Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-27 09:20 UTC

orangecheck / oc-packages

Monorepo for the @orangecheck/* npm packages + the orangecheck Python SDK. SDK, gate middleware, React bindings, wallet adapter, CLI, Strfry relay filter, airdrop-gate.

TypeScriptMIT★ 0 estrellas⑂ 0 forksdesde abr 2026Ver en GitHub ↗

orangecheck/oc-packages tiene un índice de salud de 55 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (84/100) y la más baja, Community & Adoption (34/100). Se actualizó por última vez hace 4 días. Una sola persona concentra la mayor parte del trabajo reciente.

55
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

55
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

OrangeCheckOrganización
3 seguidores19 repositorios públicosdesde abr 2025

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

84Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 4 días
9/36Cadencia de commits — 13/52 semanas con commits
18/18Volumen de commits — 309 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year309
human_commit_share1
days_since_last_push4
active_weeks_last_year13
Cómo se puntúa
27/27Publica versiones — 100 versiones publicadas
36/36Recencia de las versiones — última versión hace 6 días
27/27Cadencia de publicación — una versión cada ~2 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count100
latest_release_tagdesign-v0.28.13
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases2
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

34En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 0 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
50.4/80Descargas mensuales — 5998 descargas/mes en npm, pypi
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@orangecheck/ui, @orangecheck/cli, @orangecheck/sdk, @orangecheck/gate, @orangecheck/legal, @orangecheck/react, @orangecheck/design, orangecheck
dependents
ecosystemsnpm, pypi
total_downloads
monthly_downloads5998
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

44En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — 0% de issues cerradas
38.2/38.3Aceptación de PR — 19/19 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs19
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs0
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
4.3/25Alcance del propietario — 3 seguidores de orangecheck
12/25Trayectoria — 19 repos públicos, cuenta de ~1 años
Datos de entrada utilizados
followers3
owner_typeOrganization
is_verified
owner_loginorangecheck
public_repos19
account_age_days456
Cómo se puntúa
25/25Publicado y resoluble — 8 paquete(s) en npm, pypi
35/35Recencia de publicación — última publicación hace 6 días
20/20Historial de versiones — 55 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@orangecheck/ui, @orangecheck/cli, @orangecheck/sdk, @orangecheck/gate, @orangecheck/legal, @orangecheck/react, @orangecheck/design, orangecheck
ecosystemsnpm, pypi
any_deprecatedno
min_days_since_publish6

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

66Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 6 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30README
0/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://ochk.io
10/10Descripción del repositorio
10/10Topics — 10 topics
10/10Wiki
Datos de entrada utilizados
topicsbip322, bitcoin, express, middleware, nextjs, nostr, python, sdk, sybil-resistance, typescript
has_wiki
homepagehttps://ochk.io
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

42En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 47 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4,2
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

57Moderado · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 95 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,95
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — agent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 29 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Datos de entrada utilizados
has_nixno
has_tests
lockfilesyarn.lock
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configsagent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json
agent_commit_share0,29
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
55/55Tamaños de archivo manejables — 0/482 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes56.314
source_files_sampled482
oversized_source_files0

Datos clave

0estrellas de GitHub
1contribuidores
309commits en los últimos 12 meses
4días desde el último push
100versiones publicadas
1factor bus
1issues abiertas
npm, PyPIecosistemas de paquetes

Advertencias de recopilación de datos

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 4.2 / 10
4.2agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-27 09:20 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities47 existing vulnerabilities detected
Dependencias directas 85
RegistroPaqueteRestricción de versiónManifiesto
npm@noble/hashes^1.5.0agent-anthropic/package.json
npm@orangecheck/agent-core^0.3.0agent-anthropic/package.json
npm@orangecheck/agent-signer^0.1.0agent-anthropic/package.json
npm@noble/hashes^1.5.0agent-cli/package.json
npm@orangecheck/agent-core^0.1.0agent-cli/package.json
npmbip322-js^3.0.0agent-cli/package.json
npmcommander^12.1.0agent-cli/package.json
npm@noble/hashes^1.5.0agent-core/package.json
npm@orangecheck/stamp-core^1.0.0agent-core/package.json
npm@orangecheck/lock-core^1.0.1agent-core/package.json
npm@noble/hashes^1.5.0agent-langgraph/package.json
npm@orangecheck/agent-core^0.3.0agent-langgraph/package.json
npm@orangecheck/agent-signer^0.1.0agent-langgraph/package.json
npm@noble/hashes^1.5.0agent-mcp/package.json
npm@orangecheck/agent-core^0.1.0agent-mcp/package.json
npm@orangecheck/agent-signer^0.1.0agent-mcp/package.json
npm@noble/hashes^1.5.0agent-openai/package.json
npm@orangecheck/agent-core^0.3.0agent-openai/package.json
npm@orangecheck/agent-signer^0.1.0agent-openai/package.json
npm@noble/hashes^1.5.0agent-signer/package.json
npm@orangecheck/agent-core^0.3.0agent-signer/package.json
npm@noble/hashes^1.5.0agent-vercel/package.json
npm@orangecheck/agent-core^0.3.0agent-vercel/package.json
npm@orangecheck/agent-signer^0.1.0agent-vercel/package.json
npm@orangecheck/sdk^0.1.3airdrop-gate/package.json
npm@simplewebauthn/browser^13.3.0auth-client/package.json
npmjose^6.2.2auth-core/package.json
npm@orangecheck/me-client^0.18.0cli/package.json
npm@orangecheck/sdk^0.1.3cli/package.json
npmcommander^12.1.0cli/package.json
npm@radix-ui/react-accordion^1.2.12design/package.json
npm@radix-ui/react-checkbox^1design/package.json
npm@radix-ui/react-dialog^1.1.15design/package.json
npm@radix-ui/react-label^2.1.7design/package.json
npm@radix-ui/react-popover^1.1.15design/package.json
npm@radix-ui/react-radio-group^1design/package.json
npm@radix-ui/react-select^2.2.6design/package.json
npm@radix-ui/react-separator^1.1.7design/package.json
npm@radix-ui/react-slot^1.2.3design/package.json
npm@radix-ui/react-switch^1design/package.json
npm@radix-ui/react-tabs^1.1.3design/package.json
npmclass-variance-authority^0.7.1design/package.json
npmclsx^2.1.1design/package.json
npmqrcode^1.5.4design/package.json
npmsonner^2.0.7design/package.json
npmtailwind-merge^3.3.1design/package.json
npm@orangecheck/sdk^0.1.4gate/package.json
npm@vercel/functions^3.7.3insights-client/package.json
npm@orangecheck/lock-crypto^0.1.0lock-core/package.json
npm@noble/ciphers^1.3.0lock-crypto/package.json
npm@noble/curves^1.6.0lock-crypto/package.json
npm@noble/hashes^1.5.0lock-crypto/package.json
npm@noble/curves^1.6.0lock-device/package.json
npm@orangecheck/lock-cryptofile:../lock-cryptolock-device/package.json
npm@orangecheck/auth-core^2.0.0me-client/package.json
npm@noble/hashes^1.5.0pledge-core/package.json
npm@orangecheck/sdk^0.1.3react/package.json
npm@orangecheck/sdk^0.1.3relay-filter/package.json
PyPIhttpx>=0.25sdk-py/pyproject.toml
npm@bitcoinerlab/secp256k1^1.1.1sdk/package.json
npm@noble/curves^2.2.0sdk/package.json
npm@noble/hashes^1.5.0sdk/package.json
npm@scure/base^1.1.9sdk/package.json
npmbip322-js^3.0.0sdk/package.json
npmbitcoinjs-message^2.2.0sdk/package.json
npmbuffer^6.0.3sdk/package.json
npm@orangecheck/stamp-core^0.1.2stamp-cli/package.json
npm@orangecheck/stamp-ots^0.1.1stamp-cli/package.json
npmbip322-js^3.0.0stamp-cli/package.json
npmcommander^12.1.0stamp-cli/package.json
npm@noble/hashes^1.5.0stamp-core/package.json
npm@orangecheck/stamp-core^0.1.2stamp-ots/package.json
npm@orangecheck/vault-core^0.2.0vault-cli/package.json
npmcommander^12.1.0vault-cli/package.json
npm@noble/hashes^1.5.0vault-core/package.json
npm@orangecheck/lock-crypto^0.1.0vault-core/package.json
npm@noble/curves^1.6.0vote-cli/package.json
npm@noble/hashes^1.5.0vote-cli/package.json
npm@orangecheck/vote-core^0.1.1vote-cli/package.json
npm@orangecheck/lock-core^0.1.0vote-cli/package.json
npm@orangecheck/lock-crypto^0.1.0vote-cli/package.json
npmbip322-js^3.0.0vote-cli/package.json
npmcommander^12.1.0vote-cli/package.json
npmws^8.18.0vote-cli/package.json
npm@noble/hashes^1.5.0vote-core/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "bip322",
        "bitcoin",
        "express",
        "middleware",
        "nextjs",
        "nostr",
        "python",
        "sdk",
        "sybil-resistance",
        "typescript"
      ],
      "is_fork": false,
      "size_kb": 2104,
      "has_wiki": true,
      "homepage": "https://ochk.io",
      "languages": {
        "CSS": 77541,
        "Python": 161481,
        "JavaScript": 40861,
        "TypeScript": 2377914
      },
      "pushed_at": "2026-07-22T17:53:37Z",
      "created_at": "2026-04-22T00:05:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T17:28:43Z",
      "description": "Monorepo for the @orangecheck/* npm packages + the orangecheck Python SDK. SDK, gate middleware, React bindings, wallet adapter, CLI, Strfry relay filter, airdrop-gate.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://ochk.io",
      "name": "OrangeCheck",
      "type": "Organization",
      "login": "orangecheck",
      "company": null,
      "location": null,
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/209241724?v=4",
      "created_at": "2025-04-26T12:20:56Z",
      "is_verified": null,
      "public_repos": 19,
      "account_age_days": 456
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "design-v0.28.13",
          "kind": "other",
          "published_at": "2026-07-20T18:30:23Z"
        },
        {
          "tag": "me-client-v0.24.0",
          "kind": "other",
          "published_at": "2026-07-08T18:24:22Z"
        },
        {
          "tag": "auth-client-v2.22.0",
          "kind": "other",
          "published_at": "2026-07-06T16:59:29Z"
        },
        {
          "tag": "design-v0.28.12",
          "kind": "other",
          "published_at": "2026-07-06T16:59:23Z"
        },
        {
          "tag": "me-client-v0.23.0",
          "kind": "other",
          "published_at": "2026-07-05T00:00:01Z"
        },
        {
          "tag": "design-v0.28.11",
          "kind": "other",
          "published_at": "2026-07-04T06:33:03Z"
        },
        {
          "tag": "design-v0.28.10",
          "kind": "other",
          "published_at": "2026-07-04T03:15:39Z"
        },
        {
          "tag": "design-v0.28.9",
          "kind": "other",
          "published_at": "2026-07-03T22:13:30Z"
        },
        {
          "tag": "design-v0.28.8",
          "kind": "other",
          "published_at": "2026-07-02T22:59:03Z"
        },
        {
          "tag": "design-v0.28.7",
          "kind": "other",
          "published_at": "2026-07-02T22:20:35Z"
        },
        {
          "tag": "design-v0.28.6",
          "kind": "other",
          "published_at": "2026-07-02T21:09:54Z"
        },
        {
          "tag": "design-v0.28.5",
          "kind": "other",
          "published_at": "2026-07-02T20:37:53Z"
        },
        {
          "tag": "design-v0.28.4",
          "kind": "other",
          "published_at": "2026-07-02T20:23:02Z"
        },
        {
          "tag": "design-v0.28.3",
          "kind": "other",
          "published_at": "2026-07-02T20:10:02Z"
        },
        {
          "tag": "design-v0.28.2",
          "kind": "other",
          "published_at": "2026-07-02T19:47:25Z"
        },
        {
          "tag": "design-v0.28.1",
          "kind": "other",
          "published_at": "2026-07-02T19:25:37Z"
        },
        {
          "tag": "design-v0.28.0",
          "kind": "other",
          "published_at": "2026-07-02T19:12:44Z"
        },
        {
          "tag": "design-v0.27.0",
          "kind": "other",
          "published_at": "2026-07-02T18:35:04Z"
        },
        {
          "tag": "design-v0.26.0",
          "kind": "other",
          "published_at": "2026-07-02T18:17:23Z"
        },
        {
          "tag": "design-v0.25.0",
          "kind": "other",
          "published_at": "2026-06-30T18:02:48Z"
        },
        {
          "tag": "design-v0.24.0",
          "kind": "other",
          "published_at": "2026-06-30T17:55:10Z"
        },
        {
          "tag": "design-v0.23.0",
          "kind": "other",
          "published_at": "2026-06-30T14:28:08Z"
        },
        {
          "tag": "design-v0.22.0",
          "kind": "other",
          "published_at": "2026-06-29T15:33:36Z"
        },
        {
          "tag": "design-v0.21.0",
          "kind": "other",
          "published_at": "2026-06-25T20:02:45Z"
        },
        {
          "tag": "design-v0.20.0",
          "kind": "other",
          "published_at": "2026-06-25T19:07:04Z"
        },
        {
          "tag": "insights-client-v0.1.1",
          "kind": "other",
          "published_at": "2026-06-23T21:04:19Z"
        },
        {
          "tag": "auth-client-v2.21.0",
          "kind": "other",
          "published_at": "2026-06-23T19:50:49Z"
        },
        {
          "tag": "auth-client-v2.20.0",
          "kind": "other",
          "published_at": "2026-06-23T01:15:44Z"
        },
        {
          "tag": "design-v0.19.0",
          "kind": "other",
          "published_at": "2026-06-22T19:38:00Z"
        },
        {
          "tag": "auth-client-v2.19.0",
          "kind": "other",
          "published_at": "2026-06-22T19:08:39Z"
        },
        {
          "tag": "wallet-adapter-v0.4.1",
          "kind": "other",
          "published_at": "2026-06-16T05:08:37Z"
        },
        {
          "tag": "design-v0.18.0",
          "kind": "other",
          "published_at": "2026-06-15T17:32:58Z"
        },
        {
          "tag": "design-v0.17.0",
          "kind": "other",
          "published_at": "2026-06-12T02:28:38Z"
        },
        {
          "tag": "design-v0.16.0",
          "kind": "other",
          "published_at": "2026-06-11T23:54:28Z"
        },
        {
          "tag": "design-v0.15.0",
          "kind": "other",
          "published_at": "2026-06-11T14:49:43Z"
        },
        {
          "tag": "auth-core-v2.5.0",
          "kind": "other",
          "published_at": "2026-06-11T14:49:28Z"
        },
        {
          "tag": "auth-client-v2.18.0",
          "kind": "other",
          "published_at": "2026-06-11T14:49:23Z"
        },
        {
          "tag": "me-client-v0.22.0",
          "kind": "other",
          "published_at": "2026-06-09T22:19:58Z"
        },
        {
          "tag": "design-v0.14.0",
          "kind": "other",
          "published_at": "2026-06-05T23:07:58Z"
        },
        {
          "tag": "design-v0.13.1",
          "kind": "other",
          "published_at": "2026-06-05T23:04:05Z"
        },
        {
          "tag": "agent-core-v1.1.0",
          "kind": "other",
          "published_at": "2026-06-05T19:04:31Z"
        },
        {
          "tag": "design-v0.13.0",
          "kind": "other",
          "published_at": "2026-06-05T18:14:30Z"
        },
        {
          "tag": "design-v0.12.0",
          "kind": "other",
          "published_at": "2026-06-05T17:33:53Z"
        },
        {
          "tag": "design-v0.11.0",
          "kind": "other",
          "published_at": "2026-06-05T16:28:28Z"
        },
        {
          "tag": "legal-v0.2.1",
          "kind": "other",
          "published_at": "2026-06-04T12:00:11Z"
        },
        {
          "tag": "insights-client-v0.1.0",
          "kind": "other",
          "published_at": "2026-06-04T06:28:48Z"
        },
        {
          "tag": "design-v0.10.0",
          "kind": "other",
          "published_at": "2026-06-03T05:48:52Z"
        },
        {
          "tag": "design-v0.9.1",
          "kind": "other",
          "published_at": "2026-06-02T17:52:36Z"
        },
        {
          "tag": "design-v0.9.0",
          "kind": "other",
          "published_at": "2026-06-02T17:25:31Z"
        },
        {
          "tag": "design-v0.8.0",
          "kind": "other",
          "published_at": "2026-06-01T19:53:52Z"
        },
        {
          "tag": "design-v0.7.6",
          "kind": "other",
          "published_at": "2026-05-28T17:25:25Z"
        },
        {
          "tag": "design-v0.7.5",
          "kind": "other",
          "published_at": "2026-05-27T19:52:33Z"
        },
        {
          "tag": "design-v0.7.4",
          "kind": "other",
          "published_at": "2026-05-27T19:26:39Z"
        },
        {
          "tag": "design-v0.7.3",
          "kind": "other",
          "published_at": "2026-05-27T17:51:19Z"
        },
        {
          "tag": "design-v0.7.2",
          "kind": "other",
          "published_at": "2026-05-27T17:36:29Z"
        },
        {
          "tag": "design-v0.7.1",
          "kind": "other",
          "published_at": "2026-05-27T16:21:23Z"
        },
        {
          "tag": "design-v0.7.0",
          "kind": "other",
          "published_at": "2026-05-27T15:12:34Z"
        },
        {
          "tag": "design-v0.6.1",
          "kind": "other",
          "published_at": "2026-05-26T19:34:13Z"
        },
        {
          "tag": "design-v0.6.0",
          "kind": "other",
          "published_at": "2026-05-26T19:21:26Z"
        },
        {
          "tag": "design-v0.5.3",
          "kind": "other",
          "published_at": "2026-05-26T19:11:39Z"
        },
        {
          "tag": "design-v0.5.2",
          "kind": "other",
          "published_at": "2026-05-26T15:33:32Z"
        },
        {
          "tag": "design-v0.5.1",
          "kind": "other",
          "published_at": "2026-05-25T21:15:56Z"
        },
        {
          "tag": "design-v0.5.0",
          "kind": "other",
          "published_at": "2026-05-25T17:58:45Z"
        },
        {
          "tag": "design-v0.4.0",
          "kind": "other",
          "published_at": "2026-05-25T15:28:10Z"
        },
        {
          "tag": "design-v0.3.0",
          "kind": "other",
          "published_at": "2026-05-25T15:15:29Z"
        },
        {
          "tag": "design-v0.2.0",
          "kind": "other",
          "published_at": "2026-05-25T14:32:04Z"
        },
        {
          "tag": "design-v0.1.1",
          "kind": "other",
          "published_at": "2026-05-22T23:23:28Z"
        },
        {
          "tag": "design-v0.1.0",
          "kind": "other",
          "published_at": "2026-05-22T21:28:09Z"
        },
        {
          "tag": "auth-client-v2.17.2",
          "kind": "other",
          "published_at": "2026-05-21T05:08:14Z"
        },
        {
          "tag": "ui-v0.15.2",
          "kind": "other",
          "published_at": "2026-05-20T22:01:30Z"
        },
        {
          "tag": "ui-v0.15.1",
          "kind": "other",
          "published_at": "2026-05-20T20:03:21Z"
        },
        {
          "tag": "auth-client-v2.17.1",
          "kind": "other",
          "published_at": "2026-05-20T20:03:15Z"
        },
        {
          "tag": "ui-v0.15.0",
          "kind": "other",
          "published_at": "2026-05-20T17:45:59Z"
        },
        {
          "tag": "auth-client-v2.17.0",
          "kind": "other",
          "published_at": "2026-05-20T17:38:04Z"
        },
        {
          "tag": "auth-client-v2.15.0",
          "kind": "other",
          "published_at": "2026-05-19T15:48:40Z"
        },
        {
          "tag": "auth-client-v2.14.1",
          "kind": "other",
          "published_at": "2026-05-19T03:42:51Z"
        },
        {
          "tag": "ui-v0.14.0",
          "kind": "other",
          "published_at": "2026-05-19T01:33:04Z"
        },
        {
          "tag": "auth-client-v2.14.0",
          "kind": "other",
          "published_at": "2026-05-18T23:02:43Z"
        },
        {
          "tag": "ui-v0.13.0",
          "kind": "other",
          "published_at": "2026-05-18T17:14:16Z"
        },
        {
          "tag": "ui-v0.12.0",
          "kind": "other",
          "published_at": "2026-05-18T16:03:10Z"
        },
        {
          "tag": "auth-client-v2.13.0",
          "kind": "other",
          "published_at": "2026-05-18T15:55:11Z"
        },
        {
          "tag": "auth-core-v2.4.0",
          "kind": "other",
          "published_at": "2026-05-18T15:42:17Z"
        },
        {
          "tag": "ui-v0.11.0",
          "kind": "other",
          "published_at": "2026-05-18T15:03:31Z"
        },
        {
          "tag": "auth-client-v2.12.0",
          "kind": "other",
          "published_at": "2026-05-18T15:03:21Z"
        },
        {
          "tag": "cli-v0.2.0",
          "kind": "other",
          "published_at": "2026-05-10T04:28:36Z"
        },
        {
          "tag": "me-client-v0.18.0",
          "kind": "other",
          "published_at": "2026-05-10T04:24:27Z"
        },
        {
          "tag": "me-client-v0.17.0",
          "kind": "other",
          "published_at": "2026-05-10T04:06:56Z"
        },
        {
          "tag": "me-client-v0.16.0",
          "kind": "other",
          "published_at": "2026-05-09T08:16:44Z"
        },
        {
          "tag": "me-client-v0.15.0",
          "kind": "other",
          "published_at": "2026-05-09T08:01:03Z"
        },
        {
          "tag": "nostr-core-v0.1.1",
          "kind": "other",
          "published_at": "2026-05-09T07:14:46Z"
        },
        {
          "tag": "nostr-core-v0.1.0",
          "kind": "other",
          "published_at": "2026-05-08T19:28:42Z"
        },
        {
          "tag": "agent-core-v1.0.1",
          "kind": "other",
          "published_at": "2026-05-07T21:58:43Z"
        },
        {
          "tag": "lock-core-v1.0.1",
          "kind": "other",
          "published_at": "2026-05-07T21:57:26Z"
        },
        {
          "tag": "agent-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:57Z"
        },
        {
          "tag": "vote-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:49Z"
        },
        {
          "tag": "sdk-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:23Z"
        },
        {
          "tag": "stamp-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:18Z"
        },
        {
          "tag": "lock-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:18Z"
        },
        {
          "tag": "pledge-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T18:27:11Z"
        },
        {
          "tag": "sdk-py-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T18:27:07Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2238e09092ca384e98d417e2ce4a668259611619",
          "body": "oc-media-kit added the globe brand, so its generated glyphs.ts now carries 16\nglyphs. Re-vendor to keep design in sync (check-glyph-drift green). No version\nbump — globe's site doesn't consume the sigil glyph; this rides the next\ndesign publish.",
          "is_bot": false,
          "headline": "re-vendor glyph catalog: add globe",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-22T17:26:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69fa507175fa1ae3dc5c000b294dde7c8a00d9cf",
          "body": "globe.ochk.io shipped with `slug: 'globe' as EcosystemSlug` — a cast that\npapered over the slug being absent from the union, FAMILY_PROPERTIES and the\nswitcher ENTRIES. The visible cost: globe does not self-highlight in its own\nlogo dropdown and does not appear in any sibling's switcher at all.\n\nRegistered alongside btc as the family's second read-only terminal.",
          "is_bot": false,
          "headline": "register oc·globe in the family registry",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-20T18:29:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b866d062dba6c2a06f272bf07458a7673ab5d3d9",
          "body": "Make the live-mode revenue path actually work.\n\noc.event.fire / fireBatch gain:\n- signingSecret → X-OC-Signature HMAC authenticating the call as the\n  INTEGRATOR. Live mode 401s without it (a user session proves a user,\n  never the paying project). Server-side only.\n- bearerToken → the forwarded use\n[…]\ne) HMAC keeps the package isomorphic (no node:crypto\nimport); a parity test asserts the signature byte-matches the server's\nnode:crypto verifier, and that the secret never leaks into the request body.",
          "is_bot": false,
          "headline": "me-client: sign billable events + drop the user_address footgun",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-08T18:23:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3764727d0f9035bfc2bef888f97fcda689f074f",
          "body": "…ount a tab is on\n\nThe '§ show as' list resolves per-account via the tab's session; a tab\nsigned into a different account than your other tabs showed only a did,\nso it looked like the menu 'lost' your email. Two fixes:\n\n- design: surface the current account's identity (email/bitcoin/nostr)\n  in the \n[…]\n itself\n  so the show-as list is the tab's actual account even when called\n  outside a provider (previously relied solely on the global fetch\n  interceptor). Host already reads the header fail-closed.",
          "is_bot": false,
          "headline": "auth-client@2.22.0 + design@0.28.12: account menu tells you which acc…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-06T16:58:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22ecbd125a7faf713a598c103737984e5e5b8f7d",
          "body": "…og (#34)\n\nThe app already accepts integrator-defined event keys (open catalog, #23) but\nthe SDK still typed subtype as the closed EventSubtype union, so a custom event\nwouldn't type-check for SDK users. Add EventKey = EventSubtype | (string & {})\n— keeps built-in autocomplete, accepts any custom ke\n[…]\nEventInput.subtype, BillableEvent.subtype, the OC-Subtype webhook header,\nand validation errors. Built-in metadata + drop schedules stay closed.\nBackward-compatible (EventKey ⊇ EventSubtype). +1 test.",
          "is_bot": false,
          "headline": "me-client@0.23.0: widen EventKey — SDK matches the open project catal…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T23:59:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89d103335a5f5f86bbaf6ee838cbc248bb74d432",
          "body": "…rflow-x-auto — the latter forced overflow-y:auto and clipped the active-tab underline (regression in 0.28.10)",
          "is_bot": false,
          "headline": "design@0.28.11: TabsList wraps on overflow (flex-wrap) instead of ove…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T06:31:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cac9626d37cf0ec90bd3664e0f22a09239213664",
          "body": "…verflow the page on mobile",
          "is_bot": false,
          "headline": "design@0.28.10: TabsList scrolls on overflow so long tab rows never o…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T03:14:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80e34fc34c7b7e323e67414a12fa4fa309ebed84",
          "body": "…(prev commit reformatted the whole file with prettier defaults); TabsList scroll fix unchanged",
          "is_bot": false,
          "headline": "design: restore tabs.tsx to the package's single-quote/4-space style …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T02:58:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e613a6dee3bad3be8a3a22bd85a474c6382dce1c",
          "body": "…-x-auto, hidden scrollbar) so a long tab row never overflows the page on mobile",
          "is_bot": false,
          "headline": "design: TabsList scrolls horizontally on overflow (min-w-0 + overflow…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T02:55:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bbe622abc6241dc2094ae976198909c72b23cac",
          "body": "…gisters\n\nStrip tile frames so pictograms emboss (not the square); floor/cap strokes so\nno mark vanishes or bloats; per-verb focus sizing. Lit letterpress relief under\nember (specular leaf, chromatic shade) vs unlit echo stack under cypherpunk;\ndepth melts to transparent (composites over the aurora). Calmer pose, eased\nrelief, corner-aware mask, mobile presence floor. New band deboss preset +\nband prop; --oc-sigil-bg removed. verify-sigil-transforms guards the regexes.",
          "is_bot": false,
          "headline": "design@0.28.9: OcSigil beauty pass — mark surgery, lit relief, two re…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-03T22:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f4041c631efdbb656fc9ca97d9b8385731c64ca",
          "body": "…{{ gl: false }})\n\nFlip the provider default so a bare/true aurora (or an intensity-only object)\nmounts the GL silk field. The CSS blobs stay the floor, so failure/degradation\nbehavior is unchanged. Reading + owner-console surfaces opt out with gl:false.",
          "is_bot": false,
          "headline": "design@0.28.8: OcAuroraGL is the family default (opt out with aurora=…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T22:56:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b94e3f51162eaac84094f11d6a2d337adbcff72",
          "body": "…e-on-brand)",
          "is_bot": false,
          "headline": "design@0.28.7: OcSigil --oc-sigil-ink — mark on a coloured band (whit…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T22:18:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38d497bd7cb51cb7a538fe20ac233dcd9bb2aa39",
          "body": "…alog\n\nRe-vendored glyphs.ts (emitter now emits solid vs outline per is_glyph_only),\nsub() resolves only the ink sentinel, and the PerVerb story is a 15-mark\ncatalog that catches a broken glyph. All marks render as coherent 3D marks.",
          "is_bot": false,
          "headline": "design@0.28.6: fix broken per-verb sigil glyphs + rebuild PerVerb cat…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T21:07:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0aca867702df0ef9939bfbc53ff6aa2a81a5cec6",
          "body": "…ment",
          "is_bot": false,
          "headline": "design@0.28.5: OcSigil — light-mode presence + mobile top-right place…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T20:36:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf0117483fa18bdf9c37ff398ed59c4d83244087",
          "body": "…ment",
          "is_bot": false,
          "headline": "design@0.28.4: OcSigil — light-mode presence + mobile top-right place…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T20:21:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34b80e7f4e348935b7eba31f26680b92adbfd5cc",
          "body": "Address real feedback: the opaque corner object read loud and barely\npresent, and it was display:none on phones. Rework to a see-through 3D\nwatermark — the relief composites at --oc-sigil-opacity so the aurora reads\nthrough, softer color ramp, responsive clamp() size, and it stays visible\n(smaller/quieter) on mobile instead of vanishing. All tunable via CSS vars.",
          "is_bot": false,
          "headline": "design@0.28.3: OcSigil — translucent, muted, responsive watermark",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T20:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75115230f6215d46ab5e348cd146a5ef9f026a53",
          "body": "The sub-brand glyphs are tiles (filled square + frame + detail); filling fg\nmade a solid block. Render the outline form (fg=none) so the tile drops away,\nleaving the recognizable framed mark — an engraved seal. And replace the 6\nflat overlapping layers with 22 computed layers of real z-separation: lit\nfront face, shadowed extrusion walls, back dissolving into --background — a\ntrue 3D object catching light as it drifts. One treatment recolored per skin.",
          "is_bot": false,
          "headline": "design@0.28.2: OcSigil — fix the orange block, add real 3D extrusion",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T19:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0150cddc6c12bbfc8287e55ee2e99c329ec81be",
          "body": "The filled letterpress register was invisible on ember: a low-contrast\nsame-hue relief over the aurora's warm bloom in the same corner failed the\nminimum-visibility floor. Strengthen the relief ramp so the front face is a\ndefined --primary silhouette (opaque, occluding the aurora within the glyph)\nwhile the back layers still dissolve into --background. Wireframe register\nuntouched. Caught by real-browser taste check on the stamp pilot.",
          "is_bot": false,
          "headline": "design@0.28.1: OcSigil emboss visibility — ember-first ramp",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T19:24:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d8049605a43ba4a3ab6d8b0950eb4dc8a7ec161",
          "body": "…pth R3, ships dormant)\n\nThe figure component of the backdrop program: 6 stacked <use> layers of the\nverb's own normalized media-kit glyph under perspective+translateZ, opaque\ncolor-mix ramp toward --background (contrast ceiling + visibility floor are\ncompiled in, not consumer-tunable), damped ±5° p\n[…]\nield + one figure; one motion\nsource per hero). Glyph geometry is vendored from oc-media-kit's new\nemit_glyphs.py artifact; scripts/check-glyph-drift.mjs guards the sync and\nruns first in yarn verify.",
          "is_bot": false,
          "headline": "design@0.28.0: OcSigil — the mark as a corner-bleed emboss (aurora de…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T19:10:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f31cfe855e16d82506b54387b9852df9fefc2bd",
          "body": "… R2, default off)\n\nOne ~8KB WebGL2 fragment shader supersedes the perceptual output of the\n5-blob CSS aurora: domain-warped fBm recolored live from the same --au-*\nslots via the color-mix probe rail (scene-tokens.ts — OKLCH tokens resolve\nnatively in the browser, no parser), IGN dither so dark mode\n[…]\nde (one aurora at a time). Settle-to-static after 90s idle.\nPer-site kill: .oc-aurora { --oc-aurora-gl: off }. gl is opt-in via the\nprovider prop; chat/docs intensity objects keep compiling unchanged.",
          "is_bot": false,
          "headline": "design@0.27.0: OcAuroraGL — the token-driven silk field (aurora depth…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T18:32:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a14528f134e7b578e57f28c1aa9e984d035d02b8",
          "body": "…epth R1)\n\nWCAG 2.2.2 Pause/Stop/Hide has no exemption for >5s decorative motion and\nprefers-reduced-motion alone doesn't satisfy it — the aurora has shipped that\ngap on every family site. This release closes it: an oc_motion cookie at\nDomain=.ochk.io, applied pre-paint by getOcThemeInitScript as\nda\n[…]\nhand-rolled bg-primary/10 blur-3xl divs (mark baked from\nthe normalized media-kit render, never the raw font-space path). Groundwork\nfor aurora depth R2 (OcAuroraGL) per research/AURORA-DEPTH-PLAN.md.",
          "is_bot": false,
          "headline": "design@0.26.0: ambient-motion governance + backdrop texture (aurora d…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T18:14:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a629620f484e69e654dc59b2bf9afcb7c8c37223",
          "body": "Add optional legalCopyright / legalLinks / builtWith props so sites keep\none consistent legal-bar shape while preserving meaningful content (btc's\n'read on bitcoin' + disclaimer, me's charter link). Defaults unchanged.",
          "is_bot": false,
          "headline": "feat(design): OcFamilyFooter legal-bar overrides",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-30T18:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a2f30232ddffb0ca1a7eef1dcbd03f74382bcb8",
          "body": "Extracts the per-site LayoutFooter shape (brand block · §-labelled link\ncolumns · legal bar + built-with-bitcoin) into one component. The\nfamily product/protocol columns are driven off FAMILY_PROPERTIES via the\n`family` prop, so any footer that lists the family can never drift from\nthe canonical table again.",
          "is_bot": false,
          "headline": "feat(design): OcFamilyFooter — one canonical family footer",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-30T17:53:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00911eb0de584fe894ea22e42a8f97718aab781e",
          "body": "The dashboard/data composites (StatGrid, StatCard, DataRow lists,\nDefinitionList, data tables) + a new Panel (DataSection) now re-skin per\ntheme: flat/sharp/mono terminal under the cypherpunk skins (byte-for-byte\nunchanged), soft/warm/rounded cards under ember. Built via semantic classes\n(.oc-stat-g\n[…]\nded by an ember-scoped CSS block — so data-dense technical\nsubpages (status, dashboards, api surfaces) read as ember instead of terminal.\nVerified both skins in Storybook; themes 5/5, stories 135/135.",
          "is_bot": false,
          "headline": "design@0.23.0: ember treatments for data-dense technical surfaces",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-30T14:26:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c646f37ba9dc5d1f857f905fbd7ce2a8ef6b91c",
          "body": "ember now owns the bare :root/.dark base (the no-JS / pre-hydration / SSR\nfallback); orangecheck + phosphor + lightning + gold become attribute-only\narms imported after it. DEFAULT_OC_THEME='ember' and OC_THEMES lists ember\nfirst, so a user with no oc_skin cookie gets ember and the picker leads with\n[…]\n/--au-blue under ember so the ambient field\n  stays amber/terracotta instead of leaking cool teal/blue.\n- MarketingHeading onBrand muted clause /60 → /75 (was below AA-large on the\n  terracotta band).",
          "is_bot": false,
          "headline": "design@0.22.0: make ember the family default skin + first in the picker",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-29T15:32:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef5363f001d2cfe681d64257fbb45992ddc987f5",
          "body": "Stories for the 12 new ember-era components (Surface, IconBadge, plus the\nmarketing composites: MarketingHeading, FeatureCard, Section/BrandBand,\nComparisonTable, StepList, Faq, EmailCapture, CheckList, AccentNote,\nVerifiedChip). README documents the five skins, ember's self-hosted font,\nand the verify-script step when adding a skin. Stories-only — no version bump.\nverify-stories: 134/134 OK.",
          "is_bot": false,
          "headline": "design: Storybook stories for the ember marketing tier + skin docs",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-29T14:07:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0798432e9a5acb90aeb974feb61a01fbb7d0b91",
          "body": "Append oc·btc (category product) to FAMILY_PROPERTIES + EcosystemSwitcher\nENTRIES + the EcosystemSlug union, so btc.ochk.io shows up in every sibling's\nlogo dropdown and account menu. Additive — no existing entry changes.",
          "is_bot": false,
          "headline": "design: v0.21.0 — add btc.ochk.io to the family site-picker",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T20:01:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2d991439d4a795a8852ea3bdce61a45a0cf9d87",
          "body": "ember references 'Hanken Grotesk'; ship it IN the package (OFL variable woff2,\nlatin + latin-ext, wght 400–900) via @font-face so the skin renders correctly on\nevery consumer with ZERO per-site next/font wiring. The browser only fetches it\nwhen the family is actually used (ember active), so the cyph\n[…]\ntier (Surface,\nIconBadge, FeatureCard, MarketingHeading, Section, ComparisonTable, StepList,\nFaq, EmailCapture, CheckList, AccentNote, VerifiedChip), Button onBrand variants,\nand the self-hosted font.",
          "is_bot": false,
          "headline": "design@0.20.0: self-host Hanken Grotesk for the ember skin + release",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T19:05:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a3f4457c270335926ab3f82cd681c017359ed22",
          "body": "The terminal-window chrome (mono body, cool-gray strip, traffic-light dots,\nsharp/tight corners) is the cypherpunk skins' identity — there is no reason a\nwarm consumer skin should render Card / Modal / Confirm / Prompt as green-screen\nwindows. Skin-scoped (ember only) so the other skins keep their t\n[…]\n  → rounded, with the message + action labels in warm sans/normal-case via a\n  :has(.terminal-title) anchor; secret/value inputs stay mono.\n\nVerified: 99/99 stories, ember AA both modes, 5/5 distinct.",
          "is_bot": false,
          "headline": "design: de-terminalize the system surfaces under ember (no green-screen)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T18:40:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68b535fcd53b04de86e03ec1b5931f8a244a96e4",
          "body": "…leteness)\n\nSection-by-section comparison against the source mockups drove these:\n- Eyebrows now render TERRACOTTA, not gray. Root cause: .label-mono hardcoded a\n  muted color that overrode the caller's text-primary. Made .label-mono type-only\n  (no color); every eyebrow + SectionHeader tone + Callo\n[…]\ntrast); the OC button check sits in a chip; FAQ has its\n  hairline; the for-business closing line is back; the footer headline is one line.\n\nVerified: 99/99 stories, ember AA both modes, 5/5 distinct.",
          "is_bot": false,
          "headline": "design: tighten ember fidelity to Sou's mockups (eyebrows, type, comp…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T18:06:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be92b7ac1b5f8cd878078a941601d6d713068e73",
          "body": "The real gap the showcase exposed: no Button variant for CTAs placed ON a brand\nband or dark section, so they were hacked with classNames — and one rendered\nwhite-text-on-white (the hero \"See how it works\" was unreadable). Add proper\nvariants so the rollout just works:\n- Button `onBrand` (white pill\n[…]\n → accent-foreground\n  (adapts light↔dark).\n- checkbox/radio invalid now show a persistent destructive ring (was invisible\n  when checked).\n\nVerified: 99/99 stories, ember AA both modes, 5/5 distinct.",
          "is_bot": false,
          "headline": "design: first-class on-brand Button variants + ember legibility fixes",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T17:42:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b7570f18cc77d73ed66ba9d0d0d601bc0cd0ae3",
          "body": "…ntity\n\nFull component audit under ember (light+dark) surfaced and fixed:\n- bg-brand bands: tailwind-merge dropped bg-brand next to bg-diagonal (both read\n  as bg-*). Renamed motifs to currentColor .oc-diagonal/.oc-dots (non-bg prefix)\n  so brand/CTA bands actually render terracotta.\n- dark --primar\n[…]\na/switch) now use destructive (red)\n  for aria-invalid instead of brand — invalid no longer looks like valid.\n\nVerified: 99/99 stories render error-free, 5/5 skins distinct, ember AA-clean\nboth modes.",
          "is_bot": false,
          "headline": "design: fix ember theme across every component + embrace the warm ide…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T17:20:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9eba38dda2c5676b6c2e0b3099f360ad122fefaa",
          "body": "A new warm, consumer-grade skin (the counterpoint to the sharp/cypherpunk\ndefaults): deep burnt-sienna terracotta, peach accents, 1rem radius, pill\nbuttons, soft warm elevation, Hanken Grotesk. Full light+dark token arms,\nregistered via the data-driven registry so it reaches every site's appearance\n\n[…]\nCard\nor dashboard SectionHeader.\n\nThemes/Ember Showcase reproduces the full redesign from these components.\nVerified: 5/5 skins distinct, ember AA-clean in both modes, 99/99 stories\nrender error-free.",
          "is_bot": false,
          "headline": "design: add the ember skin + marketing composite tier",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T16:36:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e92d2c00b8511950c200686ec942bc391864a051",
          "body": "…overflows the page as a grid/flex child",
          "is_bot": false,
          "headline": "design: .terminal min-width:0 + max-width:100% so a code panel never …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T14:34:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c4b73c03bc7e1be07c8db81aa05f586dabbd330",
          "body": "cosign (5 @orangecheck/* deps), chat (8), forge (4), and vault-extension (1) were\nnever added to the global consumer list, so they silently drift on every\n@orangecheck/* package — including the insights-client@0.1.1 Lane-2 fix. All four\nhave live GitHub remotes; enroll them so the auto-bumper keeps them current\n(CI-gated auto-merge, same as the rest). Found while verifying the insights-client\nfanout reaches www/attest/me (it does — they were already enrolled).",
          "is_bot": false,
          "headline": "renovate: enroll the 4 missing family-package consumers",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T22:43:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2fde1a3cbc248834af36557c72c5f40a85ab5497",
          "body": "The fire-and-forget emit was being dropped on Vercel: the serverless function\nfreezes after the response before the keepalive POST flushes, so every\nconsumer's `void emit()` reached the collector with ZERO events (verified\nempty across www/attest/me despite tokens being set). emitEvent now hands its\n[…]\non, no per-app change. No-op outside a Vercel request\ncontext (try/catch); the keepalive fetch stays as the off-Vercel fallback.\nPatch bump so ^0.1.0 consumers auto-fanout via Renovate. 9 tests green.",
          "is_bot": false,
          "headline": "insights-client@0.1.1: deliver on Vercel via internal waitUntil",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T21:03:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82a32c9cf75d59ac73c972226fce963afb2d5fba",
          "body": "…n tabs\n\nA new tab (CTRL/⌘/middle-click) can't inherit the opener's sessionStorage\npin, so it resolved to the shared cookie's default account. The opener\nnow stamps its effective did:oc onto outgoing family-origin links\n(#oc-as=<did> — a public selector in a fragment, never the JWT), and the\nlanding\n[…]\nAccountHint are auto-installed by\nOcSessionProvider, so consumers need only the version bump. auth-core is\nunchanged (resolveSessionFromRequest already resolves the tab header\nfirst and fails closed).",
          "is_bot": false,
          "headline": "auth-client@2.21.0: inherit the tab's account into new/cross-subdomai…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T19:40:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25e101f85e51f50a4b0ae60f884dbe62de9618c3",
          "body": "OcSignIn now defaults providersFirst=true (OAuth on top, email one-time-code the\ndefault tab, BIP-322 wallet one tab away) — the email/OAuth-first ceremony is now\nthe family standard every consumer inherits without per-site props. initialPath\ndefaults to 'email'. Pass providersFirst={false} for legacy bitcoin-first order.",
          "is_bot": false,
          "headline": "auth-client@2.20.0: providersFirst on by default",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T01:14:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fc120059c5ce8e5da5349baa569715c321d4587",
          "body": "cosign.ochk.io (cofounder matching, commercial product) joins the\nproduct tier of the ecosystem switcher + family-properties registry.",
          "is_bot": false,
          "headline": "design: add oc·cosign to the family switcher",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-22T19:36:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9470cb2b2cd511e568295aab8b53339b499eafde",
          "body": "…front door\n\nThe canonical ceremony leads with the BIP-322 wallet — the right default\nfor the family, the wrong one for ochk.io's public homepage, where a\nfirst-time visitor who's never held bitcoin bounces off a wallet prompt.\n\nprovidersFirst (opt-in, default off) promotes Google/GitHub above the\np\n[…]\nl and defaults the active tab to email, with the wallet path one tab\naway as 'bitcoin · self-custody'. Email/OAuth stays the bridge; the\nBitcoin address is still the canonical identity it resolves to.",
          "is_bot": false,
          "headline": "auth-client: providersFirst on OcSignIn for a non-Bitcoiner-friendly …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-22T19:07:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30a6828b6377f02bad1842e5307c3cf344d4ce6a",
          "body": "… window.prompt (0.4.1)\n\nThe \"paste signature\" wallet invoked getSigner -> signManual -> window.prompt — an\nunstyled, un-themed, mobile-hostile native dialog every consumer (chat, vault, me)\ninherited. Clicking it now opens an inline panel inside the component: the\ncanonical message in a read-only b\n[…]\npy button, a real <textarea>, and\nUse-signature / back controls. The prompt-based signManual stays as the\nprogrammatic (non-React) fallback in sign.ts; only the React component changed.\nNo API change.",
          "is_bot": false,
          "headline": "wallet-adapter: OcWalletButton manual path is an inline textarea, not…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-16T05:07:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8050a5e4e9ac9a85996b77e8ebdc6431bb6c7b5b",
          "body": "fleet.ochk.io is now a private, owner-gated product. Recategorize it from\n'product' to 'owner' in both family registries (FAMILY_PROPERTIES and the\nEcosystemSwitcher ENTRIES -> OWNER_ENTRIES) so it's hidden from the public\nfamily switcher and visible only to owners (is_owner JWT claim), like\nanalytics/bot/forge. docsHref now points at its own origin (no public docs).",
          "is_bot": false,
          "headline": "design: move oc·fleet to the owner-only switcher section",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-15T17:30:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20b786da592393dd554e8ff4fe417d994e5525d7",
          "body": "…d theme in\n\nA centered hamburger in the middle of the header was wrong. OcPrimaryNav is\nnow desktop-inline-only; on mobile the nav + appearance live in a `☰` that\nOcAccountMenu renders to the LEFT of the identity chip, so the right cluster is\n`[☰][identity]`. The standalone appearance palette folds\n[…]\nmobile and console sites keep their desktop nav.\n\nAdds AppearanceControls (the mode+skin block) so any surface — the palette, the\naccount `☰`, a site's own Sheet drawer — can host appearance settings.",
          "is_bot": false,
          "headline": "design: move mobile nav into the account menu (left of identity), fol…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-12T02:27:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa7cfd08caa3beacf1ef59b9dd18bf8a0c49d8a8",
          "body": "The ecosystem status strip was fully transparent, so it bled the hero/aurora\nbehind it and the loud uppercase right-side tags wrapped on phones. Give it a\nfaint skin-tinted translucent band (.oc-substrip) that carries the active skin's\nhue across light/dark, collapse it to heartbeat + product below \n[…]\nhows\ninline at md+ and collapses to one shared menu disclosure below that. The\nOcAccountMenu identity chip condenses to dot + chevron below sm so a long\ndid/display-name no longer eats a phone header.",
          "is_bot": false,
          "headline": "design: shade the sub-header strip + make header chrome mobile-correct",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-11T23:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6227a27163122d340ac79815f44819d5db6437f",
          "body": "…t pinning\n\nOne browser, N roster accounts, each tab operating as its own one. A\ntab pins itself by holding its account's session JWT (sessionStorage)\nand presenting it as x-oc-tab-session — a credential verified exactly\nlike the cookie token, never a bare selector. Switching re-pins the\nswitching t\n[…]\nh provider hop (it\npreviously clamped to the embedding origin, stranding consumer-site\nusers on the ochk.io homepage after an OAuth add).\n\ndesign 0.15.0 surfaces a quiet '· this tab' hint when pinned.",
          "is_bot": false,
          "headline": "auth-core 2.5.0 + auth-client 2.18.0 + design 0.15.0 · per-tab accoun…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-11T14:48:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6c7715f1841766e992a888bba45ccba48381431",
          "body": "Optional `auth?: AuthSigner` on publishEvent/queryEvents — the caller passes a\nsigner for the kind-22242 challenge so the package stays dependency-free. On an\n`auth-required` relay's [\"AUTH\", challenge] frame, sign + send AUTH + re-send the\nEVENT/REQ; absent a signer the challenge is ignored (today'\n[…]\nrelay AUTH). NOT released — no version\nbump / no tag; the next nostr-core release picks it up. The client glue + an AUTH\nrelay to test against are the remaining gates (research/INSTITUTIONAL-PLAN.md).",
          "is_bot": false,
          "headline": "nostr-core: additive NIP-42 AUTH support (no release)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-10T16:57:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3082458c17e9754bcd72122889681e2bc7a82cbb",
          "body": "…irror\n\nDrop periods shipped on me.ochk.io: integrator-scheduled payout\nwindows where covered events' user-share matures and vests as one\nbatch at a block-denominated boundary. SDK surface:\n\n- BillableEvent.drop (signed canonical v=4 stamp: window_id +\n  close_height_target)\n- DropCadence / DropSche\n[…]\nross − platform, rebate as exact remainder — the\n  oc.event.verify replay no longer reports false divergences on edge\n  values\n- IntegratorEventConfig.agent (AgentClassOverride) was missing\n  entirely",
          "is_bot": false,
          "headline": "feat(me-client): 0.22.0 — drop-period types + re-sync the canonical m…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-09T22:19:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b01621d345536a82676f3883650b122608d8831e",
          "body": "The .app-bar utility escalated gutters like .container (px-4 sm:px-6\nlg:px-8), but a full-bleed app shell pins a fixed-width 56px icon rail\nflush left — so the header logo drifted off the rail at every width\n(worst at desktop's 32px). Fix to a flat 18px gutter, which seats the\n20px logo mark exactly over the rail's glyph column (center 28px).",
          "is_bot": false,
          "headline": "design 0.14.1: fix OcAppBar full-variant gutter",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-06T01:42:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc29a9f6e9a78586d0e2532b9ecc12d9eb8dda77",
          "body": "… utility\n\nAdds the app-surface counterpart to the constrained .container header: OcAppBar (chrome) mounts the same primitives (OcLogoDropdown/OcPrimaryNav/OcAccountMenu via start/center/end slots) in an edge-to-edge .app-bar row (gutters only, no max-width), so a full-bleed app shell aligns with the chrome above. Marketing/content pages keep .container unchanged. For chat /app and other full-screen app surfaces (analytics cockpit, forge console). Additive; purely opt-in.",
          "is_bot": false,
          "headline": "design 0.14.0 — OcAppBar: sanctioned full-bleed app header + .app-bar…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T23:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "caceaa10b078633cd9976e129ed1e26b02222dfd",
          "body": "OcPrimaryNav's active item shipped a 1px orange bottom stripe. Active is\nnow orange text only — restrained, matches the family taste. The three\nhand-rolled commercial navs (vault/fleet/me) drop the copy-pasted stripe\nin their own repos in lockstep.",
          "is_bot": false,
          "headline": "fix(primary-nav): text-only active affordance, drop the orange stripe",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T23:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ebf7822ef293aef61d13ae2d9990af51b8442d2",
          "body": "…ive)\n\nverifyFederationDelegation / verifyFederationRevocation +\ncomputeFederationDescriptorId, conformant against FEDERATION.md vectors v18-v26.\nAdditive — v1 single-address path unchanged.",
          "is_bot": false,
          "headline": "agent-core@1.1.0: federation-principal verifier (OC Agent v1.2 normat…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T19:03:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd2a8187c23d1d00d55375f572197a6d0c9b282a",
          "body": "FEDERATION.md + its v18-v26 vectors live on the oc-agent-protocol\nspec/federation-v1.2 DRAFT branch, not merged to main. CI clones spec main\n(no federation vectors) so the test hard-failed with ENOENT. Guard with\nexistsSync: run + pass where the draft fixtures exist (local branch checkout),\nskip cleanly where they don't (CI on main). The verifier itself is still\ntype-checked + built either way; conformance re-activates automatically when the\ndraft branch merges to main.",
          "is_bot": false,
          "headline": "agent-core: federation conformance test skips when draft vectors absent",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T18:57:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f875a5ffb781e9042c7be6cd5195b180cfc025b",
          "body": "The spec's federation vectors (v18-v26) were committed without a verifier, so\nagent-core's vector suite had 20 failing tests. This adds the missing v1.2\nverifier path, conformant against all of them.\n\nNew src/federation.ts — purely additive; the v1 single-address DelegationEnvelope\n+ verifyDelegatio\n[…]\n filter. Suite green: 82 passed, 0 failed.\n\nNOT published — no version bump or tag. Federation is a draft spec; ship the npm\nrelease on explicit go (it triggers the 24h Renovate fan-out to consumers).",
          "is_bot": false,
          "headline": "agent-core: federation-principal verifier (FEDERATION.md) — additive",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T18:52:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a30a164af2a8bffd9e54d3aaa4d35b77d3af7efa",
          "body": null,
          "is_bot": false,
          "headline": "design 0.13.0 — add oc·forge family slug",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T18:13:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf637f5fcf05b1e4a939e364eaa5b74bb4a7e848",
          "body": "Adds 'chat' to the EcosystemSlug union, the switcher ENTRIES, and FAMILY_PROPERTIES (chat.ochk.io, category product). Unblocks oc-chat-web scaffolding (slug:'chat' otherwise TS-errors and the family switcher omits chat). Tag design-v0.12.0 to publish; oc-chat-web pins ^0.12.0 directly at scaffold time.",
          "is_bot": false,
          "headline": "design 0.12.0 — add oc·chat family slug (#23)",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T17:31:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a4f7a1601cc1ffae2c07668ab5853af21eb88cd",
          "body": "Cards/panels over the ambient <OcAurora/> were either opaque (solid boxes\nhiding it) or fully transparent. Add .oc-surface: fill = color-mix(--card,\ntransparent) so it recolours across every skin + mode, + backdrop-blur so the\naurora bleeds through subtly while text stays legible. Mode-tuned via\n--oc-surface-translucency / --oc-surface-blur. Outermost-panel-only; @supports\nfallback to near-opaque where backdrop-filter is unavailable.",
          "is_bot": false,
          "headline": "design: v0.11.0 — .oc-surface aurora-aware frosted translucent surface",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T16:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "582fc6d7f558eea3ef4a0da3b283d2d949057fba",
          "body": "…ausible)\n\nAdd an oc insights clause beside the existing Plausible disclosure in the\nprotocol + fleet privacy policies — first-party, cookieless, no cross-site\nidentity, IP hashed + immediately discarded, DNT/GPC honored. Plausible\ndisclosure unchanged (both run side by side). Wire the legal-v* release\ntrigger. Bump 0.2.0 → 0.2.1.",
          "is_bot": false,
          "headline": "feat(legal): disclose first-party oc insights analytics (alongside Pl…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T11:59:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92213c60128a32d07d2a2de32b3e4483299b6283",
          "body": "Wire insights-client-v* tag → npm publish for @orangecheck/insights-client\n(no @orangecheck deps, so the generic install/build/publish path applies).",
          "is_bot": false,
          "headline": "ci(release): add insights-client publish trigger",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T06:27:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f6fcf2bf1d53a5510018116b3eca35bc13cce62",
          "body": "Lane 2 of oc insights (see research/INSIGHTS-PLAN.md): a server-side\nemit() API for first-party, protocol-aware events that run ALONGSIDE\nPlausible — BIP-322 success, Connect logins, settlements, attestations,\nvotes, pledges, agent delegations. Fire-and-forget and never throws into\nthe caller (an em\n[…]\n inert\nno-op when OC_INSIGHTS_INGEST_TOKEN is unset so call sites ship before\nthe collector exists. Ships the API first (invariant #6) before any\ninsights.ochk.io surface. CI matrix gains the package.",
          "is_bot": false,
          "headline": "feat(insights-client): new @orangecheck/insights-client package",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T05:54:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6172d5b5e7c656a70eb37c148fabdd8f61f6e582",
          "body": null,
          "is_bot": false,
          "headline": "renovate: track oc-bot-web (repo renamed from oc-bot)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T03:28:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6dcbd1722955fd9c89ea2f210cb6567c2986a5b",
          "body": "oc-bot now ships @orangecheck/design as a first-class owner family\nproperty; enroll it so family publishes reach it like every other\nconsumer. Pairs with oc-bot/renovate.json.",
          "is_bot": false,
          "headline": "ci(renovate): add oc-bot to the fan-out repo list",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-03T05:54:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac47a43599a82a2562624f4d47e52f9903971e88",
          "body": "Registers bot.ochk.io as an owner-category family property, mirroring\noc·analytics. OcLogoDropdown + EcosystemSwitcher surface it only when\nshowOwnerEntries (account.isOwner) is set; non-owners never see it.\nAdds the 'bot' EcosystemSlug + an OwnerView story documenting the gate.",
          "is_bot": false,
          "headline": "feat(design): add oc·bot to owner-gated family switcher",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-03T05:47:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96a33af287cd015c808e0066e34d6894be1ac2f7",
          "body": "…perms, not the window\n\nRenovate is 403 on GitHub commits/{sha}/statuses (can't read CI to auto-merge);\nthat's a RENOVATE_TOKEN scope issue, independent of the stability window. Restore\ndefaults; the design 0.9.1 fan-out resumes once the token gains commit-statuses\n+ checks read.",
          "is_bot": false,
          "headline": "chore(renovate): revert design fast-track — fan-out blocked by token …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T18:33:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fab8128c784b51b44a3d67e8a0069bd7dd11f61a",
          "body": "The earlier 403s came from cranking concurrency to 25 (registry rate-limit).\nThis keeps prConcurrentLimit/prHourlyLimit at the default 5/10 and only waives\nthe 1-day window for @orangecheck/design. Reverted once the fan-out lands.",
          "is_bot": false,
          "headline": "chore(renovate): re-apply design 0.9.1 age bypass at default concurrency",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T18:21:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b59e840c4edea366f7950d460dc8f3f507c2979b",
          "body": "The design 0.9.1 accelerated fan-out was blocked by intermittent Renovate 403s\nin the branch-update step (registry-auth infra, independent of the change) —\neven CI-green branches didn't merge. Restoring the 1-day stability window +\ndefault concurrency; design 0.9.1 (with the switcher tooltip) reaches consumers\nvia the standard flow once the Renovate 403 is resolved.",
          "is_bot": false,
          "headline": "chore(renovate): revert temp fast-track + concurrency lifts",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T18:13:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b617eef218f3c3d84b60955af996e9a6ef15d49",
          "body": "The header's title group lacked min-w-0, so the truncate on the title +\nsubtitle never engaged and long text spilled past the strip. Add min-w-0\nflex-1 to the title group and shrink-0 to the actions group.",
          "is_bot": false,
          "headline": "design: fix Card title/subtitle overflow (min-w-0 so truncate engages)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:51:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9d1737f506e1f7e23fb27887a5e2aeaf7100c5d",
          "body": "Paired with the design-only age bypass — push all consumer bump branches at\nonce. Reverted with the bypass once the rollout lands.",
          "is_bot": false,
          "headline": "chore(renovate): TEMP lift concurrency for the design 0.9.0 fan-out",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:45:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4640ecc7adfeee73cf3cd86e969cd9262e38efc0",
          "body": "Bypass the 1-day stability window for @orangecheck/design ONLY so the switcher\nhover-tooltip (already browser-verified across skins + touch) fans out now.\nGlobal window unchanged for every other package; reverted immediately after.",
          "is_bot": false,
          "headline": "chore(renovate): TEMP fast-track @orangecheck/design 0.9.0 rollout",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6faba4426058230e038ee91ab311213e9c7240",
          "body": "Adds a themed hover/focus <Tooltip> primitive (the system had none — only the\nclick-based HelpHint) on @radix-ui/react-popover: hover-intent + keyboard\nfocus, pointer-fine only (never on touch), force-closable, reduced-motion via\nthe family reset.\n\nWires it into OcLogoDropdown, replacing the native \n[…]\n\ntrigger + menu aria-labels. Click model unchanged. Verified across all four\nskins (light+dark): hover, keyboard focus, Escape, touch (no tip, menu is the\npath home), all 92 stories render error-free.",
          "is_bot": false,
          "headline": "design: v0.9.0 — Tooltip primitive + OcLogoDropdown hover tooltip",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:24:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd9da34cfad26005398127daa98243ac0f94872b",
          "body": "The scheduled Renovate job failed (run 26809354691, 11s) on a ghcr.io 502\nBad Gateway while pulling renovate:latest — renovatebot/github-action runs\ndocker run with no retry, so any registry blip reds the check. Pre-pull the\nimage with 5× retry/backoff first; docker run then uses the local image. No\nbehavior change otherwise (still :latest). Node-20 deprecation on the action\n(forced to Node 24 by 2026-06-16) noted separately.",
          "is_bot": false,
          "headline": "ci(renovate): retry image pre-pull to survive transient ghcr.io 5xx",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T15:04:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "510209562dffc881d6b5b59fb829c83afe91c469",
          "body": "…ovider\n\nAdds the bitcoin-aurora background (a soft, theme-reactive mesh gradient that\nslowly undulates) as a first-class component + CSS that auto-ships via\nstyles.css. OcThemeProvider renders it by default with an `aurora` prop escape\nhatch (false / { intensity }). Recolours across light/dark + all four skins from\n--brand/--success/--info/--primary; pure CSS, transform-only, reduced-motion safe.",
          "is_bot": false,
          "headline": "design: v0.8.0 — OcAurora ambient background, default-on in OcThemePr…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-01T19:52:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f001b554cdeaf2ec4e67bc230a69635cbc7ec10f",
          "body": "Two small additions to the @orangecheck/design/format subpath so the\nsats↔USD pattern is fully family-shared rather than copied per\nconsumer. Additive only — every existing export still works exactly\nas it did at 0.7.5.\n\nsrc/format/index.ts\n  asOf(iso) → \"as of HH:MM\" provenance caption helper.\n  nu\n[…]\n oc-me-web: drops lib/utils satsToUsd duplicates + lib/price/\n    usePrice.ts; ~10 callers migrate to @orangecheck/design imports.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): asOf + useSpotPrice (0.7.6)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-28T17:24:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf3aadd592f8f86406240caa5631ce5e24ab1ceb",
          "body": "…rsion)\n\nPorts oc-me-web's more-evolved HelpHint into the package: `size` ('xs'|'sm')\n+ `tone` ('default'|'subtle'), click-stopPropagation (so a \"?\" inside a\nclickable row doesn't trigger the row), an arrow + max-w-xs popover. Default\nside now `top`. Lets me retire its local HelpHint (38 importers) to the\npackage. SectionHeader's `hint` slot still works (title/side/children).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.5 — HelpHint gains size/tone (lifts me's richer ve…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T19:51:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b3ff9c5df966c5ae3f00e8e4f16b7ef91a7d1020",
          "body": "…tile\n\nStatBlock rendered a non-bold value while StatGrid's Tile (and StatCard, which\nwraps StatBlock) used `font-bold tabular-nums tracking-tight`. Unifies them so\nevery stat — StatBlock, StatCard, StatGrid — renders the same canonical bold\ntabular value. (Restores bold weight for fleet Stat→StatCard and me\nRecon→StatBlock converged on 0.7.2/0.7.3.)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): v0.7.4 — StatBlock value matches canonical bold/tabular …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T19:25:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cac1bdc77d5af4c264055b744cc6f9a9774c4640",
          "body": "Chrome components (AccountMenu/Dashboard/Logo&Switcher/PrimaryNav/\nLayoutSubHeader) moved Composites/* → Chrome/*; data + bitcoin primitives\nnested under Primitives/Data/* and Primitives/Bitcoin. Storybook nav now\nmirrors /primitives · /composites · /chrome. (Stories are dev-only; no\npackage version change.)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(design): align Storybook taxonomy to the 3 tiers",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T18:58:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ed5754d87811f2501b58589db441b86d67155478",
          "body": "Adds `filled` (bg-{tone}/10) to the bordered StatusPill + makeStatusPill\noptions, for the at-a-glance filled-chip emphasis me's compliance/severity\npills use on dense operator dashboards. Additive; default unfilled.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.3 — StatusPill bordered `filled` option",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T17:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d9476cfbe57f2deec0f84f2873d2e51c7c0028e6",
          "body": "The standalone counterpart to StatBlock (bare cell) and StatGrid (grid):\na single stat in a bordered bg-card frame, wrapping StatBlock. Closes the\ngap fleet (dashboard/Stat) and me (StatCell + fee/recon tiles) each hand-roll.\nAdditive; caret ^0.7.0 admits it on re-install.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.2 — StatCard composite (bordered single-stat card)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T17:35:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7900f8ef852de34c91fe4a10d6788918b20c1f23",
          "body": "… variant option\n\nAdds the bordered/uppercase status-badge variant (border-{tone}/40 text-{tone})\nthat fleet (PledgeStatusPill), www (StateBadge), and me (compliance/severity)\neach hand-roll. `<StatusPill variant=\"bordered\" />` and\n`makeStatusPill(map, { variant: 'bordered' })`. Additive; `plain` stays default.\nUnblocks the Phase-3 deep-fork convergence of those bordered pills with no\nvisual regression.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.1 — StatusPill `bordered` variant + makeStatusPill…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T16:20:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bddb7bc259101d8924fbe3fade19c57b5e08c654",
          "body": "…gence components\n\nSingle design-system package with three dependency-honest tiers:\n  - /primitives (zero-dep atoms)\n  - /composites (generic, auth-free)  ← NEW tier\n  - /chrome      (auth/family-coupled) ← NEW tier\n  - /components remains as a back-compat alias re-exporting both new tiers.\n\nThis re\n[…]\nery new/changed component; type-check, tsup build, and\nbuild-storybook all green; all stories render headless with styles applied.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.0 — fold composites+chrome into design, add conver…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T15:09:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8dbd0b0b4a3f4dcde7d5b1aabef2e39ed98b3954",
          "body": "Add [overflow-wrap:anywhere] to the ConfirmHost message body so long\nunbroken tokens (addresses, hashes, URLs) wrap inside the dialog instead\nof overflowing it.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): confirm-dialog message wraps long unbroken strings (0.6.1)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T19:33:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2fe0f93e4f85c03d2f30c27fe9b04bdc7bcc4b25",
          "body": "…ves (0.6.0)\n\nCloses the one real coverage gap the UI/UX audit surfaced: the family used\nraw native <input type=checkbox> (~18 files), type=radio (~6), and role=switch\ncontrols — unstyled, inconsistent across skins, missing the focus-ring/aria\ntreatment every other primitive has. These are Radix-bac\n[…]\nlibrary — no react-hook-form conflict. Storybook:\nPrimitives/Controls. Sites adopt incrementally (replace raw natives as touched).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): add Checkbox + RadioGroup + Switch form-control primiti…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T19:20:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1f6a1c907665ce84bb2ba9e4960d6ce06cb4a023",
          "body": "…alid (0.5.3)\n\n- prefers-reduced-motion now near-zeros ALL animations/transitions family-wide\n  (Accordion/Sheet/Dialog/Select/tw-animate overlays + skin transitions), not\n  just the working indicator — WCAG 2.3.3. Keeps 0.01ms so *end events fire.\n- Textarea gains the same aria-invalid error stylin\n[…]\nton have.\n\nNon-breaking, no brand/visual change in default motion-on state. Flows to all\nconsumers in-range (^0.5.2) via Renovate.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): a11y polish — global reduced-motion + Textarea aria-inv…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T19:10:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34920b7c3bfd5939f3c14c7f547d2f7d57568978",
          "body": "…ow skin (0.5.2)\n\ngetOcThemeInitScript installs window.__ocApplySkinChrome (single owner of the\nswap): captures the favicon's original SVG once, recolors #f97316 → the active\nskin's accent into a data: URI, and sets <meta name=theme-color>. OcThemeProvider\nre-invokes it on every skin change/cross-ta\n[…]\ne single source of truth, mirrored by oc-media-kit. Verified in\na browser: cookie=phosphor → favicon #55d671, theme-color #55d671.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): theme-aware browser chrome — favicon + theme-color foll…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T15:32:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "611bc83488adf1e40ffa42d34c899524a93ce8b2",
          "body": "Standard shadcn Sheet parts that were missing from the package — vault's\nEntryEditor (and any sheet with a footer/explicit close) needs them.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): add SheetClose + SheetFooter exports (0.5.1)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T21:15:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "748388cae7628325c8ae4a8b6e0da288fee668a4",
          "body": "oc-vote-web uses <Badge variant=\"brand\"> (brand-soft tinted badge). Adding it as\na canonical Badge variant (bg-brand-soft text-brand border-brand-soft, all\nexisting --brand utilities) so vote converges without losing its brand badge.\nStory updated.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): add Badge `brand` variant (0.5.0) (#22)",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T17:57:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a9c75ffd221a3afbb914960d68b4c910f84959f7",
          "body": "… (#21)\n\nSingle header dropdown consolidating BOTH appearance axes so every family site\ncarries exactly one control instead of two:\n  • mode  — light / dark / system (next-themes)\n  • theme — the registered skins (data-oc-theme, persisted .ochk.io)\n\nOne Palette icon → dropdown with a segmented light\n[…]\nparate ThemeToggle + OcThemePicker (both kept for standalone\nuse / mobile drawer). 73 stories, all browser-verified render+styled.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): OcAppearanceMenu — one control for mode + theme (0.4.0)…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T15:27:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c4ab69624a63982a4039169f2941449870dc626",
          "body": "…fill from deep dive) (#20)\n\nThe deep dive across me/vault/fleet/analytics showed the canonical set (extracted\nfrom simple oc-stamp-web) was missing whole categories the complex sites\nreimplement. Fills them, ported from the real implementations:\n\nData/dashboard tier: Card (terminal-frame, expand→Mo\n[…]\nge\naccent at 2.93 remains, by design). Fixed a real satsToUsd bug found by the\ngate (Intl min>max RangeError for amounts >= $100).\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.3 — data/dashboard + Bitcoin-domain primitives (gap-…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T15:14:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4b331d71c42373d376918c94074f1ffbde49044c",
          "body": "… lightning/gold (0.2.0) (#19)\n\nTheme ethos review: midnight (indigo + Manrope + 0.625 rounded) and aurora\n(teal + soft elevation + 0.75 rounded) were generic SaaS palettes that violated\nthe OrangeCheck/cypherpunk ethos (\"hard borders, no soft shadows, not SaaS\").\nReplaced with two Bitcoin-meaningfu\n[…]\n midnight/aurora removed (no consumer used them;\nthe picker reads OC_THEMES dynamically and resolveTheme() falls back to default).\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design)!: Bitcoin-ethos theme set — replace midnight/aurora with…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T14:31:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6cf13409da2906aef5037b9c40a17dc421139427",
          "body": "… gates (0.1.1) (#18)\n\nCompleteness/perfection review pass:\n- aurora light --primary darkened oklch .6→.5 so white button labels clear AA\n  (4.5:1, was 3.51) and the accent clears AA-large; ring matched. The other\n  alternate skins (midnight/phosphor) already pass AA on every pair, light+dark.\n- Add\n[…]\nthe existing production brand orange, unchanged here (parity is load-bearing);\nflagged for a separate brand decision, not altered.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): aurora AA contrast + ErrorBoundary story + contrast/page…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T23:22:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c6013c5d7418e031660a66e11cb7576e4fc74be7",
          "body": "…amp script (#17)\n\nThe oc-stamp-web pilot surfaced a required step the recipe was missing:\n@orangecheck/design must be added to next.config transpilePackages (it\nre-exports @orangecheck/ui whose ESM uses a bare next/link import; without\ntranspiling, SSR page-data collection fails). Documented so the\n[…]\noesn't\nrepeat the failure. Also adds scripts/verify-stamp.mjs (the browser parity +\nskin-switch check used to validate the pilot).\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(design): MIGRATION.md — require transpilePackages; add verify-st…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T22:50:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "817129668dc6948b14a860e2c5056bcd8b63d6a5",
          "body": "- Elevation: set orangecheck --oc-shadow-* to EXACTLY Tailwind v4 stock values\n  so adopting @orangecheck/design is a pixel no-op for the default skin (verified\n  in-browser: default shadow-lg == stock; aurora stays elevated). Prevents a\n  subtle global shadow shift on every consumer at migration ti\n[…]\n docs-sync job (oc-docs/sdk/design) stays green.\n- Add MIGRATION.md: the mechanical, per-site, no-op-for-default migration recipe.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): zero-regression hardening + publish prerequisites (#16)",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T21:27:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f32731600b1400aabac8cbfe15da0daf6ff4a75c",
          "body": "… dimension (#15)\n\nExhaustive census across ALL component dirs (not just ui/) confirmed the full\nshared surface. Additions, ported verbatim from the canonical repos:\n  · PromptDialog (prompt()/PromptHost) — pairs with ConfirmDialog\n  · Modal — family-standard near-fullscreen titled modal\n  · Paginat\n[…]\nht): 56/56 render styled &\nerror-free; 4/4 distinct skin identities; elevation provably differs (aurora vs\ndefault) in both modes.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): complete the inventory + 4th theme (aurora) + elevation…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T21:16:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e92a218b63a6342285dcb0ca3444b171a4a2798",
          "body": "…browser verification (#14)\n\nCloses the comprehensiveness + multi-theme-depth gaps surfaced in review.\n\nPrimitives — extended to the full shared set used across the family (usage\ncensus over all web repos). Added, ported verbatim from the canonical sites:\nSheet, Dialog, ConfirmDialog (confirm()/Conf\n[…]\nright, scripts/verify-*.mjs): 50/50 stories render styled\n& error-free; radius + font + primary all change per skin in both modes.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): complete primitive set, 3rd theme, shape+type theming, …",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T20:48:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "79404a7b68b546e89aeb5f9991c52c2f6f518117",
          "body": "…heme matrix (#13)\n\nExpands the design.ochk.io showcase from 12 → 37 stories:\n\n- Primitives: Form (Input/Label/Textarea), Alert, Working, Theme Toggle —\n  joining the existing Button, Badge, Tokens.\n- Composites: SectionHeader, EmptyState, StatGrid, OcPrimaryNav, OcDashboardHub,\n  AppShell, OcLogoDr\n[…]\nlti-theme\n  proof. Global theme decorator can stand down (disableGlobalTheme) so light\n  panels aren't forced dark by the toolbar.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): full Storybook coverage — all primitives, composites, t…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T20:06:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "53db8eb711054dfc4939bf39e9e80619b1798b7a",
          "body": "…m (#12)\n\nNew umbrella package @orangecheck/design (oc-packages/design):\n\n- Multi-theme token layer. Two orthogonal axes: mode (.dark, next-themes,\n  unchanged) × skin (data-oc-theme attribute). Current look ported byte-for-byte\n  as the `orangecheck` skin; `midnight` ships as a demonstrator. styles\n[…]\n+dts) green, type-check green, storybook build green. No consumer site\ntouched — migration is Phase 3+, gated behind a checkpoint.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): scaffold @orangecheck/design — multi-theme design syste…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T19:53:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c923caa1a7d94d371722e5002421fb4cf3c6e85",
          "body": "…ubdomains\n\nThe multi-account switcher (roster/switch/leave) shipped in 2.17.1 + ui 0.15.x,\nbut on consumer subdomains the roster stayed empty: the provider read it from\nthe LOCAL /api/auth/me, which verifies the JWT but has no DB and so never\ncarries the roster (it's host state). Result: the switch\n[…]\ne local /me. Bumped refresh() deps to [cfg].\n\n+2 provider tests (host fallback populates; no host call when local roster present).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "patch(auth-client@2.17.2): source roster from auth host on consumer s…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-21T05:07:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a96492a541bd2a3c4c8d9b11fa55fd70517c420",
          "body": "…uto-payouts\n\nme-client/src/subtypes.ts described the pledge_resolution billable event as\nfiring when \"an oc-pledge bonded commitment resolves (paid out, slashed,\nor refunded) on your surface\" — both \"slashed\" and \"paid out\" misrepresent\nPledge. Per oc-pledge-protocol/WHY.md H5 and H7, slashing is e\n[…]\ng fix; no API surface change. Not tagged for publish in\nthis commit — bump + tag separately if propagation to consumers is wanted.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(me-client): correct pledge_resolution subtype — no slashing, no a…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-21T00:53:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce0a82782cf2cb6dbf6c1fbd5b23a8c34734a24f",
          "body": "Fixes the visible 'dropdown flashes when I switch accounts' report.\nTwo coupled issues:\n\n1. IdentityPromoteSection used fetchedRef.current as a one-shot\n   guard — it fetched linked identities the FIRST time the popover\n   opened and never again. After a multi-account switch the section\n   was rende\n[…]\ns back to null so the section\n  returns null briefly · prevents the stale 1-option-vs-3-options\n  flash before the new data lands.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "patch(ui@0.15.2): refetch linked identities on account switch",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-20T22:00:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd4f8d521e411fdede9fd249e82551d3f063bcf3",
          "body": "ui@0.15.1\n---------\n- Empty-roster bug: the 'leave this account' button rendered even\n  when there were no peers in the roster, producing a redundant\n  second sign-out alongside the parent menu's bottom 'sign out' row.\n  Gate the per-account leave button on roster.length > 0 so the\n  empty-roster pa\n[…]\no arguments.\n\nTotal auth-client tests: 34/34 passing.\n\nCompanion to oc-www c1cfe4a (host useAuth + roster.test.ts +\nOpenAPI spec).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "patch(auth-client@2.17.1, ui@0.15.1): polish + tests for multi-account",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-20T20:02:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8ec444c839bfd0d28128b380ed0afe06b2905a9",
          "body": "Frozen-lockfile install rejected the ui-v0.15.0 publish because\nyarn.lock pinned auth-client@2.13.0 but ui's package.json now\nrequires ^2.17.0 (the new peer with the multi-account surface).\nRegenerated via yarn install in oc-packages/ui.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ui): bump yarn.lock to @orangecheck/auth-client@2.17.0",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-20T17:42:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 309,
      "latest_release_at": "2026-07-20T18:30:23Z",
      "latest_release_tag": "design-v0.28.13",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 13,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@orangecheck/ui",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "ui",
            "react",
            "internal"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/ui",
          "is_deprecated": false,
          "latest_version": "0.15.2",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 24,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 142,
          "first_published_at": "2026-04-26T14:29:12.373000Z",
          "latest_published_at": "2026-05-20T22:01:26.102000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 67
        },
        {
          "name": "@orangecheck/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "bitcoin",
            "sybil-resistance",
            "bip322",
            "cli",
            "nostr"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/cli",
          "is_deprecated": false,
          "latest_version": "0.2.0",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 71,
          "first_published_at": "2026-04-22T14:13:53.066000Z",
          "latest_published_at": "2026-05-10T04:28:33.399000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 78
        },
        {
          "name": "@orangecheck/sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "bitcoin",
            "sybil-resistance",
            "bip322",
            "nostr",
            "attestation",
            "anti-spam",
            "verification",
            "orangecheck"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/sdk",
          "is_deprecated": false,
          "latest_version": "1.3.0",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 236,
          "first_published_at": "2026-04-22T14:06:47.479000Z",
          "latest_published_at": "2026-05-18T13:10:42.630000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 69
        },
        {
          "name": "@orangecheck/gate",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "bitcoin",
            "sybil-resistance",
            "middleware",
            "express",
            "nextjs",
            "fastify",
            "hono",
            "workers",
            "bip322",
            "nostr"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/gate",
          "is_deprecated": false,
          "latest_version": "0.1.3",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 67,
          "first_published_at": "2026-04-22T14:13:43.386000Z",
          "latest_published_at": "2026-04-22T18:28:09.734000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 95
        },
        {
          "name": "@orangecheck/legal",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "legal",
            "terms",
            "privacy",
            "internal"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/legal",
          "is_deprecated": false,
          "latest_version": "0.2.1",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 218,
          "first_published_at": "2026-05-15T18:22:21.220000Z",
          "latest_published_at": "2026-06-04T12:00:04.509000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 52
        },
        {
          "name": "@orangecheck/react",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "bitcoin",
            "sybil-resistance",
            "bip322",
            "nostr",
            "react",
            "components"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/react",
          "is_deprecated": false,
          "latest_version": "0.1.3",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 66,
          "first_published_at": "2026-04-22T14:14:03.886000Z",
          "latest_published_at": "2026-04-22T21:07:35.144000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 95
        },
        {
          "name": "@orangecheck/design",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "design-system",
            "ui",
            "tokens",
            "themes",
            "react",
            "internal"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/design",
          "is_deprecated": false,
          "latest_version": "0.28.13",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 55,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 5198,
          "first_published_at": "2026-05-22T21:28:03.774000Z",
          "latest_published_at": "2026-07-20T18:30:17.142000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "orangecheck",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "attestation",
            "bip322",
            "bitcoin",
            "nostr",
            "orangecheck",
            "sybil-resistance",
            "Development Status :: 4 - Beta",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: MIT License",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.9",
            "Topic :: Internet :: WWW/HTTP",
            "Topic :: Security",
            "Typing :: Typed"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/orangecheck/",
          "is_deprecated": false,
          "latest_version": "1.0.0",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-04-22T14:19:03.838807Z",
          "latest_published_at": "2026-05-07T18:27:04.083532Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 80
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 4
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "agent-anthropic/tsconfig.json",
        "agent-cli/tsconfig.json",
        "agent-core/tsconfig.json",
        "agent-langgraph/tsconfig.json",
        "agent-mcp/tsconfig.json",
        "agent-openai/tsconfig.json",
        "agent-signer/tsconfig.json",
        "agent-vercel/tsconfig.json",
        "airdrop-gate/tsconfig.json",
        "auth-client/tsconfig.json",
        "auth-core/tsconfig.json",
        "cli/tsconfig.json",
        "design/tsconfig.json",
        "gate/tsconfig.json",
        "insights-client/tsconfig.json",
        "legal/tsconfig.json",
        "lock-core/tsconfig.json",
        "lock-crypto/tsconfig.json",
        "lock-device/tsconfig.json",
        "me-client/tsconfig.json",
        "nostr-core/tsconfig.json",
        "pledge-core/tsconfig.json",
        "react/tsconfig.json",
        "relay-filter/tsconfig.json",
        "sdk-py/orangecheck/py.typed",
        "sdk/tsconfig.json",
        "stamp-cli/tsconfig.json",
        "stamp-core/tsconfig.json",
        "stamp-ots/tsconfig.json",
        "ui/tsconfig.json",
        "vault-cli/tsconfig.json",
        "vault-core/tsconfig.json",
        "vote-cli/tsconfig.json",
        "vote-core/tsconfig.json",
        "vote-react/tsconfig.json",
        "wallet-adapter/tsconfig.json",
        "webhook-verify/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 56314,
      "source_files_sampled": 482,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "agent-anthropic/package.json",
        "agent-cli/package.json",
        "agent-core/package.json",
        "agent-langgraph/package.json",
        "agent-mcp/package.json",
        "agent-openai/package.json",
        "agent-signer/package.json",
        "agent-vercel/package.json",
        "airdrop-gate/package.json",
        "auth-client/package.json",
        "auth-core/package.json",
        "cli/package.json",
        "design/package.json",
        "gate/package.json",
        "insights-client/package.json",
        "legal/package.json",
        "lock-core/package.json",
        "lock-crypto/package.json",
        "lock-device/package.json",
        "me-client/package.json",
        "nostr-core/package.json",
        "package.json",
        "pledge-core/package.json",
        "react/package.json",
        "relay-filter/package.json",
        "sdk-py/pyproject.toml",
        "sdk/package.json",
        "stamp-cli/package.json",
        "stamp-core/package.json",
        "stamp-ots/package.json",
        "ui/package.json",
        "vault-cli/package.json",
        "vault-core/package.json",
        "vote-cli/package.json",
        "vote-core/package.json",
        "vote-react/package.json",
        "wallet-adapter/package.json",
        "webhook-verify/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "@noble/hashes",
          "manifest": "agent-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "bip322-js",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "commander",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/stamp-core",
          "manifest": "agent-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.0"
        },
        {
          "name": "@orangecheck/lock-core",
          "manifest": "agent-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-langgraph/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-langgraph/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-langgraph/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-openai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-openai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-openai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-signer/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-signer/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-vercel/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-vercel/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-vercel/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "airdrop-gate/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "@simplewebauthn/browser",
          "manifest": "auth-client/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.3.0"
        },
        {
          "name": "jose",
          "manifest": "auth-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.2"
        },
        {
          "name": "@orangecheck/me-client",
          "manifest": "cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.18.0"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "commander",
          "manifest": "cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@radix-ui/react-accordion",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.12"
        },
        {
          "name": "@radix-ui/react-checkbox",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.15"
        },
        {
          "name": "@radix-ui/react-label",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.7"
        },
        {
          "name": "@radix-ui/react-popover",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.15"
        },
        {
          "name": "@radix-ui/react-radio-group",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1"
        },
        {
          "name": "@radix-ui/react-select",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.6"
        },
        {
          "name": "@radix-ui/react-separator",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.7"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.3"
        },
        {
          "name": "@radix-ui/react-switch",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1"
        },
        {
          "name": "@radix-ui/react-tabs",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.3"
        },
        {
          "name": "class-variance-authority",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "qrcode",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.4"
        },
        {
          "name": "sonner",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.1"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "gate/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.4"
        },
        {
          "name": "@vercel/functions",
          "manifest": "insights-client/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.7.3"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "lock-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/ciphers",
          "manifest": "lock-crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "lock-crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "lock-crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "lock-device/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "lock-device/package.json",
          "ecosystem": "npm",
          "version_constraint": "file:../lock-crypto"
        },
        {
          "name": "@orangecheck/auth-core",
          "manifest": "me-client/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "pledge-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "react/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "relay-filter/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "httpx",
          "manifest": "sdk-py/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.25"
        },
        {
          "name": "@bitcoinerlab/secp256k1",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@noble/curves",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@scure/base",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.9"
        },
        {
          "name": "bip322-js",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "bitcoinjs-message",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "buffer",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.3"
        },
        {
          "name": "@orangecheck/stamp-core",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.2"
        },
        {
          "name": "@orangecheck/stamp-ots",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.1"
        },
        {
          "name": "bip322-js",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "commander",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "stamp-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/stamp-core",
          "manifest": "stamp-ots/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.2"
        },
        {
          "name": "@orangecheck/vault-core",
          "manifest": "vault-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.2.0"
        },
        {
          "name": "commander",
          "manifest": "vault-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "vault-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "vault-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/vote-core",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.1"
        },
        {
          "name": "@orangecheck/lock-core",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "bip322-js",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "commander",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "ws",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.18.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "vote-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 3,
        "merged_prs": 19,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Xaxis",
          "commits": 309,
          "avatar_url": "https://avatars.githubusercontent.com/u/396863?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "docs-drift.yml",
        "docs-sync-manual.yml",
        "packages.yml",
        "python.yml",
        "release.yml",
        "renovate.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "yarn.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "47 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2238e09092ca384e98d417e2ce4a668259611619",
        "ran_at": "2026-07-27T09:20:45Z",
        "aggregate_score": 4.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T09:14:54Z",
      "oldest_open_prs": [
        {
          "number": 1,
          "created_at": "2026-04-30T16:44:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2,
          "created_at": "2026-04-30T16:52:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 7,
          "created_at": "2026-04-30T19:46:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-06-05T17:31:52Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 11,
          "created_at": "2026-05-20T14:30:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/orangecheck/oc-packages",
    "host": "github.com",
    "name": "oc-packages",
    "owner": "orangecheck"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 42,
        "vitality": 84,
        "community": 34,
        "governance": 44,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "commits_last_year": 309,
              "human_commit_share": 1,
              "days_since_last_push": 4,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "309 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 309
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "design-v0.28.13",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 34,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "packages": [
                "@orangecheck/ui",
                "@orangecheck/cli",
                "@orangecheck/sdk",
                "@orangecheck/gate",
                "@orangecheck/legal",
                "@orangecheck/react",
                "@orangecheck/design",
                "orangecheck"
              ],
              "dependents": null,
              "ecosystems": "npm, pypi",
              "total_downloads": null,
              "monthly_downloads": 5998
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,998 downloads/month across npm, pypi",
                "points": 50.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5998,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 44,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "merged_prs": 19,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "19/19 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 19,
                      "decided": 19
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "followers": 3,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "orangecheck",
              "public_repos": 19,
              "account_age_days": 456
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of orangecheck",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "orangecheck"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "19 public repos, account ~1 yr old",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 19
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@orangecheck/ui",
                "@orangecheck/cli",
                "@orangecheck/sdk",
                "@orangecheck/gate",
                "@orangecheck/legal",
                "@orangecheck/react",
                "@orangecheck/design",
                "orangecheck"
              ],
              "ecosystems": "npm, pypi",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm, pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "55 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 55
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "bip322",
                "bitcoin",
                "express",
                "middleware",
                "nextjs",
                "nostr",
                "python",
                "sdk",
                "sybil-resistance",
                "typescript"
              ],
              "has_wiki": true,
              "homepage": "https://ochk.io",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://ochk.io",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 42,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "47 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.95,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "yarn.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "agent-anthropic/tsconfig.json",
                "agent-cli/tsconfig.json",
                "agent-core/tsconfig.json",
                "agent-langgraph/tsconfig.json",
                "agent-mcp/tsconfig.json",
                "agent-openai/tsconfig.json",
                "agent-signer/tsconfig.json",
                "agent-vercel/tsconfig.json",
                "airdrop-gate/tsconfig.json",
                "auth-client/tsconfig.json",
                "auth-core/tsconfig.json",
                "cli/tsconfig.json",
                "design/tsconfig.json",
                "gate/tsconfig.json",
                "insights-client/tsconfig.json",
                "legal/tsconfig.json",
                "lock-core/tsconfig.json",
                "lock-crypto/tsconfig.json",
                "lock-device/tsconfig.json",
                "me-client/tsconfig.json",
                "nostr-core/tsconfig.json",
                "pledge-core/tsconfig.json",
                "react/tsconfig.json",
                "relay-filter/tsconfig.json",
                "sdk-py/orangecheck/py.typed",
                "sdk/tsconfig.json",
                "stamp-cli/tsconfig.json",
                "stamp-core/tsconfig.json",
                "stamp-ots/tsconfig.json",
                "ui/tsconfig.json",
                "vault-cli/tsconfig.json",
                "vault-core/tsconfig.json",
                "vote-cli/tsconfig.json",
                "vote-core/tsconfig.json",
                "vote-react/tsconfig.json",
                "wallet-adapter/tsconfig.json",
                "webhook-verify/tsconfig.json"
              ],
              "agent_commit_share": 0.29,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "agent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "agent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "29 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 29,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 56314,
              "source_files_sampled": 482,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/482 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 482,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T09:20:52.626244Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/orangecheck/oc-packages.svg",
  "full_name": "orangecheck/oc-packages",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm, PyPI.