Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-23 17:18 UTC

myrgic / cogos

Local Go daemon that gives AI tools persistent shared workspace state. Context assembly, multi-provider inference routing, hash-chained ledger, MCP server.

GoMIT★ 2 estrellas⑂ 1 forkdesde abr 2026Ver en GitHub ↗

myrgic/cogos tiene un índice de salud de 61 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (83/100) y la más baja, Security (40/100). Se actualizó por última vez hoy. Una sola persona concentra la mayor parte del trabajo reciente.

61
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

61
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

Myrgic LabsOrganización
1 seguidor18 repositorios públicosdesde abr 2026

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Gogithub.com/myrgic/cogosv0.16.20-40hace 6 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

83Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 0 días
14.5/36Cadencia de commits — 21/52 semanas con commits
18/18Volumen de commits — 810 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year810
human_commit_share1
days_since_last_push0
active_weeks_last_year21
Cómo se puntúa
27/27Publica versiones — 38 versiones publicadas
36/36Recencia de las versiones — última versión hace 6 días
27/27Cadencia de publicación — una versión cada ~1,7 días
1/10OpenSSF Scorecard: Signed-Releases — 1 out of the last 5 releases have a total of 1 signed artifacts.
Datos de entrada utilizados
releases_count38
latest_release_tagv0.16.20
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases1,7

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

43En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 2 estrellas
0/25Forks — 1 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks1
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
6.3/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_template

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

54Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
32.8/46.8Resolución de issues — 70% de issues cerradas
37.4/38.3Aceptación de PR — 334/342 PR decididos fusionados
10.5/15OpenSSF Scorecard: Code-Review — Found 22/30 approved changesets -- score normalized to 7
Datos de entrada utilizados
merged_prs334
open_issues39
closed_issues92
issue_closed_ratio0,702
closed_unmerged_prs8
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
2.2/25Alcance del propietario — 1 seguidores de myrgic
9.9/25Trayectoria — 18 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers1
owner_typeOrganization
is_verified
owner_loginmyrgic
public_repos18
account_age_days107
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en go
35/35Recencia de publicación — última publicación hace 6 días
20/20Historial de versiones — 40 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgithub.com/myrgic/cogos
ecosystemsgo
any_deprecatedno
min_days_since_publish6

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

80Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 4 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .golangci.yml
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno
Cómo se puntúa
30/30README
25/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
10/10Topics — 6 topics
0/10Wiki
Datos de entrada utilizados
topicsai-agents, claude-code, context-assembly, golang, local-first, mcp
has_wikino
homepage
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

40En riesgo · 16% del índice global
Cómo se puntúa
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — sin datos
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
5.2/7.5Code-Review — Found 22/30 approved changesets -- score normalized to 7
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — sin datos
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
2/5Security-Policy — security policy file detected
0.8/7.5Signed-Releases — 1 out of the last 5 releases have a total of 1 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 40 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4
Excluidos de la puntuación (sin datos o no aplicable): branch_protection, packaging. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

65Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 100 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
18/18Arranque con un solo comando — Makefile
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .golangci.yml
11/11Verificación estática de tipos — Go (tipado estático)
10/10Entorno reproducible — Dockerfile, lockfile
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainerno
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsenvspec/go.mod, go.mod, harness/go.mod, pkg/bep/go.mod, pkg/cogblock/go.mod, pkg/cogfield/go.mod, pkg/coordination/go.mod, pkg/modality/go.mod, pkg/reconcile/go.mod, pkg/substrate/go.mod, pkg/uri/go.mod, sdk/go.mod
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — Go (tipado estático)
54.7/55Tamaños de archivo manejables — 4/697 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageGo
largest_source_bytes138.356
source_files_sampled697
oversized_source_files4
Cómo se puntúa
40/40Esquema de API (OpenAPI/GraphQL/proto) — bep_proto/bep.proto
20/20Servidor MCP
0/40Ejemplos ejecutables
Datos de entrada utilizados
example_dirs
has_mcp_signal
api_schema_filesbep_proto/bep.proto

Datos clave

2estrellas de GitHub
1contribuidores
810commits en los últimos 12 meses
0días desde el último push
38versiones publicadas
1factor bus
39issues abiertas
Goecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 4.0 / 10
4.0agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-23 17:18 UTC

9Binary-Artifactsbinaries present in source code
n/dBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
7Code-ReviewFound 22/30 approved changesets -- score normalized to 7
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/dPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
4Security-Policysecurity policy file detected
1Signed-Releases1 out of the last 5 releases have a total of 1 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities40 existing vulnerabilities detected
Dependencias directas 44
RegistroPaqueteRestricción de versiónManifiesto
Gogithub.com/charmbracelet/bubblesv0.21.0go.mod
Gogithub.com/charmbracelet/bubbleteav1.3.10go.mod
Gogithub.com/charmbracelet/lipglossv1.1.0go.mod
Gogithub.com/coder/acp-go-sdkv0.13.0go.mod
Gogithub.com/coder/websocketv1.8.14go.mod
Gogithub.com/fsnotify/fsnotifyv1.7.0go.mod
Gogithub.com/go-git/go-git/v5v5.16.4go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/hashicorp/hcl/v2v2.24.0go.mod
Gogithub.com/mattn/go-sqlite3v1.14.24go.mod
Gogithub.com/modelcontextprotocol/go-sdkv1.5.0go.mod
Gogithub.com/myrgic/cogos/envspecv0.0.0go.mod
Gogithub.com/myrgic/cogos/harnessv0.0.0go.mod
Gogithub.com/myrgic/cogos/pkg/cogblockv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/pkg/cogfieldv0.0.0go.mod
Gogithub.com/myrgic/cogos/pkg/coordinationv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/pkg/modalityv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/pkg/reconcilev0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/sdkv0.0.0go.mod
Gogithub.com/opencontainers/go-digestv1.0.0go.mod
Gogithub.com/opencontainers/image-specv1.1.1go.mod
Gogithub.com/santhosh-tekuri/jsonschema/v5v5.3.1go.mod
Gogithub.com/zclconf/go-ctyv1.17.0go.mod
Gogo.opentelemetry.io/otelv1.43.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.43.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.40.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.43.0go.mod
Gogo.opentelemetry.io/otel/metricv1.43.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.43.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.43.0go.mod
Gogo.opentelemetry.io/otel/tracev1.43.0go.mod
Gogolang.org/x/modv0.37.0go.mod
Gogolang.org/x/netv0.54.0go.mod
Gogolang.org/x/sysv0.44.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gooras.land/oras-go/v2v2.6.0go.mod
Gogo.opentelemetry.io/otelv1.43.0harness/go.mod
Gogo.opentelemetry.io/otel/tracev1.43.0harness/go.mod
Gogopkg.in/yaml.v3v3.0.1harness/go.mod
Gogithub.com/coder/websocketv1.8.14sdk/go.mod
Gogithub.com/fsnotify/fsnotifyv1.7.0sdk/go.mod
Gogithub.com/mattn/go-sqlite3v1.14.24sdk/go.mod
Gogopkg.in/yaml.v3v3.0.1sdk/go.mod
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "claude-code",
        "context-assembly",
        "golang",
        "local-first",
        "mcp"
      ],
      "is_fork": false,
      "size_kb": 36708,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 7261564,
        "HTML": 150293,
        "Shell": 180576,
        "Python": 153714,
        "Makefile": 6207,
        "Dockerfile": 1956,
        "JavaScript": 8817
      },
      "pushed_at": "2026-07-22T23:46:55Z",
      "created_at": "2026-04-06T17:20:02Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T23:46:58Z",
      "description": "Local Go daemon that gives AI tools persistent shared workspace state. Context assembly, multi-provider inference routing, hash-chained ledger, MCP server.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Myrgic Labs",
      "type": "Organization",
      "login": "myrgic",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/274069615?v=4",
      "created_at": "2026-04-06T17:19:21Z",
      "is_verified": null,
      "public_repos": 18,
      "account_age_days": 107
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.16.20",
          "kind": "patch",
          "published_at": "2026-07-17T13:43:00Z"
        },
        {
          "tag": "v0.16.19",
          "kind": "patch",
          "published_at": "2026-07-07T20:37:53Z"
        },
        {
          "tag": "v0.16.18",
          "kind": "patch",
          "published_at": "2026-07-07T16:32:50Z"
        },
        {
          "tag": "v0.16.17",
          "kind": "patch",
          "published_at": "2026-07-06T21:44:42Z"
        },
        {
          "tag": "v0.16.16",
          "kind": "patch",
          "published_at": "2026-07-06T19:53:36Z"
        },
        {
          "tag": "v0.16.15",
          "kind": "patch",
          "published_at": "2026-07-05T00:59:26Z"
        },
        {
          "tag": "v0.16.14",
          "kind": "patch",
          "published_at": "2026-07-04T14:37:52Z"
        },
        {
          "tag": "v0.16.13",
          "kind": "patch",
          "published_at": "2026-07-04T05:24:56Z"
        },
        {
          "tag": "v0.16.12",
          "kind": "patch",
          "published_at": "2026-07-04T00:53:06Z"
        },
        {
          "tag": "v0.16.11",
          "kind": "patch",
          "published_at": "2026-07-02T04:09:54Z"
        },
        {
          "tag": "v0.16.10",
          "kind": "patch",
          "published_at": "2026-07-01T09:18:25Z"
        },
        {
          "tag": "v0.16.9",
          "kind": "patch",
          "published_at": "2026-06-30T14:10:25Z"
        },
        {
          "tag": "v0.16.8",
          "kind": "patch",
          "published_at": "2026-06-30T13:01:07Z"
        },
        {
          "tag": "v0.16.7",
          "kind": "patch",
          "published_at": "2026-06-30T11:17:59Z"
        },
        {
          "tag": "v0.16.6",
          "kind": "patch",
          "published_at": "2026-06-27T12:54:56Z"
        },
        {
          "tag": "v0.16.5",
          "kind": "patch",
          "published_at": "2026-06-25T10:59:37Z"
        },
        {
          "tag": "v0.16.4",
          "kind": "patch",
          "published_at": "2026-06-25T09:37:49Z"
        },
        {
          "tag": "v0.16.3",
          "kind": "patch",
          "published_at": "2026-06-24T11:25:41Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-10T21:25:19Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-06-08T22:42:03Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-07T02:55:59Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-06-04T21:24:50Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2026-06-04T20:25:12Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-06-03T01:33:34Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-05-27T02:11:42Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-25T17:54:41Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-05-19T21:12:05Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-05-17T00:15:15Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-05-15T20:31:05Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-05-13T16:14:32Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-05-08T21:43:02Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-08T02:56:44Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-05-05T21:37:54Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-02T16:21:28Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-01T21:42:20Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-04-22T16:01:50Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-04-20T01:45:10Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-04-14T20:52:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "7ebe6461c7b0d381e6b90f85dbc47b9f1943bb68",
          "body": "…reconcile + ConfigExporter snapshot (#473)\n\n* refactor(providers): re-home discord provider into internal/providers/discord\n\nADR-121 Wave 4: the daemon's discordProvider registration\n(internal/providers/daemon/daemon.go) was a Health()-only stub embedding\nstubMethods, standing in for the real Recon\n[…]\nuracy (its one confirmed\nfinding) was already corrected in the PR body, and the daemon\nreconcile-loop Tokenable gap is already disclosed in the PR's \"Not in\nscope\" section as an intentional follow-up.",
          "is_bot": false,
          "headline": "feat(providers): ADR-121 Wave 4 — re-home discord provider with real …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T23:46:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c677ee4c1461680ef7dadcfd6ef31f7f0d27030",
          "body": "…(#468)\n\n* feat(marginbridge): add margin-bridge GitHub signal watcher provider\n\nKernel-native replacement for the Python bridge_github.py prototype:\noutbound-only gh-api polling of a workspace's signal inboxes and\nsettlement ledger, surfaced as kernel-native wakes (ledger event +\nbus_margin_bridge)\n[…]\ng two actions resolved in the same ApplyPlan call\ncollide if they land in the same millisecond. Mixed in a per-process\nmonotonic counter as a tiebreaker.\n\nPR #468 round-3 cog-review CHANGES_REQUESTED.",
          "is_bot": false,
          "headline": "feat(marginbridge): add margin-bridge GitHub signal watcher provider …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T23:06:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59606d76aaab39b16a4eb5eca6cc678a85e78076",
          "body": "…463)\n\nA quarantine-only ingest source — every record rejected, e.g. the\nclaude-ai-web observer's unsent composer drafts (role user-draft →\nreason draft_role) — never reaches a converged state, so the\nreconciler re-reads its unchanged ingest file every cycle. Quarantine\nwas append-only with no dedup\n[…]\nason uniformly, not just draft_role.\n\nRegression test: same record across 50 cycles and a simulated restart\n→ 1 line; distinct records still append; content-hash dedup for\nrecords without a stable_id.",
          "is_bot": false,
          "headline": "fix(conversations): make quarantine writes idempotent by stable_id (#…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T16:14:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6fcdd2a1f8740fe06c6e2a2729f44168e8c38130",
          "body": "* docs(adr): ADR-121 single-binary consolidation -- fold CLI into cogos, delete legacy root package\n\n* chore(cli): delete legacy root package main per ADR-121\n\nRemoves all 232 root-level .go files (the legacy standalone CLI,\npackage main). The shipped entrypoint is cmd/cogos -> internal/engine\nand a\n[…]\nsubsystem, which predates and is orthogonal to the\nReconcilable-provider pattern and isn't part of ADR-121's Wave 4 list.\n\nVerified: go build ./..., go build -tags fts5 ./..., go vet ./... all\nexit 0.",
          "is_bot": false,
          "headline": "chore(cli): delete legacy root package main per ADR-121 (#464)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T16:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9cb104b537b5d7211e1ec5d347d9e3520a84862",
          "body": "…, chunk 2) (#472)\n\n* feat(identity): ledger-backed identity grants + revoke (board task 60, chunk 2)\n\nChunk 1 (dce2d68, #471) proved kernel-issued identity grants in memory\nonly, with an explicitly-filed gap: a kernel restart silently invalidated\nevery live grant, and a full grant store had no non-\n[…]\ny succeeds\nonce the ledger recovers and the token dies),\nTestIdentityGrantMint_LedgerAppendFailureMapsTo503. Existing Revoke\ncall sites updated to the error-returning signature; all prior tests\ngreen.",
          "is_bot": false,
          "headline": "feat(identity): ledger-backed identity grants + revoke (board task 60…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T03:52:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dce2d6889e528f217b15df54ee7b61d04404a47a",
          "body": "…) (#471)\n\n* feat(identity): kernel-issued identity grants (board task 60, chunk 1)\n\nAdds POST /v1/identity/grants, POST /v1/identity/verify, GET /v1/identity/grants,\nand GET /v1/identity/grants/current -- an in-memory, surface-scoped credential\nissuance/verification surface following the serve_sess\n[…]\nfor both: alternating scope across repeated mints for\none surface holds byGrantID at exactly one live entry, and minting past the\ncap is rejected with the capacity error while bySurface stays bounded.",
          "is_bot": false,
          "headline": "feat(identity): kernel-issued identity grants (board task 60, chunk 1…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T00:03:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b530df6c1cb7b048e377ffc30e12162ca537f124",
          "body": "…precated temperature (#467)",
          "is_bot": false,
          "headline": "fix(dispatch): route current-generation Anthropic models and strip de…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-17T13:34:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4d7477761617d9ef8dd446a7878f52370c2fab2",
          "body": "The SiteProvider drift check was a stub (\"ArtifactSHA empty -> update;\notherwise -> skip. Full SHA comparison is planned for v0.1.\"). It only\ndeployed targets that had never been deployed, so once a target had any\ncontent, every subsequent content change was silently skipped and never\nshipped.\n\nRepl\n[…]\n, hashes the output, compares to the live hash:\n  differ or missing -> update, equal -> skip.\n\nContent-only changes now plan as update. Tests added for synced,\ncontent-drift, and missing-marker cases.",
          "is_bot": false,
          "headline": "fix(site): real per-app content-hash drift detection (#462)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-08T22:32:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32dbfc619d9d4a6f2d09a53af08b4c9cc9ab1880",
          "body": "…n (#458)\n\n* fix(conversations): atomic + cross-process-locked writes to _meta.json\n\nFixes #449. writeMetaFileLocked previously did a plain os.WriteFile with\nno cross-process coordination, so a CLI-invoked \"cog reconcile\nconversations\" run and the daemon's own reconcile cycle could each\nread-modify-\n[…]\nop races MCP writes; in cmd/cogos the eval reconcile provider is a\n  no-op stub. Comments now state the real guarded races: concurrent MCP\n  invocations, and any future real-provider reconcile wiring.",
          "is_bot": false,
          "headline": "fix(conversations): atomic + cross-process-locked writes to _meta.jso…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-08T00:25:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "62e9d337e4be0c07f27813c714d4cf030d5d3f86",
          "body": "…utation (#460)\n\n* fix(config): gate config-mutation HTTP endpoints, warn on unauthenticated non-loopback bind\n\nGET/PATCH /v1/config and POST /v1/config/rollback were reachable by any\nlocal process on the same host with no gate at all, unlike the existing\nEnableSkillExec (serve_skills.go) / EnableSe\n[…]\ne \"disabled\"/enable_config_mutation wording, matching the established\npattern for resource-read failures elsewhere in this file (resourceState).\n\nTests: TestResourceConfigMCP_GateDisabled/GateEnabled.",
          "is_bot": false,
          "headline": "fix(config): gate config-mutation HTTP endpoints behind EnableConfigM…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T22:28:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24b3ce9cf8593b35c23e860d487f76b51497e66e",
          "body": "Extends the existing lint CI job with a cheap mechanical check\n(scripts/check-shell-hardening.sh) requiring every tracked scripts/*.sh\nfile to declare `set -euo pipefail` (or `set -eu` for POSIX sh, which\nhas no pipefail) or carry a documented `# no-pipefail: <reason>`\nopt-out, plus a shellcheck err\n[…]\nened POSIX\nsh, documented opt-out, unhardened, non-shell-shebang skip, shellcheck\nerror-severity, mixed tree), plus an acceptance test running the real\ngate against this repo's own scripts/ directory.",
          "is_bot": false,
          "headline": "ci(shell): add shell-hardening gate for scripts/*.sh (ledger L15) (#459)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T21:49:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39d63c2c2ababb7c343344c90dbf839c95eb44eb",
          "body": "Adds keyless Sigstore signing of checksums.txt to the release pipeline\nusing the GitHub OIDC identity (id-token: write, scoped to the release\njob), plus a fail-closed self-verify step before publishing. Documents\nwhat is signed, the exact consumer verify command, and the trust model\nin docs/release-signing.md.\n\nRatified v1.0 alignment item L12 (release integrity), phase 1\n(release-side signing). Kernel self-update verification of this\nsignature is out of scope here and tracked in #454.",
          "is_bot": false,
          "headline": "ci(release): sign checksums.txt with Sigstore/cosign (keyless) (#456)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T21:49:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "863ce4e2919f3a83b8512730b9f5de00775cb7d9",
          "body": "…ism (#457)\n\n* fix(replay): implement real sha256 hash and wire VerifyReplayDeterminism into tests\n\nhashString was a placeholder that returned its input bytes verbatim\ninstead of hashing (replay.go:402), so ComputeReplayHash was string\nidentity dressed as a hash. VerifyReplayDeterminism, its only re\n[…]\nng covers ID/Type/branch/branchSeq\nand not Timestamp/ParentID/Data -- pre-existing scope, not a regression,\nflagged per review rather than widened, since that's a design call\noutside this fix's scope.",
          "is_bot": false,
          "headline": "fix(replay): implement real sha256 hash and wire VerifyReplayDetermin…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:48:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6d860322df832de7a1a5776e31637374a12f46e",
          "body": "…on (#455)\n\nendpointReachable unconditionally cached a negative probe result on any\nHTTP failure, including when the failure was caused by the CALLER's own\ncontext being cancelled (e.g. an HTTP client disconnecting mid-dispatch,\nsince ctx traces back to r.Context() via DispatchToHarness). That\npoiso\n[…]\nmeout firing on a genuinely slow/hung\nendpoint) is unaffected and still caches negative.\n\nAdds two regression tests: a cancelled caller ctx must not write the\ncache; a genuine connection refusal must.",
          "is_bot": false,
          "headline": "fix(dispatch): guard reachability cache against caller-ctx cancellati…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:41:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9893d6267ba79761211e37d27e13080e8428291b",
          "body": "…y + salience-strip (ADR-103) (#452)\n\n* feat(foveation): cache-aware placement, salience strip, session-scoped light-cone key\n\nUnder a plain prefix cache (llama.cpp / LM Studio / OpenAI-compat), the volatile\nfoveal doc manifest sat at the FRONT of the token stream, so its per-turn churn\nre-prefilled\n[…]\n build ./... and go test -race\n./internal/engine/... green.\n\n* chore: re-trigger review (cog-review transient error on prior head)\n\n* chore: re-trigger review (cog-review errored twice on prior heads)",
          "is_bot": false,
          "headline": "feat(foveation): cache-aware placement + session-scoped light-cone ke…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:26:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04cb2f2e87902802b7e4127ad29966ad80618d60",
          "body": "…104) (#453)\n\n* feat(engine): lms-model-state declarative reconciler (opt-in, off by default)\n\nAdd a Reconcilable that keeps an LM Studio backend loaded with the declared\nmodel at the declared context length, orthogonal to OpenAI-compat dispatch.\nModels the mlx-supervised dual-shape precedent, swapp\n[…]\nMSModelStateProviderConcurrentFieldAccess (SetToken/LoadConfig writes\n  vs FetchLive/Health reads) so -race flags any regression.\n\n* chore: re-trigger review (cog-review transient error on prior head)",
          "is_bot": false,
          "headline": "feat(inference): lms-model-state declarative reconciler, opt-in (ADR-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:26:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32d445e0b74b4c9106848b55320f836f7e37abf7",
          "body": "…ackends) (#451)\n\n* feat(inference): live /v1/models composition with admission-parity fixes\n\nLive-view GET /v1/models: enumerate every ModelLister provider (bounded,\nconcurrent, graceful-skip), emit composite \"<provider>/<model>\" ids for\nlocal/OpenAI-compat providers and bare claude ids for frontie\n[…]\next caller rebuilds\ncleanly. Mirrors the #441 Available() TTL-cache guard. Adds a regression test\n(cancelled caller -> next healthy caller still gets the full menu) and makes the\nlisterStub ctx-aware.",
          "is_bot": false,
          "headline": "feat(inference): live /v1/models composition (Anthropic + LM Studio b…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T16:21:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dcba52627fb267954c94a58a40d76eafb82c1888",
          "body": "… A-E) (#447)\n\n* feat(testkernel): First Instruments Module A — cadence + cell-lattice test surface\n\nAdds the boot/testkernel extensions needed to observe and control kernel\ncadence in tests: WithPollInterval (wires the previously-dead\nbootConfig.pollInterval into ReconcileDaemonConfig.PollInterval)\n[…]\nre-check -- multi-hour-to-multi-day wall-clock time the runner\nitself does not shorten. Running that sweep is the next action once this\nPR lands, not a step this implementation session could complete.",
          "is_bot": false,
          "headline": "feat(instruments): First Instruments Stage-2 instrumentation (Modules…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T12:54:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "207e329cd8bebcb75c1aa2384fa6732875721e1b",
          "body": "cog_fork_session and POST /v1/sessions/{id}/fork both register the child\nsession via ApplyRegister with appendFn=nil, relying on the session.fork\nbus event written just before as the child's only durable record. But\nReplaySessionRegistry's switch had no case for \"session.fork\", so the\nchild row was \n[…]\nerve.go) and the stdio MCP path (cli_mcp.go), which previously never\nwired a ForkRegistry at all. PinnedUntil is preserved via the fork body\nround-trip so GC expiry semantics survive replay unchanged.",
          "is_bot": false,
          "headline": "fix(sessions): forked sessions and lineage survive kernel restart (#446)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T22:01:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "735a138891576edee9406133197197d97eecb5a3",
          "body": "…ecord drift (#444)\n\nSelf-update writes kernel.toml (version + current-platform checksum) write-ahead before the binary swap and rolls it back on failure, so the pinned-version record stops drifting from the running daemon (#442). Dormant no-op where no kernel.toml exists; perm-restore is best-effort so a chmod failure can't strand a committed write. Hardened per Fable + cog-review.",
          "is_bot": false,
          "headline": "fix(self-update): write-ahead kernel.toml maintainer to end version-r…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T21:39:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b40c804d783614a5067d84022fec736c8fd7c8ec",
          "body": "…aware fallback (#445)\n\nProbe now bounded by an internal deadline so availMu isn't held for the full client timeout; stream_options.include_usage restores token accounting on the cancel-safe streaming path; fallback skips model-incompatible LOCAL providers (IsLocal && !AgenticHarness) so a downed local LMS fails over to a sibling serving the model instead of firing a bogus model id at a frontier provider. Addresses the Fable pipeline review.",
          "is_bot": false,
          "headline": "fix(inference): robust availability probes, end-to-end usage, compat-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T21:39:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a9bc943ea659fc419549569e3d27f02eb3e23b3",
          "body": "…v1/models polling (#443)\n\nOpenAICompat, ClaudeOAuth, and Ollama providers now cache their Available() reachability probe for 30s (availCacheTTL), so the router's 10s availability ticker and the per-request /v1/providers handler stop issuing a live GET /v1/models (and /api/tags) on every call. A cal\n[…]\nning); a probeTimeout deadline on a slow provider IS cached as unavailable. Anthropic/Codex/ClaudeCode/Pi Available() are cheap local checks needing no cache; MLXSupervised already caches.\n\nRefs #441.",
          "is_bot": false,
          "headline": "perf(inference): cache live provider Available() probes to stop 10s /…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T19:47:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c437feb6ca9cbf59aaf0659d5c63405d23bdfc0",
          "body": "* feat(dispatch): async job handle for cog_dispatch_to_harness (fixes #32001)\n\ncog_dispatch_to_harness is fully synchronous -- the MCP request blocks\nuntil every fan-out slot completes, errors, or hits its per-slot timeout\n(up to 600s). Interactive MCP clients often close their request window\nwell b\n[…]\n pre-existing MCP-side async tests\n(TestToolDispatchToHarness_AsyncReturnsImmediateJobHandle et al.) carry\nthe same latent hazard but are out of scope for this PR's confirmed\nfindings; left untouched.",
          "is_bot": false,
          "headline": "feat(dispatch): async job handle + harness capability gating (#437)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T23:15:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "776b66698d1beaff2c701b2a6cdb757b1e36268d",
          "body": "…itHub (#438)\n\n* fix(ci): gate must fail closed — neutral passes a required check on GitHub\n\nDiscovered once cog-review became a required check: GitHub treats a\n`neutral` required check-run as PASSING, not blocking. The gate mapped its\nfail-safe cases (reviewer error, sandbox-canary failure, unconfi\n[…]\nle, within the trust model): a bot CHANGES_REQUESTED review at\nhead -> reconcile; a COMMENTED review or none (errors post none) ->\nescalate to operator (exit 4), matching the script's header contract.",
          "is_bot": false,
          "headline": "fix(ci): gate must fail closed — neutral passes a required check on G…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T22:31:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b00db12b9c7e5d426274526d1125b0e165ed94aa",
          "body": "…ge stays local (#436)\n\n* ci(review): repo-resident cog-review gate — approve-authority, merge stays local\n\nAdds a two-tier PR gate that any contributor's PR passes through identically\n(the gate is identity-blind; merge authority is not):\n\n- mechanical: deterministic Conventional-Commits title check\n[…]\np mechanical job re-validates; guard the expensive\ncog-review job with action != 'edited' since a title/body edit leaves the\ndiff (and thus the code verdict) unchanged — no wasted AI review on a typo.",
          "is_bot": false,
          "headline": "ci(review): repo-resident cog-review gate with approve authority, mer…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T20:55:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed0714aa94770edf7e7948e878ce0af76771746e",
          "body": "…ispatch_to_harness (#435)\n\nOperator directive (2026-07-04): \"expand the timeout caps to at least 5m.\nWith agentic workflows that will likely get pushed even further out, so\nthe timeout should be a parameter, not hardcoded.\"\n\n- Per-slot timeout cap becomes config-driven: dispatch_timeout_cap_seconds\n[…]\nday), which deliberately raised the default to 240s as\nan incident fix (zombie generations under a 30s ceiling). The default is\nleft at 240s to avoid regressing that fix; the doc strings now state it.",
          "is_bot": false,
          "headline": "feat(dispatch): config-driven timeout cap + doc-drift fixes for cog_d…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T00:53:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4e6acae5c60ffa8a66073d97c0b2b592d521eb7",
          "body": "…etries (#432) (#434)\n\nNon-streaming completion calls to LM Studio (openai-compat) did not abort\ngeneration server-side when the kernel gave up waiting: the client-side\nComplete() call returns on ctx cancel, but the connection isn't torn down\nin time for the server to notice, so the model keeps gene\n[…]\n, so without the override a countingProvider wrapping a\ncancel-safe-capable provider silently fell back to plain Complete on the\ndispatch path specifically. Found via the retry-dedup integration test.",
          "is_bot": false,
          "headline": "fix(engine): propagate local-inference cancellation, bound timeouts/r…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-04T14:32:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "704ae050bc02c8a7102e58625e90eccdc3a7bc63",
          "body": "…lt (#431)\n\ncog_dispatch_to_harness silently discarded an explicit model the caller\nrequested in two places: DispatchRequest.Normalize() collapsed any\nnon-enum model string to \"e4b\" before routing ever saw it, and the\nexplicit-provider / harness-provider-default / state-routing paths in\nDispatchToHa\n[…]\nuest over the config default. When the provider cannot serve the\n  requested model it still fails loudly via the existing non-2xx wire\n  error path — no client-side substitution was added.\n\nFixes #430",
          "is_bot": false,
          "headline": "fix(dispatch): honor caller-explicit model over provider config defau…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-04T05:18:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19c17189d39e451be74ef85288d30d2780a8fd7e",
          "body": "…ace (#426)\n\n* fix(dispatch): default local-LLM endpoint to LM Studio :1234, not Ollama :11434\n\nopenaiCompatDefaultEndpoint had drifted back to Ollama's decommissioned\n:11434 after PR #417 moved the default local backend to LM Studio\n(lmstudio-darkstar, 127.0.0.1:1234). A no-provider cog_dispatch_to\n[…]\nlog, ~57 entries, one\nscan per rejection) to help with typos.\n\nExtends the existing TestToolInvoke_* family with both cases plus focused\nunit tests on the new eagerToolExists/nearestToolNames helpers.",
          "is_bot": false,
          "headline": "fix(dispatch,mcp): LM Studio default endpoint + eager-tool error surf…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-04T00:48:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e03ad3860f2672270c478fabed903601973235c0",
          "body": "… leftovers (#419)\n\n* fix(constellation): harden the FTS write path — serialize index writes, refresh mtime on hash-skip, prune ghost rows on reindex\n\nThree write-path fixes in the constellation indexer:\n\n1. Concurrent IndexFile corrupted transaction state: upsertFTSRow issued\n   SAVEPOINT/RELEASE a\n[…]\nsion exercises the real\nStreamable HTTP transport without a prior register call and asserts the\ndenial; the existing TestToolInvoke_EnforcesCapabilityGating (registered\nallow/deny paths) still passes.",
          "is_bot": false,
          "headline": "fix: FTS write-path hardening, drift-repair correctness, decommission…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-02T04:04:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e38ae77becca59e261418b841e5542b303cec222",
          "body": "feat(mcp): porcelain/plumbing tool surface — lean eager set fronting a deferred catalog",
          "is_bot": false,
          "headline": "Merge pull request #418 from myrgic/feat/porcelain-plumbing-tool-surface",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T09:12:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "136f71de7cff537d1545aa719cbfc32a8cfadf0a",
          "body": "…quote corruption\n\n- backfillEagerSchemas ran only in the constructor, before RegisterMCPExtensions\n  fires in registerMCPRoutes — so extension eager tools (cog_search_conversations,\n  cog_get_conversation_turn) kept nil InputSchema and cog_tool_search returned null\n  schemas for them. Re-run the idempotent backfill after the extension hook.\n- revert 3 doc-comment backtick pairs mangled into curly quotes by a find-replace\n  in mcp_modality_proxy.go; fix stale ~13 -> ~14 porcelain-count comment.",
          "is_bot": false,
          "headline": "fix(mcp): backfill extension-registered eager schemas + revert curly-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T09:06:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baa4df273c378209b09567a151e6ccef8b6e3698",
          "body": "…s schema\n\nFixes toolInvokeInput.Args: json.RawMessage infers as an array/null\nJSON Schema (byte slice), not an object, so any real args payload\nfailed schema validation before the handler ever ran. Switched to\nmap[string]any (re-marshaled to JSON before handing to the deferred\nhandler, which still \n[…]\nt)\n  - a porcelain tool (cog_get_state) is still directly callable\n  - a deferred tool (cog_read_ledger, mod3_speak) is absent from\n    ListTools/tools-list while still present in the toolMeta catalog",
          "is_bot": false,
          "headline": "test(mcp): regression coverage for porcelain/plumbing split + fix arg…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T08:48:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a929214aa4f12c95c9454cee4ef3fc2503c81389",
          "body": "Server-autonomous porcelain/plumbing split (workflow wkweyu50g, plan\ncog:mem/semantic/architecture/mcp-tool-surface-tier-then-trim.cog.md\n#Mechanism, RESOLVED). The kernel cannot ask a harness to defer-load\nspecific MCP tools, so it shrinks what it advertises instead.\n\n- trackToolDeferred (serve_man\n[…]\n KernelToolRegistry (tool_loop.go)\nis unaffected — it calls handler functions directly and was never\nrouted through mcp.AddTool or m.server, so named scopes (audit, emit,\netc.) keep working unchanged.",
          "is_bot": false,
          "headline": "feat(mcp): partition tool surface into porcelain + deferred plumbing",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T08:44:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5877ccaf013b0ae6f8846ef6d2940cefc49df35b",
          "body": "mcpToolMeta gains Eager and InputSchema fields. trackTool captures\nt.InputSchema before the pointer reaches mcp.AddTool (which internally\ncopies via tt := *t, so inferred schemas never write back onto the\noriginal pointer). A new backfillEagerSchemas queries the live server\nvia the same in-process L\n[…]\nhema instead of nil.\n\nGroundwork for the porcelain/plumbing tool-surface split (workflow\nwkweyu50g): the deferred catalog needs InputSchema on every entry for\ncog_tool_search to return usable results.",
          "is_bot": false,
          "headline": "feat(mcp): capture InputSchema on toolMeta, backfill eager schemas",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T08:37:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d37652088f72c9329e94b227e015de11540c75f",
          "body": "chore(dispatch): decommission Ollama backend; default to LM Studio",
          "is_bot": false,
          "headline": "Merge pull request #417 from myrgic/chore/drop-ollama-backend",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:05:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c321093a4d9636ab8f548448a6bf0436f39ddf27",
          "body": "…d issue template ref\n\n- .cog/config/node/manifest.yaml: removed ollama observed-service block (port 11434)\n- .github/workflows/nightly-integration.yml: removed integration-ollama job (ollama/ollama\n  service container, OLLAMA_HOST env, wait-for-Ollama step); updated header comment\n- .github/ISSUE_TEMPLATE/bug_report.yml: updated provider example from\n  'ollama (gemma4:e4b)' to 'lmstudio-darkstar (gemma-4-26b)'",
          "is_bot": false,
          "headline": "chore(ci+config): remove Ollama service container, manifest entry, an…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:00:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19b0a2808b0dc0983988113612958c69273b1057",
          "body": "… lmstudio-darkstar\n\n- provider_ollama.go: added decommission header; defaultOllamaModel kept for compat\n- provider_ollama_integration_test.go: removed (Ollama CI service gone)\n- router.go: applyLocalModelConfig now covers lmstudio/openai-compat types;\n  defaultProvidersConfig Ollama branch emits a \n[…]\nscription updated (LM Studio as default);\n  Model jsonschema updated (no longer says 'e4b default, local Ollama');\n  cog_patch_config patch fields list removes ollama_embed_endpoint/ollama_embed_model",
          "is_bot": false,
          "headline": "chore(providers): tombstone Ollama provider; default providers.yaml →…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:00:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "159ecc33f803b6cdeab43663d8c83786c32673fb",
          "body": "… backend\n\n- detectLocalLLMTarget now probes OpenAI-compat (/v1/models) first, Ollama second\n- resolvePreferredLocalModel no longer hard-codes defaultOllamaModel as a priority\n  floor; falls back to models[0] (first model the server advertises)\n- localModelHint returns empty string when LocalModel i\n[…]\nrom Ollama wire format (/api/tags + /api/chat) to OpenAI-compat\n  (/v1/models + /v1/chat/completions); legacy state-routing fallback tests work via\n  the secondary Ollama probe in detectLocalLLMTarget",
          "is_bot": false,
          "headline": "feat(dispatch): decommission Ollama as default; LM Studio is the live…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:00:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0752cba4b3f90ab925e569bb7021f3b62fe008e",
          "body": "IndexWorkspace accumulated per-doc parse/index errors in indexErr and\nreturned it after a fully successful walk + commit + ref-resolve + FTS\nrebuild. A single cogdoc with malformed YAML frontmatter therefore caused\n'cogos reindex' to exit 1 even when 14,000+ other docs indexed cleanly.\n\nPer-doc fail\n[…]\nwith the exact YAML error class seen in production (mapping values\nnot allowed in this context), asserts IndexWorkspace returns nil, and\nverifies the valid sibling docs are indexed and FTS-searchable.",
          "is_bot": false,
          "headline": "fix(cli): cogos reindex tolerates per-doc parse failures (#416)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T13:33:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "906f5f245c256d56e4199e0eaafaae39a3d672c9",
          "body": "fix(search): idempotent lazy FTS reindex — keep cog_search_memory current",
          "is_bot": false,
          "headline": "Merge pull request #415 from myrgic/fts-lazy-reindex",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:54:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e1f869e6ee1d6e7abba4de2e623a084c3546e0e",
          "body": "…space\n\nThe generalized purge (DELETE FROM documents WHERE path NOT LIKE <root>/%)\nintroduced in the portability pass was unsafe on two counts: (1) it would\ndelete legitimately-indexed rows whose path falls outside the workspace root\n(conversation/session documents indexed from ~/.claude), and (2) t\n[…]\nxing is idempotent and does not require it.\nOrphan cleanup (rows whose file no longer exists) is deferred to a dedicated\nstat-based sweep. Test rewritten to assert out-of-workspace rows are preserved.",
          "is_bot": false,
          "headline": "fix(constellation): remove unsafe out-of-workspace purge in IndexWork…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:48:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "429a1758594988be62a54a5aeb17a467d4887329",
          "body": "…rkspace\n\nsdk/constellation/indexer.go:70 contained a literal DELETE predicate\n  WHERE path LIKE '/Users/slowbro/cog-workspace/%'\nwhich silently purged nothing on any machine other than the original author's\nand would never purge correctly if the workspace was renamed or moved.\n\nReplace with a param\n[…]\nhose absolute path falls\noutside the current workspace root — the actual portability-correct intent\nof the CRITICAL-4 purge — and uses a bound ? parameter so no literal path\nappears in the SQL source.",
          "is_bot": false,
          "headline": "fix(constellation): variabilize hardcoded stale-path purge in IndexWo…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:37:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2d779679f593319af6f749b1c9a017ec6fb4bb6",
          "body": "~/.cog/config is a directory holding self-update.yaml.  The old fallback\npath in loadGlobalConfig checked only statErr2 == nil before assigning\npath = oldPath, so os.ReadFile would attempt to read a directory and crash\non any kernel that has a self-update config installed.\n\nFix:\n- oldPath branch: us\n[…]\nh: widen the fallback condition from os.IsNotExist-only to\n  also cover the case where newPath exists but is a directory, so the\n  legacy fallback is tried when the canonical file path is itself a dir",
          "is_bot": false,
          "headline": "fix(providers/all): guard IsDir in loadGlobalConfig config-path fallback",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:37:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "28291a46597f97a36a284c5e9eca619db1fa56d5",
          "body": "…index\n\nlazy drift-repair (d11f3a4) warns users to run `cogos reindex` when\nwidespread drift is detected (>10 drifted rows), but the command was\nmissing — the CLI exited with 'unknown command reindex'.\n\nAdd internal/engine/cli_reindex.go modeled on cli_reconcile.go:\n- own flag.NewFlagSet with --work\n[…]\n_*.go files may\n  import sdk/constellation — only the long-lived daemon boot path may not\n- register case \"reindex\": in the switch in cli.go (~:159) and add a\n  printUsage line adjacent to \"reconcile\"",
          "is_bot": false,
          "headline": "feat(cli): add `cogos reindex` command to rebuild FTS5 constellation …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:36:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6ba790468a94a07670660fddbc2aa8342409476",
          "body": "Add MemWatcher (internal/engine/mem_watcher.go) to keep FTS current for\n.cog/mem/ writes that bypass the MCP write path (direct editor saves, ingest\nCLI, CI scripts).\n\nTwo behaviours:\n\n1. Recursive-add on directory Create.  macOS kqueue (and Windows\n   ReadDirectoryChangesW) is non-recursive: a newl\n[…]\npkgFTSRepairIndexer being non-nil.  In tests and CLI paths where no\n  indexer is wired the block is a no-op.\n- Watcher goroutine is stopped via a context-cancel listener when kernelCtx\n  is cancelled.",
          "is_bot": false,
          "headline": "feat(engine): mem-watcher with recursive subdir-add on fsnotify Create",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:34:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c6d2f19dec835f6d4713b1bcbe124fea4dda3bc",
          "body": "… FTS hook\n\nRemove the direct sdk/constellation import from internal/engine/mcp_stubs.go\n(package-boundary guard #2 per cogdoc_service.go:22).\n\nThe lazy drift-repair path in searchMemoryFTSDriftRepair previously called\nconstellation.Open directly.  Replace with pkgFTSRepairIndexer, a package-level\nC\n[…]\ng FTS in lockstep with the\nfile system.  WithConstellationIndexer is now called from a production path\n(MCPServer.SetConstellationIndexer) — previously the setter existed but had\nno production caller.",
          "is_bot": false,
          "headline": "fix(engine): kill sdk/constellation boundary violation; wire on-write…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:31:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d11f3a46bc46d6a579076e0c6b4b1c4c8e0a0aca",
          "body": "Before running the FTS5 query, sample up to 100 recently-indexed documents\nand compare their stored file_mtime to os.Stat.  For ≤10 drifted paths,\ncall constellation.IndexFile (now O(1) upsert) within a 200ms budget.\nIf drift is widespread, log once and fall through to serve current results\n(bulk repair belongs to `cogos reindex`).  No latency impact on the common\ncase (0 drifted rows in sample).",
          "is_bot": false,
          "headline": "feat(search): lazy FTS drift repair on every searchMemoryFTS call",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a3af8cf185f10eb3b8045abaa690e18baf87d32",
          "body": "…n tests\n\nReplace the per-file rebuildFTS() (O(N) full table rebuild) in IndexFile\nwith upsertFTSRow(), a targeted DELETE+INSERT FROM documents WHERE id=? pair\nwrapped in a savepoint for crash-consistency.  A package-level ftsMu\nserialises all FTS mutations so a watcher-triggered IndexFile cannot\nin\n[…]\nh a CLI-driven rebuildFTS.  IndexWorkspace continues to use\nrebuildFTS after the full walk.\n\nAdd three regression tests: FTSIndexFileSearchable, FTSIndexFileIdempotent,\nand FTSIndexFileChangedContent.",
          "is_bot": false,
          "headline": "feat(constellation): incremental FTS upsert + mutex guard + regressio…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:02:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b21d4a96912aa0ffb1e5ec85dd47d8d1cabce616",
          "body": "…ance\n\nWave 2 — harness: provisional-binding conformance",
          "is_bot": false,
          "headline": "Merge pull request #414 from myrgic/harness/wave2-provisional-conform…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T11:11:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aeabdc5d70793478469507758ea8901aed9b0341",
          "body": null,
          "is_bot": false,
          "headline": "style(harness): gofmt changed files",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T11:07:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96f3823151d95e6369700a05c0cafed3e458a1a9",
          "body": "…-B (ADR-031, RFC-020 subset)",
          "is_bot": false,
          "headline": "feat(harness): four-element is_error bodies for loop sentinels + gate…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c566316168cf19489267bcc21fb2d0978fd8a802",
          "body": "…pe reads (ADR pointer-first)",
          "is_bot": false,
          "headline": "refactor(harness): pointer-first (res=abstract) default for audit-sco…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:56:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859a672897e969d8372f042e3bf98f6be21fe03c",
          "body": "…C-016)",
          "is_bot": false,
          "headline": "refactor(harness): scope catalog cleanup + task-type micro-scopes (RF…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:50:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91c7311c348e8666b4c4eb38cf29a0e399ee2bff",
          "body": "…018, ADR-066)",
          "is_bot": false,
          "headline": "feat(harness): four-bundle orientation block on dispatch prompt (RFC-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:46:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef67f47a7fa235395d228aaface2fbe09518f7f4",
          "body": "…ymous fallback (RFC-identity-embedding)",
          "is_bot": false,
          "headline": "feat(harness): thread dispatch identity into inference + events, anon…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:44:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9438bed3ad3e5a72bad806348bb9a1b42f3ceeda",
          "body": "Wave 1 — harness: accepted-ADR conformance",
          "is_bot": false,
          "headline": "Merge pull request #413 from myrgic/harness/wave1-adr-conformance",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:09:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e05cffea3def9610775e650c8e330c7fbf2dbd28",
          "body": "… handling",
          "is_bot": false,
          "headline": "docs(harness): correct misleading comment on autonomic cycle sentinel…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:05:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "407cc86ba17b4296e793e69c8825ae27e23bee9e",
          "body": "… cog_get_index (ADR-045, ADR-066)",
          "is_bot": false,
          "headline": "refactor(harness): dedupe URI block, reconcile tool descriptions, cap…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:51:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa0b97aea386ffd679ac4a5cd21b360badd625bf",
          "body": "…83, ADR-033, ADR-072)",
          "is_bot": false,
          "headline": "feat(harness): emit cycle-trace + ledger events for dispatches (ADR-0…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:48:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e67f25ac652ae3cd32bd8ea78691f72bc7e7ec51",
          "body": "…rrors, respond hard-break (ADR-031, ADR-052)",
          "is_bot": false,
          "headline": "fix(harness): legible loop exits — max-turns/no-progress structured e…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:44:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bc157076b15de9b0baa0a75bf2d95c817f0693f",
          "body": "…ch (ADR-eigen, RFC-027)",
          "is_bot": false,
          "headline": "fix(harness): output contract + channel-token sanitization for dispat…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:41:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "507df4ffa1e90a24f83f5aaeecd1bf260ed67d59",
          "body": "…t-keyed RequestID (ADR-066)",
          "is_bot": false,
          "headline": "refactor(harness): make dispatch temp/max_tokens overridable + conten…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:39:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1a5f18819d5ddf3f3a348f9304bbecab5f54138",
          "body": "* feat(embed): use OpenAI /v1/embeddings instead of Ollama-native API\n\nSwitch the two embedding clients from Ollama's native endpoints to the\nOpenAI-compatible /v1/embeddings surface, so the kernel can use LM Studio\n(or any OpenAI-compatible server) for embeddings:\n\n- internal/engine/trm_context.go \n[…]\nndpoint+model stay config-driven (OllamaEmbed* keys retained for compat).\nOllama also serves /v1/embeddings, so this works against both backends during\nthe transition.\n\n* chore: bump VERSION to 0.16.6",
          "is_bot": false,
          "headline": "feat(embed): OpenAI /v1/embeddings instead of Ollama-native API (#412)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-27T12:49:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ee0175df4f073182eeca4cfb36b2484872c57d7",
          "body": "Ships the reconcile-driven self-update feature (#410) so the daemon can keep\nitself current with GitHub releases. After this release, install once to\nbootstrap, then 'cogos self-update' (or auto-apply) handles subsequent updates.",
          "is_bot": false,
          "headline": "chore: bump version to 0.16.5 (#411)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T10:54:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99f264b966396b5270986213efb7f2dcb72af70c",
          "body": "…eases (#410)\n\nAdds a SelfUpdate Reconcilable provider + a 'cogos self-update' CLI subcommand\nthat keep the launchd-managed daemon current with GitHub releases, per the\nreconcile philosophy (the kernel reconciles its own version like everything\nelse).\n\nProvider (internal/providers/selfupdate): throt\n[…]\ng\n.cog/config/self-update.yaml with enabled:true (intended opt-in). Chicken-and-\negg: this code must be in a release first, so v0.16.x must be installed once to\nbootstrap, after which it self-updates.",
          "is_bot": false,
          "headline": "feat(self-update): reconcile-driven cogos self-update from GitHub rel…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T10:50:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb53d8ea4e9cba3aa6f856f676ebba9907801649",
          "body": "Cuts a release of the overnight audit-remediation batch: #396-#408 (two\npath-traversal security sweeps, the worktree ledger-scan CPU fix, log/map leak\nfixes, data-race + deadlock fixes, reconcile hygiene + purity, and per-cycle\nperf reductions). Release notes auto-generate from PR titles since v0.16.3.",
          "is_bot": false,
          "headline": "chore: bump version to 0.16.4 (#409)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:32:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "820054c4c5b3e62f91e63e79606a72f23d29e2d1",
          "body": "…-reading the corpus (#408)\n\nAudit Q1 (projection_reconciler.go:387) + Q2 (decision_lineage_reconciler.go:219).\nBoth ApplyPlan implementations re-read and re-parsed the entire nodes/decision\ncorpus and re-rendered the projection — work FetchLive + ComputePlan already did\nearlier in the same reconcil\n[…]\ne per-action logs use the count already in Details.\n\nTest: ApplyPlan writes a sentinel carried in Details verbatim (proving no\nre-derive); existing full-cycle reconciler tests still green under -race.",
          "is_bot": false,
          "headline": "perf(reconcile): carry rendered projection in ApplyPlan instead of re…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:27:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "00c9cebeba790b054e343917d22bc3e1c1c1f125",
          "body": "ServiceProvider.Health() issues a Docker Ping plus one ContainerList per declared\nservice on every call, with no caching. Health() is on hot paths — every\nPOST /v1/infer (foveated context buildHealthBlock), every autonomic tick, and\nafter every reconcile cycle — so a workspace with N docker-mode ser\n[…]\n cache. Service liveness changes are still picked\nup within the TTL and at the latest by the next ~30s reconcile cycle.\n\nTest: a fresh cache is returned without recompute; an expired cache recomputes.",
          "is_bot": false,
          "headline": "perf(service): cache ServiceProvider.Health() behind a short TTL (#407)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:27:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e6abf615070178f0eddb4a62e41eeea3f77f4ed",
          "body": "…chLive (#406)\n\nEvalProvider.ComputePlan called readAndClearDispatchTriggers(e.root), which\nDESTRUCTIVELY clears the eval-dispatch-triggers.json sidecar. ComputePlan is\ncontractually pure (deterministic, side-effect-free) — the reconcile daemon may\ncall it and discard the plan, and a concurrent daem\n[…]\nin the audit.)\n\nTest: the dispatch-trigger test now drives the real flow — FetchLive drains the\nsidecar into live state, ComputePlan produces the non-skip action, and the\nsidecar is confirmed cleared.",
          "is_bot": false,
          "headline": "fix(eval): make ComputePlan pure by draining dispatch triggers in Fet…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:26:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e07dfc3b865ab219712c0d074b3f924a58e3520",
          "body": "…Config init race (#404)\n\nTwo related worktree-reconciler defects from the 2026-06-25 audit (C2 high, C3).\n\nC2 (worktree_reconciler.go:648) — perpetual Degraded after alarm acknowledgement.\nApplyPlan's health loop counted ANY action whose Details[\"classification\"] is an\nalarm type, including the Act\n[…]\nes the field race) that don't conflict with a later C1.\n\nTests: alarm-idempotent test now asserts Degraded while firing then Healthy after\nacknowledgement (C2); constructor defaults nil adapters (C3).",
          "is_bot": false,
          "headline": "fix(worktree): stop acknowledged alarms pinning Degraded; remove Load…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:26:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "843825f3da7751e4f36b580f1a2a6895e14073d1",
          "body": "… order (#405)\n\nTwo bus_session robustness fixes from the 2026-06-25 audit (A1/A2).\n\nA1 (bus_session.go:232) — saveRegistry used os.WriteFile (truncate-before-write).\nA SIGKILL/crash between truncate and write leaves registry.json empty;\nloadRegistry swallows the parse error and returns an empty reg\n[…]\nus until the next append recreated it. Move\nthe cache reset inside the create-succeeded branch; on create failure, warn and\nretain the cache.\n\nTest: saveRegistry round-trips and leaves no .tmp behind.",
          "is_bot": false,
          "headline": "fix(engine): atomic bus registry write + correct rotation cache-reset…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T16:12:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da224b444f2261fa83f6588a588c784baba838ef",
          "body": "…#403)\n\nThe manual SIGTERM->SIGKILL escalation path (taken when proc.cancel is nil, i.e.\nthe foreground streaming providers) spawned a goroutine that slept an\nuninterruptible 5s. On daemon shutdown it outlived the daemon by up to that 5s,\nfiring a pointless SIGKILL at an already-reaped PID (harmless\n[…]\ncalations during shutdown\nstill fire; only goroutines still pending after teardown abort.\n\nTest: Shutdown closes shutdownCh and a repeat Shutdown does not panic (double\nclose guarded by shutdownOnce).",
          "is_bot": false,
          "headline": "fix(engine): abort procmgr SIGKILL-escalation goroutine on shutdown (…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:55:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "837ffdf1eb2df70ed02ef0b120a7cb6cdd8508f8",
          "body": "…eopen (#402)\n\nRegression in #397 found by the 2026-06-25 audit. rotateLocked() closed the\nactive handle up front, then on either failure branch (rename succeeds but the\npost-rename reopen fails on a full disk; or rename fails AND the recovery reopen\nfails) returned with w.f still pointing at that c\n[…]\nd of writing to a dead descriptor.\n\nTests: Write-after-Close self-heal, and a forced post-failed-rotation state\n(closed handle, nil w.f, size over cap) that must not panic and must persist the\nrecord.",
          "is_bot": false,
          "headline": "fix(engine): keep rotating log writer's handle valid after a failed r…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:51:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "559f87e4ea159e48c11bf5d07524b1a8b561c3b4",
          "body": "The 2026-06-24 deep audit found four caller-supplied-path sites on the loopback\nHTTP+MCP surface that #396 did not cover. All reuse the pathWithin/containedJoin\nhelpers #396 already established. All are reject-only — valid inputs are\nunaffected; only previously-exploitable inputs are now refused.\n\n-\n[…]\ntName helper and apply it to both. (LOW)\n\nTests: sector-containment on both fallback paths; validClaudeProjectName table.\nLoopback-only by default, so these are local-access hardening, not remote RCE.",
          "is_bot": false,
          "headline": "fix(security): close path-traversal holes the #396 sweep missed (#401)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:43:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e31bf99e1111c0d7a361d4bc891d3aaf13f4c48",
          "body": "…very (#400)\n\nTestBuildRouterRegistersMLXSupervisedType failed on any host running LM Studio\non :1234: BuildRouter live-probes well-known OpenAI-compat backends and\nregisters a reachable 'lmstudio' ahead of the configured mlx-gemma, so\nFirstLocalProvider returned 'lmstudio'. It passed in CI only bec\n[…]\nys on by default); only the test opts out so\nrouter construction no longer depends on what LLM servers are live on the host.\n\nVerified: with LM Studio live on :1234, the test now passes (was failing).",
          "is_bot": false,
          "headline": "test(router): make BuildRouter MLX test hermetic via WithoutAutoDisco…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:13:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "847e08a43c4a2a7e061869eec4542c1a555d26fe",
          "body": "…(#399)\n\nWorktreeReconciler.LoadConfig runs every ~30s reconcile cycle and calls\nFilesystemLedgerReader.ReadWorktreeEvents, which listed every\n.cog/ledger/<session>/ dir and fully read + JSON-parsed each events.jsonl to\nextract a handful of worktree.* events. On a long-lived workspace that is\nhundre\n[…]\nam so the test can count cache-miss\nparses (mirrors the existing psLookup seam).\n\nTest: cache-hit on unchanged file (no re-parse), re-parse on append, eviction\non delete, and repoRoot-keyed isolation.",
          "is_bot": false,
          "headline": "perf(worktree): cache per-session ledger scans in ReadWorktreeEvents …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T14:57:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24ceef2542c6c3c98c0d89839329981770cf2646",
          "body": "…r-cycle work (#398)\n\nReconcile-contract cluster from the codebase audit, low-risk subset (the\ncontract-semantics items — worktree re-degrade, eval ComputePlan write, MLX\nconvergence, per-cycle subprocess batching — are deferred to review-required\nfollow-ups).\n\n- reconcile.GetProvider: recursive-RLo\n[…]\nmon (mirrors WorktreeReconciler.ComputePlan).\n\nTests: registry deadlock regression (verified it hangs against the buggy code),\ncogdoc disabled-skips-walk, decision-lineage wrong-live-type error paths.",
          "is_bot": false,
          "headline": "fix(reconcile): kill GetProvider deadlock + stop disabled-pipeline pe…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T14:34:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "87708bc7a9175899e81e59d882186724f403b537",
          "body": "…ks (#397)\n\n* fix(engine): cap kernel log growth and stop procmgr map/goroutine leaks\n\nTwo unbounded-resource bugs found in the codebase audit:\n\n1. kernel.log.jsonl grew without bound. The slog JSON sink was opened\n   O_APPEND and left open for the process lifetime with no rotation,\n   reaching ~446\n[…]\nats read it). Add a dedicated -race regression so the loadStatus/\nsnapshot guard can't silently regress. Processes use an unstarted cmd so the\nescalation goroutine is skipped and no real signals fire.",
          "is_bot": false,
          "headline": "fix(engine): cap kernel log growth and stop procmgr map/goroutine lea…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T14:24:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d52cb71615a65fb00374bb4a659a08d1b6c9b18",
          "body": "…(#396)\n\nThe kernel's HTTP/MCP surface treats callers as trusted-local, but several\nsites built filesystem paths from caller input via filepath.Join with no\ncontainment check — each an arbitrary read/write surface via \"../\" traversal\nor an absolute path:\n\n  - WriteCogDoc / cog_write_cogdoc (mcp_serv\n[…]\nt and contains\nto the workspace root (it legitimately reaches .cog/ontology, so cogRoot is the\nboundary). Tests cover traversal rejection, the absolute-containment nuance, and\nthe memory-resolver gap.",
          "is_bot": false,
          "headline": "fix(security): contain caller-supplied paths on the HTTP+MCP surface …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T13:58:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7ead4a0ad33a594fc5568cdf96f8a74975a93c3",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.16.3 (#395)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T11:20:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f21948a8b4ac58d0b27909504f7cbe60b2c063b",
          "body": "GitHub's macos-13 runners chronically sit queued for hours, and the release job\nneeds the full build matrix, so the darwin-amd64 (Intel Mac) build wedges every\nrelease — it cancelled v0.16.1 after 24h and stalled v0.16.2. Drop it; release\ntargets are arm64 Mac + linux (+ windows). The Makefile `all` target still\ncross-builds darwin-amd64 for local use; re-add the matrix entry when an\nIntel-Mac target or a reliable runner is needed.",
          "is_bot": false,
          "headline": "ci(release): drop darwin-amd64 from the release matrix (#394)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T11:11:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3131cd1d1728170cf72687bf6c39591c56971e87",
          "body": "…hash (#393)\n\nFetchLive re-spawned `python3 cogblock.py parse` for every source cogdoc on\nevery reconcile cycle — one subprocess per file, ~1.5s/cycle with the current\ncorpus (per the per-phase timing from #389; the convergence self-reporter from\n#391 flagged projection-compiler as the next over-bud\n[…]\nwnstream in ComputePlan/ApplyPlan, so sharing the\npointer is safe). Cache entries for deleted/renamed sources are evicted.\n\nSole-corpus fetch_ms drops from ~1.5s toward a few ms (file reads + hashes).",
          "is_bot": false,
          "headline": "perf(projection-compiler): cache cogblock.py parse by source content …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T11:09:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ccc94826a53f5987ecf03f3c9466cb290947244",
          "body": "…392)\n\nFetchLive reloaded the entire conversation index from disk every reconcile\ncycle (idx.Load reads _meta.json + every per-session turn file) — ~950ms and\n~92% of the cycle per the per-phase timing added in #389 (cycle fetch_ms). But\nthe daemon is almost always the sole writer: UpsertSession/Del\n[…]\n cycle.\n\nBoth the reconcile daemon and the autonomic ticker drive FetchLive, so this\nremoves the dominant per-cycle cost from both loops. Sole-writer fetch_ms drops\nfrom ~950ms toward single-digit ms.",
          "is_bot": false,
          "headline": "perf(conversations): skip FetchLive reload when index is unchanged (#…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:57:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01102bf5f9f5235389412b108fe96079c2a20123",
          "body": "The reconcile daemon recorded per-cycle cost but nothing watched the stream, so\na misbehaving provider only surfaced when an operator noticed elevated CPU and\nhand-traced the logs. Add a convergence tracker that flags two clean signals and\nemits a WARN (de-duped) plus a queryable snapshot:\n\n  - cost\n[…]\n behaviour (flagged / not-flagged), not just code\npaths — see convergence_tracker_test.go, which asserts the real ~950ms\nconversations regression would be flagged and a fast healthy provider never is.",
          "is_bot": false,
          "headline": "feat(reconcile): self-report per-provider reconcile anomalies (#391)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:21:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff5364f54b76d903362cebdf4b47b80cc9cb6d06",
          "body": "…ssions (#387)\" (#390)\n\nThis reverts commit ecdc366d746579999f0417b13db7bd9004d9cd33.",
          "is_bot": false,
          "headline": "Revert \"perf(conversations): incremental append-aware parse for CC se…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:21:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f1a78272b82389604af165d0ff17d8e66735454",
          "body": "The reconcile daemon recorded only the opaque cycle total (cycle.duration_ms),\nso a slow provider cycle could not be attributed to a phase without attaching a\nprofiler. Time each phase (LoadConfig, FetchLive, LoadState, ComputePlan,\nApplyPlan, BuildState+WriteState) and emit the breakdown both in th\n[…]\ntelemetry alone, without attaching a profiler.\n\nThis immediately surfaced that the conversations provider spends ~92% of its\n~1s cycle in FetchLive (a full index reload from disk), not in parse/apply.",
          "is_bot": false,
          "headline": "feat(reconcile): per-phase timing in the reconcile cycle (#389)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ecdc366d746579999f0417b13db7bd9004d9cd33",
          "body": "…#387)\n\nThe Conversations Observatory reconcile cycle never converged: every cycle\nre-read and re-parsed each growing Claude Code session JSONL from byte 0.\nA live session whose mtime/size changes each cycle forever triggered\nActionUpdate -> full ParseSession -> UpsertSession -> drift again, holding\n[…]\nce regression\nguard; full-reparse fallback on rewrite; and an end-to-end reconcile that\nasserts an append yields an is_append_only update and a no-change cycle\nconverges to zero create/update actions.",
          "is_bot": false,
          "headline": "perf(conversations): incremental append-aware parse for CC sessions (…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T02:13:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1823a2db614b7b2c6872ed5f1894bddcaad64a77",
          "body": "…(#388)\n\nIn the daemon binary LoadRegistry is intentionally nil — it is wired only\nthrough the cog CLI DI seams — so the component provider is inert: LoadConfig\nreturns nil and the reconcile cycle reports \"in sync\" with nothing to observe.\nHealth(), however, returned Degraded/Unknown for that same n\n[…]\nw mirrors the other nil-handling paths (LoadConfig,\nFetchLive, ComputePlan) and returns Synced/Healthy when LoadRegistry is nil.\n\nAdds a test asserting the inert nil-LoadRegistry path reports Healthy.",
          "is_bot": false,
          "headline": "fix(component): report Healthy when LoadRegistry is unwired (daemon) …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T02:13:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94c5031a7d82de1320f2cbf93d7bfd6adead7edd",
          "body": "…ts (#386)\n\nUnsent composer drafts captured by the claude-ai-web observer carry role\n\"user-draft\", which the ingest schema did not recognize. Every reconcile\ncycle re-rejected all of them (one log line per record) and held the\nconversations provider permanently Degraded, so it never reached a\nconver\n[…]\nxisting convergence-safe terminal\n(mirrors the unmapped-component path), so the source becomes fully\naccounted and the loop stops while the drafts are preserved, not dropped.\n\nBumps version to 0.16.2.",
          "is_bot": false,
          "headline": "fix(conversations): recognize user-draft role; quarantine unsent draf…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T00:40:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d73ff42f8a22dc0e13ed62f19f21451b9154528",
          "body": "…nged sources\n\nStop the per-cycle full-corpus coverage re-parse in the conversations reconcile: cache per-source coverage, serve unchanged (ActionSkip) sources from cache, recompute only on create/update, cold-fill once after restart, prune removed sources. Eliminates a ~3-core CPU sink. Verified with build/vet/race tests + 3-lens adversarial review.",
          "is_bot": false,
          "headline": "fix(conversations): cache per-source coverage; skip re-parse on uncha…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-17T01:33:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "229a3d39d38efcc2ba5201bd884ac96f1b750e37",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.16.1",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-16T20:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebb2a15f45c7e5cc2f98ddfafa0d816a7ee60d3d",
          "body": "Side-effect-free kernel-boundary admission check (IsKnownModel + AvailableModelIDs): handleChat rejects an unknown non-empty model id with HTTP 400 naming the model + available menu, instead of forwarding to the default provider and emitting an opaque 500-wrapped upstream 404.",
          "is_bot": false,
          "headline": "fix(engine): reject unknown model ids at kernel boundary with 400",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-16T20:24:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1566ae21263abd239fac030050d5b0be898ffd1",
          "body": "Scrub private cog:// slugs, hardcoded user paths, and a resolvable private RFC path from public docs; gitignore runtime/private spill dirs (.cog/blobs, .cog/mem/episodic, .cog/mem/working, .hermes). Docs + .gitignore only; no code change.",
          "is_bot": false,
          "headline": "chore(docs): scrub residual private refs and ignore runtime spill",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-16T20:18:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6e0d1f205299f220bd7bc8563afb98ebfe2be80",
          "body": "…ls have working FTS5 search (#381)\n\n* fix(release): build with CGO_ENABLED=1 + -tags fts5 so released kernels have working FTS5 search\n\nThe release workflow built every artifact with CGO_ENABLED=0 and no -tags\nfts5. The kernel reaches sqlite's FTS5 engine through mattn/go-sqlite3, a\nCGO binding tha\n[…]\n=0 / missing -tags fts5\nregression — which shipped silently in v0.16.0 — from recurring: the\nrelease fails loudly if the build path drifts away from the Makefile's\nBUILD_TAGS=fts5 + host-CGO contract.",
          "is_bot": false,
          "headline": "fix(release): build with CGO_ENABLED=1 + -tags fts5 so released kerne…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-15T12:47:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "462fbfbf09ca78b71895548686e7981bd17d61f5",
          "body": "* docs(adr): flatten yaml-cog-block frontmatter and scrub private refs in ADR-100/101\n\nADR-100 and ADR-101 used a nonstandard nested cog: YAML block instead of\nflat frontmatter. Flatten to standard flat YAML. In the same pass, replace\nall cog:// private-corpus URIs in the refs fields:\n- ADR-091 and \n[…]\nvate internal research corpus name) in §1b and Discussion log\n- Replace RFC-025 body reference in §4 Composition with description\n- Replace private memory-file slugs in §8 Provenance with descriptions",
          "is_bot": false,
          "headline": "docs: remove internal references from public ADRs/RFCs (#379)",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-11T23:53:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13c0368546e167c6ae13af168f5812b30eee0f7e",
          "body": "Release content: conversations observatory ingest surface v0.1 (#369),\nquery-aware URI resolver per ratified RFC (#370), MCP tool-output byte\ncaps (#371), e2e MCP transport probe (#372), daemon wiring test +\nproviders/all extraction (#374), chat 501 fix (#376), nightly\nintegration workflow (#377), ontology-as-class enforcement (#375).",
          "is_bot": false,
          "headline": "chore: bump version to 0.16.0 (#378)",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T21:19:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e084b372f4ec8ee7b0cacf16fb1598fd5dfc4b17",
          "body": "…uarantine, coverage metric (v0.2 groundwork) (#375)\n\n* feat(conversations): add ontology loader, quarantine writer, coverage tracker (v0.2 data layer)\n\nIntroduces the four data-layer types that back ontology-as-class enforcement:\n\n- ontology.go: ParseL1Ontology (L0 grammar validation), LoadOntology\n[…]\nwo cycles,\nhermes-darkstar degenerate=14690 (baseline 14690), hermes-cog\ndegenerate=1857 (baseline 1857), counts stable across cycles.\n\n* test: t.Fatal on nil LoadedOntology guard (staticcheck SA5011)",
          "is_bot": false,
          "headline": "feat(conversations): ontology-as-class enforcement — load L0/L1/L2, q…",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T20:17:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b7a7dd1926ed26a8c0f77253ddaa6548de71637",
          "body": "Job 1 runs the self-contained -tags integration suites (httptest/tempdir\nbased); job 2 attempts the Ollama-dependent set, clearly labeled and\ncontinue-on-error. No || true on enforced jobs. Re-verified on current\nmain after fix(engine) #376 unblocked TestIntegrationFullLifecycle.\nSupersedes #373 (branch history unmergeable after squash cascade).",
          "is_bot": false,
          "headline": "ci(nightly): run the dormant integration-tagged test suites (#377)",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T20:09:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25185470009346b8e5b82cbaf352b86074e91f02",
          "body": "…nfigured (#376)\n\nMoves the s.router == nil guard to the top of handleChat, ahead of the\nio.ReadAll / json.Unmarshal calls. Previously a nil or empty request body\n(e.g. the integration test's bare POST) would hit the JSON parser first and\nreturn 400 before reaching the 501 branch — breaking\nTestIntegrationFullLifecycle/chat_returns_501. The duplicate nil-check lower\nin the function is removed; behavior for the router-present path is unchanged.",
          "is_bot": false,
          "headline": "fix(engine): return 501 before parsing chat body when no router is co…",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T20:03:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 38,
      "commits_last_year": 810,
      "latest_release_at": "2026-07-17T13:43:00Z",
      "latest_release_tag": "v0.16.20",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 1.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/myrgic/cogos",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/myrgic/cogos",
          "is_deprecated": false,
          "latest_version": "v0.16.20",
          "repository_url": "https://github.com/myrgic/cogos",
          "versions_count": 40,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-17T13:34:45Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-04-06",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 39
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "bep_proto/bep.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "envspec/go.mod",
        "go.mod",
        "harness/go.mod",
        "pkg/bep/go.mod",
        "pkg/cogblock/go.mod",
        "pkg/cogfield/go.mod",
        "pkg/coordination/go.mod",
        "pkg/modality/go.mod",
        "pkg/reconcile/go.mod",
        "pkg/substrate/go.mod",
        "pkg/uri/go.mod",
        "sdk/go.mod"
      ],
      "largest_source_bytes": 138356,
      "source_files_sampled": 697,
      "oversized_source_files": 4,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "envspec/go.mod",
        "go.mod",
        "harness/go.mod",
        "sdk/go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/charmbracelet/bubbles",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.0"
        },
        {
          "name": "github.com/charmbracelet/bubbletea",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.10"
        },
        {
          "name": "github.com/charmbracelet/lipgloss",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/coder/acp-go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.0"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.0"
        },
        {
          "name": "github.com/go-git/go-git/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.16.4"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/hashicorp/hcl/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.24.0"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.24"
        },
        {
          "name": "github.com/modelcontextprotocol/go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/myrgic/cogos/envspec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/myrgic/cogos/harness",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/cogblock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/cogfield",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/coordination",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/modality",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/reconcile",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/opencontainers/go-digest",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/opencontainers/image-spec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.1"
        },
        {
          "name": "github.com/santhosh-tekuri/jsonschema/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/zclconf/go-cty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.17.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.40.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.37.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.54.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.44.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "oras.land/oras-go/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.6.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "harness/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "harness/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "harness/go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.0"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.24"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 334,
        "open_issues": 39,
        "closed_ratio": 0.702,
        "closed_issues": 92,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "chazmaniandinkle",
          "commits": 611,
          "avatar_url": "https://avatars.githubusercontent.com/u/357329?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "nightly-integration.yml",
        "pr-review.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 7,
            "reason": "Found 22/30 approved changesets -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 1,
            "reason": "1 out of the last 5 releases have a total of 1 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "40 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "7ebe6461c7b0d381e6b90f85dbc47b9f1943bb68",
        "ran_at": "2026-07-23T17:18:20Z",
        "aggregate_score": 4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T11:16:28Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-22T23:46:54Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 98,
          "created_at": "2026-04-30T16:59:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 101,
          "created_at": "2026-04-30T17:01:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 105,
          "created_at": "2026-04-30T18:29:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 205,
          "created_at": "2026-05-06T02:33:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 206,
          "created_at": "2026-05-06T02:33:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 207,
          "created_at": "2026-05-06T02:33:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 208,
          "created_at": "2026-05-06T02:34:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 274,
          "created_at": "2026-05-17T16:24:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 275,
          "created_at": "2026-05-17T16:24:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 276,
          "created_at": "2026-05-17T16:24:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 301,
          "created_at": "2026-05-19T16:41:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 302,
          "created_at": "2026-05-19T18:00:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 310,
          "created_at": "2026-05-20T22:56:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 321,
          "created_at": "2026-05-26T00:28:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 322,
          "created_at": "2026-05-26T00:29:04Z",
          "last_comment_at": "2026-05-26T01:15:26Z",
          "last_comment_author": "chazmaniandinkle"
        },
        {
          "number": 330,
          "created_at": "2026-05-26T01:46:07Z",
          "last_comment_at": "2026-05-26T03:10:16Z",
          "last_comment_author": "chazmaniandinkle"
        },
        {
          "number": 340,
          "created_at": "2026-05-27T11:52:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 383,
          "created_at": "2026-06-17T01:31:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 384,
          "created_at": "2026-06-17T01:33:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 385,
          "created_at": "2026-06-17T01:33:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/myrgic/cogos",
    "host": "github.com",
    "name": "cogos",
    "owner": "myrgic"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 61,
      "inputs": {
        "security": 40,
        "vitality": 83,
        "community": 43,
        "governance": 54,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 810,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "810 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 810
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 91,
            "inputs": {
              "releases_count": 38,
              "latest_release_tag": "v0.16.20",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 1.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "38 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 38
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 43,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 334,
              "open_issues": 39,
              "closed_issues": 92,
              "issue_closed_ratio": 0.702,
              "closed_unmerged_prs": 8
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "70% of issues closed",
                "points": 32.8,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 70
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "334/342 decided PRs merged",
                "points": 37.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 334,
                      "decided": 342
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 22/30 approved changesets -- score normalized to 7",
                "points": 10.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "myrgic",
              "public_repos": 18,
              "account_age_days": 107
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of myrgic",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "myrgic"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "18 public repos, account ~0 yr old",
                "points": 9.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 18
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/myrgic/cogos"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "40 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 40
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "claude-code",
                "context-assembly",
                "golang",
                "local-first",
                "mcp"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 40,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 22/30 approved changesets -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "40 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 65,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "envspec/go.mod",
                "go.mod",
                "harness/go.mod",
                "pkg/bep/go.mod",
                "pkg/cogblock/go.mod",
                "pkg/cogfield/go.mod",
                "pkg/coordination/go.mod",
                "pkg/modality/go.mod",
                "pkg/reconcile/go.mod",
                "pkg/substrate/go.mod",
                "pkg/uri/go.mod",
                "sdk/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 138356,
              "source_files_sampled": 697,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/697 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 697,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": [
                "bep_proto/bep.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "bep_proto/bep.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "bep_proto/bep.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T17:18:42.764479Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/myrgic/cogos.svg",
  "full_name": "myrgic/cogos",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasGo.