host pair one host with another host's bundle. Publish both\nunder a dedicated _host_lock and add wizard.host_snapshot(); the two handlers\nthat read the pair (_serve_status, _post_providers_install) now take one\nsnapshot. set_host builds the new bundle outside the lock (keeps the #406\nguarantee) and early-returns on a non-allow-listed host.",
"is_bot": false,
"headline": "fix(web): capture host + host_paths as one atomic snapshot (#407) (#433)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T23:31:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b070af5dd46a244cce0027677e8521565fd05663",
"body": "Bump 0.10.26 -> 0.10.27 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the report-flag changes merged since\n0.10.26 (#428 / #429 / #430 / #431).\n\nAdded — structured, localizable report-flag chips on the Reports dashboard:\nflags persisted via mureo_state_report\n[…]\nview skills author flags in this shape.\n\nChanged — mureo_state_report_set validates report flags (unknown non-custom\ncodes rejected, severities defaulted); legacy bare-string flags still pass through.",
"is_bot": false,
"headline": "chore(release): 0.10.27 (#432)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T22:50:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d11ce91b3d858ac11a60d7f23fafd6e8c1daa49",
"body": "…l-review (#431)\n\nBring the weekly-report and goal-review skills onto the canonical\n{code, severity, params} flag vocabulary (both copies each, byte-identical),\nmatching daily-check. Keeps detail in params, not baked into the code;\ndocuments the custom escape hatch. Completes the report-flag migration.",
"is_bot": false,
"headline": "feat(skills): author structured report flags in weekly-report and goa…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T09:26:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9312e7d027fe763e80457734dd7afc359c7b206e",
"body": "… (#430)\n\nUpdate the daily-check skill (both copies) to persist report flags as\nstructured {code, severity, params} objects drawn from the canonical\nvocabulary, keeping detail in params (not baked into the code) so the\ndashboard renders coarse, localizable chips with a drill-down. Documents\nthe custom escape hatch and severity buckets; legacy string flags still work.",
"is_bot": false,
"headline": "feat(daily-check): author structured report flags from the vocabulary…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T08:32:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a96ae8ba214c433e8feeb5a9e1507a1bc942671",
"body": "…(#429)\n\nLocalize report-flag chips by canonical code (dashboard.reports_flag_<code>)\nin both en and ja, colour them by the four severity buckets (adds a neutral\nis-info), and move per-flag detail (adspot ids, yen, ctr) off the chip face\ninto a click-to-expand drill-down built from the flag's params. Custom flags\nuse their author-supplied label; legacy bare-string flags still humanize.",
"is_bot": false,
"headline": "feat(web): render structured report flags as coarse, localized chips …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T08:25:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24906d4d6711e312b6bb9625d04602c97ac85772",
"body": "…ation (#428)\n\nAdd a fixed vocabulary of report-flag codes each mapped to a severity\nbucket (action/watch/info/positive), and validate/normalize a report's\n`flags` in mureo_state_report_set. Structured flags {code, severity,\nparams} keep detail in params (not the code) so the dashboard can show a\ncoarse, localizable chip; a `custom` code carries an author label for\nnovel findings. Legacy bare-string flags pass through unchanged.",
"is_bot": false,
"headline": "feat(context): canonical report-flag vocabulary with severity + valid…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T07:55:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c8ad3d607f6c548f865a28f0f28b2b7e9cab7486",
"body": "Bump 0.10.25 -> 0.10.26 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the two changes merged since 0.10.25.\n\nAdded — extensions can contribute a DashboardCard to the Reports tab (#425):\n\"reports\" joins \"advanced\" in BUILTIN_CARD_GROUPS so an extension can pla\n[…]\nhboard\ninstall read ✓ while absent. Each part is now detected on every status read;\nthe flag file is no longer written or read.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "chore(release): 0.10.26 (#427)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T01:29:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "90c591752773753c3ec8f1d38c5b3177017e7a2a",
"body": "BUILTIN_CARD_GROUPS accepted only \"advanced\", where operator *settings*\nlive. An extension that wants to offer a reporting action — \"refresh\nevery client's numbers now\", a cross-client daily-check — had no home for\nit beside the built-in report cards; Advanced is the wrong fit and a whole\nseparate t\n[…]\nensions.js CARD_GROUPS and asserts it\nequals BUILTIN_CARD_GROUPS exactly (one-sided drift fails red). Docs +\nCHANGELOG updated.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "feat(web): allow a \"reports\" DashboardCard group (#425) (#426)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-15T00:52:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8fc2b4cc114aad23abae65c582921afdaae20d36",
"body": "…ling a flag (#424)\n\nEvery row on the status snapshot is read off the filesystem — except the three\nbasic-setup rows, which came from `setup_state.json`, a record only the\ndashboard's own actions ever wrote. So the record drifted from reality the\nmoment anything else touched the filesystem:\n\n- Skill\n[…]\ninstallers through the\ndetectors rather than hand-written fixtures, so the writer and the reader cannot\ndrift apart in silence.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(configure): detect the basic-setup parts on disk instead of recal…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T22:46:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9ef734318058a9aebacb4052506314a907fb6e1f",
"body": "Bump 0.10.24 -> 0.10.25 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the two changes merged since 0.10.24.\n\nFixed — a budget declaration no longer switches off max_daily_budget_increase_pct\nor max_total_daily_budget (#418). The declaration seam (#414) replac\n[…]\nich is untrue for those shapes; it now shows the\nnormalize-and-delegate gate to register instead, and the rules it must follow.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "chore(release): 0.10.25 (#422)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T12:25:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "435ec8da21245b69ec0f5f651bad5bb52574aea7",
"body": "…dget (#417) (#421)\n\nA declaration (#414) names a TOP-LEVEL argument key. Two ordinary plugin shapes\nare outside what that can express, as #417 reports from adopting the seam:\n\n- The budget is NESTED. A native passthrough tool takes the platform's raw\n request body, so the budget is at `body.daily_\n[…]\n75) is the right extension\npoint for these shapes, and mureo's decision layer stays the single owner of\nwhat a guardrail means.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "docs: what to do when a budget declaration cannot reach a plugin's bu…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T11:31:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "79e4d6aae8a7ee5aa5ca5355363e0ffdd9afb175",
"body": "…t or total budget caps (#418)\n\nThe declaration seam (#414) replaced the built-in key scan for EVERY channel —\nincluding the two budget figures the CALLER supplies rather than the tool. A\nplugin that declared the expected, documented shape (just `daily`) therefore had\n`max_daily_budget_increase_pct`\n[…]\nhe seam in a provider plugin: declaring `daily` made the\nplugin's own percentage-cap regression test start passing calls it used to refuse.\n\nTDD, red first, in tests/test_plugin_budget_declaration.py.",
"is_bot": false,
"headline": "fix(policy): a budget declaration must not switch off the increase-pc…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T10:22:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1da1c5b74363c22dae202121c07300b00e5e1490",
"body": "Bump 0.10.23 -> 0.10.24 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the seven changes merged since\n0.10.23:\n\nSecurity — workspace-scope Meta account_id / Google customer_id on\nmulti-account backends (#411) and fail closed on non-finite / oversized\nbudgets s\n[…]\n6).\nDocs — Japanese skill triggers (#396), plugin-authoring.md refresh\n(#414), and the credentials-backup rotation note (#394).\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "chore(release): 0.10.24 (#420)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T06:28:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3356ee69ddbfa4321a49008440e450f6b17cc7a6",
"body": "…t bypass caps (#419)\n\nStrategyPolicyGate's budget extraction read a proposed budget with a bare\nfloat(). A Python int too large for float64 — int(\"9\"*309), 10**400 — makes\nfloat() raise OverflowError, which was uncaught and bubbled to\nStrategyPolicyGate.evaluate's blanket `except Exception: return\n\n[…]\napped channel, and the increase-pct-only current\ncase. Legitimate large-but-finite budgets and \"no budget proposed\" still pass.\n\nClaude-Session: https://claude.ai/code/session_01UFvgHU2TbFPPu4qckkLhNM",
"is_bot": false,
"headline": "fix(policy): fail closed on non-finite budgets so oversized/NaN canno…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T06:04:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0991cbfda4cdfccda4b68e196a9b4e4d731317e3",
"body": "…s reach them (#414) (#416)\n\nStrategyPolicyGate (#360) enforces STRATEGY.md ## Guardrails before\ndispatch, but its budget extraction is hard-wired to the built-in\nGoogle/Meta argument keys. A plugin tool that carries its budget under any\nother name was read as \"no budget proposed\" and sailed past ev\n[…]\nypes and both\nchannels, the registry, an end-to-end gate denial against a real\nSTRATEGY.md, and the server wiring.\n\nCloses #414\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "feat(policy): let plugin tools declare their budget keys so Guardrail…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T04:07:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "871fcdf914e042069b4385b2e84d96595289e507",
"body": "…ve workspace (#411) (#415)\n\nMost Meta Ads and Google Ads MCP tools take the per-account id as a free\ncaller argument, and the shared handler choke point (_get_client — every\ntool funnels through it) used it with the operator-shared credentials\nwithout validating it against the active workspace's bo\n[…]\n these\nresolvers but are unreachable from any wired tool today, are tracked as\n#413 and carry a warning docstring.\n\nCloses #411\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(security): scope Meta account_id / Google customer_id to the acti…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T03:59:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21053c9ec9d87a543504e2318eb4e7e612fbd409",
"body": "…) (#410)\n\nCreative Studio writes generated visuals and composed banners to\n<workspace>/creative_studio/<run_id>/ with a provenance manifest.json,\nbut the filesystem was the only viewer. Add a read-only gallery tab to\nthe configure dashboard.\n\nBackend — new pure data layer mureo/web/creative_gallery\n[…]\n layer (envelope, query\nforwarding, uniform 404 incl. the vanished-file branch), static-asset\nguards, i18n parity.\n\nCloses #409\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "feat(web): Creative Studio gallery tab with per-client browsing (#409…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T01:36:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "982250c54736dd632368bd6a159a406900ccfd8c",
"body": "…entials-path race (#406) (#408)\n\nThe configure server is threaded, but ConfigureWizard.set_host()\npublished the freshly rebuilt base HostPaths BEFORE re-applying the\ncredentials-path override (#194/#196). Between the two, concurrent\nrequests read — or wrote — the unresolved host-default credentials\n[…]\n pre-existing seam (handlers pairing session.host and\nhost_paths via two unsynchronized reads) is tracked as #407.\n\nCloses #406\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(web): publish host_paths atomically in set_host to close the cred…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-14T00:23:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "704a3570661b7d97ab2e9a1f771ff17231dcd27d",
"body": "…guidance (#394) (#404)\n\nInvestigation of #394 found most of it already resolved or not\nreproducible from mureo's own machinery: credentials only ever get a\nsingle rolling backup (credentials.json.bak, overwritten each save,\n0o600 via secure_chmod), the generation-accumulating timestamped mode\nis ST\n[…]\nwas considered and deferred (bounded, protected,\nsingle-generation exposure). Full analysis recorded on the issue.\n\nCloses #394\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "docs(security): document the rolling credentials backup and rotation …",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-13T03:58:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fdb57a38541d65de04c26f86a8d1af0eb3c48755",
"body": "…ptions (#396) (#403)\n\nOperators phrase requests in Japanese, but 12 older operational skills\nhad English-only description frontmatter (the skill-firing trigger\nsurface), lowering match confidence for natural Japanese asks — e.g.\nrescue only matched \"Use when the user reports a sudden CPA spike\"\naga\n[…]\n(splitting the two large foundation SKILL.md\nfiles into references/) is deferred — decision recorded on the issue.\n\nCloses #396\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(skills): add Japanese trigger phrases to operational skill descri…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-13T03:34:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd0c41b2055ef6e7f9c6ac1a62ab7d83eb20c0f4",
"body": "Bump version 0.10.22 -> 0.10.23 (pyproject, __init__, plugin.json, all\n51 SKILL.md frontmatters). Cut CHANGELOG [0.10.23] with the\ncredential-guard fix train: the guard now actually blocks via deny-JSON\n(#393), `mureo upgrade` refreshes stale installed hooks (#398), and the\ndashboard (re)install but\n[…]\ninstallations to run `mureo upgrade` once (or press\nthe configure UI's Reinstall button) to replace the old non-blocking\nhooks.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "chore(release): 0.10.23 (#402)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-13T02:52:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "816039663a0afe0776a303fc9c860ed82710f791",
"body": "…ttons (#400) (#401)\n\nThe per-row (re)install buttons on the dashboard's basic-setup section\n(credential-guard hook, workflow skills) only toasted the error\nenvelope; ok and noop reloaded status silently. On an already-installed\nrow nothing visible changes, so pressing \"Reinstall\" produced zero\nreac\n[…]\ncInstallButton\nblock in test_web_assets_dashboard_cards_and_toasts.py, following the\nhouse patterns of both files.\n\nCloses #400\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(web): toast success and noop outcomes on dashboard (re)install bu…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-13T02:39:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d82f09b8d011a23737a07fbac911583381f2498e",
"body": "…#398) (#399)\n\n#393 (PR #397) made the credential-guard installers upgrade-aware, but\nthey only run from setup — `mureo upgrade` alone left the old\nnon-blocking sys.exit(1) hooks in ~/.claude/settings.json and\n~/.codex/hooks.json forever.\n\nAdd _refresh_credential_guard() to the post-upgrade refresh,\n[…]\ntall (both surfaces + tag-outside-entries),\nabsent-file no-op, error swallowing, and _post_upgrade_refresh wiring.\n\nCloses #398\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(upgrade): refresh stale credential-guard hooks on mureo upgrade (…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-13T01:45:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a423db4f215cd1e0f4546b84893039c1672f9dc4",
"body": "…N (#393) (#397)\n\nThe PreToolUse credential-guard hooks installed into Claude Code's\n~/.claude/settings.json and Codex's ~/.codex/hooks.json used\nsys.exit(1), which both hosts treat as a NON-blocking hook error — the\ntool call proceeds. Reading ~/.mureo/credentials.json was never\nactually blocked (r\n[…]\nbling-dir\nfalse-positive guard. Installer tests cover upgrade, legacy-schema\nmigration, and both-location removal.\n\nCloses #393\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
"is_bot": false,
"headline": "fix(credential-guard): actually block credential access with deny JSO…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-13T00:48:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "411a3128791c162c3016e759f903a36eff863675",
"body": "Bump version 0.10.20 -> 0.10.22 (pyproject, __init__, plugin.json, all\n51 SKILL.md frontmatters). Restructure CHANGELOG: record the shipped\nskills-only [0.10.21] section verbatim from release/0.10.21, and cut\n[0.10.22] with the Creative Studio feature set (visual layer,\ncomposition, /creative-genera\n[…]\n0 -> 0.10.22.\n\nTest: derive the creative-generate frontmatter version pin from\nmureo.__version__ instead of a hardcoded string.\n\nClaude-Session: https://claude.ai/code/session_01DjF1BFWDKrZYTN6YWMM8Tt",
"is_bot": false,
"headline": "chore(release): 0.10.22 (#392)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T09:24:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b8212f8b1747128df4b7553a23b70aa75ca368d",
"body": "…dent-postmortem workflow skills (#391)\n\nFour new bundled workflow skills, each with a packaged copy under\nmureo/_data/skills/ and a byte-identical repo-root mirror under skills/:\n\n- experiment (A/Bテスト設計・実行・評価): turns an ad-hoc change into a\n designed experiment — a falsifiable hypothesis (variable\n[…]\nional skills); getting-started\noperational count 16->20 and upload list +4 in both languages; CHANGELOG\nUnreleased Added entry.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(skills): experiment, audience-review, ad-fatigue-check, and inci…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T07:19:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3e66e5d9d0e23d406a7d0644ece29d84cac68d4",
"body": "…flow skills (#390)\n\nThree new bundled workflow skills, each with a packaged copy under\nmureo/_data/skills/ and a byte-identical repo-root mirror under skills/:\n\n- tracking-health (計測ヘルスチェック): preventive conversion-tracking\n audit — Meta pixel inventory/health (meta_ads_pixels_list/get/stats/\n eve\n[…]\n.ja workflow tables +3 rows; CHANGELOG\nUnreleased Added entry; getting-started operational-skill count 11→16\nin both languages.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(skills): tracking-health, budget-pacing, and monthly-report work…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T06:41:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "071f97abeb65d75f1f7a8057803c8a00216a61ff",
"body": "…ix stale labels (#389)\n\n- Dedup the ~20-line learning-insights + advisor diagnostic preamble into a\n single canonical \"Diagnostic preamble\" section in _mureo-shared/SKILL.md.\n Nine workflow skills (daily-check, rescue, budget-rebalance, goal-review,\n search-term-cleanup, competitive-scan, creati\n[…]\ns name/description/version against pyproject for every\npackaged SKILL.md. All skills stay byte-identical between the two trees.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "chore(skills): deduplicate diagnostic preamble, normalize versions, f…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T06:11:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6fb4b77a62183d80e2fd1db0d4ba47bfe620c89c",
"body": "…te-aware negative space (#388)\n\nRaise the ceiling of generated visuals by systematizing prompt craft and\nenforcing composition mechanically.\n\nCode:\n- Add TEMPLATE_NEGATIVE_SPACE mapping each composer template id to one precise\n English composition sentence.\n- Extend build_visual_prompt(user_prompt\n[…]\nmplate rejection) and\ntest_creative_generate_skill.py pins (scaffold, genre presets, provider table,\ntemplate-arg instruction).\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(creative-studio): visual prompt engineering framework and templa…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T05:26:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3877a240448234e4bb6ff48db4ec58c2fd2723d",
"body": "… provider parse hardening, format dedupe (#387)\n\nM1: compose() now resolves manifest fonts via asyncio.to_thread so the\nsynchronous httpx download never blocks the event loop; ensure_font()\nnegative-caches a failed download (<filename>.unavailable, 24h TTL) so an\noffline / egress-filtered host no l\n[…]\nler defensively dedupes (order-preserving) before calling compose.\n\nAlso pins the OpenAI edit multipart request shape in tests.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "fix(creative-studio): review follow-ups — async-safe font resolution,…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T05:03:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c77574ee12eb2196e097c2231cecac434752a5a4",
"body": "…er keys (#386)\n\nAdds a first-class \"Creative Studio (image generation)\" section to the\nconfigure dashboard's Setup tab for the three image-provider API keys\n(OPENAI_API_KEY / GEMINI_API_KEY / FAL_KEY), sitting between the plugin\ncredentials card and the advanced env list.\n\nEach provider gets a labe\n[…]\neased line. Tests: i18n EN/JA parity\nclass + static-asset section-shell/wiring guards (no JS harness in repo,\nper house style).\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(creative-studio): dashboard credentials section for image-provid…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T02:50:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d20da70c31dd38d9ca262f388c67a36b93941a5a",
"body": "* feat(creative-studio): /creative-generate skill and documentation\n\nPR-C (final slice) of Creative Studio: the operator-facing surface over\nthe creative_studio_* MCP tools shipped in PR-A/PR-B.\n\n- New bundled skill creative-generate/SKILL.md (packaged copy under\n mureo/_data/skills + repo-root ski\n[…]\n: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp\n\n* test: add creative-generate to the bundled-skill remove allow-list\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(creative-studio): /creative-generate skill and documentation (#385)",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T02:22:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0e916f3d0db66131a6ce6d539032e708a50d6f95",
"body": "… font pipeline (#384)\n\n* feat(creative-studio): HTML/CSS composition engine, brand kit, and JP font pipeline\n\nPR-B of Creative Studio adds the typography & layout layer that composites ad\ncopy over the text-free key visuals produced by PR-A, plus the three new MCP\ntools that drive it.\n\nModules:\n- c\n[…]\n runners). Mirrors the accepted win32 tolerance in\ntest_web_handlers.py's spoofed-Host tests; POSIX still requires a clean\n413.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(creative-studio): HTML/CSS composition engine, brand kit, and JP…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T01:50:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6d3bb71177834512af13f79f7a780cb66eddf428",
"body": "…on tools (#383)\n\nAdd the visual layer of Creative Studio (PR-A): a pluggable, BYO-API-key\nimage-provider abstraction plus MCP tools to enumerate providers and\ngenerate text-free ad key visuals.\n\n- mureo/creative_studio/providers: ImageProvider Protocol, first-wins\n registry with fault-isolated ent\n[…]\nistration gated by MUREO_DISABLE_CREATIVE_STUDIO=1.\n- Tests: providers (mocked httpx), workspace, formats, MCP tools, env gate.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
"is_bot": false,
"headline": "feat(creative-studio): image provider abstraction and visual generati…",
"author_name": "Hirokazu Yoshinaga",
"author_login": "hyoshi",
"committed_at": "2026-07-12T00:33:34Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 72,
"commits_last_year": 498,
"latest_release_at": "2026-08-01T13:05:52Z",
"latest_release_tag": "v0.10.38",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 18,
"days_since_latest_release": 0,
"mean_days_between_releases": 1.5
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "mureo",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"advertising",
"ai-agent",
"cli",
"google-ads",
"mcp",
"meta-ads",
"orchestration",
"strategy",
"workflow",
"Development Status :: 4 - Beta",
"Intended Audience :: Developers",
"License :: OSI Approved :: Apache Software License",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Topic :: Software Development :: Libraries"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/mureo/",
"is_deprecated": false,
"latest_version": "0.10.38",
"repository_url": "https://github.com/logly/mureo",
"versions_count": 69,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 5105,
"first_published_at": "2026-04-20T12:04:45.211193Z",
"latest_published_at": "2026-08-01T13:06:31.547109Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 3,
"stars": 23,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-07-20",
"count": 1
},
{
"date": "2026-07-28",
"count": 1
},
{
"date": "2026-07-30",
"count": 1
}
],
"complete": true,
"collected": 3,
"total_forks": 3
},
"star_history": null,
"open_issues_and_prs": 3
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 138910,
"source_files_sampled": 595,
"oversized_source_files": 10,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 23836
},
"dependencies": {
"manifests": [
"pyproject.toml"
],
"advisories": {
"error": "No resolved dependencies carried a version and a supported ecosystem",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 25,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "google-ads",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=28.0,<30"
},
{
"name": "google-auth",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.28,<3"
},
{
"name": "google-auth-oauthlib",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.2,<2"
},
{
"name": "facebook-business",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=20.0,<22"
},
{
"name": "httpx",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.27,<1"
},
{
"name": "beautifulsoup4",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.12,<5"
},
{
"name": "lxml",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=6.1,<7"
},
{
"name": "pydantic",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.5,<3"
},
{
"name": "typer",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.12,<1"
},
{
"name": "rich",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=13.0,<14"
},
{
"name": "simple-term-menu",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.6,<2"
},
{
"name": "mcp",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.0,<2"
},
{
"name": "jsonschema",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.20,<5"
},
{
"name": "openpyxl",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.1,<4"
},
{
"name": "pyyaml",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=6.0,<7"
},
{
"name": "packaging",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=23.0,<26"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "beautifulsoup4",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "facebook-business",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "google-ads",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "google-auth",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "google-auth-oauthlib",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "jsonschema",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "lxml",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mcp",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "openpyxl",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "packaging",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pydantic",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "rich",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "simple-term-menu",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "typer",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "black",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "jinja2",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "playwright",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-asyncio",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-cov",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-mock",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "ruff",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 25,
"direct_count": 16,
"indirect_count": 9
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 397,
"open_issues": 3,
"closed_ratio": 0.973,
"closed_issues": 110,
"closed_unmerged_prs": 9
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "hyoshi",
"commits": 491,
"avatar_url": "https://avatars.githubusercontent.com/u/4027404?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"quickstart-smoke.yml",
"release.yml",
"security.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 3,
"reason": "dependency not pinned by hash detected -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "fa9bcf2df1d5ce4786425cced4e8ed3ef6e34968",
"ran_at": "2026-08-01T13:11:31Z",
"aggregate_score": 7.4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-08-01T13:10:47Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-08-01T13:05:48Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 104,
"created_at": "2026-05-16T08:58:30Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 121,
"created_at": "2026-05-18T23:23:40Z",
"last_comment_at": "2026-07-30T12:18:16Z",
"last_comment_author": "hyoshi"
},
{
"number": 359,
"created_at": "2026-07-06T22:51:30Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/logly/mureo",
"host": "github.com",
"name": "mureo",
"owner": "logly"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": "The weighted overall 69 is calibrated to 81 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 69,
"calibrated": 81,
"calibration": "2026-08-02"
}
}
],
"value": 81,
"inputs": {
"security": 74,
"vitality": 86,
"community": 57,
"governance": 56,
"calibration": "2026-08-02",
"engineering": 77,
"ai_readiness": 54,
"weighted_overall_raw": 69
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 86,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 76,
"inputs": {
"commits_last_year": 498,
"human_commit_share": 0.97,
"days_since_last_push": 0,
"active_weeks_last_year": 18
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "18/52 weeks with commits",
"points": 12.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 18
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "498 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 498
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "exceptional",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 72,
"latest_release_tag": "v0.10.38",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 1.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "72 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 72
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.5 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 57,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 24,
"inputs": {
"forks": 3,
"stars": 23,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "23 stars",
"points": 21.8,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 23
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "3 forks",
"points": 2.5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 3
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 62,
"inputs": {
"packages": [
"mureo"
],
"dependents": null,
"ecosystems": "pypi",
"total_downloads": null,
"monthly_downloads": 5105
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "5,105 downloads/month across pypi",
"points": 49.4,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 5105,
"ecosystems": "pypi"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 56,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 81,
"inputs": {
"merged_prs": 397,
"open_issues": 3,
"closed_issues": 110,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": 0.973,
"closed_unmerged_prs": 9,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "97% of issues closed",
"points": 40.9,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 97
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "397/406 decided PRs merged",
"points": 29.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 397,
"decided": 406
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "weak",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 49,
"inputs": {
"followers": 0,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "logly",
"public_repos": 7,
"account_age_days": 5016
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of logly",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "logly"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "7 public repos, account ~13 yr old",
"points": 18.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 7
}
},
{
"code": "account_age_years",
"params": {
"years": 13
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"mureo"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "69 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 69
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 77,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"advertising",
"ai-agents",
"cli",
"google-ads",
"marketing",
"mcp",
"model-context-protocol",
"python",
"agentic-ai",
"claude-code",
"codex",
"cursor",
"gemini-cli",
"marketing-automation",
"search-console",
"meta-ads",
"facebook-ads"
],
"has_wiki": false,
"homepage": "https://mureo.io",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://mureo.io",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "17 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 17
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 74,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 74,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 7.4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 54,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 23836
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "97 of 97 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 97,
"sampled": 97
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "weak",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 43,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.03
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "3 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 3,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 138910,
"source_files_sampled": 595,
"oversized_source_files": 10
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "10/595 source files over 60KB",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 595,
"oversized": 10
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"labels": [
"mcp-server",
"cli",
"library"
],
"scores": {
"cli": 6,
"library": 6,
"mcp-server": 7
},
"primary": "mcp-server",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:pypi",
"weight": 6
},
{
"tier": "dependencies",
"label": "cli",
"source": "dep:typer",
"weight": 4
},
{
"tier": "dependencies",
"label": "mcp-server",
"source": "dep:mcp",
"weight": 4
},
{
"tier": "structure",
"label": "mcp-server",
"source": "mcp_signal",
"weight": 3
},
{
"tier": "tags",
"label": "cli",
"source": "tag:cli",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": true
},
"metrics_version": "2.3.1"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"deps.dev does not index pypi:mureo@0.10.38; advisories assessed against the repository dependency graph instead",
"No resolved dependencies carried a version and a supported ecosystem"
],
"report_type": "repository",
"generated_at": "2026-08-01T13:11:47.694642Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/logly/mureo.svg",
"full_name": "logly/mureo",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}