Registro público
Informe de salud del softwareesquema 0.23.0 · métricas 1.13.0 · 2026-07-21 18:20 UTC

thrillmade / clud-bug

Claude PR review with project-aware skills. Encode your team standards (brand voice, API contracts, compliance, test discipline) as Markdown skills the bot cites by name on every PR. One-command install: npx clud-bug init.

TypeScript · JavaScriptMIT★ 1 estrella⑂ 0 forksdesde mar 2026Ver en GitHub ↗

thrillmade/clud-bug tiene un índice de salud de 58 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (78/100) y la más baja, Community & Adoption (33/100). Se actualizó por última vez hace 4 días. Una sola persona concentra la mayor parte del trabajo reciente.

58
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

58
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

thrillmadeOrganización
0 seguidores8 repositorios públicosdesde may 2024

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npmclud-bug0.6.34346972hace 49 díasclaudeclaude-codegithub-actioncode-reviewpull-requestaiskills

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

78Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 4 días
6.9/36Cadencia de commits — 10/52 semanas con commits
18/18Volumen de commits — 199 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year199
human_commit_share0,96
days_since_last_push4
active_weeks_last_year10
Cómo se puntúa
16.2/27Publica versiones — 70 etiquetas de versión (sin releases de GitHub)
36/36Recencia de las versiones — última versión hace 4 días
27/27Cadencia de publicación — una versión cada ~2 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count70
latest_release_tagv0.7.0-rc.24
releases_from_tags
days_since_latest_release4
mean_days_between_releases2
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

33En riesgo · 18% del índice global
Cómo se puntúa
0/60Estrellas — 1 estrellas
0/25Forks — 0 forks
0/15Observadores — 1 observadores
Datos de entrada utilizados
forks0
stars1
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
47.2/80Descargas mensuales — 3469 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packagesclud-bug
dependents
ecosystemsnpm
total_downloads
monthly_downloads3469
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

46En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
18.7/46.8Resolución de issues — 40% de issues cerradas
33.1/38.3Aceptación de PR — 198/229 PR decididos fusionados
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs198
open_issues3
closed_issues2
issue_closed_ratio0,4
closed_unmerged_prs31
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
0/25Alcance del propietario — 0 seguidores de thrillmade
11.3/25Trayectoria — 8 repos públicos, cuenta de ~2 años
Datos de entrada utilizados
followers0
owner_typeOrganization
is_verified
owner_loginthrillmade
public_repos8
account_age_days796
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 49 días
20/20Historial de versiones — 72 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagesclud-bug
ecosystemsnpm
any_deprecatedno
min_days_since_publish49

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

77Bueno · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 7 flujo(s) de trabajo
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentación

90Excelente
Cómo se puntúa
30/30README
25/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://cludbug.dev
10/10Descripción del repositorio
10/10Topics — 13 topics
0/10Wiki
Datos de entrada utilizados
topicsai-code-review, claude, claude-code, cli, code-review, github-actions, npm-package, pr-review, pull-request, skills, skills-sh, skdd, skill-driven-development
has_wikino
homepagehttps://cludbug.dev
has_readme
has_docs_dir
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

53Moderado · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5,3
Excluidos de la puntuación (sin datos o no aplicable): signed_releases. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

77Bueno · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — .cursorrules, AGENTS.md, CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 96 de 96 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share1
agent_instruction_files.cursorrules, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes2711
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
11/11Verificación estática de tipos — site/tsconfig.json, tsconfig.json
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 56 de los últimos 100 commits con autoría o crédito de agente
8/8Mantenimiento automatizado — 4 de los últimos 100 commits son actualizaciones automáticas de dependencias
2/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configssite/tsconfig.json, tsconfig.json
agent_commit_share0,56
toolchain_manifests
dependency_bot_commit_share0,04
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
54.7/55Tamaños de archivo manejables — 1/159 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes108.699
source_files_sampled159
oversized_source_files1

Datos clave

1estrellas de GitHub
1contribuidores
199commits en los últimos 12 meses
4días desde el último push
70versiones publicadas
1factor bus
3issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 5.3 / 10
5.3agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-21 18:20 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Dependencias directas 4
RegistroPaqueteRestricción de versiónManifiesto
npmzod^4.4.3package.json
npmnext^16.2.9site/package.json
npmreact^19.2.7site/package.json
npmreact-dom^19.2.7site/package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "ai-code-review",
        "claude",
        "claude-code",
        "cli",
        "code-review",
        "github-actions",
        "npm-package",
        "pr-review",
        "pull-request",
        "skills",
        "skills-sh",
        "skdd",
        "skill-driven-development"
      ],
      "is_fork": false,
      "size_kb": 1928,
      "has_wiki": false,
      "homepage": "https://cludbug.dev",
      "languages": {
        "CSS": 30314,
        "JavaScript": 674035,
        "TypeScript": 756254,
        "Go Template": 116892
      },
      "pushed_at": "2026-07-17T13:23:56Z",
      "created_at": "2026-03-11T05:14:54Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T13:24:36Z",
      "description": "Claude PR review with project-aware skills. Encode your team standards (brand voice, API contracts, compliance, test discipline) as Markdown skills the bot cites by name on every PR. One-command install: npx clud-bug init.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "thrillmade",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/170016379?v=4",
      "created_at": "2024-05-16T14:34:15Z",
      "is_verified": null,
      "public_repos": 8,
      "account_age_days": 796
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.7.0-rc.24",
          "kind": "prerelease",
          "published_at": "2026-07-17T01:29:39Z"
        },
        {
          "tag": "v0.7.0-rc.23",
          "kind": "prerelease",
          "published_at": "2026-07-11T18:48:36Z"
        },
        {
          "tag": "v0.7.0-rc.22",
          "kind": "prerelease",
          "published_at": "2026-07-03T19:04:21Z"
        },
        {
          "tag": "v0.7.0-rc.21",
          "kind": "prerelease",
          "published_at": "2026-06-30T00:18:35Z"
        },
        {
          "tag": "v0.7.0-rc.20",
          "kind": "prerelease",
          "published_at": "2026-06-29T21:47:10Z"
        },
        {
          "tag": "v0.7.0-rc.19",
          "kind": "prerelease",
          "published_at": "2026-06-29T20:12:28Z"
        },
        {
          "tag": "v0.7.0-rc.18",
          "kind": "prerelease",
          "published_at": "2026-06-29T18:08:47Z"
        },
        {
          "tag": "v0.7.0-rc.17",
          "kind": "prerelease",
          "published_at": "2026-06-29T17:33:44Z"
        },
        {
          "tag": "v0.7.0-rc.15",
          "kind": "prerelease",
          "published_at": "2026-06-29T12:37:27Z"
        },
        {
          "tag": "v0.7.0-rc.14",
          "kind": "prerelease",
          "published_at": "2026-06-29T03:57:22Z"
        },
        {
          "tag": "v0.7.0-rc.8",
          "kind": "prerelease",
          "published_at": "2026-06-28T02:42:55Z"
        },
        {
          "tag": "v0.7.0-rc.7",
          "kind": "prerelease",
          "published_at": "2026-06-27T21:45:22Z"
        },
        {
          "tag": "v0.7.0-rc.6",
          "kind": "prerelease",
          "published_at": "2026-06-27T20:23:49Z"
        },
        {
          "tag": "v0.7.0-rc.5",
          "kind": "prerelease",
          "published_at": "2026-06-26T05:11:34Z"
        },
        {
          "tag": "v0.7.0-rc.4",
          "kind": "prerelease",
          "published_at": "2026-06-17T15:19:10Z"
        },
        {
          "tag": "v0.7.0-rc.3",
          "kind": "prerelease",
          "published_at": "2026-06-10T15:17:33Z"
        },
        {
          "tag": "v0.7.0-rc.2",
          "kind": "prerelease",
          "published_at": "2026-06-09T21:36:50Z"
        },
        {
          "tag": "v0.6.34",
          "kind": "patch",
          "published_at": "2026-06-02T18:14:21Z"
        },
        {
          "tag": "v0.6.33",
          "kind": "patch",
          "published_at": "2026-06-01T18:12:24Z"
        },
        {
          "tag": "v0.6.32",
          "kind": "patch",
          "published_at": "2026-06-01T14:15:46Z"
        },
        {
          "tag": "v0.6.31",
          "kind": "patch",
          "published_at": "2026-06-01T12:43:29Z"
        },
        {
          "tag": "v0.6.30",
          "kind": "patch",
          "published_at": "2026-06-01T04:02:58Z"
        },
        {
          "tag": "v0.6.29",
          "kind": "patch",
          "published_at": "2026-05-31T18:01:04Z"
        },
        {
          "tag": "v0.6.28",
          "kind": "patch",
          "published_at": "2026-05-30T23:28:05Z"
        },
        {
          "tag": "v0.6.27",
          "kind": "patch",
          "published_at": "2026-05-30T04:48:50Z"
        },
        {
          "tag": "v0.6.26",
          "kind": "patch",
          "published_at": "2026-05-30T03:21:13Z"
        },
        {
          "tag": "v0.6.25",
          "kind": "patch",
          "published_at": "2026-05-30T02:02:01Z"
        },
        {
          "tag": "v0.6.24",
          "kind": "patch",
          "published_at": "2026-05-29T23:49:03Z"
        },
        {
          "tag": "v0.6.23",
          "kind": "patch",
          "published_at": "2026-05-29T19:12:32Z"
        },
        {
          "tag": "v0.6.22",
          "kind": "patch",
          "published_at": "2026-05-29T15:17:55Z"
        },
        {
          "tag": "v0.6.21",
          "kind": "patch",
          "published_at": "2026-05-29T14:17:35Z"
        },
        {
          "tag": "v0.6.20",
          "kind": "patch",
          "published_at": "2026-05-29T14:08:52Z"
        },
        {
          "tag": "v0.6.19",
          "kind": "patch",
          "published_at": "2026-05-29T13:50:04Z"
        },
        {
          "tag": "v0.6.18",
          "kind": "patch",
          "published_at": "2026-05-29T13:43:42Z"
        },
        {
          "tag": "v0.6.16",
          "kind": "patch",
          "published_at": "2026-05-29T12:59:59Z"
        },
        {
          "tag": "v0.6.15",
          "kind": "patch",
          "published_at": "2026-05-29T05:15:16Z"
        },
        {
          "tag": "v0.6.14",
          "kind": "patch",
          "published_at": "2026-05-29T04:58:37Z"
        },
        {
          "tag": "v0.6.13",
          "kind": "patch",
          "published_at": "2026-05-28T22:08:44Z"
        },
        {
          "tag": "v0.6.12",
          "kind": "patch",
          "published_at": "2026-05-28T17:13:08Z"
        },
        {
          "tag": "v0.6.11",
          "kind": "patch",
          "published_at": "2026-05-28T15:28:39Z"
        },
        {
          "tag": "v0.6.10",
          "kind": "patch",
          "published_at": "2026-05-28T14:01:50Z"
        },
        {
          "tag": "v0.6.8",
          "kind": "patch",
          "published_at": "2026-05-28T13:27:51Z"
        },
        {
          "tag": "v0.6.7",
          "kind": "patch",
          "published_at": "2026-05-28T03:05:03Z"
        },
        {
          "tag": "v0.6.6",
          "kind": "patch",
          "published_at": "2026-05-28T02:43:43Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-05-28T02:32:18Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-05-28T02:24:08Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-05-28T02:08:20Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-05-28T00:48:53Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-05-27T10:37:23Z"
        },
        {
          "tag": "v0.5.16",
          "kind": "patch",
          "published_at": "2026-05-26T21:32:05Z"
        },
        {
          "tag": "v0.5.15",
          "kind": "patch",
          "published_at": "2026-05-26T18:02:02Z"
        },
        {
          "tag": "v0.5.14",
          "kind": "patch",
          "published_at": "2026-05-26T17:42:04Z"
        },
        {
          "tag": "v0.5.13",
          "kind": "patch",
          "published_at": "2026-05-26T17:33:30Z"
        },
        {
          "tag": "v0.5.12",
          "kind": "patch",
          "published_at": "2026-05-26T16:04:07Z"
        },
        {
          "tag": "v0.5.11",
          "kind": "patch",
          "published_at": "2026-05-26T15:38:41Z"
        },
        {
          "tag": "v0.5.10",
          "kind": "patch",
          "published_at": "2026-05-18T22:37:17Z"
        },
        {
          "tag": "v0.5.9",
          "kind": "patch",
          "published_at": "2026-05-18T22:12:17Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-05-18T19:45:13Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-05-18T19:32:16Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-05-18T17:06:09Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-05-18T15:50:50Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-05-18T15:33:25Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-05-15T19:49:20Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-05-15T17:18:07Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-05-15T16:14:50Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-15T15:21:25Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-15T13:44:51Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-15T13:19:50Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-05-15T04:32:54Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-05-15T04:17:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "10ae1dc4c3708546ad49f0d416060cd2d1d40961",
          "body": "…notarize step + init installs both) (#238)\n\n## ZP3 — route the self-hosted GitHub Action through the notary\n\nLocal max mode already notarizes reviews (ZP2), but the self-hosted\nGitHub Action\nposted only a **self-attested** `clud-bug-review` check — so the\nun-forgeable notary\ntrust boundary never co\n[…]\n[Claude Code](https://claude.com/claude-code)\n\nhttps://claude.ai/code/session_01NnvyVPvKfy81AgcS6NFTku\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ZP3: self-hosted Action → notary (build-bundle + base-ref-guarded CI …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-17T13:23:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e95f7c07a6ef726ac1def77f5a7a303a0423dcd",
          "body": "## Summary\n\nPhase ZP2 (CEO decision): flips the local-max-mode notary from\nopt-**in**\n(only engaged when an operator manually set `CLUD_BUG_NOTARY_URL`) to\nopt-**out**, default-ON — a PR-trigger local review now certifies via\nthe\nhosted notary (`https://app.cludbug.dev`) unless the repo says\notherwi\n[…]\n[Claude Code](https://claude.com/claude-code)\n\nhttps://claude.ai/code/session_01NnvyVPvKfy81AgcS6NFTku\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ZP2: notary default-on (config resolver + deterministic §5) (#237)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-17T04:08:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8eadd244c9af62e97eb8a77cd9419debfcbbfe7a",
          "body": "Bumps clud-bug to **0.7.0-rc.24** to ship the Phase Z4 CLI\nchallenge/response handshake (#233) to installs — `post-check-run`\nfetches a single-use nonce from the notary before submitting. Opt-in\n(inert unless `CLUD_BUG_NOTARY_URL` is set). Version pin propagated to\nthe 3 workflow templates + `strict\n[…]\n0.7.0-rc.24` → OIDC publish to `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump to 0.7.0-rc.24 (ships the Z4 CLI notary handshake) (#234)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-17T01:29:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22b24be7aad7308b8f63e08b562659e087e45148",
          "body": "…#233)\n\nThe CLI half of the Z4 notary handshake. `post-check-run`'s\n`submitToNotary` now mints a single-use nonce (SPEC §10.3.3 ①\nreplay-closure) before submitting: `POST {repo, pr, head_sha}` →\n`/notarize/challenge` → echo `{nonce}` in the bundle → `POST /notarize`.\n\n**Adversarial-review fixes fold\n[…]\nbranch\n`feat-notary-z4`, separate PR).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase Z4 (CLI): challenge/response nonce handshake before /notarize (…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-16T21:43:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63ca77d381c0196fcb68d23f980dec3f63da7fb5",
          "body": "…20 runner (#231)\n\n**The v0.7.0-rc.23 publish failed** — not our code, a CI env drift. The\nworkflow runs `npm install -g npm@latest`, but `npm@latest` is now **npm\n12**, whose engine requires Node `>=22.22 / 24.15`. On the workflow's\n**Node 20** runner it `EBADENGINE`-fails *before* the publish step\n[…]\nn's fixed workflow — no re-tag needed.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci): pin npm-publish to npm@11 so OIDC publish works on the Node …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-11T19:01:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "feba3cbd35cf3e18a6bf375aa07cc4948bfb66ea",
          "body": "Bumps clud-bug to **0.7.0-rc.23** to publish the Phase Z3 notary\ncontract so `clud-bug-app` can import it for Z4 (the `/notarize`\nserver).\n\n**Publishes:** `NotaryBundle` / `buildBundle` / `parseBundle` /\n`notaryResponseIsRejection` (notary-bundle) + `validateBundle` /\n`validateCoverage` / `validateG\n[…]\n\nworkflow ships it to dist-tag `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump to 0.7.0-rc.23 (ships Phase Z3 — the CLI notary side) (#230)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-11T18:48:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd59efd3d974af3b909d3189868a88ebaf65d93e",
          "body": "…tation bundle + submit-bundle handshake (#229)\n\n## Phase Z3 — the clud-bug CLI notary side\n\nBuilds the CLI half of the **un-forgeable review notary** (protocol SPEC\n§10.3.3). clud-bug becomes a NOTARY that VALIDATES + CERTIFIES a review\nbefore a green `clud-bug-review` check can gate a merge — the \n[…]\nBundle` + `notaryResponseIsRejection`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase Z3: clud-bug CLI notary side — deterministic validators + attes…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-11T18:33:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fa5c627f75910217ba64a25adcdf9fb0506d5c9d",
          "body": "…itic bar) (#224)\n\n## What\n\nAdds `designing-elite-ui` to the CLI design-kit\n(`templates/skills/design/`) as a 4th bundled default `kind: design`\nskill, so the hosted design-critic measures rendered UIs against a\n**concrete elite bar** (one-axis color, APCA-gated contrast,\nfloating/stable chrome, dar\n[…]\ng-elite-ui` alongside the other three.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add designing-elite-ui as a 4th bundled kind: design skill (design-cr…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-04T04:36:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e97c1bd9b1f8bcb4b87d258e6a6104a76264d1e",
          "body": "…rity) (#223)\n\n## What\n\nMigrates `clud-bug configure-github` from the **retired classic\nbranch-protection API** to the **v2 rulesets API**, matching protocol\nSPEC v0.8.0 §7 + reporulez's `skdd` variant.\n\nBefore, the bundled `data/canonical-v1.json` +\n`src/core/configure-github.ts` applied out-of-spe\n[…]\n24 in the two\nconfigure-github files).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "configure-github: classic branch-protection → v2 rulesets (spec §7 pa…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-04T02:58:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5879fad94ec1c4ddd89083355174e8a03ed6b1cf",
          "body": "Bumps `package.json` 0.7.0-rc.21 → **0.7.0-rc.22**. Publishing this\nships the full Phase R review-hardening batch (R1–R7 + benchmark). After\nmerge, cut the release with a tag push (`v0.7.0-rc.22`) —\n`npm-publish.yml` builds/tests/publishes and auto-routes the `-rc`\nversion to the `next` dist-tag. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump to 0.7.0-rc.22 (ships the Phase R hardening batch) (#222)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T19:05:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "878525a1806c6cdde48a67225ecb32cb49f50627",
          "body": "…e, design-critic (#221)\n\nSurfaces the four Marketplace capabilities the homepage never showed, as\nadditive field-guide sections (hero + existing sections untouched;\nrenumbered §I–§X):\n- **§IV Weight of Evidence** — reproduction-as-grounding + the 3 bug\nclasses + the 20-scenario **100% recall / 100%\n[…]\n zero exclamations. Remaining Phase S: 5\nscreenshots (need the live bot) + tagline/category (yours). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase S: landing refresh — max-mode, hardened review, auto-fix/resolv…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T18:55:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "741741a72b3cc96947f1a92663c4fe3a137ab1f6",
          "body": "…ss) (#220)\n\nAdds the `/docs` subtree the Marketplace SUPPORT policy references. Five\npages in the field-guide `.doc` style, each grounded in the real modules\n(no invented options): the index + **skills** (SKILL.md, base-ref load,\nslugs), **config** (every `.clud-bug.json` option incl. the new\n`inva\n[…]\n0-scenario benchmark). Adds a\n`.doc-body pre` code-block style. Build green; all 5 routes prerender. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase S: /docs self-service pages (skills, config, auto-fix, multi-pa…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T18:43:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e10ad82d6cb2394f6329108be68f9dadbbd5f80",
          "body": "…sion (#219)\n\nFinalizes the launch-gate benchmark at **20 scenarios** (14\ntrue-positive across all 3 classes + 6 clean decoys). Scoreboard:\n**42/42 buggy caught (100% recall)**, all reproduction-grounded ·\n**18/18 clean correct (100% precision)**, zero false positives (60\nreviews). **Meets the seeded-benchmark launch criterion.** README +\nRESULTS updated. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R7: 20-scenario benchmark scoreboard — 100% recall + 100% preci…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T17:16:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e94ac1921470e9d5239dbe67c049d03627416a9",
          "body": "Unblocks 3 of the 5 hard Marketplace URL requirements. Ports\n`site/app/{privacy,terms,pricing}/page.tsx` fresh from the held A6a\nbranch (avoiding its stale 11-commit conflict debt) + the 137-line\n`.doc`/`.tier` CSS block. Fixes the pricing-link inconsistency: the\nlanding now points `pricing` at the \n[…]\nr.\nRemaining Phase S: landing-refresh\n(max-mode/design/auto-fix/auto-resolve) + /docs + screenshots. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase S: privacy/terms/pricing pages + pricing-link fix (#218)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T17:13:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0514941adf7eeb9413af1e50e91f1b3102b1663d",
          "body": "… nudge (#217)\n\nVoluntary support for the free tiers (max mode + self-hosted Action run\non the user's own resources — no metered charge fits):\n- **`.github/FUNDING.yml`** — `github: [thrillmade]` (the repo Sponsor\nbutton + a shareable URL). The Stripe 'coffee' link slots into `custom:`\nonce created.\n[…]\nHub Sponsors + create the Stripe Payment Link\n→ I uncomment `custom:`. init tests pass, `tsc` clean. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase M: monetize free tiers — FUNDING.yml (Sponsors) + on-voice init…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T17:06:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "940d38176cd392c19759abe5c95540484129353a",
          "body": "…ecision (#216)\n\nGrows the launch-gate benchmark 3→9 to test **generalization +\nprecision** (both Option B criteria):\n- **3 diverse true-positives** (b4 shared-mutable-state leak · b5\nhalf-open/inclusive boundary · b6 local-time `dayKey` in another module)\n— different mechanisms than the originals.\n\n[…]\n and reported no bug. The hardening\ngeneralizes **and** stays precise. / updated. No `src/` changes. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R7): expand benchmark to 9 scenarios — 100% recall + 100% pr…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T16:52:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6d72fb8b82f605b740cbaababb1ee7508d8ef28",
          "body": "…§3c probe-run step (#215)\n\nConnects R1 (the invariants config + `shouldRunProbes` gate) to the\nlocal recipe. When a repo declares `invariants` in `.clud-bug.json` and\nthis is a `pr` review, the recipe renders a **§3c \"Invariant probes\"**\nstep (mirrors the §3b design step): it lists each invariant a\n[…]\next: R6-action (the Action's sandboxed CI job — the execution\nsurface for untrusted/serverless PRs). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R6-local): wire .clud-bug.json invariants into the recipe's …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T16:34:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c625c4bfa27f50bf5a9bdd7283ee3caff530f0c0",
          "body": "…/9 catch) (#214)\n\nThe **Option B launch gate**: proves clud-bug catches the bugs that live\non no single changed line.\n\n**Harness** (`benchmark/`): 3 faithful, self-contained, reproducible\nplanted-bug scenarios — one per class, modeled on the real misses:\n- `s1-emergent-marker` (emergent, MAJOR ← lo\n[…]\nios + the 10-PR shadow streak before\nthe manual panel comes off. No `src/` changes; 914 tests green. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R7): seeded review-hardening benchmark + first scoreboard (9…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T16:08:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b9a0af80d41fb1c7e2028cb572a2d9f051392bb",
          "body": "…ng (no execution) (#213)\n\nExtends R2's grounding to the **hosted** bot (serverless — patch only,\nno shell). Rule 2 in both hosted system prompts now grounds a finding in\nfile+line OR a **named violated invariant** reasoned from the diff\n(emergent/combinatorial/cross-cutting), names the cross-packag\n[…]\nurface. 914\ngreen, `tsc` clean. Probe execution for this path is the Action's\nsandboxed CI job (R6). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R2-hosted): hosted grounding accepts named-invariant reasoni…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T15:45:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35c0cefb22d7a34cfcde40e061a85c6ee5b7c2e8",
          "body": "… unverified invariant change (#212)\n\nThird slice of review-hardening (**clud-bug-app #87**).\n\n**What:** adds `unverified` to `ReviewVerdict`\n(`src/core/check-verdict.ts`). `deriveCheck` maps it to a **neutral**\ncheck — never `success` (no false-green), never a hard block (no outage\non inability to \n[…]\n-run` → `neutral`. Note: the\nhosted app will add an `unverified` handler at the rc.22 lockstep bump.\n🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R3): the 'unverified' verdict — no false-green 'clean' on an…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T15:41:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "972d6a43a4fcd72735adcb128638b66512c52ca3",
          "body": "…o MAJOR watch-item (#211)\n\nSecond slice of the review-hardening (**clud-bug-app #87**).\n\n**What (local recipe `src/cli/review-prompt.ts`):** the grounding gate\nchanges from *\"quote the exact line or DROP\"* → **ground in a quoted\nline OR a reproduction (command + observed output) OR a named violated\n[…]\n**Tests:** grounding + severity assertions added; 913 green, `tsc`\nclean, recipe renders coherently. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R2): grounding = quote OR reproduction OR named invariant; n…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T15:09:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "feee1d426ce241be365a9265bf66c7e9aa47ddc1",
          "body": "… keystone) (#210)\n\nFirst slice of the review-hardening (**clud-bug-app #87** — retire the\nmanual adversarial panel).\n\n**What:** a new pure module `src/core/invariants.ts` (mirrors\n`design.ts`) that resolves an `.clud-bug.json` `invariants` block into\n`{ enabled, invariants[] }` and exposes `shouldR\n[…]\n probe).\n\n**Tests:** 11 new (`test/core/invariants.test.js`), full suite **913\ngreen**, `tsc` clean. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Phase R (R1): executable-probe invariants — config module + gate (#87…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-07-03T14:27:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e0aaf32bd3e227236be3f3d7b93469e8afcd93a",
          "body": "The last core-dup gap. `buildVerifierPrompt` gains `outputMode: 'json' |\n'structured'` (default json — CLI unchanged); `VERIFIER_SYSTEM`\nrefactored into a shared body + mode tail via\n`buildVerifierSystem(mode)`, with `VERIFIER_SYSTEM =\nbuildVerifierSystem('json')` for back-compat. Verified byte-iden\n[…]\ntep rc.21. **[CEO]** publish `v0.7.0-rc.21` → then\nclud-bug-app deletes its copies + imports core's. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.21 (C1): parameterize verifier prompt/system by outputMode (#207)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-30T00:18:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dacdef843bf8f8d9d88c433b21a43f5fbd232b9",
          "body": "Switches clud-bug's commit-review hook from an exact pin to floating\n`@next` (via `init --local-only` on rc.20). The hook now auto-fetches\nthe latest recipe every commit — delivering H1–H4 + future hardening\nwith no re-pin. Verified: hook pins `clud-bug@next`, zero Action\nworkflows. The last manual re-pin. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "re-pin: float the max-mode hook to @next (auto-update) (#206)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T22:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb646689bfc6fbd3347975efd2f03a80abb85333",
          "body": "…(#205)\n\nThe **effortless-update story**: (1) the max-mode hook floats to\n**`@next`** (auto-fetches the latest recipe — no per-release re-pin;\noverridable for a frozen pin); (2) an **update notifier**\n(brew/gh/vercel pattern — cached daily check, detached background\nrefresh, never blocks, TTY + non-\n[…]\nion. Lockstep rc.20; full suite green. **[CEO]**\npublish `v0.7.0-rc.20`, then I do the final re-pin. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.20: floating @next hook + update notifier + update local-only fix …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T21:47:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae5af78dd744bbf68339ba316f00c6af8cc12d6c",
          "body": "Release bump shipping the hardened max mode: **H1** adversarial recipe\ndepth, **H2** contextual review instructions + anti-injection fence,\n**H3** the `post-check-run` merge-gate + local self-attested check,\n**H4** hook retry + diagnostic marker. Lockstep version pins\n(package.json + 3 templates + strict-mode-gate action);\nrelease-discipline + full suite green. **[CEO]** publish `v0.7.0-rc.19`\nafter merge, then re-pin the 7 repos. 🤖",
          "is_bot": false,
          "headline": "rc.19: batch Phase H max-mode hardening (H1–H4) (#204)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T20:12:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd9c4aa3254750c2fce390538ba25afa45c479a2",
          "body": "…-review check (#203)\n\nLets a max-mode review **gate merge**. New shared\n`core/check-verdict.ts` (`deriveCheck`: clean→success,\ncritical+strict→failure/blocks, critical+non-strict→neutral,\nfailed→neutral) + a `clud-bug post-check-run` verb (posts the\n`clud-bug-review` check via `gh`; best-effort, `-\n[…]\null suite green. Action-path posting deferred (no\nproduction Action users post-F4). No version bump. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H3: merge-gate parity — post-check-run + local self-attested clud-bug…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T20:10:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4499e3c8648718a0dd09426ffa7b5e72deea1506",
          "body": "Two hook-robustness fixes: **retry once** (sleep 1 + re-fetch) on a\ntransient npx/network blip before giving up, and a\n**`.git/clud-bug-review-skipped` diagnostic marker** when the fetch\nultimately fails — so a failed review is distinguishable from a clean\none. Still exit-0 (never blocks the commit). New `sh -n`\nsyntax-validation test. No version bump. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H4: harden the commit hook (retry + diagnostic skip marker) (#202)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T19:51:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "419947a11b32d0e9268ff45c9dc005f1246b663a",
          "body": "…trusted per-PR) (#201)\n\nAdds a **contextual layer** on top of the static skills — the max-mode\ndifferentiator. Three trust tiers: **trusted** `.clud-bug.json`\n`reviewContext` (injected by the local recipe §2b *and* the hosted\nprompt-builder); the **local session-context edge** (the recipe folds in\n\n[…]\ned side passes the\nparams); spec-v0.6.4 (the config key + anti-injection contract). No\nversion bump. 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H2: contextual review instructions (trusted reviewContext + fenced un…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T19:42:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a93626d6b1f104809cbac05ea38a0c12b8407db",
          "body": "Makes clud-bug's own review (max mode) match a rigorous adversarial\nreview — the path to retiring ad-hoc adversarial passes. **Recipe text\nonly** (engine untouched; multi-pass was already wired).\n`src/cli/review-prompt.ts`: (1) cross-check pass is now **adversarial**\n— Wasp tries to **refute** pass-\n[…]\n. New test locks it\nfor single + multi pass; full suite green. No version bump (batches into\nrc.19). 🤖\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "H1: harden the max-mode review recipe to adversarial quality (#200)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T19:23:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e60f44d9d5c8090fe42562c99fc9570292521df2",
          "body": "…(#199)\n\nF4 rollout (clud-bug). `clud-bug init --local-only` adds the\n`/clud-bug-review` slash command + the `type: command` commit hook (max\nmode on the session subscription) — **no GitHub Action, no API key**.\nManifest unchanged except the version stamp; no skills dropped; zero\nworkflow files. 🤖 max-mode rollout\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "max mode: init --local-only (slash command + commit hook, no Action) …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T18:23:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9b4f3d2a7ca3bd78103858455d963e525c5f4c9",
          "body": "Adds `clud-bug init --local-only`: installs **max mode** (slash command\n+ the rc.17 commit hook) but **skips the GitHub Action workflows** that\nrun `claude-code-action` with `ANTHROPIC_API_KEY`. The F4 rollout\nprimitive — and a clean product command (clud-bug on your Claude\nsubscription, no key, no \n[…]\n** publish\n`v0.7.0-rc.18` after merge.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.18: init --local-only (max mode, no API-key Action) (#198)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T18:08:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ae06784b13afb2ae1405cd01d7e9d774136d2c5",
          "body": "…) (#197)\n\n## The bug (dogfooding caught it)\n\n`clud-bug init --with-hooks` has **never worked for anyone**. It\nscaffolds a Claude Code **`type: agent`** PostToolUse hook, but agent\nhooks get only Read/Grep/Glob — **no Bash, not configurable** (official\ndocs). So the review subagent could never run t\n[…]\ns`, commit,\nwatch the recipe surface).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.17: fix the broken max-mode commit hook (type:agent → type:command…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T17:33:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14778121c8115695f4c18bdd362dfc73cf2a4ad2",
          "body": "## What\n\nMakes the design-critic **installable in one command** and available on\nthe Action surface — completing \"everywhere.\"\n\n- **`clud-bug init --with-design`** — installs the 3 bundled `kind:\ndesign` skills (`templates/skills/design/*`) via a new bundled-only\n`loadDesignKit` (no network), and fl\n[…]\nprerelease-aware; `latest` untouched).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.16: clud-bug init --with-design + Action browser-MCP opt-in (#195)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T15:41:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df3bb81e03d702a2ead774a573313b8fb79fe4f1",
          "body": "…ep (#194)\n\n## What (rc.15 — local design-critic, the CEO's priority feature)\n\nSecond half of the design-critic lens. Builds on B1a (`kind: design` +\nthe design kit). **Off by default, cost-gated.**\n\n- **`core/design.ts`** — `readDesignConfig` (the `.clud-bug.json`\n`design` block; default `{ enabled\n[…]\nhe hosted Vercel-Sandbox render path).\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "design-critic B1b (rc.15): the design pass — config + gated recipe st…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T12:37:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6d962e817307187d3c57c265ef70382c5ff8cb03",
          "body": "## What (foundation for the design-critic, Track B)\n\nFirst half of the design-critic lens. **No version bump** — this is the\nskill-model + content foundation; the pass/config/recipe/installer land\nin B1b (rc.15).\n\n- **`kind: design`** — adds `design` as a third `SkillKind` alongside\n`rule`/`voice` (\n[…]\narse as `kind=design, mode=dedicated`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "design-critic B1a: kind:design skill lens + design baseline kit (#193)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T12:14:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0a5716565cf6be88f672888efb3be00f8c50c4bc",
          "body": "…(#192)\n\n## What\n\nThe marketing landing page had drifted from the shipped product.\nTargeted accuracy fixes (no redesign):\n\n- **\"Pro tier\" → \"Team tier\"** (×2 in `page.tsx`, + the OpenGraph\ndescription in `layout.tsx`). There is no Pro tier — tiers are Trial /\nSolo / Team, and multi-pass is a **Team*\n[…]\nated → none). Vercel preview\ncheck will render it. (When the design-critic lands, I'll run it against\nthis page's preview per the plan.)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "site: reconcile landing copy to shipped pricing + multi-pass reality …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T03:57:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd84e093d51812ec8a90fb34631668f690edd0c3",
          "body": "… prose (#191)\n\n## What (rc.14 — the \"6c\" cut)\n\nShips the conditional **Mantis arbiter** as a pure decision in `core`,\nso the hosted bot and the local recipe share one rule (SPEC §11.5).\n\n- **`shouldEscalate(...)`** (`src/core/multi-pass-aggregate.ts`,\nexported from `core`) — pure gate, true only wh\n[…]\nwiring, which\nbumps the dep to rc.14.)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.14 (6c): conditional Mantis arbiter — pure shouldEscalate + recipe…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T03:48:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a10a1727656dd538899bfd0b1cd72fad13d07889",
          "body": "## What\n\nclud-bug's own `.claude/skills/.clud-bug.json` had `installed: []` while\nthe baseline skill dirs sat on disk, so the dogfood commit-review hook\n(`review-prompt --trigger commit`) resolved **0 skill files**. This\npopulates `installed[]` with the 4 baseline skills, matching what\n`clud-bug ini\n[…]\npackage.json#files`); no\nversion bump.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Dogfood: populate clud-bug's own skill manifest (4 baseline) (#190)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-29T03:24:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fabe40b6c199839cf8ad4b3e0d6925fe9345096d",
          "body": "…ersion (#189)\n\nrenderMultiPassMarkdown emits the NORMATIVE pass + consensus markers; init --with-hooks pins npx clud-bug@<version>. Adversarial review clean. 843 tests green.",
          "is_bot": false,
          "headline": "rc.13: render SPEC §6.8.1/§6.10.1 markers + pin the hook's clud-bug v…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T22:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89b0b4fb038bc05dc1d55a0f864daf0a0ed3fc60",
          "body": "Scaffolds a native Claude Code type:agent commit-review hook (backgrounded, session-subscription, prompt runs review-prompt + follows it). Review caught + fixed clobbering malformed settings.json + dropping co-located user hooks. 841 tests green.",
          "is_bot": false,
          "headline": "Wave 6b: clud-bug init --with-hooks — native commit-review hook (#188)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T20:41:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9d482b4495ba8874fdd5851389201ff1556b9bd",
          "body": "review-prompt emits the plan-aware local-review recipe (commit → fast single pass; push/pr → multi-pass fan-out) via planReview. 2-lens review caught + fixed 6 issues (rawSkillMd dead override, origin/HEAD empty-diff, cross-check coherence, summary, trigger typo, mode). 831 tests green.",
          "is_bot": false,
          "headline": "Wave 6b: clud-bug review-prompt — plan-aware local-review recipe (#187)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T20:24:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccde109bcd371428cc6d5d2f4934a2d0737937d6",
          "body": "core/plan-review.ts composes resolveReviewPasses + estimateBudget into the single planning entry point every consumer shares; trigger/diff tiering. Review caught + fixed an off-by-one + a tiered-cost overestimate. 825 tests green.",
          "is_bot": false,
          "headline": "Wave 6b: planReview — shared review-plan entry point (SPEC §11.5) (#186)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T19:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d567f95f3100de3604cbef5385a96227498c2af",
          "body": "…185)\n\nShared review engine (review-plan / budget-plan / multi-pass-aggregate) extracted from clud-bug-app/lib into clud-bug/core, behavior-identical (77 App tests ported). Adversarial review caught + fixed a consensus type-erasure regression (now rides core's canonical UnifiedFinding). 816 tests green.",
          "is_bot": false,
          "headline": "Wave 6b PR 0: extract the review engine into clud-bug/core (rc.12) (#…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T18:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a153d84b6b4d36fd96614cdbac65c98f7a8bd88",
          "body": "… (#184)\n\n## Wave 6b — local review mode (slash-command MVP) (rc.11)\n\nThe CEO's highest-priority pre-launch feature, in its first shippable\nform: **local review\nruns inside a Claude Code session using that session's own tokens** — no\nhosted App, no new\nauth.\n\n### What ships\n- **`clud-bug init --with\n[…]\n `v0.7.0-rc.11` → publishes to `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Wave 6b: local-review slash command MVP (--with-local-review) (rc.11)…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T05:56:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd0922645842c0c26d706cabff5d3c5008163961",
          "body": "…load (rc.10) (#183)\n\n## Wave 6a — SPEC v0.5.1 conformance closure (rc.10)\n\nCloses two NORMATIVE gaps from the v0.5.1 audit.\n\n### §6.6 conformance-fixture gate (NORMATIVE release-gate)\n- New `fixtures/reviews/<scenario>/{input.json, expected.md}` for 5\ncanonical scenarios: **clean, critical-only, mi\n[…]\n `v0.7.0-rc.10` → publishes to `next`.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Wave 6a: §6.6 conformance-fixture gate + §3.23.1 configure-github pay…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T05:14:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e42bbd9c8a2a5908a32dcbabf05bd2c779aa98c3",
          "body": "… (#182)\n\n## Wave 5b.1 — rc.9 graceful PAT-or-fallback resolve\n\nWave 5b smoke surfaced that the GraphQL `resolveReviewThread` mutation\nfails with\n`Resource not accessible by integration` under the Actions\n`GITHUB_TOKEN` — a known\nGitHub limitation, not a code bug. This makes auto-resolve\n**PAT-optio\n[…]\nr the\nPAT-path + cached-resolve smoke.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Wave 5b.1: rc.9 graceful PAT-or-fallback resolve + idempotent markers…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T04:43:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dc350085ee91ec0c779a01b24e65956dad415add",
          "body": "## Summary\n\nOSS parity push, part 2 of 2 (builds on Wave 5a rc.7 inline threads). On\nfix-push events, the workflow asks the Anthropic Messages API per\nbot-authored unresolved inline thread whether the new commit addressed\nthe original finding. ADDRESSED threads get auto-resolved (with a marker\nreply\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wave 5b: D.2.6 auto-resolve on fix-push (clud-bug rc.8) (#181)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-28T02:42:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c649b191fc7370aec083a5421e8d89513416a15",
          "body": "…7) (#180)\n\n## Summary\n\nOSS parity push, part 1 of 2. Brings per-finding inline review threads\n(D.2.X) from the hosted clud-bug-app to the npm `clud-bug` workflow\ntemplate path so self-hosted users get first-class GitHub review threads\nanchored to file+line, instead of one bundled summary comment li\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Wave 5a: D.2.X per-finding inline review threads in npm workflow (rc.…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-27T21:45:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8eed01f2fa813819015ffdceafe6e2089aa3242c",
          "body": "## Summary\n\nImplements the consumer-side surface for SPEC v0.5.1 §1.10.1's new\n`applies_to.author` field. Extends `SkillFrontmatter` +\n`parseFrontmatter` to surface `kind` + `voice_scope` +\n`applies_to.author` (the Wave 4d reviewer-flagged silent-drops are now\nfirst-class). Adds new `appliesToAuthor\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "rc.6: applies_to.author filter (Wave 4e.2, SPEC v0.5.1 consumer) (#179)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-27T20:23:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd816c5e673153c568895f6e84a547b736bfbc15",
          "body": "…] (#178)\n\nSlots in the held dependabot bump (#162) as a CTO-curated migration PR.\nPer CEO direction (\\\"is bump typescript in clud bug in our plan? seems\nlike that dependabot PR is key\\\"), TS6 should be in the plan.\n\n## What\n\nBumps `typescript` devDep from `^5.5.0` to `^6.0.3` and applies two\nminor \n[…]\nloat the rc.5\nrelease PR's scope.\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ts): migrate to TypeScript 6 — ignoreDeprecations + types:[node…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-26T05:11:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f51e8c2c5a1e02c4b31c64b1e5913086cc6ab1df",
          "body": "…ookup (#177)\n\nCloses task #234.\n\n## What\n\nReplaces the module-load `readFileSync(package.json)` in\n`src/core/render.ts` with an import from generated\n`src/core/version.ts`. The version is baked by `scripts/gen-version.mjs`\nat every build (`prebuild` hook) and every test run (`pretest` hook).\n\n`src/\n[…]\name flow as rc.1/rc.2/rc.3/rc.4.)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): rc.5 — bake PKG_VERSION at build, remove runtime fs l…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-26T05:08:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "40907445e75319ab0359a1f588663db2abc9c7d1",
          "body": "…0.0 (#173)\n\nBumps\n[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)\nfrom 22.19.20 to 26.0.0.\n<details>\n<summary>Commits</summary>\n<ul>\n<li>See full diff in <a\nhref=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\">compare\nview</a></li>\n[…]\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: thrillmot <devintwilmot@gmail.com>",
          "is_bot": true,
          "headline": "[skip-logmind] chore(deps-dev): bump @types/node from 22.19.20 to 26.…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T03:12:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8267b3259f04f3ea6ce4334102f0488896345a4",
          "body": "Bumps\n[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)\nfrom 2.1.9 to 4.1.9.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/vitest-dev/vitest/releases\">vitest's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v4.1.9</h2>\n<h3>🐞 Bug Fixes</h3>\n[…]\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: thrillmot <devintwilmot@gmail.com>",
          "is_bot": true,
          "headline": "[skip-logmind] chore(deps-dev): bump vitest from 2.1.9 to 4.1.9 (#167)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T03:12:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d8da9a426a779ca227ba47ec704541a02138d39a",
          "body": "… test (#175)\n\nBundles two independent CI fixes that are both required to unblock main.\nPer CTO direction on this PR specifically: the locked \"workflow files in\ntheir own PR\" rule's rationale (Anthropic action validation 401 on\n`clud-bug-review.yml`) doesn't apply on clud-bug — that workflow was\ndel\n[…]\nst 2→4), #173\n(@types/node 22→26)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci): unblock main — drop stale workflow refs + fix time-dependent…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-26T02:47:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "36045c93bb7d7e1446823a4cf014fbf73886467d",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to\n7.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/checkout/releases\">actions/checkout's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v7.0.0</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>blo\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6 to 7 (#172)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T02:27:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb72798aa360f89544a78f6bad68bf9a7dcc1871",
          "body": "… updates (#174)\n\nBumps the minor-and-patch group with 4 updates in the /site directory:\n[next](https://github.com/vercel/next.js),\n[react](https://github.com/facebook/react/tree/HEAD/packages/react),\n[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react)\nand\n[react\n[…]\n of the specified dependency and ignore\nconditions\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the minor-and-patch group across 1 directory with 4…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T02:27:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "673499372469d16a8d17e95c50af14eb39759cc8",
          "body": "Closes the rc.4 publish warning. npm internally normalizes string-form\nbin to object-form during publish; bringing source in line so future\npublishes go through clean. No behavior change.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(package): bin field — string → object shape (#171)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T18:17:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "371ce029e9c889c7aa456e87d9cca007b5856540",
          "body": "… — stop API-key bleed (#170)\n\n## Summary\n\nStops the Anthropic API-key bleed on this repo. Tonight's 4-PR overnight\nwave fired both workflows on every push, generating real billing on the\nuser's direct ANTHROPIC_API_KEY.\n\n**`clud-bug-review.yml`** — npm workflow Action PR review. Phase 5.3\npaused th\n[…]\ncord established. Removed.\n\nWhen App reviews re-enable on this repo (Phase 5.3 exit criteria),\nhosted bot is the sole review path.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(workflows): remove clud-bug-review.yml + claude-code-review.yml…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T15:19:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0be28e7eba1821f688bf2119a817c8400cd968b6",
          "body": "…ded for review (#169)\n\n## Summary\n\nCEO observation tonight after the cludbug.dev rewrite (PR #165 +\nbrand-power follow-up): the brand voice exists in code but isn't encoded\nas a reviewable skill, so future copy changes can drift without signal.\nCloses that gap.\n\n**Local to clud-bug only** — not pus\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(skill): clud-bug-brand-voice — naturalist field-guide voice enco…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T15:05:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ba94ea769e85ca832b73bdec9c00769412015c2",
          "body": "…ng (#166)\n\n## Summary\n\nThree SPEC-aligned core enhancements bundled for the v0.7.0 Marketplace\nprep ship train. All three land in `src/core/` so clud-bug-app's Phase 4\nre-import lands them in one wave.\n\n- **Wave A — `clud-bug configure-github <owner>/<repo>`** (Phase 6 task\n#227). Pure diff + idemp\n[…]\n](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rc.4): configure-github + cache comment + resolved findings nami…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T14:59:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5a28ce88de2c261a813d723314d9b72941ad1579",
          "body": "## Summary\n\nApp-first marketing rewrite for cludbug.dev. The clud-bug GitHub App\nwent live earlier today (Phase 5 BOT_MAINTENANCE_MODE flipped false), so\nthe marketing site now leads with the App install CTA. The npm workflow\npath stays as a demoted **§VI — Self-hosted alternative**.\n\n## Messaging s\n[…]\n runtime — pre-existing\nbehavior, unchanged by this PR)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(site): App-first marketing rewrite (G6.c) (#165)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-17T14:57:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bf0927a634553e39d5c0153dc7120f472336cc2f",
          "body": "…upport) (#164)\n\nBumps the reusable workflow pin to pick up the change from PR #3 on\n`thrillmade/.github` (drops the major-bump early-stop step). After\nmerge, major dependabot bumps in this repo will auto-merge on CI pass\nlike patch/minor already do.\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: bump dependabot-auto-merge caller pin to 6e1f9df (major-bump s…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-10T15:25:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f43636ff640ac93bd38909b88bee96ee08c1122b",
          "body": "… A) (#163)\n\n## Summary\n\nPhase 7 PR A closes 5 SPEC v0.2.0 conformance gaps in clud-bug core and\nships the workflow-path bridge for formal APPROVE reviews. After this\nlands, clud-bug-app's Phase 7 PR B will consume via dep bump + small\nwiring; the npm workflow path inherits via the new template post\n[…]\normal-review,\nwire author_association.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: v0.7.0-rc.3 — SPEC §1.8.1 + §7.2.1 + §6.7.3 closure (Phase 7 PR…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-10T15:17:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4521938fa4f34f5f2d0dc581eec8b2feb6b8778",
          "body": "…lock) (#158)\n\n## Summary\n\nPhase 4 of the Bug 9 migration (clud-bug-app deletes ~6,500 LOC of\nduplicate code by importing from `clud-bug/core`) needed App-shape\nexports that rc.1 didn't ship. This adds them ADDITIVELY — the CLI-shape\nexports stay first-class.\n\n**Net LOC added to core: +1212 LOC acro\n[…]\now/clud-bug && npm publish --tag next`\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: v0.7.0-rc.2 — add AI-Gateway-shape exports to core (Phase 4 unb…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-09T21:36:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9a067b722505432312bd9abae3233fa43e29e81",
          "body": "…ourcemap fix) (#157)\n\n## Summary\n\nThree coordinated changes that all hinge on the v0.6.35 → v0.7.0-rc.1\nversion bump.\n\n## Changes\n\n### 1. Version bump\n- `package.json` `0.6.35` → `0.7.0-rc.1`\n- All 3 workflow templates' `strict-mode-gate@v0.6.35` → `@v0.7.0-rc.1`\n- `action.yml` header docstring exa\n[…]\ninstalls via `pnpm add clud-bug@next`)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: v0.7.0-rc.1 release prep (version bump + classifier vendor + s…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-09T20:17:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "28ee7a1ccae1af24d1c5abc84799b54d2dbe2178",
          "body": "…ug 9 Phase 2) (#156)\n\n## Summary\n\n**Phase 2 of the Bug 9 mission** (plan §\"Bug 9 mission plan\"). Migrates\nthe entire `lib/*.js` codebase to TypeScript and restructures into\n`src/core/` (pure library) + `src/cli/` (init/update/audit commands),\nexposed via subpath export so consumers can `import { ..\n[…]\nv0.7.0-rc.1`, `npm publish --tag next`\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: v0.7.0 — TypeScript migration + clud-bug/core subpath export (B…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-08T22:48:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0af5ec65b03741e602570168bd247cbaa1822dc8",
          "body": "## The bug\n\n\\`MAX_DIFF_BYTES: '80000'\\` (80KB) at\n\\`templates/workflow.yml.tmpl:404\\` was silently capping diffs via\n\\`head -c\\` before sending to Claude. Real-world PRs over 80KB got\nhalf-reviews — Claude only ever saw the first 80KB of the diff.\n\nThis was the original-author intent (cap input cost\n[…]\nff should NEVER be a blocker or guard\"\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.35: never block on large diffs (MAX_DIFF_BYTES 80K → 5MB) (#153)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-08T19:40:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "09710ab50a07382c4f7b154875dbd5b2ca8bf2ef",
          "body": "Small standalone PR so it can land FIRST, then review all subsequent PRs\n(including PR #153 — the v0.6.35 MAX_DIFF_BYTES fix).\n\n## Why\n- npm clud-bug never had \\`clud-bug-review.yml\\` installed in its own\nrepo. Only \\`claude-code-review.yml\\` ran (stock Claude action, no\nskills, no clud-bug specific\n[…]\nl so its broken state\ncan't interfere.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: dogfood clud-bug on itself (install own review workflow) (#154)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-08T19:34:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7726bcbabb2dddbfb2464b29a8dd2c4423dc9ee",
          "body": "….0 (#152)\n\nFixes CI on all workflows. Migration sweep yesterday hardcoded @v1.0.1\nwhich doesn't exist; only v1.0.0 shipped. One-line fix in 3 workflows.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] fix(setup-logmind): correct broken @v1.0.1 pin → @v1.0…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-07T19:10:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "905d300739eb044b64033105fc3a0bc96dc45fb3",
          "body": "…nfig (#150)\n\n## Summary\n\nMigrates this repo to the v1.1.0 distribution-lock pattern (per master\nplan §Architectural Decisions 2026-06-05).\n\n- Replaces the curl-install block in `check-doc-links.yml` +\n`regen-timeline.yml` with `uses: thrillmade/setup-logmind@v1.0.1`\n(immutable pin).\n- Rewrites `log\n[…]\navored migration commit — no decision file\nrequired.\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: clud-bug[bot] <0+clud-bug[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: migrate to setup-logmind action + Dependabot co…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-06T00:05:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c1e806efe36f9408abcff141b044be1a592549e",
          "body": "…xclude docs/reviews/) (#149)\n\n## Summary\n\nBumps the logmind install pin in `.github/workflows/check-doc-links.yml`\nfrom `v1.0.0` → `v1.0.1` so this repo's CI picks up the orphan-markdown\nfix shipped in [logmind PR\n#145](https://github.com/thrillmade/logmind/pull/145).\n\n## Why\n\nlogmind v1.0.1 (shipp\n[…]\nd with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: clud-bug[bot] <0+clud-bug[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: bump logmind pin v1.0.0 → v1.0.1 (check-links e…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-05T20:16:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d341e990022a8a8e2da25e950051efaec84add63",
          "body": "…Hub App (G3.b) (#147)\n\n## Summary\n\nMigrate this repo's automated PR reviews from the per-repo\n`clud-bug-review.yml` workflow to the `clud-bug[bot]` GitHub App\n(installed at org scope across all `thrillmade/*` repos). This is\n**dogfooding**: the App lives in `thrillmade/clud-bug-app` but its\nreview \n[…]\nstream consumer repos that haven't\ninstalled the App.\n\nGenerated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: clud-bug[bot] <0+clud-bug[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: migrate PR review from workflow to clud-bug Git…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-05T19:01:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7b424ab6e75be805a8b6fc4c9f6f8c4955ae0053",
          "body": "…) (#144)\n\n## Summary\n\n- Adds a tiny caller workflow that delegates Dependabot patch + minor\nauto-merge to the reusable workflow at `thrillmade/.github`.\n- Major bumps are still surfaced for human review.\n\n## Why\n\nPath A from org master plan §8.1 — near-term unblock for org-wide\ndependency hygiene. \n[…]\n next Dependabot patch/minor PR get auto-approved and\nmerged.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: add dependabot auto-merge caller workflow (§8.1…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-04T15:37:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "54c1b2125386122df17be9ebbbae8e62f9287f4a",
          "body": "…nary (#143)\n\n## Summary\n\nMigrate this repo's three logmind-shipped CI workflows off `pip install\n\"logmind==0.6.14\"` (the now-frozen Python wheel) and onto the v1.0 Go\nbinary released at\nhttps://github.com/thrillmade/logmind/releases/tag/v1.0.0. All workflows\nnow bootstrap via `curl -fsSL https://lo\n[…]\nreview on this PR. The clud-bug workflow itself is\nuntouched.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] chore: cut over from pip install logmind to v1.0 Go bi…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-03T18:07:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "682955587aa4fa4c17a2116b729b1b980d538bc2",
          "body": "Follow-up to PR #140. Bump canonical workflow's strict-mode-gate pin\nfrom @v0.6.33 → @v0.6.34 now that the v0.6.34 tag exists.\n\nMatches historical pattern (#93, #115, #119, #126, #128, #130, #132):\nself-propagation always happens in a separate PR after the release tag\nexists, so CI can resolve the a\n[…]\nhrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.34 (#142)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T18:19:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8dc2588411ad13d143e88b34a5ed33f2ee939e5a",
          "body": "…mics Concern 2) (#140)\n\nFix from tokenomics agent's v0.6.14 verification report. Transient\nAnthropic API errors (`Claude encountered an error after 1m 45s`) now\nemit a `neutral` check-run instead of `failure` — PRs no longer get\nblocked when the tool fails without producing content findings.\n\n## Su\n[…]\ne Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.34: clud-bug-review emits neutral on transient AI errors (tokeno…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T18:14:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90db8bb6ebb53d0a87831cf6facd22f80cc0da5b",
          "body": "Automated upgrade from logmind 0.6.13 → 0.6.14.\n\nRefresh mode (v0.2.1+) only touched workflow templates whose `#\nlogmind-template-version:` marker is stale; `docs/`,\n`.logmind/config.yml`, and agent files were left alone.\n\nReview the diff. To stop self-updates after this, add `pinVersion:\n\"0.6.14\"` to `.logmind/config.yml` before merging.\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] logmind self-update: 0.6.13 → 0.6.14 (#139)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T04:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6316fa3e583648826b81cb91f9e6e9004168e7e2",
          "body": "Automated propagation of logmind v0.6.13. PR opened manually because the\nconsumer-repo's current v5 self-update template uses GITHUB_TOKEN for\n`gh pr create` and hit the \"Allow Actions to create PRs\" per-repo gate.\nThe v6 template included in this PR uses the PAT for `gh pr create` too\n— fixes v0.6.14+ propagation.\n\nGenerated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] logmind self-update: 0.6.12 → 0.6.13 (#138)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T02:45:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "427983dd29c3854c5ef28a6ac3c0f602d18a1e7d",
          "body": "Automated upgrade from logmind 0.6.11 → 0.6.12.\n\nPR-creation step in the self-update workflow failed because GitHub\nActions is not permitted to create PRs in this repo. Branch was already\npushed via the PAT; this PR is manually created for it. Adding the PAT\nto the gh pr create step is queued as a v0.6.13 candidate in the plan.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "logmind self-update: 0.6.11 → 0.6.12 (#137)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-02T01:39:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "60d22ad9d4dba69591bc085ab7a4b8e136eb3e9c",
          "body": "Bootstrap fix for v0.6.11 propagation cycle: refreshes\n\\`logmind-self-update.yml\\` to v5 template (PAT-based push for workflow\nrefreshes). The initial v0.6.11 propagation used \\`logmind agents update\n--apply\\` which only does pin bumps; the v5 template change came in via\na marker bump that requires \n[…]\ne Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>\nCo-authored-by: logmind-auto-regen[bot] <logmind-auto-regen@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: refresh logmind-self-update.yml to v5 (PAT bootstrap) (#136)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T23:30:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a760c3fb3f6d603e01a0e46bfefdb9f57df4da53",
          "body": "Workflow pins v0.6.9 → v0.6.11. Manually propagated.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: refresh logmind v0.6.9 → v0.6.11 (#135)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T23:24:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "134db994580376367d667da9d76f21ea554cf010",
          "body": "Workflow pins from v0.5.13 → v0.6.9. Picks up v0.6.9 `logmind\nfile-structure --check`, v0.6.8 `--with-skdd`, v0.6.7 post-merge\nunstaged fix.\n\nOrg self-update workflow failed at push step (GITHUB_TOKEN lacks\n`workflows: write`). Manually propagated via local logmind v0.6.9 + PAT.\nCaptured as v0.6.10 candidate.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: refresh logmind v0.5.13 → v0.6.9 (#134)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T21:19:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a07f0b2ac60b00e50b72469c71674bd2bc6ca5ef",
          "body": "…mirror) (#133)\n\n## Summary\n\nSymmetric mirror of logmind v0.6.8's `--with-skdd` flag. Node-first\nusers get the same one-command bootstrap as Python-first users:\n\n```bash\nnpx clud-bug init --with-skdd   # clud-bug + logmind, one command\n```\n\nWhichever ecosystem the user starts in, the flag pulls in t\n[…]\nx] Graceful no-Python warning path verified via spawnSync with\nscrubbed PATH\n- [ ] Self-review on this PR via clud-bug-review\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.33: clud-bug init --with-skdd flag (unified install, Node entry …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T18:12:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7cb38487ec742973bf404e66ae6dd530dd0eede",
          "body": "Self-propagation of v0.6.32.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.32 (#132)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T14:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8140fdc54c0027e01dc8745ee836d2b4037f3390",
          "body": "…(#131)\n\n## Summary\n\nLocks in the v0.6.31 hotfix (`include-hidden-files: true`) with a\nrelease-discipline assertion that fails CI if the flag is ever removed\nfrom any workflow template. Also drops the now-stale \"v0.6.30 will add\"\nframing from the dashboard placeholder.\n\n## Why\n\nv0.6.31's fix is a si\n[…]\n1 new release-discipline\nassertion)\n- [x] Smoke-test verified guard fails on regression\n- [ ] Self-review on this PR via clud-bug-review\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.32: release-discipline guard for v0.6.31 + stale dashboard text …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T14:15:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fe56e94a2905c8d7ecb22e2cc15ec85e35f89d1",
          "body": "Self-propagation of v0.6.31 hotfix.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.31 (hotfix) (#130)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T12:45:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7776acf2019f6a127f04c7bb083c6ca988333d3",
          "body": "…ilent breakage) (#129)\n\n## Summary\n\n**Critical hotfix.** v0.6.29's `Upload skill-usage artifact` step has\nbeen silently dropping every artifact across the entire org since\n2026-05-31.\n\n## Root cause\n\n`actions/upload-artifact@v4` excludes hidden files by default.\n`.claude/` (directory) and `.clud-bu\n[…]\n + a step that warns-but-succeeds is a\nsilent-failure pattern. Consider a smoke-test in v0.6.32+ that asserts\nnon-empty artifact upload.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.31: hotfix — upload-artifact excludes hidden files (v0.6.29-30 s…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T12:43:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd17eadff541c05a92ba41850c0a92239373ac93",
          "body": "Self-propagation — clud-bug eats its own templates at pin @v0.6.30.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.30 (cross-review aggregation) (#128)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T04:05:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2690affd67d28b50070886c6779b6450d52d9f9e",
          "body": "…oard (#127)\n\n## Summary\n\nCloses the SkDD usage loop. v0.6.29 wired up per-PR artifact uploads,\nbut the v0.6.28 dashboard still read only the local `.clud-bug.json`\n(always empty unless someone ran `update-skill-usage` locally). v0.6.30\nmakes `clud-bug usage --health` walk workflow artifacts + merge\n[…]\nagainst the v0.6.29 propagation cycle's\naccumulated artifacts → expect real `loads` + `citations` data instead\nof placeholder\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.30: cross-review aggregation reads workflow artifacts into dashb…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-06-01T04:02:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "403418eab6c5d19bf6f1ec32e4d96d5dba26d330",
          "body": "Clud-bug eats its own templates — own clud-bug-review workflow now\nwrites skill-usage deltas + uploads artifact like the consumers do.\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: self-propagate v0.6.29 (skill-usage workflow integration) (#126)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-31T18:23:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbdd97f763864eeec0d723b0616af009e90cdc19",
          "body": "…e (#125)\n\n## Summary\n\n- New CLI subcommand `clud-bug update-skill-usage --stdin` — reads\nstructured-output JSON, computes per-skill delta, merges into\n`.claude/skills/.clud-bug.json` (atomic temp+rename).\n- Two new post-steps in all 3 workflow templates (workflow.yml.tmpl,\nworkflow-ts, workflow-py)\n[…]\nreview) emits a skill-usage\nartifact\n- [ ] Propagation cycle: consumer PRs after merge pull the new templates\n+ write to their workspace\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "v0.6.29: Component 4 — workflow integration auto-populates skill usag…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-31T18:01:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bfe47299899e0cdaa123b45d768249e17bc78782",
          "body": "… usage --health (#124)\n\n**Components 1+2 of the pragmatic SkDD pivot** (2026-05-30). Replaces\nspeculative recursive-meta-skill direction with deterministic usage\ntracking + human-gated approval.\n\n## What ships\n\n### `lib/skill-usage.js` — pure data layer\n- `computeSkillUsageDelta(reviewJson)` — extr\n[…]\nmoted from v0.6.28 per the pivot)\n- L4 permission-to-continue\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "[skip-logmind] feat(v0.6.28): skill-usage tracking library + clud-bug…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T23:28:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "074d7e51740684e335ee9a9ca51accd4b38e6b59",
          "body": "…4a) (#122)\n\nStream 4a from the token-cost-compression plan. Surface the two recent\nwins on cludbug.dev in field-guide voice.\n\n## What's added\n\n### §IV — Field Economy\n> _\"Even the largest specimens get a full examination.\"_\n\nSmart review budget tailored to PR diff size:\n- Tiny PR → ~5 turns\n- Large\n[…]\nble.\n- [ ] User async-review approves messaging before merge.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "site: §IV Field Economy + §V Habitat Expansion + version pin (Stream …",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T17:56:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b4b1765aa8a867f4f8da4cd7635beb2ce350d315",
          "body": "Stream 5 cleanup. Adds identical 'Part of the thrillmade SkDD toolchain'\nfooter to clud-bug README.md. Parallel commits land on logmind +\nagent-skills.\n\nFooter:\n- Names SkDD (Zak Elfassi's methodology, links his blog)\n- Lists the 4 thrillmade toolchain parts\n- Captures the end-to-end auto-dev loop\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: SkDD toolchain footer for clud-bug README (#123)",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T17:46:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "78166ef843f8b288f885fd13bc55b9c27ec4a5e8",
          "body": "…n (#121)\n\n## Summary\n\nPrompt-only addition: the AI must emit a single-line `[budget]`\nheartbeat every 5 tool_uses showing files_reviewed/total,\nturns_used/max, and ok/behind pace. When behind, pivot to one-sentence\nverdicts so every file in the diff gets reviewed before budget runs out\n— silent ski\n[…]\nd as `clud-bug update` output and auto-skips clud-bug-review.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(v0.6.27): Smart Budget Phase 3 — Layer 3 mid-review self-check-i…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T04:48:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "026b8445f5b1fb48714a940b401d01b2827aabc8",
          "body": "…k render-from-inlines (#120)\n\n## Summary\n\nTwo adjacent fixes that ship together. **L5 auto-retry deferred to\nv0.6.27** because it restructures the workflow's job-dependency graph\n(separate concern, bigger surface area).\n\n### 0.0.W² — widen workflow-only-skip allowlist (paths-check)\n\nEvery prior `cl\n[…]\n fires). FIRST\npropagation cycle requiring zero admin-bypass.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(v0.6.26): Smart Budget Phase 2a — 0.0.W² widen skip + L6 fallbac…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T03:21:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "168143b16e60a61a0d166e8fd951c8481597d33f",
          "body": "…) (#119)\n\nRe-renders clud-bug's own workflow against v0.6.25 templates. Without\nthis, clud-bug-review runs on clud-bug PRs with the legacy\nv0.6.22-rendered `--max-turns=15` hardcode, defeating the smart budget\non the repo that SHIPS it.\n\nPR #118 (v0.6.25 itself) hit exactly that — paths-check compu\n[…]\nd), this will be the LAST admin-bypass needed on\nclud-bug self-upgrades.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: clud-bug self-upgrade to v0.6.25 (dogfood Smart Budget Phase 1…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T02:33:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac190404bdfa8aa92dc8226ea4d63f502476c582",
          "body": "…leanups (#118)\n\n## Summary\n\nShips **Phase 1 of the 7-layer Smart Budget System** (full architecture\nin plan §5.5; remaining layers in v0.6.26 / v0.6.27 / v0.6.28 / v0.7.0).\nMotivated by tokenomics PR #21 exhausting v0.6.23's adaptive\n`--max-turns=25` while emitting a structured-output summary on a \n[…]\n4 workflows continue to function — output\nschema is additive.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(v0.6.25): Smart Budget System Phase 1 (Layers 1 + 1.5 + 2) + 3 c…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-30T02:02:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21224684b03912be0592f936fe422d983de4f208",
          "body": "…rs on private repos under v0.6.23 (#117)\n\n## Summary\n\nv0.6.23 added `actions: read` permission to the `clud-bug-review` job\nfor the bundled `github_ci` MCP server. Forensics on tokenomics show\nthis broke `pull_request` trigger firing on **private** consumer repos:\n\n- **tokenomics** (private): clud-\n[…]\nt-skills repo, v0.6.24 doesn't regress any\nexisting behavior.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: thrillmot <thrillmot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "hotfix(v0.6.24): back out 'actions: read' — broke pull_request trigge…",
          "author_name": "thrillmot",
          "author_login": "thrillmot",
          "committed_at": "2026-05-29T23:49:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 70,
      "commits_last_year": 199,
      "latest_release_at": "2026-07-17T01:29:39Z",
      "latest_release_tag": "v0.7.0-rc.24",
      "releases_from_tags": true,
      "days_since_last_push": 4,
      "active_weeks_last_year": 10,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "clud-bug",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "claude",
            "claude-code",
            "github-action",
            "code-review",
            "pull-request",
            "ai",
            "skills"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/clud-bug",
          "is_deprecated": false,
          "latest_version": "0.6.34",
          "repository_url": "https://github.com/thrillmade/clud-bug",
          "versions_count": 72,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3469,
          "first_published_at": "2026-05-15T04:24:33.379000Z",
          "latest_published_at": "2026-06-02T18:16:52.252000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 49
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [
          {
            "date": "2026-03-25",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_stars": 1
      },
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "site/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 108699,
      "source_files_sampled": 159,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        ".cursorrules",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 2711
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "site/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "next",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.2.9"
        },
        {
          "name": "react",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        },
        {
          "name": "react-dom",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.7"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 198,
        "open_issues": 3,
        "closed_ratio": 0.4,
        "closed_issues": 2,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "thrillmot",
          "commits": 191,
          "avatar_url": "https://avatars.githubusercontent.com/u/15040426?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "check-decisions.yml",
        "check-doc-links.yml",
        "ci.yml",
        "dependabot-auto-merge.yml",
        "logmind-self-update.yml",
        "npm-publish.yml",
        "regen-timeline.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "10ae1dc4c3708546ad49f0d416060cd2d1d40961",
        "ran_at": "2026-07-21T18:20:04Z",
        "aggregate_score": 5.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/thrillmade/clud-bug",
    "host": "github.com",
    "name": "clud-bug",
    "owner": "thrillmade"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 53,
        "vitality": 78,
        "community": 33,
        "governance": 46,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 78,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "commits_last_year": 199,
              "human_commit_share": 0.96,
              "days_since_last_push": 4,
              "active_weeks_last_year": 10
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "10/52 weeks with commits",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "199 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 199
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 70,
              "latest_release_tag": "v0.7.0-rc.24",
              "releases_from_tags": true,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "70 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 70
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "clud-bug"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3469
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,469 downloads/month across npm",
                "points": 47.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3469,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "merged_prs": 198,
              "open_issues": 3,
              "closed_issues": 2,
              "issue_closed_ratio": 0.4,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "198/229 decided PRs merged",
                "points": 33.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 198,
                      "decided": 229
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "thrillmade",
              "public_repos": 8,
              "account_age_days": 796
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of thrillmade",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "thrillmade"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "8 public repos, account ~2 yr old",
                "points": 11.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 8
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "clud-bug"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 49
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 49 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 49
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "72 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 72
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai-code-review",
                "claude",
                "claude-code",
                "cli",
                "code-review",
                "github-actions",
                "npm-package",
                "pr-review",
                "pull-request",
                "skills",
                "skills-sh",
                "skdd",
                "skill-driven-development"
              ],
              "has_wiki": false,
              "homepage": "https://cludbug.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://cludbug.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "13 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 53,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 77,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                ".cursorrules",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 2711
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursorrules, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursorrules, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 96 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 96
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "site/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.56,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.04
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "site/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "site/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "56 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 56,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "4 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 4,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 108699,
              "source_files_sampled": 159,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/159 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 159,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T18:20:23.308225Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/thrillmade/clud-bug.svg",
  "full_name": "thrillmade/clud-bug",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.23.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.