Registro público
Informe de salud del softwareesquema 0.26.0 · métricas 1.13.0 · 2026-07-22 11:35 UTC

sdsrss / gsd-lite

AI orchestration tool for Claude Code with MCP state management, review workflows, and plugin auto-update

JavaScriptSin licencia detectada★ 3 estrellas⑂ 0 forksdesde mar 2026Ver en GitHub ↗

sdsrss/gsd-lite tiene un índice de salud de 55 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (78/100) y la más baja, Community & Adoption (24/100). Se actualizó por última vez hace 5 días. Una sola persona concentra la mayor parte del trabajo reciente.

55
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

55
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

sdsrssCuenta personal
3 seguidores12 repositorios públicosdesde sept 2025

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npmgsd-lite0.8.5117156hace 5 díasclaudeclaude-codemcporchestrationai-agenttask-management

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

78Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 5 días
6.2/36Cadencia de commits — 9/52 semanas con commits
18/18Volumen de commits — 229 commits en el último año
10/10OpenSSF Scorecard: Maintained — 26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year229
human_commit_share1
days_since_last_push5
active_weeks_last_year9
Cómo se puntúa
27/27Publica versiones — 48 versiones publicadas
36/36Recencia de las versiones — última versión hace 5 días
27/27Cadencia de publicación — una versión cada ~9,4 días
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Datos de entrada utilizados
releases_count48
latest_release_tagv0.8.5
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases9,4

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

24Crítico · 18% del índice global
Cómo se puntúa
4.9/60Estrellas — 3 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars3
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
0/22.5Licencia — no se detectó ningún archivo de licencia
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
40.9/80Descargas mensuales — 1171 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesgsd-lite
dependents
ecosystemsnpm
total_downloads
monthly_downloads1171
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

52Moderado · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
46.8/46.8Resolución de issues — 100% de issues cerradas
38.2/38.3Aceptación de PR — 2/2 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs2
open_issues0
closed_issues1
issue_closed_ratio1
closed_unmerged_prs0
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
4.3/25Alcance del propietario — 3 seguidores de sdsrss
9.9/25Trayectoria — 12 repos públicos, cuenta de ~0 años
Datos de entrada utilizados
followers3
owner_typeUser
is_verified
owner_loginsdsrss
public_repos12
account_age_days320
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 5 días
20/20Historial de versiones — 56 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesgsd-lite
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

74Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 2 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — biome.json
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno

Documentación

60Moderado
Cómo se puntúa
30/30README
0/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
10/10Topics — 8 topics
10/10Wiki
Datos de entrada utilizados
topicsai-agent, automation, claude-code, claude-plugin, mcp, nodejs, orchestration, task-management
has_wiki
homepage
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

37En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Licencia — license file not detected
7.5/7.5Maintained — 26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3.8/7.5Vulnerabilities — 5 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3,7

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

47En riesgo · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 78 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,78
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
11/11Configuración de lint / formato — biome.json
0/11Verificación estática de tipos
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 79 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_config
typecheck_configs
agent_commit_share0,79
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
0/45Código verificable por tipos — JavaScript sin configuración de verificación de tipos
53.7/55Tamaños de archivo manejables — 2/85 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageJavaScript
largest_source_bytes118.176
source_files_sampled85
oversized_source_files2
Cómo se puntúa
0/40Esquema de API (OpenAPI/GraphQL/proto)
20/20Servidor MCP
0/40Ejemplos ejecutables
Datos de entrada utilizados
example_dirs
has_mcp_signal
api_schema_files

Datos clave

3estrellas de GitHub
1contribuidores
229commits en los últimos 12 meses
5días desde el último push
48versiones publicadas
1factor bus
0issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:gsd-lite@0.8.5; advisories assessed against the repository dependency graph instead

Más detalle

OpenSSF Scorecard 3.7 / 10
3.7agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-22 11:35 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
5Vulnerabilities5 existing vulnerabilities detected
Dependencias directas 1
RegistroPaqueteRestricción de versiónManifiesto
npm@modelcontextprotocol/sdk^1.27.1package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "ai-agent",
        "automation",
        "claude-code",
        "claude-plugin",
        "mcp",
        "nodejs",
        "orchestration",
        "task-management"
      ],
      "is_fork": false,
      "size_kb": 770,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 14901,
        "JavaScript": 1168465
      },
      "pushed_at": "2026-07-16T20:18:30Z",
      "created_at": "2026-03-09T23:05:22Z",
      "owner_type": "User",
      "updated_at": "2026-07-16T20:18:32Z",
      "description": "AI orchestration tool for Claude Code with MCP state management, review workflows, and plugin auto-update",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "sdsrss",
      "company": null,
      "location": null,
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/230400260?v=4",
      "created_at": "2025-09-04T15:33:31Z",
      "is_verified": null,
      "public_repos": 12,
      "account_age_days": 320
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.5",
          "kind": "patch",
          "published_at": "2026-07-16T20:20:06Z"
        },
        {
          "tag": "v0.8.4",
          "kind": "patch",
          "published_at": "2026-07-16T19:50:17Z"
        },
        {
          "tag": "v0.8.3",
          "kind": "patch",
          "published_at": "2026-07-16T19:05:29Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-07-16T18:40:15Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-07-16T18:16:02Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-16T16:37:57Z"
        },
        {
          "tag": "v0.7.9",
          "kind": "patch",
          "published_at": "2026-06-08T15:50:23Z"
        },
        {
          "tag": "v0.7.8",
          "kind": "patch",
          "published_at": "2026-06-08T15:19:03Z"
        },
        {
          "tag": "v0.7.7",
          "kind": "patch",
          "published_at": "2026-05-23T17:19:26Z"
        },
        {
          "tag": "v0.7.6",
          "kind": "patch",
          "published_at": "2026-04-23T13:33:20Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-04-23T12:49:24Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2026-04-23T12:34:41Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-04-20T16:05:02Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-04-20T15:59:48Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-04-20T15:52:47Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-29T02:34:04Z"
        },
        {
          "tag": "v0.6.9",
          "kind": "patch",
          "published_at": "2026-03-28T10:57:09Z"
        },
        {
          "tag": "v0.6.8",
          "kind": "patch",
          "published_at": "2026-03-28T03:47:38Z"
        },
        {
          "tag": "v0.6.7",
          "kind": "patch",
          "published_at": "2026-03-28T02:42:39Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-03-27T15:35:21Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-03-25T17:22:42Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-03-25T16:24:13Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-03-22T11:42:01Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-03-22T10:05:04Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-22T09:41:07Z"
        },
        {
          "tag": "v0.5.15",
          "kind": "patch",
          "published_at": "2026-03-22T08:34:02Z"
        },
        {
          "tag": "v0.5.14",
          "kind": "patch",
          "published_at": "2026-03-22T07:44:41Z"
        },
        {
          "tag": "v0.5.13",
          "kind": "patch",
          "published_at": "2026-03-22T06:43:18Z"
        },
        {
          "tag": "v0.5.12",
          "kind": "patch",
          "published_at": "2026-03-22T06:01:50Z"
        },
        {
          "tag": "v0.5.11",
          "kind": "patch",
          "published_at": "2026-03-22T05:32:07Z"
        },
        {
          "tag": "v0.5.10",
          "kind": "patch",
          "published_at": "2026-03-17T06:22:05Z"
        },
        {
          "tag": "v0.5.9",
          "kind": "patch",
          "published_at": "2026-03-17T04:57:27Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-03-17T04:43:29Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-03-17T04:10:10Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-03-17T03:24:04Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-03-17T02:04:16Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-03-17T01:30:00Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-03-17T00:52:59Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-03-17T00:12:13Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-03-16T23:05:44Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-03-16T21:18:31Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-03-16T20:12:27Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T19:41:51Z"
        },
        {
          "tag": "v0.3.17",
          "kind": "patch",
          "published_at": "2026-03-16T17:45:05Z"
        },
        {
          "tag": "v0.3.16",
          "kind": "patch",
          "published_at": "2026-03-14T19:08:19Z"
        },
        {
          "tag": "v0.3.15",
          "kind": "patch",
          "published_at": "2026-03-14T19:00:58Z"
        },
        {
          "tag": "v0.3.14",
          "kind": "patch",
          "published_at": "2026-03-14T19:00:45Z"
        },
        {
          "tag": "v0.3.13",
          "kind": "patch",
          "published_at": "2026-03-11T23:40:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2b44e6cf195cac5d15d1bdf7f114863881d47018",
          "body": null,
          "is_bot": false,
          "headline": "0.8.5",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T20:17:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ee182a37f9f22e85ec356d7a540e2bb0d0b2c73",
          "body": "…ools + statusLine\n\ne2e-install.test.js asserts the installed FILE TREE; this adds the missing\n\"is it usable\" layer. It populates the plugin cache the way /plugin install\ngsd@gsd does, boots the MCP server through the real .mcp.json entry point\n(launcher.js), drives a session over JSON-RPC (initiali\n[…]\nesulting live state. Fully isolated\nunder tmpdir via HOME + CLAUDE_CONFIG_DIR; cleaned up in after().\n\n8 tests. Suite 1080 → 1088.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(e2e): driven plugin-install E2E — boot MCP via launcher, drive t…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T20:13:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8b4ca56d61334598e23842ecfc13d6773fe4a0b3",
          "body": "…ng guard\n\n[allow-banned-vocab]\n\nCode review of R-11/R-11b surfaced two anti-downgrade / robustness gaps:\n\n- requireSignature gated on the full semver, so a prerelease of\n  MIN_SIGNED_VERSION (e.g. 0.8.3-rc.1) sorted below 0.8.3 and skipped\n  verification while still being a valid update for any pre\n[…]\ntate the guarantee that holds (asset == hashed file).\n\nTests: +3 (prerelease gate, last-match, over-long sig bound). 1080 passing.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(auto-update): close prerelease-strip downgrade gap + CI key-pairi…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T19:42:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48c5d33b1f8c39f5bf13c15a6bb525168abcc6c8",
          "body": null,
          "is_bot": false,
          "headline": "0.8.3",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T19:03:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fb3f6178869639b2e7712ddc267b77c6bc97233",
          "body": "…ing)\n\nAdds authenticity on top of the R-11 checksum. CI signs each release's SHA-256\nwith a private key held only in the RELEASE_SIGNING_KEY secret; the updater\nverifies it against an embedded Ed25519 public key before install. Releases at\nor after MIN_SIGNED_VERSION (0.8.3) MUST carry a valid sign\n[…]\n\n  parses the signature.\n\nTrust boundary: now tamper-proof (authenticity), not just corruption detection.\nTests 1071 -> 1077 (+6).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(auto-update): Ed25519 signature verification (R-11b tamper-proof…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T19:02:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "563dfd4dc4fd405a13550b8753dea4f9f26409c8",
          "body": null,
          "is_bot": false,
          "headline": "0.8.2",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T18:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4393c8af0996f6aaf64e3123c49a41b72438d951",
          "body": "…et (R-11)\n\nThe integrity gate (SHA-256 verify-before-install) shipped in 0.8.0 was inert:\nrelease.yml never published a checksum, so every update took the skip path. And\nGitHub's source tarball has no stable-checksum guarantee, so publishing its hash\nwould eventually fail-closed for all clients.\n\n-\n[…]\netects transit corruption/truncation, not tampering (that\nneeds an out-of-band signature — not in scope). Tests 1069 -> 1071 (+2).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(auto-update): verify updates against a deterministic release ass…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T18:37:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ec288acf4941d4537012bebbc0ba42191de7d33c",
          "body": null,
          "is_bot": false,
          "headline": "0.8.1",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T18:13:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6620d7580f29f52bf2de47b100ad0d095de6ce27",
          "body": "Post-0.8.0 review follow-ups (audit H1/H3):\n- R-03: L3 human-confirmation gate is now level-driven, not flag-driven —\n  covers phase-scoped reviews and mixed batches (non-L3 siblings still\n  accept); preflight no longer clears an active hold on a passive resume.\n- M-2: an L3 task with review_require\n[…]\n running-task check.\n- M-1: executor failed-path persist carries expectedVersion.\n\nTests 1063 -> 1069 (+6), all green; lint clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): harden R-03 L3 gate + R-01 lock reclaim + R-02 parity",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T18:11:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "edf546ddf16e12d8b95ede5219289ffa6494fd89",
          "body": null,
          "is_bot": false,
          "headline": "0.8.0",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T16:35:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9b2829ef8111ca4be0eb9f504cca61337ae579b",
          "body": "Implements all 26 items from docs/optimization-roadmap-2026-07-14.md.\n\nP0 (data/safety): file-lock ownership tokens (R-01), incremental-validation\ncross-invariants (R-02), L3 human-confirmation gate (R-03), unified evidence\n{id,scope,type?} contract (R-04), resume phase-complete fix (R-05).\n\nP1 (sil\n[…]\nt be {id,scope,type?}; update() rejects fabricated task lifecycles\nand current_phase < 1; MCP tool calls ignore injected basePath.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: complete audit optimization roadmap P0-P3 (26/26)",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-07-16T16:34:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56f46efda15ea75fb5bec51ad355f106f7e10310",
          "body": null,
          "is_bot": false,
          "headline": "0.7.9",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-06-08T15:48:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a205de80f85b562693ab03ff89a7516835cfa261",
          "body": "…tion\n\n- orchestrator: a zero-task (empty milestone) phase no longer loops forever in\n  review. selectRunnableTask gates trigger_review on review-not-yet-passed, and\n  resume auto-completes empty phases — was oscillating executing_task↔reviewing_phase\n  indefinitely, hanging the whole workflow.\n- sc\n[…]\norder_tasks reports duplicate IDs clearly instead of a misleading\n  \"circular dependency\" error.\n\n+7 regression tests (982 → 989).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(state): prevent zero-task phase deadlock + harden plan/dep valida…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-06-08T15:47:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e09d00b59f0b0b73605f8bf17bf854757c7f03ad",
          "body": null,
          "is_bot": false,
          "headline": "0.7.8",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-06-08T15:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4664fb2116df339c2dc30f49592eb85c8f539af9",
          "body": "actions/checkout@v4 and actions/setup-node@v4 run on the deprecated Node 20\nruntime; GitHub forces Node 24 from 2026-06-16 and removes Node 20 from\nrunners 2026-09-16. v5 of both actions runs on Node 24, clearing the\ndeprecation annotation in CI/release logs.\n\nsoftprops/action-gh-release@v2 already runs on Node 24 — left unchanged.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: bump checkout/setup-node to v5 (Node 24 runtime) (#3)",
          "author_name": "sdsrss",
          "author_login": "sdsrss",
          "committed_at": "2026-06-08T15:15:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "67673b9b5df53c3640f2eae501ef886d108c6854",
          "body": "npm runs the dev-only POSIX `prepare` git-hook script after `npm install`.\nOn Windows it executes via cmd.exe, which fails parsing `[`/`ln`/`|| true`,\nso `npx gsd-lite install` aborted with a false \"Failed to install runtime\ndependencies\" even though node_modules was fully populated.\n\n- install runt\n[…]\n` in ~/.claude/gsd does not re-trigger the failure\n- e2e regression assertion: runtime package.json has scripts stripped\n\nFixes #2\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(install): skip lifecycle scripts so Windows runtime install succeeds",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-06-08T15:06:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e2827f2d9b50b10b8874d1c0ce8e5bc793fc2459",
          "body": "…visories\n\nknown-red baseline: prior v0.7.7 Release + CI runs failed at the same `npm audit --omit=dev` step this commit fixes; pushing this lands the cure.\n\nRelease CI for v0.7.7 failed at npm audit — transitive deps via\n@modelcontextprotocol/sdk had advisories: fast-uri (high, path traversal +\nhos\n[…]\nerrides allowed newer versions but the lockfile was pinned. `npm audit fix`\nbumps lockfile entries; no package.json change needed.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): refresh lockfile past hono/fast-uri/ip-address/qs audit ad…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-05-23T17:10:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b559bc2f01d36efa202fa43b80aac9cf28502c5c",
          "body": null,
          "is_bot": false,
          "headline": "0.7.7",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-05-23T17:05:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f26391c34ce9e8ebaf830b51ee8126c69e2998fd",
          "body": "…es state behind\n\nClaude Code's /plugin uninstall only updates installed_plugins.json + enabledPlugins.\nIt does NOT invoke our uninstall.js, leaving hook scripts, runtime dir, settings.json\nhook/statusLine/marketplace entries, and the composite statusline registry behind.\nHooks keep firing and gsd-s\n[…]\n-cleanup.test.js cover install marker writing, the four\norphan-detection paths, and the auto-update guard. Full suite: 982 passed.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(uninstall): self-clean orphaned hooks when /plugin uninstall leav…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-05-23T17:04:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6c6bffd5001725f4084a58431f41ca08fca2f2f5",
          "body": null,
          "is_bot": false,
          "headline": "0.7.6",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T13:31:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a39df2af9b2eb762a5068e06e8e93eda77678a1",
          "body": "…rs runnable\n\nBlocked executor outcome short-circuited workflow_mode to awaiting_user\neven when independent tasks in the same phase were still runnable,\nviolating the \"execution continues with remaining tasks\" contract from\nREADME + design doc (§1399: \"0 runnable task → awaiting_user\").\n\nProbe selec\n[…]\n.js 3.3/3.4 to match\nthe design-correct dispatch of 1.2; added orchestrator.test.js\nregression for the blocked-with-runnable case.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): keep phase executing when blocked task leaves othe…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T13:30:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e558aefcda618ad2bd50ad1fb9cdf753034a80e",
          "body": "Split the handoff-gate \"verification failed\" path: missing verification\nnow returns a specific hint naming the required arg shape, distinct from\nthe case where a check actually failed. Also realign run_verify schema\ndescription and execution-flow.md — the state layer does not execute\nexternal tools, so callers must run lint/typecheck/test externally and\npass results via the verification parameter.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ux): clarify phase-complete verification errors and sync docs",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T13:29:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "78cf100d51928d0a0d02bd25a86f0c6f38f99e6f",
          "body": null,
          "is_bot": false,
          "headline": "0.7.5",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T12:47:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4351965e24428fc0e337dd71b55ea201fbe2fdad",
          "body": "code-graph-mcp's statusline-chain.js `register gsd <cmd>` is id-scoped,\nso ghost entries whose command is our gsd-statusline but whose id isn't\n`gsd` (notably `_previous`, left over when code-graph composite-took-over\na pre-existing top-level GSD statusLine) slip through id-based upsert\nand produce \n[…]\nr scrub still runs.\n\nFallback direct-write path retained the same findIndex+replace logic\nthat silently accumulated ghosts when both _previous and gsd existed —\nthe new normalize covers that case too.",
          "is_bot": false,
          "headline": "fix(statusline): post-scrub ghost entries in composite registry",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T12:46:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90f319739057c49c784ff5ff246fdccea5eef9cd",
          "body": null,
          "is_bot": false,
          "headline": "0.7.4",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T12:32:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9237494bcb3b07f0e5e79afc43cbe6faa8d215b",
          "body": "When installed as a Claude Code plugin, the plugin system serves\ncommands/agents/workflows/references directly from\n~/.claude/plugins/cache/gsd/gsd/<version>/. Writing user-scope copies\nat ~/.claude/{commands,agents,workflows,references}/gsd/ caused every\nslash-command to register twice and drift si\n[…]\nuser-scope; e2e\n  assertInstallTree gains { userScope } option and the plugin-mode\n  call site asserts user-scope dirs are absent.\n\nRuntime (~/.claude/gsd/src/) and hooks registration paths unchanged.",
          "is_bot": false,
          "headline": "fix(install): skip user-scope copies in plugin mode, clean legacy dirs",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-23T12:31:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72317dcb7dc0b1f19fa503a6cf6118a3c6d3e5c2",
          "body": null,
          "is_bot": false,
          "headline": "0.7.3",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T16:04:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4acbbbb3164915570bfbe2dcfa12e2f52de3c72d",
          "body": "…te advisories\n\n@modelcontextprotocol/sdk@1.27.1 pulls in hono@4.12.7 and @hono/node-server@1.19.11,\nboth flagged moderate (7 GHSAs total: cookie validation, path traversal, middleware\nbypass, etc.). Latest SDK 1.29.0 still requires hono ^4.11.4 and @hono/node-server\n^1.19.9, so bumping the SDK does\n[…]\nixed versions:\n- hono 4.12.7  → 4.12.14\n- @hono/node-server 1.19.11 → 1.19.14\n\nnpm audit --omit=dev now reports 0 vulnerabilities.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): pin hono + @hono/node-server via overrides to clear modera…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T16:04:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f1fd50e734b6d3ae3f1ad55bb9fbba7c9c410866",
          "body": null,
          "is_bot": false,
          "headline": "0.7.2",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T15:59:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e5928d478689037d2f19636004945b37becba28",
          "body": "When the state layer can't find a .gsd directory, the previous message\n\"No .gsd directory found\" left first-time users with no actionable hint.\nIt now points at /gsd:start and /gsd:prd, matching the friendlier message\nalready used for the \"state.json missing\" sibling case.\n\nUncovered by CI for v0.7.\n[…]\ntions runner\nit hit the unhelpful branch and failed.\n\nAlso update server.test.js's NO_PROJECT_DIR regex to accept either phrasing.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ux): NO_PROJECT_DIR error now names next-step command",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T15:58:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa1faee6795cd085420b1e5e443180ea5a161387",
          "body": null,
          "is_bot": false,
          "headline": "0.7.1",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T15:52:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e15b3367cb5a6832231588b74a76fac148180060",
          "body": "Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: bump README test count 909 → 966",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T15:51:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ae5db3636057c03b1bd2b55504a3a0bd0395c262",
          "body": "Drives the MCP server over real stdin/stdout the way Claude Code would, catching\nissues that import-based unit tests bypass (JSON-RPC serialization, schema-level\nerror messages, multi-step orchestration).\n\n- round1 (5 tests): tools/list, health, state-init/read, executor checkpoint,\n  unknown-tool e\n[…]\nrcher decision storage, terminal-state resume is noop\n  (no _version bump), paused resume, reviewer/debugger field-specific errors\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add 3-round user-simulation stdio test suite (+23 tests)",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T15:50:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5bf5a9955f52ca390d3e43791f48b0fbff9c2014",
          "body": "- doctor: check all 4 hook registrations (StatusLine + PostToolUse + SessionStart + Stop)\n  and 3 statusline paths (direct + cache registry + backup mirror)\n- status: add 'planning' workflow_mode guidance\n- resume: replace vague planning-mode message with actionable /gsd:start, /gsd:prd, or\n  state-\n[…]\ndirect\n  cache-registry write for older code-graph versions\n- install.test: add test asserting chain CLI is invoked when available\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ux): doctor/status/resume guidance + composite statusline chain CLI",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-04-20T15:50:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d2721281aa2188999f93af770afc8696514b9edf",
          "body": "- fix(cache): prune regex now matches pre-release versions (install.js, gsd-auto-update.cjs)\n- fix(semver): sort comparator handles pre-release suffixes per semver spec\n- feat(lock): per-basePath mutation queues for multi-project safety\n- feat(resume): clear .session-end marker on resume (crash reco\n[…]\nlow → L2 upgrade path to review-classification\n- test: fix test isolation for workflow_mode transition, update sentinel assertions\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.7.0",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-29T02:33:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4241fa7543ea08bea7c31b83bfea154260feefec",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.6.9",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T10:56:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d249953e0160375563bfd0f493c875f2770f2bff",
          "body": "Add Layer B E2E tests (Tasks 7 & 8) verifying the complete install path\nfrom a real npm tarball: npm pack + install -g lifecycle (6 tests) and\nnpx from tarball (4 tests). Fix install.js to fall back from `npm ci` to\n`npm install --omit=dev` when no lockfile is present (npx tarball installs\ndon't include package-lock.json).\n\nTotal: 32 E2E tests (22 Layer A + 10 Layer B), 941 tests overall.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(e2e): Layer B real npm pack + npx tarball — full package lifecycle",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T10:48:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ae8dc3e9016fb5db365a8b5b7d90f79f3244161f",
          "body": "Add 13 new E2E tests covering plugin mode install (MCP skip, statusLine,\nhooks, file tree, cache pruning), manual+plugin uninstall (clean removal,\nnon-GSD hook preservation, plugin dir cleanup), and double-install idempotency.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(e2e): Layer A plugin install + uninstall + idempotency",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T10:39:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0a514bfef468918b5ea9f91f69fface5ff426437",
          "body": "Add Layer A E2E tests for manual/npm install path (6 tests) and npx\ninstall path with npm ci fallback (3 tests). Fix install.js to copy\npackage-lock.json to RUNTIME_DIR so npm ci succeeds when node_modules\nare absent (npx scenario).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(e2e): Layer A manual/npm + npx install E2E",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T10:36:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a01dbdbe873a4c0f73da951942fa4b584f11e9d5",
          "body": "Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(e2e): scaffold e2e-install.test.js with shared helpers",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T10:32:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c5bf398f9c32559e02ad66aca697d268fcc95097",
          "body": "…d new sections\n\n- Test count 866→909, source files ~48→~15\n- Add Auto-Update & Version Management feature section\n- Add Workflows table (6) and References table (8)\n- Add Context health monitoring, composite StatusLine, version drift detection\n- Expand hooks/ structure with individual file descript\n[…]\nnce\n- Add Requirements section (Node.js >= 20, Claude Code)\n- Update Comparison table with auto-update and context monitoring rows\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): update README with accurate stats, missing features, an…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T05:08:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a7be23b958535886a4d2cb88976c3d1bb98c1cd8",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.6.8",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T03:47:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a5fdec09a8d77f28b7e9fa2797a31d4e14162f83",
          "body": "… alignment, test coverage\n\nP0 Critical:\n- Fix sentinel file leak on storeResearch validation failure (logic.js)\n- Sanitize workflowMode/shortHead/ended_at in CLAUDE.md injection (session-init)\n- Validate redirect chain with manual redirect + host whitelist (auto-update)\n- Add install.js existence +\n[…]\nlarification\n- Add debugging.md Write tool constraint note\n- Add research.md contract cross-reference\n\n909 tests pass, lint clean.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(audit): comprehensive code audit — security, state bugs, contract…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T03:46:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ae0bffd509883d03d12d74e4dcb2fdf6ae77665",
          "body": "…on, concurrent range, and unknown field\n\n- decisions.test.js: boundary/below-threshold overlap, empty inputs, English text\n- state.test.js: init() HTML-comment stripping and 200-char truncation\n- concurrent.test.js: tighten remaining_percentage to 91-100 range\n- incremental-validation.test.js: additional unknown field key test\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(coverage): add missing test cases for decisions, init sanitizati…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T03:25:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9e433e1c5065b86b81d13d10515bba16032524ea",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(lint): remove unused imports in researcher-handler.test.js",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T03:04:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "33e1272af308aff5852b00c7195916c66aca176b",
          "body": "…n, cache dir filter, settings.json parse safety\n\n- C1: Add validateTarballUrl() with HTTPS-only + GitHub host whitelist;\n  use manual redirect to prevent Authorization header leakage to CDN\n- C2: Add safeName() to strip <!-- --> from project/phase/task names\n  before CLAUDE.md injection (defense in\n[…]\n: Distinguish ENOENT from parse errors when reading settings.json;\n  corrupted files are preserved instead of silently overwritten\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): tarball URL whitelist, CLAUDE.md injection sanitizatio…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T03:02:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e3d5c8e3cf8c9aeb5138dcf7a1674cc3375c3da2",
          "body": "… M4 unconditional stderr\n\n- H2: persist()/persistAndRead() now forward expectedVersion to update()\n  for optimistic concurrency conflict detection between read and write\n- H4: storeResearch writes crash-consistency sentinel file before artifact\n  renames, removes it after state.json commit\n- M4: unhandledRejection always writes to stderr (safe for MCP stdio)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(reliability): H2 persist expectedVersion + H4 research sentinel +…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T03:01:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "457f3e1d77bee3313d62d7dc03ceecc64970c376",
          "body": "- C3: Add 8 missing actions to execution-flow.md action table (trigger_review,\n  phase_failed, task_failed, review_retry_exhausted, research_stored,\n  awaiting_user, await_manual_intervention, noop); fix termination set\n- C4: Fix researcher.md BLOCKED path to return valid JSON passing\n  validateRese\n[…]\n  show actual path (reviewing_phase->executing_task->completed via\n  phase-complete); add running->accepted auto-accept transition\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: sync 4 prompt files with actual code behavior (C3/C4/L9/L10)",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T02:59:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6276276bab0b4586d18147be324c176e44cda092",
          "body": null,
          "is_bot": false,
          "headline": "0.6.7",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T02:42:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1be22285d0111acd030343445d9fb8d22aae516f",
          "body": "…lities\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): update path-to-regexp to fix high severity ReDoS vulnerabi…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T02:41:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3040200eeba0747e33b07745b07e6f18ad7e7ec0",
          "body": null,
          "is_bot": false,
          "headline": "0.6.6",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T02:39:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bee5ce2e4b239be9cbf56e0213e384ad41bc330d",
          "body": "- Fix HANDOFF_GATE bug: phases with all L0 auto-accepted tasks could\n  never complete because required_reviews_passed stayed false\n- Enrich phase-complete response with phase_name, next_phase, workflow_mode\n- Fix state-patch update_task API inconsistency: support both flat fields\n  and nested task o\n[…]\nnt with add_task)\n- Clean up unused imports in test files\n- Add biome-ignore for intentional template literal in session-init hook\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): L0 auto-accept phase-complete gate + UX improvements",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-28T02:39:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "486721695c71ed483b96d0fbff7cb3b87140c4c5",
          "body": "…ount)\n\n- Pre-commit: version consistency across 3 git-tracked files + local CLAUDE.md\n- sync-versions.js: also updates CLAUDE.md test count on npm version/publish\n- CLAUDE.md is gitignored, updated locally only\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: 4-location sync (pkg + plugin + marketplace + CLAUDE.md test c…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-27T15:47:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "48180d159caabd84d0dabb0c5ea11add7e3815ed",
          "body": "- Auto-syncs plugin.json/marketplace.json when package.json version changes\n- Runs biome lint on staged src/tests/hooks files\n- Runs test suite when src/tests files change\n- Installed via npm prepare script (symlink to scripts/pre-commit.sh)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: add pre-commit hook for version sync, lint, and tests",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-27T15:43:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3e5d2e2b2458469ceb33d29b14abaa7df09c2d5d",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.6.5",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-27T15:34:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "14039ae7c424007888d324ee1895c5bd17c9161e",
          "body": "- Always register hooks in settings.json regardless of install method\n  (plugin system hooks.json auto-loading is unreliable)\n- Clear hooks.json entries to prevent double execution\n- Fix SessionStart matcher: startup → startup|clear|compact\n- Update result contract docs: summary|title with alias note\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): reliable hook registration + decision contract alignment",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-27T15:30:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bb6ae549b39412ae388255ec9e57a29e45bf16b7",
          "body": "The executor result contract documents decisions as { id, title, rationale }\nbut buildDecisionEntries() only checked for decision.summary, silently\ndropping decisions that used the contract-specified title field.\n\nNow accepts both fields: summary takes precedence when both exist,\ntitle is used as summary when only title is provided.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): accept both title and summary in decision entries",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-27T14:50:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "77ff1cbdbc0266feca50579066418fa67aeaff11",
          "body": "- Strip full state from state-update response, return only _version\n- Strip result_contract from orchestrator responses (static reference data)\n- Enrich phase-complete response with progress info\n- Replace raw ENOENT errors with friendly user-facing messages\n\nSaves ~4800 tokens per typical project orchestration cycle.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ux): reduce token waste and improve error messages",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-27T14:19:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c5a8eddeed68eba0249fcd32bb3f9a39cf54f7e6",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.6.4",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-25T17:22:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8de9ee8b37ec60e200477300d583f30d03032a56",
          "body": "fix(orchestrator): lazy plan-hash baseline, workflow transition gaps",
          "is_bot": false,
          "headline": "Merge pull request #1 from sdsrss/fix/plan-drift-and-execution-flow",
          "author_name": "sdsrss",
          "author_login": "sdsrss",
          "committed_at": "2026-03-25T17:21:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c400bd93f4cc028d8d3b32fd05bc60313b1cdcbb",
          "body": "… execution-flow docs\n\nPlan drift detection was triggering false replan_required on every fresh\n/gsd:start because state-init hashed placeholder files that the agent\nimmediately overwrote with real plan content. This caused the AI to guess\ninvalid workflow_mode values (\"executing\", \"execute\", \"activ\n[…]\nl description\n- Add complete Action handler table to execution-flow.md with all 15\n  actions and phase-complete parameter guidance\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): lazy plan-hash baseline, workflow transition gaps,…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-25T17:13:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f0b25712cb285512b2dc3524c203815180bbfdf3",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.6.3",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-25T16:23:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fdff93b247c02025c2014ce879308e061f6d8ce7",
          "body": "… composite systems\n\nstatusLine is a top-level settings.json config that the plugin system's\nhooks.json cannot manage. Previously install.js skipped statusLine\nregistration when isPluginInstall=true, leaving no statusLine for plugin\nusers. Now statusLine is always registered regardless of install me\n[…]\nosite statusLine, GSD registers as a provider in the composite\nregistry instead of overwriting. Session-init self-heals if missed.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(install): always register statusLine for plugin installs, support…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-25T16:23:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "51814737bbc1235721a1e92d6c0dac32c375a59d",
          "body": "…rity tests\n\n- Add missing _version increment in patchPlan() for TOCTOU consistency\n- Extend reviewer rework fallback to include accepted tasks (not just checkpointed)\n- Add context deep-merge, migrateState calls, full validation for decisions/propagation\n- Add null guard for auto-update GitHub API \n[…]\nphase rollback before research refresh (safety-critical)\n- Add tests for hint priority ordering and reviewer empty-rework fallback\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(state+reviewer): _version consistency, rework fallback, hint prio…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T11:40:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8db389992c133dbca77c61bdda2ac39d59db5fd1",
          "body": "fix(orchestrator): recover orphaned running tasks on resume\nfix(reviewer): accurate accepted/rework counts from actual patches\nfix(context-monitor): correct MCP tool name in critical warning\ndocs: sync README test count (866), source files, installer metrics\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "0.6.1",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T10:04:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "db858576db9a30e40a92c2b70e568255b7d74dd3",
          "body": null,
          "is_bot": false,
          "headline": "0.6.0",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:40:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "815ab43e9ea6bcb2ef6fd25214b243528668fe13",
          "body": "…tation\n\n- state-diagram: add failed→active recovery path (H-3)\n- deviation-rules: document L1→L0 downgrade exception with evidence\n- execution-loop: add L1→L0 exception note\n- start.md: add orchestrator discipline rules\n- doctor.md: fix trailing whitespace\n- session-init-phase6.test: fix PLUGIN_AUTO_UPDATE env value\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: sync state diagram, deviation rules, and start.md with implemen…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:40:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "717cca75262a70158763c3a89fe4e522a205d91a",
          "body": "- crud.js: Replace dynamic import('node:path') with static import for relative\n- gsd-auto-update.cjs: Replace local compareVersions with shared semverSortComparator\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(review): static import for node:path, deduplicate compareVersions",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:36:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4c09f4c66fc9c08874fd34325dfd76b32b7d158f",
          "body": "Improvement #3: orchestrator-resume responses now include a `summary`\nfield with workflow_mode, current_phase, current_task, phase_progress,\nand recent_decisions. This eliminates redundant state reads in\nresume.md STEP 1, saving ~2000 tokens per resume cycle.\n\nImprovement #5: Replace mtime-based pla\n[…]\nd at init time and stored in\ncontext.plan_hashes. Prevents false positives from `touch` and\ncatches reverts that mtime would miss.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(orchestrator): resume summary + content-hash plan drift detection",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:21:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3899b75d6e85c82ed687ed0f52d3fb673366fe82",
          "body": "…d code\n\nImprovement #8: Add _version counter to state for TOCTOU protection.\n- createInitialState sets _version: 0\n- update() auto-increments _version on every successful write\n- Optional expectedVersion param returns VERSION_CONFLICT on mismatch\n- Backward compatible: existing callers unaffected\n\n\n[…]\ns and gsd-auto-update.cjs)\n- Part B: Shared detectCycles() exported from schema.js\n  (replaces duplicate _detectCycles in crud.js)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(state): add optimistic concurrency version check + extract share…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:18:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "013f50ce6af14c0ee2252274c1b9ad2cc4b8732d",
          "body": "…add plugin/pruning install tests\n\nContext-monitor: replace legacy ESM wrapper tests with real process spawning\nagainst gsd-context-monitor.cjs — covers thresholds, debouncing, severity\nescalation, stale metrics, and non-GSD session handling.\n\nInstall: add plugin-mode tests (skip hook registration, \n[…]\ncleanup, stale\nentry removal) and cache pruning tests (keep-latest-3, semver sort, no-prune\nwhen <=3 versions or non-plugin mode).\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(hooks): rewrite context-monitor tests for CJS production hook + …",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:12:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b33343665f3e2cb4584680b35b5c7d089da85b3a",
          "body": "Mirrors the ESM _gsdDirCache pattern from src/utils.js. Caches positive\nresults per startDir to eliminate redundant statSync calls. Negative\nresults (null) are intentionally not cached so .gsd directories created\nlater can still be discovered. Exports clearFindGsdDirCache() for test\nisolation.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(hooks): add Map cache to findGsdDir in gsd-finder.cjs",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:10:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "52f00c40b40415131f5ebc3d12310156793bc75e",
          "body": "… behavior\n\n- debugger: clarify Phase 4 returns fix_direction + test case description (no Write tool)\n- debugger: document outcome values and fix_attempts source\n- debugging workflow: Phase 4 rewritten for diagnosis-only role\n- prd: add STEP 0 existing-project detection (mirrors start.md)\n- prd: imp\n[…]\nications\n- review-classification: separate L2/L3 flows, L3 -> awaiting_user\n- review-cycle: add L3 section with awaiting_user flow\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(prompts): debugger diagnosis/impl split, prd STEP 0, L3 distinct…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T09:09:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1b30f6770ad90668d0f5caddf705c819da429ecf",
          "body": "Cache pruning now checks `ps aux` for running processes before\ndeleting old version directories. Versions with active MCP server\nprocesses are preserved to avoid disrupting running sessions.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(install): skip pruning cache versions with active processes",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T08:40:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b8bd91e9fbabdb545b57791142aa4c6d4a7db2b5",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.5.15",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T08:32:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "271f4fbeb7fb9816387a751fb4c945ac2f415f0b",
          "body": "Adds cache cleanup to both install.js and auto-update:\n- install.js prunes old versions during plugin-mode install\n- syncPluginCache prunes after successful cache sync\n- Semver-sorted, keeps 3 most recent, removes rest\n- Freed 245MB (12 versions → 3) on first run\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(install): prune old plugin cache versions — keep latest 3",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T08:31:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "61ecabc9076a9ed652f9aaf8fd422e367536275a",
          "body": "When installed as a plugin, hooks are managed by hooks.json via the\nplugin system. install.js was also registering the same hooks in\nsettings.json, causing double execution of SessionStart, PostToolUse,\nand Stop hooks. Now install.js detects plugin mode and:\n- Skips hook registration in settings.json\n- Cleans up stale manual hook entries left from previous runs\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(install): skip settings.json hook registration for plugin installs",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T08:28:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1974990a062f47eaede7f875b9ea2189c0d8e774",
          "body": "- Executor auto-transitions pending→running for parallel_available tasks,\n  fixing TRANSITION_ERROR when submitting results for undispatched tasks\n- install.js: add gsd-session-stop.cjs, hooks/lib/ dir, Stop hook registration\n- uninstall.js: clean up session-stop hook, hooks/lib/gsd-finder.cjs, Stop\n[…]\nistry,\n  update statusLine path after version change, fix backup file location\n- Add parallel auto-start test case (827→828 tests)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(core): parallel task auto-start + plugin install hardening",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T08:23:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ccd630af39243942182537a9dfa631a4fd80460f",
          "body": "…m versions\n\nThe publish step now checks npm registry before publishing, avoiding E403\nwhen the version was already published locally. The gh-release step uses\nmake_latest: true to update existing releases instead of failing.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): make release workflow idempotent — skip already-published np…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T07:49:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4254fe40a0beecf6488fba04fec91e7473bff549",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): 0.5.14",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T07:44:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4003811c2d13b24450d72cacc940529a1d31ec90",
          "body": "…ndler consistency (0.5.14)\n\nP0: withFileLock throws on retry exhaustion instead of silent unlocked execution\nP1: crud.js decoupled from verify.js — state layer no longer imports external tool runner\nP1: researcher handler returns action object (aligned with executor/reviewer/debugger contract)\nP1: \n[…]\n phase review retry limit (MAX_PHASE_REVIEW_RETRY=5) prevents infinite review cycles\nTests: 826 passing (+4 new), coverage 94%/83%\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(core): architecture hardening — lock safety, layer decoupling, ha…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T07:43:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f4fbe6364f8cfb23688db25d111b99aebfcd98f",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): 0.5.13",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T06:42:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "710ecf8a6414c2c957ef920fbad7217ef5161c52",
          "body": "…mpact analysis + auto PR (0.5.13)\n\nCompetitive analysis-driven enhancements:\n\n- Executor confidence field (high/medium/low): auto-adjusts review level\n  - low confidence → L1 upgrades to L2 (stronger review)\n  - high confidence + no contract change → L1 downgrades to L0 (self-review sufficient)\n- R\n[…]\n is optional, parallel_available only appears when >1 task,\npr_suggestion is informational.\n\n822 tests pass (was 804), lint clean.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(orchestrator): confidence-based review + parallel scheduling + i…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T06:42:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34a0aba5aa52b226fb037b5d52b8b825aaa135f3",
          "body": "…njection (0.5.12)\n\n- Add Stop hook (gsd-session-stop.cjs): writes .session-end marker on\n  non-graceful exit for crash protection\n- Enhance SessionStart (Phase 6): inject GSD project status block into\n  CLAUDE.md for persistent visibility across sessions\n- Add resume.md Step 0: detect .session-end marker and inform user\n- Extract shared hook utilities to hooks/lib/gsd-finder.cjs\n- 25 new tests (804 total), all passing\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hooks): session lifecycle — Stop hook + SessionStart CLAUDE.md i…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T06:01:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5b2ad484b7584e4fbe40a970feb3115186348d2c",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(test): add git env vars for CI in patch-plan tests",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T05:33:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c7d9fba528274e115154dc0f8ed5fc3de1a12000",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): 0.5.11",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T05:31:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "106928423085c312a4138d3014bd3b3982380557",
          "body": "…s update (0.5.11)\n\n- New state-patch MCP tool: add/remove/reorder tasks, update fields, add dependencies\n- P0: update() returns merged state, persistAndRead() eliminates re-reads\n- Fix: retry_count reset after debugger success\n- Fix: spec_passed/quality_passed gating in reviewer handler\n- Fix: migr\n[…]\nk\n- researcher.md: document decision_index contract\n- README/CLAUDE.md: align with current state (779 tests, 11 tools, 6 commands)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(state-patch): incremental plan modification + 10 bug fixes + doc…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T05:31:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "331dcdafaf58c0e85aecfdb090c5870bd6baffcc",
          "body": "… directory\n\nSplit 1244-line orchestrator.js into src/tools/orchestrator/ with 6 modules:\nhelpers.js (shared constants + functions), resume.js, executor.js, debugger.js,\nreviewer.js, researcher.js, and index.js re-exports. All 760 tests pass.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(orchestrator): split monolithic orchestrator.js into modular…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T04:51:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dd90c8ce16bdeeebb842369ca0fb90ad6e579782",
          "body": "Split 1150-line src/tools/state.js into src/tools/state/ with:\n- constants.js: ERROR_CODES, lock infrastructure, shared constants\n- crud.js: init, read, update, phaseComplete, addEvidence, pruneEvidence\n- logic.js: selectRunnableTask, propagateInvalidation, buildExecutorContext, etc.\n- index.js: re-\n[…]\n API surface\n\nUpdated all import paths (src + tests + scripts + references) from\nstate.js to state/index.js for ESM compatibility.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(state): split monolithic state.js into modular state/ directory",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-22T04:40:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5deef3a27a7ae21870b47572bf0b235ef5fe8cfb",
          "body": "…ing (0.5.10)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(version): unified version sync, plugin mode detection, drift warn…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T06:20:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6c8e8344401f8300079aa5e112788233621468e4",
          "body": "…ewer scope_id fallback\n\n- Reset retry_count to 0 when reviewer marks tasks for rework or\n  propagation sets needs_revalidation, preventing selectRunnableTask\n  from skipping rework tasks that hit the retry limit during prior\n  executor failures\n- Reject empty phases array in state-init (previously \n[…]\naccepted by\n  init() but not declared in tool definition)\n- Update tests for empty phases validation, add new test case (752 pass)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): rework retry_count reset, empty phases guard, revi…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T06:19:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5224f523579dc454609ecfe207eaa2db753b155b",
          "body": "…ing (0.5.9)\n\n- Fix getInstallMode() misdetecting plugin installs as manual (check installed_plugins.json first)\n- Extend version drift detection to plugin mode (check plugin registry, not just dev-mode disk)\n- Add runtime dir + auto-update state sync to sync-versions.js\n- Add missing git tags v0.5.5, v0.5.6\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(version): unified version sync, plugin mode detection, drift warn…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T04:57:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d874f1ead1eef14728261e2a798717a22793152",
          "body": "…tusline check (0.5.8)\n\n- sync-versions.js now copies source files to ~/.claude/plugins/cache/ after version bump\n- doctor.md checks composite statusline registry in addition to direct settings.json\n- doctor.md compares source/server/runtime versions for better drift detection\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(dev): plugin cache sync in sync-versions.js, doctor composite sta…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T04:40:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cb6849d0b61f7b78c6fc08b787ae0dbb1e4e2498",
          "body": "…block, version drift detection (0.5.7)\n\n- Fix phase dependency string/number type mismatch in selectRunnableTask (dep.id\n  as string vs phase.id as number caused cross-phase deps to never resolve)\n- Add rework_feedback to executor context when task is re-dispatched after\n  reviewer rejection, so ex\n[…]\nool description to document reason|description fields\n- Sync marketplace.json version\n- 3 new regression tests (751 total, 0 fail)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): phase dep type coercion, rework feedback, force-un…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T04:03:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4d9bbe587d737263bdbcb9b24beaa41e194aaba",
          "body": "…d, manual unblock resume (0.5.6)\n\n- L3 tasks now trigger immediate per-task review (same as L2), fixing a\n  security gap where highest-risk tasks (auth/payment/core arch) were\n  silently downgraded to L1 batch review\n- phase-complete handles active→accepted by auto-advancing through the\n  reviewing\n[…]\nblock found matches\n- critical_issues validation accepts both reason and description fields,\n  reducing reviewer contract friction\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): L3 immediate review, phase-complete active→accepte…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T03:23:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8509627a39cb7168be6e44991b37ec603920d9d",
          "body": "…al unblock resume, and description field\n\nCover four recent bug fixes with new tests:\n- L3 tasks now trigger immediate review dispatch (like L2)\n- phaseComplete handles active → accepted transition via reviewing intermediate\n- Resume from awaiting_user works when blockers are manually cleared (no decisions needed)\n- validateReviewerResult accepts both 'reason' and 'description' in critical_issues\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add regression tests for L3 review, active phase-complete, manu…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T03:17:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4fc8641701cace82e29f26c97b1d34829cd7a0db",
          "body": "…d plugin cache sync\n\n- Add result_contract to all dispatch responses (executor/reviewer/debugger) so agents\n  produce valid results on the first call without trial-and-error schema discovery\n- Auto-advance phase lifecycle from active→reviewing in complete_phase path, fixing\n  invalid transition err\n[…]\nd runtime dir, causing version mismatch after updates\n- Add test for complete_phase auto-advance behavior (742 tests, all passing)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): result contracts, phase lifecycle auto-advance, an…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T02:47:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "92b8f3f06301cc013eb1b80e97ec64dbf71de4ff",
          "body": "…, and agent prompt docs (0.5.5)\n\n- Fix needs_revalidation → running transition error by adding two-step\n  lifecycle reset (needs_revalidation → pending → running) in orchestrator resume\n- Accept L1 as valid review_level in reviewer result validation alongside\n  L2 and L1-batch, with improved error \n[…]\n valid review_level option\n- Update debugger.md with structured evidence format and clearer\n  hypothesis_tested field requirements\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestrator): needs_revalidation resume, review_level validation…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T02:03:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fc8a76a2b198b456235e6a042f39022881c0bf65",
          "body": "… tool schema improvements (0.5.4)\n\n- Add WORKFLOW_TRANSITIONS whitelist to prevent invalid workflow_mode jumps\n  (e.g., executing_task→completed now blocked; must go through reviewing_phase)\n- Guard 'completed' state: requires all phases accepted in both validateStateUpdate\n  and validateState\n- Fi\n[…]\nhema: decisions as [{id,summary,rationale}], evidence as string[]\n- Fix statusline bridge needsWrite to also check has_gsd changes\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(schema): workflow_mode transition whitelist, verification UX, and…",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T01:29:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f02a226a71d8e20b4d991bcb645b90ae9fd316ae",
          "body": "…schema docs (0.5.3)\n\n- Validate requires entries in createInitialState: reject strings, check\n  referenced task/phase IDs exist, validate kind field\n- Guard against division-by-zero in statusline when GSD_AUTOCOMPACT_BUFFER >= 100\n- Add full agent result contract descriptions to all handle-*-result\n[…]\n Document verification object format for phase-complete\n- Fix tool name references in start.md and doctor.md (gsd health → health)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(schema): dependency validation, division-by-zero guard, and tool …",
          "author_name": "sds.rs",
          "author_login": "sdsrss",
          "committed_at": "2026-03-17T00:51:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 48,
      "commits_last_year": 229,
      "latest_release_at": "2026-07-16T20:20:06Z",
      "latest_release_tag": "v0.8.5",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 9.4
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "gsd-lite",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "claude",
            "claude-code",
            "mcp",
            "orchestration",
            "ai-agent",
            "task-management"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/gsd-lite",
          "is_deprecated": false,
          "latest_version": "0.8.5",
          "repository_url": "https://github.com/sdsrss/gsd-lite",
          "versions_count": 56,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1171,
          "first_published_at": "2026-03-10T18:57:45.536000Z",
          "latest_published_at": "2026-07-16T20:19:59.876000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 3,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 118176,
      "source_files_sampled": 85,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.27.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 2,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 1,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "sdsrss",
          "commits": 229,
          "avatar_url": "https://avatars.githubusercontent.com/u/230400260?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 5,
            "reason": "5 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2b44e6cf195cac5d15d1bdf7f114863881d47018",
        "ran_at": "2026-07-22T11:35:12Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-16T20:20:11Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-06-08T15:15:23Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/sdsrss/gsd-lite",
    "host": "github.com",
    "name": "gsd-lite",
    "owner": "sdsrss"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 37,
        "vitality": 78,
        "community": 24,
        "governance": 52,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 78,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "commits_last_year": 229,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "229 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 229
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 48,
              "latest_release_tag": "v0.8.5",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 9.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "48 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 48
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~9.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 9.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 5,
            "inputs": {
              "forks": 0,
              "stars": 3,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "3 stars",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "packages": [
                "gsd-lite"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 1171
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "1,171 downloads/month across npm",
                "points": 40.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 1171,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 52,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "merged_prs": 2,
              "open_issues": 0,
              "closed_issues": 1,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2/2 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "followers": 3,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "sdsrss",
              "public_repos": 12,
              "account_age_days": 320
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of sdsrss",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "sdsrss"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "12 public repos, account ~0 yr old",
                "points": 9.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 12
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "gsd-lite"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "56 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 56
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "topics": [
                "ai-agent",
                "automation",
                "claude-code",
                "claude-plugin",
                "mcp",
                "nodejs",
                "orchestration",
                "task-management"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 37,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "26 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "5 existing vulnerabilities detected",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 47,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.78,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "78 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 78,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.79,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "79 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 79,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 118176,
              "source_files_sampled": 85,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/85 source files over 60KB",
                "points": 53.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 85,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:gsd-lite@0.8.5; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T11:35:19.530839Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/sdsrss/gsd-lite.svg",
  "full_name": "sdsrss/gsd-lite",
  "license_state": "absent",
  "license_spdx": null
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.26.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.