Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-23 23:17 UTC

lux-db / lux

A Redis-compatable key-value store. Up to 10x faster. Native vector support.

RustMIT★ 272 estrellas⑂ 21 forksdesde mar 2026Ver en GitHub ↗

lux-db/lux tiene un índice de salud de 63 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (81/100) y la más baja, Security (49/100). Se actualizó por última vez hace 4 días. Una sola persona concentra la mayor parte del trabajo reciente.

63
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

63
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

LuxOrganización
4 seguidores2 repositorios públicosdesde mar 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
crates.iolux0.1.2167hace 3612 días
crates.iolux-cliapunta a otro repositorio; no se puntúa0.39.2543155hace 1 díaluaneovimbuildpackagemanagerluarockscommand-line-utilitiesdevelopment-tools
npm@luxdb/sdk2.10.0223725hace 5 díasluxdatabaseapplication-databaseauthtablesvectorsrealtimerediscachequeuestimeseries

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

81Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 4 días
11.1/36Cadencia de commits — 16/52 semanas con commits
18/18Volumen de commits — 359 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year359
human_commit_share1
days_since_last_push4
active_weeks_last_year16
Cómo se puntúa
27/27Publica versiones — 99 versiones publicadas
36/36Recencia de las versiones — última versión hace 4 días
27/27Cadencia de publicación — una versión cada ~0,6 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count99
latest_release_tagcli-v0.26.1
releases_from_tagsno
days_since_latest_release4
mean_days_between_releases0,6

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

58Moderado · 18% del índice global
Cómo se puntúa
39.5/60Estrellas — 272 estrellas
10.8/25Forks — 21 forks
0/15Observadores — 2 observadores
Datos de entrada utilizados
forks21
stars272
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
44.7/80Descargas mensuales — 2253 descargas/mes en crates, npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packageslux, @luxdb/sdk
dependents
ecosystemscrates, npm
total_downloads27.898
monthly_downloads2253
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

54Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
1.3/22.5Distribución de commits — el principal contribuyente firma el 94% de los commits
6.8/13.5Amplitud de contribuyentes — 5 contribuyentes
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Datos de entrada utilizados
bus_factor1
contributors_sampled5
top_contributor_share0,942
Cómo se puntúa
40.1/46.8Resolución de issues — 86% de issues cerradas
30.6/38.3Aceptación de PR — 32/40 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs32
open_issues1
closed_issues6
issue_closed_ratio0,857
closed_unmerged_prs8
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
5/25Alcance del propietario — 4 seguidores de lux-db
4.2/25Trayectoria — 2 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers4
owner_typeOrganization
is_verified
owner_loginlux-db
public_repos2
account_age_days130
Cómo se puntúa
25/25Publicado y resoluble — 2 paquete(s) en crates, npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 25 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packageslux, @luxdb/sdk
ecosystemscrates, npm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

71Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 6 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Cómo se puntúa
30/30README
0/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://luxdb.dev
10/10Descripción del repositorio
10/10Topics — 9 topics
10/10Wiki
Datos de entrada utilizados
topicslux, redis, database, embeddings, rust, vector, dragonflydb, postgres, supabase
has_wiki
homepagehttps://luxdb.dev
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

49En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — sin datos
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
1.5/7.5Vulnerabilities — 8 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4,8
Excluidos de la puntuación (sin datos o no aplicable): branch_protection. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

59Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 100 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Justfile
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — sdk/tsconfig.json
10/10Entorno reproducible — Dockerfile, Nix, lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nix
has_tests
lockfilesCargo.lock
has_dockerfile
typed_language
bootstrap_filesJustfile
has_devcontainerno
has_linter_configno
typecheck_configssdk/tsconfig.json
agent_commit_share0
toolchain_manifestsCargo.toml, cli/Cargo.toml, fuzz/Cargo.toml
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Rust (tipado estático)
49.1/55Tamaños de archivo manejables — 12/112 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageRust
largest_source_bytes291.115
source_files_sampled112
oversized_source_files12

Datos clave

272estrellas de GitHub
5contribuidores
359commits en los últimos 12 meses
4días desde el último push
99versiones publicadas
1factor bus
1issues abiertas
crates.io, npmecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • crates package 'lux-cli' points at a different repository (https://github.com/lumen-oss/lux); excluded from ecosystem scoring
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

Historial de estrellas y forks 0 ★ / 21 ⇿
0Estrellas
21Forks
71Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

48121620242152026-032026-052026-06
Mayor 0Menor 19Parche 31
OpenSSF Scorecard 4.8 / 10
4.8agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-23 23:17 UTC

10Binary-Artifactsno binaries found in the repo
n/dBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
2Vulnerabilities8 existing vulnerabilities detected
Dependencias directas 34
RegistroPaqueteRestricción de versiónManifiesto
crates.iotokio1Cargo.toml
crates.iorayon1Cargo.toml
crates.iobytes1Cargo.toml
crates.iobase640.22Cargo.toml
crates.iofutures-util0.3Cargo.toml
crates.ioparking_lot0.12Cargo.toml
crates.iohashbrown0.14Cargo.toml
crates.ioordered-float4Cargo.toml
crates.iomlua0.10Cargo.toml
crates.iosha1_smol1Cargo.toml
crates.iormp0.8Cargo.toml
crates.ioserde_json1Cargo.toml
crates.iotokio-tungstenite0.24Cargo.toml
crates.ioargon20.5Cargo.toml
crates.iobcrypt0.17Cargo.toml
crates.iojsonwebtoken10Cargo.toml
crates.iop2560.13Cargo.toml
crates.iorand_core0.6Cargo.toml
crates.ioserde1Cargo.toml
crates.iosha20.10Cargo.toml
crates.ioring0.17Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.ioclap4cli/Cargo.toml
crates.ioreqwest0.12cli/Cargo.toml
crates.iorustls0.23cli/Cargo.toml
crates.ioserde1cli/Cargo.toml
crates.ioserde_json1cli/Cargo.toml
crates.iotokio1cli/Cargo.toml
crates.iodirs6cli/Cargo.toml
crates.iocolored3cli/Cargo.toml
crates.ioopen5cli/Cargo.toml
crates.iochrono0.4cli/Cargo.toml
crates.iowebpki-roots0.26cli/Cargo.toml
npmioredis^5.0.0sdk/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "lux",
        "redis",
        "database",
        "embeddings",
        "rust",
        "vector",
        "dragonflydb",
        "postgres",
        "supabase"
      ],
      "is_fork": false,
      "size_kb": 7534,
      "has_wiki": true,
      "homepage": "https://luxdb.dev",
      "languages": {
        "Nix": 898,
        "Just": 1980,
        "Rust": 3245131,
        "Shell": 36080,
        "Dockerfile": 519,
        "TypeScript": 224622
      },
      "pushed_at": "2026-07-19T21:49:13Z",
      "created_at": "2026-03-15T18:07:32Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T20:35:03Z",
      "description": "A Redis-compatable key-value store. Up to 10x faster. Native vector support.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "https://luxdb.dev",
      "name": "Lux",
      "type": "Organization",
      "login": "lux-db",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/268421784?v=4",
      "created_at": "2026-03-15T18:06:17Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 130
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "cli-v0.26.1",
          "kind": "other",
          "published_at": "2026-07-19T21:29:40Z"
        },
        {
          "tag": "v0.32.2",
          "kind": "patch",
          "published_at": "2026-07-18T15:29:07Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-07-18T14:51:50Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-07-18T02:50:08Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-07-17T02:05:35Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-07-16T21:21:50Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-07-16T18:09:44Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-07-16T13:00:08Z"
        },
        {
          "tag": "cli-v0.26.0",
          "kind": "other",
          "published_at": "2026-07-15T19:09:15Z"
        },
        {
          "tag": "cli-v0.25.0",
          "kind": "other",
          "published_at": "2026-07-14T03:25:06Z"
        },
        {
          "tag": "cli-v0.24.0",
          "kind": "other",
          "published_at": "2026-07-14T02:55:06Z"
        },
        {
          "tag": "cli-v0.23.0",
          "kind": "other",
          "published_at": "2026-07-08T00:35:01Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-07-08T00:36:55Z"
        },
        {
          "tag": "v0.26.2",
          "kind": "patch",
          "published_at": "2026-07-07T22:01:09Z"
        },
        {
          "tag": "v0.26.1",
          "kind": "patch",
          "published_at": "2026-07-07T17:44:11Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-07-06T14:39:31Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-07-05T18:50:49Z"
        },
        {
          "tag": "cli-v0.22.0",
          "kind": "other",
          "published_at": "2026-07-05T18:45:10Z"
        },
        {
          "tag": "v0.24.6",
          "kind": "patch",
          "published_at": "2026-07-03T01:52:24Z"
        },
        {
          "tag": "v0.24.5",
          "kind": "patch",
          "published_at": "2026-07-03T00:56:18Z"
        },
        {
          "tag": "v0.24.4",
          "kind": "patch",
          "published_at": "2026-06-28T21:57:50Z"
        },
        {
          "tag": "v0.24.3",
          "kind": "patch",
          "published_at": "2026-06-28T16:03:57Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2026-06-25T00:49:27Z"
        },
        {
          "tag": "v0.24.1",
          "kind": "patch",
          "published_at": "2026-06-23T19:06:29Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-06-23T02:11:18Z"
        },
        {
          "tag": "v0.23.1",
          "kind": "patch",
          "published_at": "2026-06-23T01:35:19Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-06-22T23:31:45Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-06-22T03:45:38Z"
        },
        {
          "tag": "v0.21.6",
          "kind": "patch",
          "published_at": "2026-06-21T16:32:52Z"
        },
        {
          "tag": "v0.21.5",
          "kind": "patch",
          "published_at": "2026-06-21T03:01:41Z"
        },
        {
          "tag": "cli-v0.21.1",
          "kind": "other",
          "published_at": "2026-06-21T02:43:15Z"
        },
        {
          "tag": "cli-v0.21.0",
          "kind": "other",
          "published_at": "2026-06-21T02:09:36Z"
        },
        {
          "tag": "cli-v0.20.0",
          "kind": "other",
          "published_at": "2026-06-20T21:39:51Z"
        },
        {
          "tag": "v0.21.4",
          "kind": "patch",
          "published_at": "2026-06-20T20:21:11Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2026-06-19T18:33:45Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2026-06-19T18:12:12Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-06-19T17:49:34Z"
        },
        {
          "tag": "cli-v0.19.0",
          "kind": "other",
          "published_at": "2026-06-19T01:52:33Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-06-19T01:54:23Z"
        },
        {
          "tag": "v0.20.4",
          "kind": "patch",
          "published_at": "2026-06-18T18:34:17Z"
        },
        {
          "tag": "cli-v0.18.3",
          "kind": "other",
          "published_at": "2026-06-18T18:27:39Z"
        },
        {
          "tag": "v0.20.3",
          "kind": "patch",
          "published_at": "2026-06-18T15:15:36Z"
        },
        {
          "tag": "cli-v0.18.2",
          "kind": "other",
          "published_at": "2026-06-18T15:08:23Z"
        },
        {
          "tag": "v0.20.2",
          "kind": "patch",
          "published_at": "2026-06-18T14:18:11Z"
        },
        {
          "tag": "cli-v0.18.1",
          "kind": "other",
          "published_at": "2026-06-18T14:11:49Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-06-18T00:07:22Z"
        },
        {
          "tag": "cli-v0.18.0",
          "kind": "other",
          "published_at": "2026-06-18T00:00:41Z"
        },
        {
          "tag": "cli-v0.17.0",
          "kind": "other",
          "published_at": "2026-06-17T22:56:51Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-06-17T22:40:12Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-06-17T19:57:25Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-06-14T20:18:21Z"
        },
        {
          "tag": "cli-v0.16.0",
          "kind": "other",
          "published_at": "2026-06-14T19:46:37Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-13T18:41:59Z"
        },
        {
          "tag": "cli-v0.15.0",
          "kind": "other",
          "published_at": "2026-06-13T00:52:01Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-12T23:28:25Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-12T20:06:12Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2026-06-09T00:57:15Z"
        },
        {
          "tag": "cli-v0.14.2",
          "kind": "other",
          "published_at": "2026-06-07T21:06:01Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-06-06T15:16:31Z"
        },
        {
          "tag": "cli-v0.14.1",
          "kind": "other",
          "published_at": "2026-06-05T13:30:28Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-06-04T23:48:46Z"
        },
        {
          "tag": "cli-v0.14.0",
          "kind": "other",
          "published_at": "2026-06-04T23:31:25Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-05-30T22:30:47Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-05-30T21:44:29Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-04-19T00:07:28Z"
        },
        {
          "tag": "luxctl-v0.4.0",
          "kind": "other",
          "published_at": "2026-04-12T03:20:48Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-04-12T03:24:59Z"
        },
        {
          "tag": "luxctl-v0.3.2",
          "kind": "other",
          "published_at": "2026-04-05T01:22:56Z"
        },
        {
          "tag": "luxctl-v0.3.1",
          "kind": "other",
          "published_at": "2026-04-03T23:05:02Z"
        },
        {
          "tag": "luxctl-v0.3.0",
          "kind": "other",
          "published_at": "2026-04-03T21:57:50Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-04-03T22:04:49Z"
        },
        {
          "tag": "v0.11.2",
          "kind": "patch",
          "published_at": "2026-03-26T05:31:25Z"
        },
        {
          "tag": "v0.11.1",
          "kind": "patch",
          "published_at": "2026-03-26T05:20:23Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-03-26T04:38:21Z"
        },
        {
          "tag": "luxctl-v0.2.0",
          "kind": "other",
          "published_at": "2026-03-24T00:31:27Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-03-23T03:38:28Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-03-23T03:15:31Z"
        },
        {
          "tag": "luxctl-v0.1.3",
          "kind": "other",
          "published_at": "2026-03-22T20:00:15Z"
        },
        {
          "tag": "luxctl-v0.1.2",
          "kind": "other",
          "published_at": "2026-03-22T19:50:43Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-03-22T01:24:24Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-03-21T23:30:53Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-03-21T18:14:35Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-03-21T00:45:18Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-03-20T16:21:26Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-03-20T04:48:15Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-03-20T04:04:06Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-03-20T02:54:44Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-19T21:47:51Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-03-19T01:19:15Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-19T00:07:41Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-03-18T22:05:06Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-03-18T05:22:07Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-03-17T17:48:01Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-03-17T02:33:31Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-03-16T20:01:38Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T19:46:37Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-16T17:28:24Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-03-16T03:13:56Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-03-16T02:40:16Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "5d72ef9c35176922d780d46eeb3c86c86fe6149d",
          "body": "…(#51)\n\nThe set-op length guards were written as `const + numkeys > args.len()`,\nwhich overflows usize and panics when numkeys is huge (parse_zstore_numkeys\naccepts any u64). The nightly `command` fuzz target hit this on ~half its\nseeds (e.g. sorted_sets.rs:975). Compare as `numkeys > len.saturating_sub(N)`\nso the guard rejects the input instead of crashing. Covers ZUNION/ZINTER/\nZDIFF (+STORE) and ZMPOP/BZMPOP. Adds a regression test.",
          "is_bot": false,
          "headline": "fix(zset): overflow-safe numkeys guards in ZUNION/ZINTER/ZDIFF/ZMPOP …",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-19T21:49:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "062a75dcd10391b5ce195f366babbaf1da413802",
          "body": "The instances->projects rename removed /instances, so login/list/create/exec\n404'd. Validate login against /workspaces, resolve the token's workspace for\nproject list + create, and move /instances/:id/* to /projects/:id/*. Bump 0.26.1.",
          "is_bot": false,
          "headline": "fix(cli): repoint to /projects, resolve workspace from token (#52)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-19T21:27:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15b3027f7fe76bf950c4537d12b5c089a256df1e",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.32.2",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T15:20:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12205317e97e22275dcfbbe54cec314b5326b98b",
          "body": "* feat(push): unregister-by-token + admin stats endpoint\n\n- DELETE /v1/push/devices { token } (operator): remove a device by its token,\n  for logout-time unregister where the client has the token, not the id.\n- GET /v1/push/admin/stats (operator): process-level sends/delivered/failed/\n  devices coun\n[…]\nn scoped to the token (other device survives).\n- push_admin_routes_require_operator: a signed-in user and an unauthenticated\n  caller are both denied on DELETE /push/devices and GET /push/admin/stats.",
          "is_bot": false,
          "headline": "feat(push): unregister-by-token + admin stats endpoint (#50)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T15:19:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af957b7a4fa696a25367bbd457cf89994d0fe708",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.32.1",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T14:42:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36485f9388e88243f1aa3108886d0a83a9661695",
          "body": "The worker cached the APNs/Web Push sink by app+platform for its whole lifetime\nand never re-read credentials, so a topic/environment/key or VAPID change only\ntook effect after an engine restart. Fingerprint the resolved credentials and\nrebuild the sink when it changes, keeping the provider-token cache between\nsends. Adds a regression test.",
          "is_bot": false,
          "headline": "fix(push): rebuild the delivery sink when credentials change (#49)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T14:40:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d6edd8d9fe1aee138785f8b42c315396d6a0265",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.32.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T02:41:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02b9eb8b7a7bb9c1079961df673c6b3338802ad1",
          "body": null,
          "is_bot": false,
          "headline": "feat(push): native push notifications (APNs + Web Push) (#48)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T02:39:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f082bfafe8ccf53c683ddf60fa900f9c075c9e48",
          "body": "* feat(live): incremental view maintenance for .live() table queries\n\nEmit a typed row-delta at the table mutation leaves and maintain each\neligible live query's result from the delta by re-evaluating only the\nchanged pk, instead of re-running the whole query and diffing on every\nwrite.\n\nEligible = \n[…]\ne() clients transparently get the\nfaster path. Delta subscriptions are torn down on socket disconnect so\nthe broker's per-table channel and subscriber gate don't leak.\n\n* chore: bump version to 0.31.0",
          "is_bot": false,
          "headline": "feat(live): incremental view maintenance for .live() table queries (#47)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-17T01:52:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e92e695bb3d4974405e5049da8c19f4229ad0c3d",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.30.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T21:13:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44f581b886c8f621313c412ebc1c68dc83fa57c3",
          "body": "Add per-field expiry to hashes: HEXPIRE/HPEXPIRE/HEXPIREAT/HPEXPIREAT\n(NX/XX/GT/LT), HTTL/HPTTL/HEXPIRETIME/HPEXPIRETIME, HPERSIST, HGETEX,\nHGETDEL. StoreValue::Hash now carries an absolute-ms per-field expiry\nmap; all hash reads filter expired fields and value-setting commands\nclear a field's TTL. \n[…]\no WAL replay is deterministic; the snapshot format gains an 'h' hash\nrecord (backward-compatible with 'H') so TTLs survive save/restore. A\nhash whose last field expires is reclaimed on the next write.",
          "is_bot": false,
          "headline": "feat(hash): implement hash field TTLs (Redis 7.4)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T21:00:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd733d2e0f55d9cbe53d95dc6b671b1ef415b23c",
          "body": "Models BullMQ's Redis choreography in Rust (no JS/TS): cached-script\n(EVALSHA) add/complete/fail, blocking BRPOPLPUSH wait->active handoff,\nconcurrent exactly-once workers, event stream consumer groups, delayed-job\nzset promotion, and post-workload responsiveness. Exercises the Lua +\nstreams + blocking + multi-connection combination that regressed before.",
          "is_bot": false,
          "headline": "test(bullmq): add BullMQ compatibility regression suite",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T18:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f875ebd02bb2233293531ea4847162ea85cd9d04",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.29.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T18:02:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62bc0930f7b7e15f588d1566236d774fd289685e",
          "body": "PUBSUB CHANNELS [pattern] / NUMSUB [channel...] / NUMPAT / HELP read live\nbroker subscription state. SPUBLISH/SSUBSCRIBE/SUNSUBSCRIBE return explicit\nunsupported errors (sharded pub/sub exists for Redis Cluster, which Lux\ndoes not run) rather than unknown-command.",
          "is_bot": false,
          "headline": "feat(pubsub): PUBSUB introspection; reject sharded pub/sub",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T16:59:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6eac25430207d5d501cd07f877a091cac95b66f",
          "body": "BITFIELD applies GET/SET/INCRBY over arbitrary-width signed/unsigned\nfields at absolute or #-indexed bit offsets, atomically under one lock,\nwith OVERFLOW WRAP (default) / SAT / FAIL. SET returns the prior value,\nINCRBY the new one, FAIL yields nil. BITFIELD_RO permits only GET.\nRaw-logged as a write (keyed at args[1], deterministic on replay).",
          "is_bot": false,
          "headline": "feat(bitmap): implement BITFIELD and BITFIELD_RO",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T16:22:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10dee3adc875428a9fe37913522cc93e61ea18a5",
          "body": "BZMPOP is the blocking ZMPOP: immediate path self-logs the ZREM effect,\nblocked path polls via handle_block_zmpop and logs on wake. ZRANGESTORE\ncomputes a ZRANGE (by index / BYSCORE / BYLEX, REV, LIMIT) from src and\nstores it into dst via write_computed_zset, self-logging DEL+ZADD keyed on\ndst for c\n[…]\nediate-BZPOPMIN/BZPOPMAX durability gap found alongside:\nthe non-blocking pop path popped without logging, so replay resurrected\nthe member. Now self-logs a keyed ZREM (completes the ENG-1317 family).",
          "is_bot": false,
          "headline": "feat(zset): implement BZMPOP and ZRANGESTORE",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T16:03:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1be7fd73374c3ccd9a307c8c36b6e3b2371e0960",
          "body": "LMPOP pops up to COUNT from the first non-empty list among the keys\n(LEFT/RIGHT), self-logging the effect keyed on the popped list so a\nsharded WAL replays it correctly. BLMPOP is the blocking variant (polls,\nlogs on wake). BRPOPLPUSH is BLMOVE src dst RIGHT LEFT, reusing the move\npath incl. its blocked-completion WAL logging.",
          "is_bot": false,
          "headline": "feat(lists): implement LMPOP, BLMPOP, BRPOPLPUSH",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T15:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0545090059dc1e7c02fe5c0d52bd1d576f448640",
          "body": "DUMP/RESTORE serialize a value through the snapshot format and round-trip\nwithin Lux (not RDB-compatible); RESTORE re-keys to a caller-chosen key\nwith REPLACE/ABSTTL/TTL. TOUCH returns the existing-key count. MIGRATE and\nWAITAOF return explicit unsupported errors instead of unknown-command,\nsince they conflict with Lux topology/durability. WAIT already returned 0.",
          "is_bot": false,
          "headline": "feat(compat): implement DUMP/RESTORE/TOUCH, reject MIGRATE/WAITAOF",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T15:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e76e91779481687e7c76e8f6cb5bed98f22fc6a6",
          "body": "CREATECONSUMER/DELCONSUMER were stubs returning 1/0. Implement real\naccounting: CREATECONSUMER creates the consumer (1 new, 0 existing),\nDELCONSUMER removes it and returns its pending count, dropping those\nentries from the group PEL. Add XGROUP HELP, XINFO CONSUMERS, and reject\nduplicate XGROUP CREATE with BUSYGROUP.",
          "is_bot": false,
          "headline": "feat(streams): real XGROUP consumer lifecycle + XINFO CONSUMERS",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T15:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "050af937fed9006bfa67bea558c748de375d395b",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.28.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T12:51:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2477f6ca132af17618c6d9651bda74db7e69f62a",
          "body": "…#43)\n\n* fix: correct WAL replay for multi-key writes on sharded WALs\n\nRaw-logging a multi-key command into one WAL shard replays it out of\norder vs the other key's shard. Self-log resolved single-key effects\nkeyed to the right shard: *STORE, LMOVE/RPOPLPUSH, SMOVE, COPY.\n\n* fix: self-log MSET/MSETN\n[…]\ne_block_zpop pops straight from the store outside the WAL, so a\nblocked (or immediate) BZPOP mutated memory without a durable record and\nreplay resurrected the member. Log the removal as a keyed ZREM.",
          "is_bot": false,
          "headline": "fix: correct WAL replay for multi-key and blocked-consumer list ops (…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T04:03:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "472614042848dc6ccf8ea60ce928177393121fdc",
          "body": "ZRANDMEMBER key [count [WITHSCORES]]: no count returns a single member;\npositive count returns up to N distinct members; negative count returns\n|N| with repeats. Read-only, so no WAL concerns. Selection follows sorted-\nset order, matching the deterministic SRANDMEMBER.",
          "is_bot": false,
          "headline": "feat(zset): add ZRANDMEMBER",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T02:10:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88d305145dea866680b250c4a9ea96717551d49e",
          "body": "ZMPOP numkeys key [key ...] MIN|MAX [COUNT count] pops from the first\nnon-empty key, reusing ZPOPMIN/ZPOPMAX. It self-logs its effect as a keyed\nZREM: the raw ZMPOP would be WAL-sharded on its numkeys arg (not the key),\nlanding in the wrong shard's WAL and replaying out of order. Covered by a\nfunctional test and a crash-recovery WAL-replay test.",
          "is_bot": false,
          "headline": "feat(zset): add ZMPOP",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T01:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cda74f7786e634b23833eb9641efab3460d0a2f1",
          "body": "Direct-return sorted-set set operations alongside the existing *STORE\nvariants, with WEIGHTS/AGGREGATE/WITHSCORES and ZINTERCARD LIMIT. The\nunion/inter/diff compute is factored out of the *STORE handlers and\nshared; this also fixes a latent ZUNIONSTORE bug where AGGREGATE MIN/MAX\nseeded the accumulator with 0.0 instead of the first member's score.",
          "is_bot": false,
          "headline": "feat(zset): add ZUNION, ZINTER, ZDIFF, ZINTERCARD",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T01:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57495472f3678456bcec36802df0ee81e39915ad",
          "body": "A stub returning +OK where a client expects an integer or array silently\ncorrupts client logic. Now:\n- WAIT -> :0 (no replication), COMMAND COUNT -> real registry count\n- SELECT >0 / SWAPDB / DUMP / FUNCTION (non-LIST) -> clear unsupported errors\n- SELECT 0 -> OK; FUNCTION LIST / COMMAND INFO / LATENCY reporting -> correct\n  array shape; LATENCY RESET -> :0; RESET -> +RESET",
          "is_bot": false,
          "headline": "fix(server): honest responses for stub commands instead of fake OK",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T00:45:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7875ad59e4339a6f7623a80b665418a1ffef437a",
          "body": "A '*' server-generated timestamp was logged verbatim, so WAL replay\nre-resolved it against the recovery-time clock and the sample landed at a\ndifferent timestamp. Self-log the resolved timestamp, mirroring XADD.",
          "is_bot": false,
          "headline": "fix(timeseries): persist resolved TSADD/TSMADD timestamp to the WAL",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T20:24:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0d90b9d122d868599bc57ef3cb5646ee4731edf",
          "body": "SMOVE removed the member from the source before validating the destination\ntype, so a wrong-type dst returned WRONGTYPE with the member already gone.\nValidate the dst type first.\n\nFK cascade/restrict/set-null decoded the child's stored FK bytes as INT\nregardless of the column type, so UUID/FLOAT/STR foreign keys never matched\nand the action silently no-opped. Decode with the column's real field_type.",
          "is_bot": false,
          "headline": "fix: prevent data loss in SMOVE and FK cascade",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T20:24:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a14f13292e175a75e8d061ded70b205df3ae3e9f",
          "body": "…, format ref)",
          "is_bot": false,
          "headline": "fix: resolve clippy 1.97 lint errors (values_mut, keys, question_mark…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T19:39:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a4561fe8510b050174ce249fcb55c40fe9f97dd",
          "body": "… 5890",
          "is_bot": false,
          "headline": "docs(readme): reposition as The Application Database; local HTTP port…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T19:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4ba543e288dd20e25c7de3febd7c848103c2971",
          "body": null,
          "is_bot": false,
          "headline": "feat(cli): default ports 5890/5891 and honor LUX_URL for Studio",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T19:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a94e04e3e5817c74ef2921d45d27f1b0acdf45f6",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): bump to 0.25.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T03:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13018ca54db3558a3ad02a545a7d75744b8cf9f2",
          "body": "Exit 1 when any local migration is pending, so `migrate status` can gate a\nPR / CI job. Default behavior (no --check) is unchanged.",
          "is_bot": false,
          "headline": "feat(cli): `lux migrate status --check` fails on unapplied migrations",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T03:19:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83feeaddab6223a0207696693d6dafdee23b9e82",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): bump to 0.24.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T02:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d25bbb94de6060cbb56113566bc6706205d63524",
          "body": "Bare `lux migrate [project]` now applies pending migrations (run is the\ndefault action). get_applied_migrations probes with PING first so an\nunreachable or unauthenticated target errors clearly instead of silently\nreporting everything as pending.",
          "is_bot": false,
          "headline": "feat(cli): implicit `lux migrate` run + surface migrate errors",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T02:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74925591e3c3f6a2bd463e6e023ed1fa04982daf",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): bump to 0.23.0 (non-interactive login)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-08T00:31:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b35f114d0d94abd482eaa7c1fadc39f57185dd2",
          "body": "`lux login <token>` or LUX_TOKEN lets CI/CD authenticate without a prompt\n(e.g. to apply migrations); omitting both keeps the interactive paste flow.",
          "is_bot": false,
          "headline": "feat(cli): non-interactive login via token arg or LUX_TOKEN (#41)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-08T00:24:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4af39b8404b98fd36f0fa3ec0e54c7b68af51744",
          "body": "…] (#40)\n\n* feat(tables): add TSET/TGET point access by primary key\n\nAddress a table row's cells directly by PK without a WHERE query. TSET\nroutes through the same update leaf as TUPDATE (type coercion, FK/unique,\nall index maintenance, per-cell encryption, TTL, WAL self-log), so it is a\ntyped fast \n[…]\nV. Adds an integration test proving point access\nworks with a UUID primary key end to end.\n\n* chore: bump version to 0.27.0\n\n* refactor(sdk): LuxTableRow class instead of returning closures from row()",
          "is_bot": false,
          "headline": "feat: table point access by primary key (TSET/TGET + .row()) [v0.27.0…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-08T00:20:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b739018c8a634851d96b2aa3f3b1cfd742d68ee",
          "body": "* fix: multiple grant conditions with different column references\n\n* release: v0.26.2",
          "is_bot": false,
          "headline": "release: v0.26.2",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-07T21:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e2ee99e750ebbdeca1983f002d19bba6e051863",
          "body": "* fix: include null fields in full row serialization\n\n* release: v0.26.1",
          "is_bot": false,
          "headline": "release: v0.26.1",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-07T17:37:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90a8b7a3e6b578bdd45ddbe7e1e6635c3e02146e",
          "body": "…ning (#37)\n\n* feat(enc): encrypt list elements and stream field values\n\nLPUSH/RPUSH and XADD accept a trailing ENCRYPTED flag (mirroring\nSET/HSET): elements/field-values are sealed as envelopes at rest and\ndecrypted on read. List AAD is key-independent so LMOVE/RPOPLPUSH relocate\nciphertext without\n[…]\n\nit can't regress.\n\n* chore: release engine v0.26.0\n\nEncryption v2 (grant-gated decryption, encrypted lists/streams, encrypted\nvectors) plus the durability/safety hardening from the adversarial audit.",
          "is_bot": false,
          "headline": "release: engine v0.26.0 — encryption v2 + adversarial data-loss harde…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-06T14:24:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd52f261c9ad99b2158ac84d3b86aa0070036d3b",
          "body": "* feat(enc): grant-gated decryption for encrypted columns\n\nEncrypted columns now decrypt only for the operator/secret key and real\nauthenticated users; anonymous (signInAnonymously) callers get the column\nomitted from reads. is_anonymous flows from the access token into\nAuthPrincipal (derived from u\n[…]\nsserts operator and real users see the decrypted value\nwhile an anonymous (signInAnonymously) session gets the column omitted but\nstill sees the row. Covers the full token->principal->read-gate chain.",
          "is_bot": false,
          "headline": "feat(enc): grant-gated decryption for encrypted columns (#34)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-05T20:23:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af1fc237ecfe78d67225cc18ae33f6a07bdd5eaf",
          "body": "Encryption at rest (column + KV envelope encryption, searchable blind\nindex, env-sourced seal) and the `lux enc` CLI / auto-init in lux start.",
          "is_bot": false,
          "headline": "release: engine v0.25.0 + cli v0.22.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-05T18:39:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7c6cd2b189785de5d898ad46fe23f71739250b4",
          "body": "* feat(enc): encryption at rest with env-sourced seal\n\nEnvelope encryption for table columns and KV values (per-value DEK\nwrapped by keyring keys, AAD bound to table/field/pk), searchable\ncolumns via blind index, and ENC key lifecycle. Seal key sourced from\nLUX_ENC_SEAL_KEY (off the data volume) wit\n[…]\nenc via --project\n\n`lux enc <sub> --project <name|id|url>` proxies ENC to a hosted instance\nusing the CLI's cloud auth (or a direct connection URL); omitting\n--project keeps the local-engine behavior.",
          "is_bot": false,
          "headline": "feat(enc): encryption at rest with env-sourced seal (#32)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-05T18:32:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dedd3138f33113b7d14b8a3154dc6426b25d0852",
          "body": "* feat: add single modifier to mutation builder",
          "is_bot": false,
          "headline": "release(sdk): v2.8.4",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-03T17:59:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8618d38293d9da60b722b52c128c3af1b55ade1",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.24.6",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-03T01:19:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6420dab759c546257091406280996bae728dea",
          "body": "* ci(compat): add Redis compatibility scanner\n\n* revert: remove Redis compatibility scanner\n\n* fix(resp): improve Valkey string command compatibility\n\n* fix(keyspace): align Valkey keyspace compatibility\n\n* fix(streams): support XGROUP SETID\n\n* test(redis): add core parity inventory\n\n* test(redis): \n[…]\ny compatibility recipe\n\n* feat: add auth migration and query parity\n\n* feat: add runtime auth flow settings\n\n* feat(auth): add postmark email delivery\n\n* fix(auth): harden redirects and token handling",
          "is_bot": false,
          "headline": "feat: improve Redis and auth parity (#28)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-03T01:16:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67d741148c540af08d9123b05cc6f2914993264a",
          "body": "* fix: preserve missing aliased projection keys\n\n* feat: support nested and cumulative auth grants\n\n* release: 0.24.5",
          "is_bot": false,
          "headline": "Feat/grant subquery nesting (#29)",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-03T00:48:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46368cc218ed21988ec1f84596742be6c4ee382",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.24.4",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-28T21:50:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65dd9cf445b887f201dc7f00465b75ca22f4c42c",
          "body": null,
          "is_bot": false,
          "headline": "release(sdk): v2.8.3",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-28T21:48:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60258600097823032126af379f14c3e6d87a4c92",
          "body": "* fix: typed insert, upsert, update, and delete\n\n* fix: type-aware parsing\n\n* fix: clippy errors",
          "is_bot": false,
          "headline": "Fix/typed parsing (#27)",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-28T21:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13ce1367357b6ed5eb1a2b3875d5cbb0972a4af3",
          "body": null,
          "is_bot": false,
          "headline": "test(lua): relax busy script liveness probe",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:56:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4a7b18eb595b78cb10257ca74362c7869f04a73",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.3",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:44:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c17c332b348f20f9b8fad843674a5731a87aa73",
          "body": null,
          "is_bot": false,
          "headline": "test(ci): remove external compat smoke tests",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:43:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "183e924f0ef890dbfb0ca18398d62b7b0a4ab75e",
          "body": null,
          "is_bot": false,
          "headline": "fix(resp): support Lua scripts in transactions",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:32:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d3e167764bd7fd65e1175ab2e2227bb43d19323",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.2",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-25T00:40:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83a11cf0f28481a03cac05dcee52f09726fb706a",
          "body": "…(SMOVE)\n\nBoth #[ignore]'d so main stays green; un-ignore to fix. FK cascade decodes\nnon-INT FKs as INT (orphaned children); SMOVE removes from src before\nvalidating dst type (data loss).",
          "is_bot": false,
          "headline": "test(audit): quarantined repros for ENG-1278 (FK non-INT) + ENG-1279 …",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-25T00:27:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc155829e3010a20fc5dc42adc102c3101423cb3",
          "body": "Same root cause as ENG-1276 (XADD *): server-generated value resolved at\nexec time but raw `*` is WAL-logged, so replay picks a new wall-clock ts.\n#[ignore]'d so main stays green; one fix closes both.",
          "is_bot": false,
          "headline": "test(audit): quarantined repro for ENG-1277 (TSADD * replay determinism)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-25T00:13:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8797d0048dce081a9d479b013d3714101b4c1de",
          "body": "The upsert-on-conflict branch applied the row TTL outside the WAL, and a\nTTL-only upsert (no non-key fields) logged no command at all, so the\nrefreshed deadline was dropped on replay and the row never expired. Route\nthe TTL through the update leaf, carrying a TTL-only refresh on a no-op\nwrite of the conflict column so it is logged and replayed.",
          "is_bot": false,
          "headline": "fix(tables): WAL-log TTL set by an UPSERT on the conflict path",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-24T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c634041530eb99c24b325deafa18e93d23f8b11",
          "body": "The update path applied a row TTL in the caller, after the leaf, outside\nthe WAL: TUPDATE carried only SET/WHERE. On WAL-only recovery the TTL was\ndropped and the row lived forever. Thread the TTL op into the update leaf\nso it applies and logs as a trailing `TTL <secs>` clause atomically with\nthe row update. Upsert's TTL-on-conflict path is unchanged and still has\nthe same latent gap (follow-up).",
          "is_bot": false,
          "headline": "fix(tables): WAL-log TTL set by an UPDATE so replay preserves it",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-24T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d1bd289061cda0e9633c63e94f3105766cbbc76",
          "body": "next_id bumps _t:<table>:seq via a direct, un-WAL'd incr; the id only\nrides inside the replayed TINSERT. On WAL-only recovery the counter\nstayed stale, so the next insert reused an id and silently overwrote a\nrecovered row (INT PK) or lost every row (no-PK table, implicit id was\nrejected as an unknown column). Advance the counter on explicit/replayed\nids and accept the implicit id when no PK is declared.",
          "is_bot": false,
          "headline": "fix(tables): restore auto-increment seq on WAL replay",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-24T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "142a396db615b0adf949cf533a4aa6f65c93b2d2",
          "body": "feat(sdk): sync cookie session across tabs",
          "is_bot": false,
          "headline": "Merge pull request #26 from lux-db/feat/session-sync",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T21:18:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8df270a962287acd8b9b35d443e39beb1dd5131d",
          "body": null,
          "is_bot": false,
          "headline": "release(sdk): v2.8.2",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T20:54:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdf357338e3711eebc3c6a5604619684d313a301",
          "body": null,
          "is_bot": false,
          "headline": "feat(sdk): sync cookie session across tabs",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T20:50:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0b38ba3294523a47dc6ac70b591a87b3483da94",
          "body": "Fix realtime subscriptions for joined tables and auth dependencies",
          "is_bot": false,
          "headline": "fix: realtime subscriptions to joined tables",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T18:55:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf46ca24aae564c0123c69263c099f3e8f2213d",
          "body": null,
          "is_bot": false,
          "headline": "fix(http): type complexity errors",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T16:30:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7162e3c33133b003c2956ea9f45e167b584c17c4",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.1",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T16:07:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c6928197e1dd1a7e440e9a5c683d22259e294a1",
          "body": null,
          "is_bot": false,
          "headline": "chore(sdk): bump version",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T16:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa6a803b3e5c28f28db3c027fc76a18a13284785",
          "body": null,
          "is_bot": false,
          "headline": "fix: realtime subscription to joined tables",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T15:38:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ef1f5efdb3d5f39bee086a83b1ad8c2166144ba",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): sdk-v2.8.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:49:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ca9c58ce4c0aa0153a2dacbc5ebf48823a47c75",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:48:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4bb58c769bccc183695e3077b9f9c3b90901a6b",
          "body": "lux.auth.signInAnonymously() POSTs /auth/v1/signin/anonymous and saves\nthe session like signUp. Adds is_anonymous to LuxAuthUser.",
          "is_bot": false,
          "headline": "feat(sdk): signInAnonymously()",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:47:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cd7d35338ffdc9d4a0e4eda8fe2d951c3a38a60",
          "body": "POST /auth/v1/signin/anonymous mints a user with no email/password and\nissues a session, so a browser holds a real principal (auth.uid()) for\nRLS-gated reads and .live() without collecting credentials. Flagged via\nraw_app_meta_data.provider=anonymous (no schema column, no migration);\nuser JSON exposes is_anonymous. Gated by auth.anonymous_enabled\n(LUX_AUTH_ANONYMOUS, default on).",
          "is_bot": false,
          "headline": "feat(auth): signInAnonymously for accountless sessions",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30d2b8311a28d698a5de03ae99b340697b58d4fe",
          "body": "VECTOR columns and JSON/ARRAY columns now read back with the same shape\n(arrays/objects) no matter which operation returned them -- select,\nstream, or the insert/update RETURNING echo -- fixing a string-vs-typed\nmismatch that bit on reading back what you just wrote.",
          "is_bot": false,
          "headline": "chore(release): v0.23.1",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:25:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5433af56d28b602256a588404c3c1343d3e15ee6",
          "body": null,
          "is_bot": false,
          "headline": "test(http): JSON/ARRAY same shape in RETURNING echo as in select",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:21:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffe158e4133c96fa0c1f2ff39fedb4f062ef1bbb",
          "body": "config.toml already carried project name + ports; add an engine_version\nkey so a project can pin a specific engine (e.g. 0.23.0) instead of\ntracking :latest. Maps to ghcr.io/lux-db/lux:<version>; re-read each\nstart so editing config.toml takes effect. Blank value falls back to\n:latest.",
          "is_bot": false,
          "headline": "feat(cli): pin local engine version via lux/config.toml",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:47:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5049f6c31b5d7c5f55ef5058d3ac06060c56215f",
          "body": "Expose the local-engine host ports as flags (shown in lux start --help)\ninstead of config keys you had to discover by grepping the binary. An\nexplicit port is pinned with a clear error if taken; without a flag the\nexisting auto-bump-past-conflict behavior is unchanged.",
          "is_bot": false,
          "headline": "feat(cli): --resp-port / --http-port flags for lux start",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:40:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "812e76962c9ae130fa3d80c52fa4eecaac6f0f1b",
          "body": "A VECTOR column is stored comma-joined and was emitted as a quoted\nstring (\"1,2,3\"), while lux types generates the column as number[] --\nso reading a vector back through the SDK gave a string, not an array.\nConsolidate the three row-JSON renderers (read, streaming, write\nRETURNING) behind one type-aware field writer that emits VECTOR as\n[1,2,3] and also fixes JSON/ARRAY columns on the RETURNING path.",
          "is_bot": false,
          "headline": "fix(http): render VECTOR columns as JSON arrays, not strings",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:37:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c880bf4bbb6c1d591645bc1471b098e302bb048",
          "body": "The _t: reserved-namespace guard (which blocks raw-KV access to auth\ninternal storage -- password hashes, the JWT signing key, OAuth secrets)\nwas only tested on the write path. Add read-path coverage, single and\npipelined, so the protection can't silently regress.",
          "is_bot": false,
          "headline": "test(auth): cover raw-KV read of reserved _t: namespace",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:11:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fdb834267aba2d2bb55c711ddbda2e70eb4f302",
          "body": "Security + reliability hardening: snapshot/msgpack fail-closed bounds and\nOOM/crash DoS fixes (found by new fuzzers), Lua sandbox + effects-based\nscript durability, restore V2-header + surgical purge, string-growth caps,\nshard-count validation. Plus GA contract docs and a fuzzing harness.",
          "is_bot": false,
          "headline": "chore(release): v0.23.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0678f50a4c578a143fc96c77e6c314f729840e2c",
          "body": "Scheduled + manual cargo-fuzz over all five decoder targets, time-boxed,\nuploads crash repros on failure. PRs stay gated by the proptest fuzz\ntargets in cargo test; this is the deep continuous pass.",
          "is_bot": false,
          "headline": "ci: nightly coverage-guided fuzzing (cargo-fuzz matrix)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fec2284083111d53916d03e47dd63c1996827095",
          "body": "Add a coverage-guided cargo-fuzz crate (fuzz/) with libfuzzer targets for\nthe snapshot loader, RESP parser, command path, TSELECT parser, and Lua\nmsgpack decoder, driven through a feature-gated fuzz_api module. Seed\ncorpus + FUZZING.md with run commands.\n\nWithin seconds it found two snapshot OOM DoS\n[…]\nound all snapshot pre-allocation by a fixed element\ncap so a lied-about count can't reserve gigabytes; the loop still reads\nreal data and hits EOF. Both inputs kept as corpus seeds + unit regressions.",
          "is_bot": false,
          "headline": "test(fuzz): cargo-fuzz harness; fix snapshot OOM DoS found by it",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ff345ea3079054ea0fe9c1b062bed01f9053396",
          "body": "Add in-crate proptest fuzz targets (matching the existing disk.rs ones)\nfor the snapshot loader, RESP parser, TSELECT query parser, command\ndispatch, and Lua msgpack decoder -- every untrusted-bytes entrypoint\nthe GA fuzzing gate names. They run on stable in CI.\n\nThe msgpack target immediately found\n[…]\nua as table[nil]=v aborts the\n  process; skip invalid keys instead.\n- unbounded decode recursion could stack-overflow on nested-array markers;\n  cap nesting depth.\nBoth have explicit regression tests.",
          "is_bot": false,
          "headline": "test(fuzz): proptest fuzz targets for all decoders; fix msgpack crashes",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "beb70029557b8d580d42578e69f29d4a07cfc616",
          "body": "Every integration test spawned its server on a hardcoded port and derived\nits data dir from that port, so two tests sharing a port (within or across\nfiles) would fight over the port AND clobber each other's data. That is\nthe bug class behind the earlier crash-test flake.\n\nAdd tests/common/mod.rs wit\n[…]\nuite passes in isolation and parallel-within-binary. A separate,\npre-existing load transient (per-file read .unwrap() under full-suite\nsaturation) rotates across tests and is unrelated to this change.",
          "is_bot": false,
          "headline": "test: shared harness with OS-assigned ports + unique data dirs",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed303bfd54018695be6c35f6e4cacb18a5aed503",
          "body": "crash_recovery_lua_script_writes reused port 17207, which keys the same\ntemp data dir as rapid_writes_then_crash. Run concurrently they wiped\neach other's data dir and fought over the port, so rapid_writes\nrecovered 0 keys and failed. Move to 17210.",
          "is_bot": false,
          "headline": "test(crash): fix port/data-dir collision in lua crash test",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebc71e495423bae014eb6465d1aeb127e3356730",
          "body": "GA.md (1.0 release gate), COMPATIBILITY.md (Redis-compat classes +\ndivergences), DURABILITY.md (snapshot/WAL/restore/crash contract), and a\nSecurity Model + Sensitive Surfaces + Resource Exhaustion section in\nSECURITY.md. README links the contract docs. Durability doc describes\nLua effects-replication (writes logged individually, script never\nre-run) and the restricted list is KEYS/FLUSHALL/FLUSHDB/DEBUG to match\nthe engine.",
          "is_bot": false,
          "headline": "docs: add GA/durability/compatibility contracts, expand security",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cf9352bc85c821765270da5be8a58c3c64bb757",
          "body": "shards=0 made the fx_hash % shards.len() router divide by zero at\nruntime; validate_shard_count rejects 0 and >65536 up front. Also add a\ntest pinning the intended no-password behavior: admin endpoints stay\nreachable (loopback-only instance has no auth boundary anyway), the\ninverse of locking the local operator out.",
          "is_bot": false,
          "headline": "fix(config): reject invalid shard counts; cover no-password admin",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f556e0ede564a6446bababc97a4dbc136d27d87",
          "body": "A single value could be grown without bound (repeated APPEND, or\nSETRANGE/SETBIT at a huge offset), each call RESP-bounded but the\nrunning total unbounded. Cap the resulting size at the configured\nrequest ceiling so a value can't be ballooned to exhaust memory.",
          "is_bot": false,
          "headline": "fix(strings): cap APPEND/SETRANGE/SETBIT growth at max_resp_request",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c62106f32f78f4422b96d3d6fda998e14dd437c",
          "body": "redis.call writes went through bare execute, so KV writes from a script\nwere never WAL-logged and a crash lost them. Route through\nexecute_with_wal: KV effects get logged (concrete args -> deterministic\nreplay), table writes still self-log their resolved command, and the\nreserved-key guards now apply to scripts too. Log effects, not the\nscript, so replay never re-runs Lua and can't diverge on a generated PK\nor now() default.",
          "is_bot": false,
          "headline": "fix(lua): make script writes durable via effects logging",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22387944f0489d143ea6e2c95ff5edaec81ad130",
          "body": "Restore guard accepted only V1 and V3 headers, silently rejecting any\nbackup written while V2 was the format even though load_binary handles\nall three. Also narrow the storage purge to shard_* dirs we own instead\nof nuking the whole storage dir, so a storage.dir misconfigured to\noverlap data_dir can never delete the freshly-written lux.dat.",
          "is_bot": false,
          "headline": "fix(snapshot): accept V2 backups on restore, purge only owned shards",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "703dbb8f8e1958aab54f5af5ae74c4032c09b6eb",
          "body": "Nil out os/io/package/require/load/loadstring/debug/collectgarbage so\nuser scripts can't touch the filesystem, spawn processes, load bytecode,\nor introspect via debug. Split redis.call (raises on error) from\nredis.pcall (returns an error table), and deny admin/control commands\n(SAVE, MULTI, SUBSCRIBE, WATCH, etc.) from scripts. Cap cmsgpack.unpack\ncontainer lengths and never pre-allocate past the remaining input, so a\nhostile length prefix can't drive runaway allocation.",
          "is_bot": false,
          "headline": "feat(lua): sandbox scripts + bound msgpack decoding",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1865768f27b28dac0d3389ae48fafeebc7325b5",
          "body": "… prefix)\n\nA corrupt or hostile snapshot could drive a huge up-front allocation from an\nattacker-chosen length prefix (Vec::with_capacity / vec![0u8; len]) -> OOM or\npanic during load. Bound every byte-string and collection-count read against\nMAX_SNAPSHOT_BYTES / MAX_SNAPSHOT_ITEMS; over-limit loads are rejected as\nInvalidData. Test crafts huge list-count and byte-string prefixes and asserts a\nclean rejection. (Re-authored from the adversarial GA audit; Data-Safety gate.)",
          "is_bot": false,
          "headline": "fix(snapshot): fail-closed bounds on load (no OOM from corrupt length…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1800a8711dd35b9f6953bdd1e242055d18acca26",
          "body": "* fix: improve browser sdk\n\n* chore(sdk): bump version to 2.7.0\n\n* feat(sdk): session cookie chunking",
          "is_bot": false,
          "headline": "fix(sdk): improve browser sdk (#22)",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-22T19:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f02e255a9ddc525da7449ef081a7ce075e153952",
          "body": "Toward airtight-without-locks: the index is advisory and reads already\nre-validate against the authoritative row, so harden the write side to match.\n\n- Insert now commits the row hash LAST, after :ids/indexes/uniq/vector/TTL.\n  A reader that sees a reach-structure pointing at an uncommitted row re-f\n[…]\nss check is read-validated: only reject when a LIVE row genuinely\n  still holds the value; a stale uniq entry (holder gone / value changed) is\n  dropped and the insert allowed -- no false 'duplicate'.",
          "is_bot": false,
          "headline": "feat(tables): atomic row commit + read-validated uniqueness",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T03:27:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a82b7ea5de0106a768ad0937d29a6d10d7ccce1c",
          "body": "…pdate\n\nevict_key dropped the shard lock between serializing a key to disk and\nremoving it from memory. A concurrent write in that window updated the key to\na new value, which the unconditional remove then discarded -- the key reverted\nto its pre-eviction value and the update was lost (and made dura\n[…]\nusly across the disk write and the\nremoval so the serialized entry is exactly the one removed. Lock order is\nshard->disk; try_promote releases its disk lock before taking a shard lock, so\nno deadlock.",
          "is_bot": false,
          "headline": "fix(eviction): hold shard lock across evict-to-disk to prevent lost u…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T03:07:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a50bc0cdb7edb79ba83745d1d650ea24414a917d",
          "body": "A VECTOR column stores its embedding in a side key (_t:{t}:vec:{col}:{pk}) with\nits own ANN index, but table_delete_inner and table_drop never removed it. So\ndeleting a row or dropping a table left orphaned vectors: search kept returning\nthem and they leaked. Delete the vector side key (which also clears its index)\nin both paths.",
          "is_bot": false,
          "headline": "fix(tables): clean vector index on row delete + table drop",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T02:56:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7705a8eb1d6517568d04b2d3435b3a60d74cc6af",
          "body": "V2 snapshots stored remaining-ms and rebased it to load time, so a TTL'd key\npaused across downtime and a key that should have expired while the process was\ndown came back alive (and sub-ms-remaining keys became immortal). Snapshot\nformat V3 stores an absolute epoch-ms deadline; load subtracts elaps\n[…]\ns RDB (absolute expiry) and Lux's own\nrow TTLs.\n\nNote: the cold disk tier and WAL replay still use relative TTLs (bounded by the\nsnapshot interval, since SAVE truncates the WAL) -- separate follow-up.",
          "is_bot": false,
          "headline": "fix(snapshot): persist key TTLs as absolute deadlines (V3)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T02:51:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8f9de91763d87f6108e4217aac930dc586aba9a",
          "body": "Table data writes are now logged from the table layer as a RESOLVED command\n(explicit generated PK + resolved now()/defaults), and execute_with_wal no\nlonger raw-logs T-commands. Two bugs fixed at once:\n\n- HTTP table writes (browser SDK + cloud project client) bypassed\n  execute_with_wal and were ne\n[…]\nch writes with no\ndouble-apply. WAL is tiered-mode only (production default); memory mode stays\nsnapshot-only. Un-ignores wal_replay_preserves_autogenerated_uuid_pk; all 13\ncrash-recovery tests green.",
          "is_bot": false,
          "headline": "fix(wal): durable, deterministic table writes (resolved-command WAL)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T02:41:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a536782a49555d594e21f909833a0237181bb26",
          "body": "- eviction: never permanently evict reserved _t:* table/auth/ttl keys in\n  memory mode (allkeys-* could silently corrupt tables / lose rows); tiered\n  mode is unaffected (evict-to-disk is fault-safe).\n- TDROP: clear each row's _t:_ttl deadline so a dropped table's stale entry\n  can't expire a re-cre\n[…]\nhe auth API.\n\nAdds crash-recovery + regression tests. Known issue documented (ignored test):\nWAL replay regenerates uuid()/now() values (PK identity changes); fix-forward\nby logging resolved commands.",
          "is_bot": false,
          "headline": "fix(engine): reliability hardening from data-loss audit",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T00:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ac649777043bcca2c22ac6b6d4721f54143b884",
          "body": null,
          "is_bot": false,
          "headline": "chore: release engine v0.22.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-21T23:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd69ff048444d6c7cbaa3320c5a9e15168d4a28c",
          "body": "TINSERT/TUPSERT/TUPDATE accept TTL <secs> (and HTTP ?ttl=); rows auto-expire\nand fire a .live() delete (RLS-gated) via a table-aware sweep. TTL 0 clears;\nbare writes keep the deadline; TCREATE ... WITH TTL sets a per-table default.\nSDK gains a { ttl } option on insert/upsert (2.6.0).",
          "is_bot": false,
          "headline": "feat(tables): row TTL with realtime expiry",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-21T23:08:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 99,
      "commits_last_year": 359,
      "latest_release_at": "2026-07-19T21:29:40Z",
      "latest_release_tag": "cli-v0.26.1",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 16,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 0.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "lux",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": null,
          "registry_url": "https://crates.io/crates/lux",
          "is_deprecated": false,
          "latest_version": "0.1.2",
          "repository_url": null,
          "versions_count": 7,
          "total_downloads": 27898,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 16,
          "first_published_at": "2014-11-20T20:41:03.548117Z",
          "latest_published_at": "2016-09-01T20:32:53.257034Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 3612
        },
        {
          "name": "lux-cli",
          "exists": true,
          "license": "LGPL-3.0+",
          "keywords": [
            "lua",
            "neovim",
            "build",
            "packagemanager",
            "luarocks",
            "command-line-utilities",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/lux-cli",
          "is_deprecated": false,
          "latest_version": "0.39.2",
          "repository_url": "https://github.com/lumen-oss/lux",
          "versions_count": 155,
          "total_downloads": 37792,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 543,
          "first_published_at": "2025-02-18T21:40:45.243646Z",
          "latest_published_at": "2026-07-22T18:31:19.689461Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 1
        },
        {
          "name": "@luxdb/sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lux",
            "database",
            "application-database",
            "auth",
            "tables",
            "vectors",
            "realtime",
            "redis",
            "cache",
            "queues",
            "timeseries"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@luxdb/sdk",
          "is_deprecated": false,
          "latest_version": "2.10.0",
          "repository_url": "https://github.com/lux-db/lux",
          "versions_count": 25,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2237,
          "first_published_at": "2026-03-11T23:26:59.401000Z",
          "latest_published_at": "2026-07-18T15:21:00.428000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 21,
      "stars": 272,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-15",
            "count": 4
          },
          {
            "date": "2026-03-16",
            "count": 5
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          },
          {
            "date": "2026-03-21",
            "count": 1
          },
          {
            "date": "2026-03-22",
            "count": 3
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-05-09",
            "count": 1
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 21,
        "total_forks": 21
      },
      "star_history": null,
      "open_issues_and_prs": 5
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "sdk/tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "cli/Cargo.toml",
        "fuzz/Cargo.toml"
      ],
      "largest_source_bytes": 291115,
      "source_files_sampled": 112,
      "oversized_source_files": 12,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "cli/Cargo.toml",
        "fuzz/Cargo.toml",
        "sdk/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "tokio",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "rayon",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "bytes",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "base64",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "futures-util",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "parking_lot",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "hashbrown",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14"
        },
        {
          "name": "ordered-float",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "mlua",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "sha1_smol",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "rmp",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tokio-tungstenite",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.24"
        },
        {
          "name": "argon2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.5"
        },
        {
          "name": "bcrypt",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "jsonwebtoken",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "10"
        },
        {
          "name": "p256",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "rand_core",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.6"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "ring",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "clap",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "reqwest",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "rustls",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "serde",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tokio",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "dirs",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "6"
        },
        {
          "name": "colored",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "open",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "5"
        },
        {
          "name": "chrono",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "webpki-roots",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26"
        },
        {
          "name": "ioredis",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 32,
        "open_issues": 1,
        "closed_ratio": 0.857,
        "closed_issues": 6,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "mattyhogan",
          "commits": 338,
          "avatar_url": "https://avatars.githubusercontent.com/u/67698941?v=4"
        },
        {
          "type": "User",
          "login": "coachjackferg",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/133680445?v=4"
        },
        {
          "type": "User",
          "login": "only-cliches",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/14365337?v=4"
        },
        {
          "type": "User",
          "login": "skorotkiewicz",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/899351?v=4"
        },
        {
          "type": "User",
          "login": "neutralinsomniac",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/92071?v=4"
        }
      ],
      "contributors_sampled": 5,
      "top_contributor_share": 0.942
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "cli.yml",
        "docker.yml",
        "fuzz.yml",
        "publish-sdk.yml",
        "release.yml",
        "test.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 2,
            "reason": "8 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "5d72ef9c35176922d780d46eeb3c86c86fe6149d",
        "ran_at": "2026-07-23T23:17:36Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T08:18:56Z",
      "oldest_open_prs": [
        {
          "number": 20,
          "created_at": "2026-05-31T04:21:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 25,
          "created_at": "2026-06-23T18:41:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 35,
          "created_at": "2026-07-05T21:25:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 36,
          "created_at": "2026-07-05T23:17:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-19T21:49:01Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 21,
          "created_at": "2026-06-01T06:36:19Z",
          "last_comment_at": "2026-06-08T05:51:47Z",
          "last_comment_author": "only-cliches"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/lux-db/lux",
    "host": "github.com",
    "name": "lux",
    "owner": "lux-db"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 63,
      "inputs": {
        "security": 49,
        "vitality": 81,
        "community": 58,
        "governance": 54,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "commits_last_year": 359,
              "human_commit_share": 1,
              "days_since_last_push": 4,
              "active_weeks_last_year": 16
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "16/52 weeks with commits",
                "points": 11.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 16
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "359 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 359
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 99,
              "latest_release_tag": "cli-v0.26.1",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 0.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "99 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 99
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 58,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "forks": 21,
              "stars": 272,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "272 stars",
                "points": 39.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 272
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "21 forks",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "lux",
                "@luxdb/sdk"
              ],
              "dependents": null,
              "ecosystems": "crates, npm",
              "total_downloads": 27898,
              "monthly_downloads": 2253
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,253 downloads/month across crates, npm",
                "points": 44.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2253,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 5,
              "top_contributor_share": 0.942
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 94% of commits",
                "points": 1.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "5 contributors",
                "points": 6.8,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "merged_prs": 32,
              "open_issues": 1,
              "closed_issues": 6,
              "issue_closed_ratio": 0.857,
              "closed_unmerged_prs": 8
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "86% of issues closed",
                "points": 40.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 86
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "32/40 decided PRs merged",
                "points": 30.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 32,
                      "decided": 40
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 39,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "lux-db",
              "public_repos": 2,
              "account_age_days": 130
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of lux-db",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "lux-db"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "lux",
                "@luxdb/sdk"
              ],
              "ecosystems": "crates, npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on crates, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "25 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "lux",
                "redis",
                "database",
                "embeddings",
                "rust",
                "vector",
                "dragonflydb",
                "postgres",
                "supabase"
              ],
              "has_wiki": true,
              "homepage": "https://luxdb.dev",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://luxdb.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "9 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "8 existing vulnerabilities detected",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 59,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "sdk/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml",
                "cli/Cargo.toml",
                "fuzz/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "sdk/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "sdk/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 291115,
              "source_files_sampled": 112,
              "oversized_source_files": 12
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "12/112 source files over 60KB",
                "points": 49.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 112,
                      "oversized": 12
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "crates package 'lux-cli' points at a different repository (https://github.com/lumen-oss/lux); excluded from ecosystem scoring",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T23:17:47.829665Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/lux-db/lux.svg",
  "full_name": "lux-db/lux",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadascrates.io, npm.