Registro público
Informe de salud del softwareesquema 0.27.0 · métricas 1.13.0 · 2026-07-27 05:31 UTC

vidaldiego / znvault-plugin-payara

Payara application server plugin for zn-vault-agent with WAR diff deployment

TypeScriptSin licencia detectada★ 0 estrellas⑂ 0 forksdesde ene 2026Ver en GitHub ↗

vidaldiego/znvault-plugin-payara tiene un índice de salud de 52 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (83/100) y la más baja, Community & Adoption (25/100). Se actualizó por última vez hace 6 días. Una sola persona concentra la mayor parte del trabajo reciente.

52
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

52
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

DiegoCuenta personal
1 seguidor19 repositorios públicosdesde oct 2012None

Este repositorio pertenece a una cuenta personal. Un proyecto con un único propietario conlleva más riesgo de continuidad que uno respaldado por una organización.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicaciónEtiquetas
npm@zincapp/znvault-plugin-payara2.7.0513386hace 6 díasznvaultpayaraglassfishwardeploymentpluginsecretsvault

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

83Bueno · 22% del índice global
Cómo se puntúa
36/36Recencia de push — último push hace 6 días
7.6/36Cadencia de commits — 11/52 semanas con commits
18/18Volumen de commits — 252 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year252
human_commit_share1
days_since_last_push6
active_weeks_last_year11
Cómo se puntúa
27/27Publica versiones — 84 versiones publicadas
36/36Recencia de las versiones — última versión hace 6 días
27/27Cadencia de publicación — una versión cada ~2 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count84
latest_release_tagv2.7.0
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases2
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

25Crítico · 18% del índice global
Cómo se puntúa
0/60Estrellas — 0 estrellas
0/25Forks — 0 forks
0/15Observadores — 0 observadores
Datos de entrada utilizados
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
0/22.5Licencia — no se detectó ningún archivo de licencia
0/18Guía CONTRIBUTING
0/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
Cómo se puntúa
49.5/80Descargas mensuales — 5133 descargas/mes en npm
0/20Dependientes en el registro — no lo informa este ecosistema
Datos de entrada utilizados
packages@zincapp/znvault-plugin-payara
dependents
ecosystemsnpm
total_downloads
monthly_downloads5133
Excluidos de la puntuación (sin datos o no aplicable): Dependientes en el registro. Los pesos restantes se han renormalizado.

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

35En riesgo · 24% del índice global
Cómo se puntúa
9/54Factor bus — la mitad de los commits recae en 1 contribuyente(s)
0/22.5Distribución de commits — el principal contribuyente firma el 100% de los commits
1.4/13.5Amplitud de contribuyentes — 1 contribuyentes
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Datos de entrada utilizados
bus_factor1
contributors_sampled1
top_contributor_share1
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
10/30Respaldo de la propiedad — cuenta personal (usuario)
0/20Dominio verificado — no aplicable a cuentas de usuario
2.2/25Alcance del propietario — 1 seguidores de vidaldiego
21.5/25Trayectoria — 19 repos públicos, cuenta de ~13 años
Datos de entrada utilizados
followers1
owner_typeUser
is_verified
owner_loginvidaldiego
public_repos19
account_age_days5045
Excluidos de la puntuación (sin datos o no aplicable): Dominio verificado. Los pesos restantes se han renormalizado.
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en npm
35/35Recencia de publicación — última publicación hace 6 días
20/20Historial de versiones — 86 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packages@zincapp/znvault-plugin-payara
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

68Moderado · 20% del índice global
Cómo se puntúa
24/24Flujos de trabajo de CI — 2 flujo(s) de trabajo
24/24Pruebas presentes
16/16Configuración de linter — .eslintrc.json
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_ci
has_tests
has_editorconfigno
has_linter_config
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

50Moderado
Cómo se puntúa
30/30README
0/25Directorio de documentación
0/15Sitio de documentación / página del proyecto
10/10Descripción del repositorio
0/10Topics
10/10Wiki
Datos de entrada utilizados
topics
has_wiki
homepage
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

44En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Licencia — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
2.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 35 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,5
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, signed_releases. Los pesos restantes se han renormalizado.
Cómo se puntúa
14/35Dependencias directas libres de avisos conocidos — 1 afectados: adm-zip 0.5.18 (high 7.5)
25/25Dependencias indirectas libres de avisos conocidos — ninguna dependencia indirecta tiene un aviso conocido
40/40Sin avisos pendientes — ningún aviso lleva público más de 90 días
Datos de entrada utilizados
sourceosv
advisories1
affected_packages1
assessed_packages78
unassessed_packages0
affected_by_severityhigh 1
direct_affected_packages1
Se cotejó el cierre de dependencias en tiempo de ejecución de npm:@zincapp/znvault-plugin-payara@2.7.0 —lo que arrastra la instalación del paquete publicado—: 78 paquetes. No se analiza la alcanzabilidad.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

80Bueno · 0% del índice global
Cómo se puntúa
45/45Instrucciones para agentes — CLAUDE.md
0/15Documentación legible por máquinas (llms.txt)
40/40Historial de commits legible — 96 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,96
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes13.116
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
11/11Configuración de lint / formato — .eslintrc.json
11/11Verificación estática de tipos — tsconfig.json
10/10Entorno reproducible — lockfile
10/10Práctica demostrada con agentes — 15 de los últimos 100 commits con autoría o crédito de agente
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
5/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
Datos de entrada utilizados
has_nixno
has_tests
lockfilespackage-lock.json
has_dockerfileno
typed_language
bootstrap_files
has_devcontainerno
has_linter_config
typecheck_configstsconfig.json
agent_commit_share0,15
toolchain_manifests
dependency_bot_commit_share0
Cómo se puntúa
45/45Código verificable por tipos — TypeScript (tipado estático)
55/55Tamaños de archivo manejables — 0/87 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languageTypeScript
largest_source_bytes59.403
source_files_sampled87
oversized_source_files0

Datos clave

0estrellas de GitHub
1contribuidores
252commits en los últimos 12 meses
6días desde el último push
84versiones publicadas
1factor bus
0issues abiertas
npmecosistemas de paquetes

Advertencias de recopilación de datos

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Más detalle

OpenSSF Scorecard 3.5 / 10
3.5agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-27 05:31 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
5Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 5
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/dSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities35 existing vulnerabilities detected
Dependencias directas 7
RegistroPaqueteRestricción de versiónManifiesto
npm@zincapp/znvault-deploy-core^0.1.0package.json
npm@zincapp/znvault-migrate^1.0.0package.json
npmadm-zip^0.5.16package.json
npminquirer^13.2.1package.json
npmlistr2^10.0.0package.json
npmmysql2^3.16.1package.json
npmpino^10.2.1package.json
Todas las dependencias no recopilado

No fue posible recopilar el conjunto de dependencias resuelto para este informe: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Avisos de dependencias 1

Instalar npm:@zincapp/znvault-plugin-payara@2.7.0 arrastra 78 paquetes, directos y transitivos: 1 tienen avisos conocidos, de los cuales 1 son dependencias directas.

PaqueteVersiónRelaciónGravedadAvisosCorregido en
adm-zip0.5.18directaalta10.6.0

Un aviso significa que la versión registrada en el grafo de dependencias cae dentro del rango afectado de un aviso. No se analiza la alcanzabilidad, y el grafo incluye fijaciones de desarrollo y prueba: un hallazgo puede referirse al utillaje y no al software distribuido.

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1410,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "TypeScript": 662576
      },
      "pushed_at": "2026-07-20T16:31:25Z",
      "created_at": "2026-01-09T05:40:22Z",
      "owner_type": "User",
      "updated_at": "2026-07-20T16:32:31Z",
      "description": "Payara application server plugin for zn-vault-agent with WAR diff deployment",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Diego",
      "type": "User",
      "login": "vidaldiego",
      "company": "None",
      "location": "Madrid",
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/2470562?v=4",
      "created_at": "2012-10-02T09:14:43Z",
      "is_verified": null,
      "public_repos": 19,
      "account_age_days": 5045
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-07-20T16:32:47Z"
        },
        {
          "tag": "v2.6.1",
          "kind": "patch",
          "published_at": "2026-07-04T17:58:17Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-07-04T16:42:03Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-04T14:21:18Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-07-04T13:13:56Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-04T12:59:43Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-07-03T21:39:06Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-07-03T19:44:28Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-07-03T17:47:48Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-07-02T20:16:47Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-07-02T18:58:26Z"
        },
        {
          "tag": "v1.28.3",
          "kind": "patch",
          "published_at": "2026-07-02T17:31:51Z"
        },
        {
          "tag": "v1.28.2",
          "kind": "patch",
          "published_at": "2026-07-02T17:18:49Z"
        },
        {
          "tag": "v1.28.1",
          "kind": "patch",
          "published_at": "2026-07-02T16:58:54Z"
        },
        {
          "tag": "v1.28.0",
          "kind": "minor",
          "published_at": "2026-07-02T16:16:09Z"
        },
        {
          "tag": "v1.27.0",
          "kind": "minor",
          "published_at": "2026-07-02T10:48:18Z"
        },
        {
          "tag": "v1.26.0",
          "kind": "minor",
          "published_at": "2026-07-02T06:08:11Z"
        },
        {
          "tag": "v1.25.1",
          "kind": "patch",
          "published_at": "2026-07-01T16:19:09Z"
        },
        {
          "tag": "v1.25.0",
          "kind": "minor",
          "published_at": "2026-07-01T15:29:43Z"
        },
        {
          "tag": "v1.24.3",
          "kind": "patch",
          "published_at": "2026-07-01T09:04:24Z"
        },
        {
          "tag": "v1.24.2",
          "kind": "patch",
          "published_at": "2026-07-01T05:49:26Z"
        },
        {
          "tag": "v1.24.1",
          "kind": "patch",
          "published_at": "2026-07-01T05:40:42Z"
        },
        {
          "tag": "v1.24.0",
          "kind": "minor",
          "published_at": "2026-07-01T05:12:40Z"
        },
        {
          "tag": "v1.23.0",
          "kind": "minor",
          "published_at": "2026-07-01T04:54:51Z"
        },
        {
          "tag": "v1.22.1",
          "kind": "patch",
          "published_at": "2026-06-23T12:25:05Z"
        },
        {
          "tag": "v1.22.0",
          "kind": "minor",
          "published_at": "2026-06-23T11:32:00Z"
        },
        {
          "tag": "v1.21.1",
          "kind": "patch",
          "published_at": "2026-06-23T09:22:54Z"
        },
        {
          "tag": "v1.21.0",
          "kind": "minor",
          "published_at": "2026-06-22T18:22:20Z"
        },
        {
          "tag": "v1.20.0",
          "kind": "minor",
          "published_at": "2026-06-22T17:55:35Z"
        },
        {
          "tag": "v1.19.0",
          "kind": "minor",
          "published_at": "2026-06-22T12:44:27Z"
        },
        {
          "tag": "v1.18.1",
          "kind": "patch",
          "published_at": "2026-06-17T04:59:03Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2026-06-16T19:22:16Z"
        },
        {
          "tag": "v1.17.1",
          "kind": "patch",
          "published_at": "2026-02-14T08:44:52Z"
        },
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2026-02-14T08:36:24Z"
        },
        {
          "tag": "v1.16.1",
          "kind": "patch",
          "published_at": "2026-02-06T11:58:13Z"
        },
        {
          "tag": "v1.16.0",
          "kind": "minor",
          "published_at": "2026-01-26T19:49:05Z"
        },
        {
          "tag": "v1.15.0",
          "kind": "minor",
          "published_at": "2026-01-26T12:57:45Z"
        },
        {
          "tag": "v1.14.1",
          "kind": "patch",
          "published_at": "2026-01-26T11:15:33Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2026-01-26T10:43:01Z"
        },
        {
          "tag": "v1.13.2",
          "kind": "patch",
          "published_at": "2026-01-25T19:13:45Z"
        },
        {
          "tag": "v1.13.1",
          "kind": "patch",
          "published_at": "2026-01-25T16:51:58Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2026-01-24T14:15:34Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-01-24T13:29:27Z"
        },
        {
          "tag": "v1.11.8",
          "kind": "patch",
          "published_at": "2026-01-24T12:06:22Z"
        },
        {
          "tag": "v1.11.7",
          "kind": "patch",
          "published_at": "2026-01-24T11:39:48Z"
        },
        {
          "tag": "v1.11.6",
          "kind": "patch",
          "published_at": "2026-01-24T11:00:27Z"
        },
        {
          "tag": "v1.11.5",
          "kind": "patch",
          "published_at": "2026-01-24T10:41:04Z"
        },
        {
          "tag": "v1.11.4",
          "kind": "patch",
          "published_at": "2026-01-24T10:22:53Z"
        },
        {
          "tag": "v1.11.3",
          "kind": "patch",
          "published_at": "2026-01-24T07:28:57Z"
        },
        {
          "tag": "v1.11.2",
          "kind": "patch",
          "published_at": "2026-01-23T17:08:59Z"
        },
        {
          "tag": "v1.11.1",
          "kind": "patch",
          "published_at": "2026-01-22T19:25:41Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2026-01-22T18:39:04Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-01-22T18:14:04Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2026-01-22T17:50:06Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-01-22T17:05:10Z"
        },
        {
          "tag": "v1.7.18",
          "kind": "patch",
          "published_at": "2026-01-22T13:03:16Z"
        },
        {
          "tag": "v1.7.17",
          "kind": "patch",
          "published_at": "2026-01-15T14:51:44Z"
        },
        {
          "tag": "v1.7.16",
          "kind": "patch",
          "published_at": "2026-01-15T13:29:24Z"
        },
        {
          "tag": "v1.7.15",
          "kind": "patch",
          "published_at": "2026-01-15T13:23:22Z"
        },
        {
          "tag": "v1.7.14",
          "kind": "patch",
          "published_at": "2026-01-15T13:09:04Z"
        },
        {
          "tag": "v1.7.13",
          "kind": "patch",
          "published_at": "2026-01-14T21:04:05Z"
        },
        {
          "tag": "v1.7.12",
          "kind": "patch",
          "published_at": "2026-01-13T16:46:33Z"
        },
        {
          "tag": "v1.7.11",
          "kind": "patch",
          "published_at": "2026-01-13T13:49:35Z"
        },
        {
          "tag": "v1.7.10",
          "kind": "patch",
          "published_at": "2026-01-13T11:15:26Z"
        },
        {
          "tag": "v1.7.9",
          "kind": "patch",
          "published_at": "2026-01-13T10:35:17Z"
        },
        {
          "tag": "v1.7.8",
          "kind": "patch",
          "published_at": "2026-01-13T10:21:45Z"
        },
        {
          "tag": "v1.7.7",
          "kind": "patch",
          "published_at": "2026-01-13T10:04:30Z"
        },
        {
          "tag": "v1.7.6",
          "kind": "patch",
          "published_at": "2026-01-12T20:42:13Z"
        },
        {
          "tag": "v1.7.4",
          "kind": "patch",
          "published_at": "2026-01-11T15:54:20Z"
        },
        {
          "tag": "v1.7.3",
          "kind": "patch",
          "published_at": "2026-01-10T21:01:45Z"
        },
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2026-01-10T20:21:08Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2026-01-10T20:13:16Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-01-10T20:00:56Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2026-01-10T19:12:13Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-01-10T18:57:44Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-01-10T15:47:21Z"
        },
        {
          "tag": "v1.4.3",
          "kind": "patch",
          "published_at": "2026-01-10T14:52:29Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2026-01-10T14:45:27Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-01-10T09:38:34Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-01-10T09:27:55Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-01-09T16:19:14Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-01-09T10:34:40Z"
        },
        {
          "tag": "v1.0.6",
          "kind": "patch",
          "published_at": "2026-01-09T09:52:44Z"
        },
        {
          "tag": "v1.0.4",
          "kind": "patch",
          "published_at": "2026-01-09T09:03:10Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4fd704bd0853d4c6087b67433452fd1b81f7724a",
          "body": "…brary\n\nRefactor onto the published @zincapp/znvault-deploy-core (was a local file:\npath); config-store shim locked by tests. Behavior unchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.7.0 — adopt @zincapp/znvault-deploy-core shared li…",
          "author_name": "vidaldiego",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-20T16:25:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8c7da11f4cbf949282f752772519262e4a9f0216",
          "body": "…ocal file: path)\n\nFull suite green (337 pass/3 skip) against the published registry tarball,\nproving parity with the local build.",
          "is_bot": false,
          "headline": "chore: depend on published @zincapp/znvault-deploy-core@^0.1.0 (was l…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-09T10:24:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1e1e1c5119820951dba4d97be0123730ab9a07f",
          "body": "…al-review Minor #1)",
          "is_bot": false,
          "headline": "test: lock config-store shim's wrapped-shape + throw-on-miss API (fin…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-08T19:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9269cbe42c391d12faf63bd90e8a9309ba0ac343",
          "body": "- swap imports of 15 generic modules to the shared package\n- config-store.ts becomes a thin shim over deploy-core's parameterized API\n  (preserves payara's original zero-arg signatures + throw-on-miss)\n- runMigrationPhase/siblingIntegrityDirs now imported from deploy-core;\n  payara injects its MySQL\n[…]\nd modules + relocate their tests to deploy-core\n- byte-identical 'payara deploy to staging --dry-run' plan verified\n- full suite green: 332 pass / 3 skip (coverage relocated to deploy-core, none lost)",
          "is_bot": false,
          "headline": "refactor: adopt @zincapp/znvault-deploy-core; behavior unchanged",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-08T19:30:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60d6846364e7acc5c61266da796ac8cd769d2057",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v2.6.1 — docs for rootDir + config templates",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T17:57:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dacd22fee1f4ff43e1984302c9c17789246c939f",
          "body": "… + CLAUDE.md",
          "is_bot": false,
          "headline": "docs: document rootDir (v2.5.0) + config templates (v2.6.0) in README…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T17:56:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6a14051ffb90bb177c81a20626ea0d27d1ca726",
          "body": "…file)",
          "is_bot": false,
          "headline": "chore(release): v2.6.0 — config templates (import/export/deploy-from-…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T16:40:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc521ad49136bcf684db511ed367d1db140a5435",
          "body": "…root",
          "is_bot": false,
          "headline": "Merge: config templates (import/export/deploy-from-file) with --with-…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T16:40:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "656befb42f270302f788d7514ca8c064da07102b",
          "body": "…rtable + lossless)",
          "is_bot": false,
          "headline": "test(config): prove export→import round-trip resolves identically (po…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T16:15:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5875d923044b53ae64c8dc8a0098fc8d38a5cdce",
          "body": null,
          "is_bot": false,
          "headline": "feat(cli): deploy run accepts a config file path + --with-root override",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T16:10:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af8c58ac0589a362a24f3a929d86d55cf7fbe601",
          "body": "…ith-root, upgrade-with-confirm, --name)",
          "is_bot": false,
          "headline": "feat(cli): payara config import — read a template into the store (--w…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T16:05:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7973b1622cb7c9b00350b2f84be27a9a63c5065",
          "body": "…stripped)",
          "is_bot": false,
          "headline": "feat(cli): payara config export — write a portable template (rootDir …",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T16:00:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a75bfadaea6ac247cd7138ed198160c185346e55",
          "body": "…ctor",
          "is_bot": false,
          "headline": "feat(config): isConfigFilePath — lexical file-path-vs-saved-name dete…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T15:58:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73751eabe5124a99326f3a3baec6406537b7516c",
          "body": "… --with-root anchoring",
          "is_bot": false,
          "headline": "feat(config): loadConfigFromFile — read a DeployConfig from JSON with…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T15:55:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90c6cbc5a61ec208998f2ed39294e71f0d88f47c",
          "body": "…oy paths",
          "is_bot": false,
          "headline": "chore(release): v2.5.0 — config-level rootDir for relative local depl…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T14:20:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9656fc626ce1291054dd403471014cc0c0f481ee",
          "body": null,
          "is_bot": false,
          "headline": "Merge: config-level rootDir for relative local deploy paths",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T14:19:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7088e3c510086277d91f6251fc1ce8c30c32ed26",
          "body": "…tigial cast\n\nFinal-review Minor #1: the pre-resolve validation pass owns warning output,\nso the three per-branch validateDeployConfig calls no longer re-emit warnings\n(they were doubling on relative-path configs). Also drop the now-unneeded\nrootDir defensive cast in the resolver (Task 2 added the typed field).",
          "is_bot": false,
          "headline": "fix(deploy): surface rootDir warnings once (not per-branch); drop ves…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T14:17:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc399d9e71f23b4fc8d40ed089d6cb8745de1ed5",
          "body": "…lute (staging fixture)",
          "is_bot": false,
          "headline": "test(config): prove rootDir+relative resolves identically to all-abso…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T14:09:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a71ca3da87efc4e60367b63a900aa1b983b1f4b",
          "body": null,
          "is_bot": false,
          "headline": "feat(cli): config set rootdir + show Root line",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T14:05:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e352fba6e1b2ac533c1c28f611881afc25d68e5",
          "body": "…lidate as-stored, run absolute)",
          "is_bot": false,
          "headline": "feat(deploy): resolve config paths against rootDir before rollout (va…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T14:00:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cac0196bb66abb03a72808686c3401e4d65be8ac",
          "body": "… scaffolding rule when rootDir set)",
          "is_bot": false,
          "headline": "feat(config): validate rootDir + relative-local-path rules (supersede…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T13:54:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8e6c68c990f21a1b6c96effdf829b045de617de",
          "body": null,
          "is_bot": false,
          "headline": "feat(config): add DeployConfig.rootDir field",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T13:50:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b40bf892e3ee7ee58e499c8d5a301ca453879c7a",
          "body": "…ns-root, tilde-expand)",
          "is_bot": false,
          "headline": "feat(config): pure rootDir path resolver (absolute-wins, relative-joi…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T13:47:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fb05c7b31b45b4b2640f78732a58d376d26c587",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v2.4.1 — fix znvault-migrate dependency declaration",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T13:12:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31524ec806bfccf968e2fb276a4d191636c60753",
          "body": "…tional peer)\n\nThe plugin's deploy-run.ts imports runMigrations/mysqlAdapter from\n@zincapp/znvault-migrate as VALUE imports (real runtime code), but 2.4.0\ndeclared it as an optional peerDependency — so npm did not install it into\nthe plugin's node_modules, and loading the plugin failed at runtime with\n'Cannot find package @zincapp/znvault-migrate'. It is host-provided by\nneither the agent nor the CLI, so it must be a regular dependency.",
          "is_bot": false,
          "headline": "fix: declare @zincapp/znvault-migrate as a regular dependency (not op…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T13:12:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8613731a26f53b17a204186cd32fd35feba8ef5e",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v2.4.0 — consume @zincapp/znvault-migrate shared library",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T12:58:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af210da2cb126c22995933d454eee8fa0c1e188a",
          "body": null,
          "is_bot": false,
          "headline": "Merge: consume @zincapp/znvault-migrate shared library (byte-identical)",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T12:57:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce76b682713351bba9eb930224c119b618cc0304",
          "body": "Drop the local npm link; install the published package. Peer dep >=1\n(optional) + devDep ^1.0.0. Plugin suite stays byte-identical (39 files /\n436 tests) against the real package.",
          "is_bot": false,
          "headline": "chore: consume @zincapp/znvault-migrate from npm (v1.0.0 published)",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T12:57:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "add9a9b8dc5b62e9677e0f3f13f81004322f468e",
          "body": "…/migrate (byte-identical)",
          "is_bot": false,
          "headline": "refactor(migrate): consume @zincapp/znvault-migrate; delete local src…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-04T11:20:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3793fde73db8e0f9df4c55db2849c28b271c78de",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v2.3.0 — retire the migration routine-bundle config path",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T21:37:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ed799cea8f1708b7f5efa450f2b3bc6b149c846",
          "body": "Staging migrations are on the scaffolding path; the routine-bundle mechanism\nis unused. Removes MigrationConfig.routines, applyRoutines, the --routines-*\nCLI flags, and dedicated tests/docs. Whole-branch reviewed clean (519 tests;\nscaffolding path zero diff footprint).",
          "is_bot": false,
          "headline": "Merge: retire the migration routine-bundle config path (Phase 2)",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T21:35:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51a2b025811eeb7e3c1bf9cf54ab849f3ea5f671",
          "body": null,
          "is_bot": false,
          "headline": "test+docs(plugin): remove routine-bundle tests and doc references",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T20:58:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9e916ec2ae6d5163110f734dcb3810e61c2ef92",
          "body": "…aging is on scaffolding)",
          "is_bot": false,
          "headline": "refactor(plugin): remove the migration routine-bundle config path (st…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T20:51:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99b84b8649ae28b28a0cba50e35127dbd198fa3e",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v2.2.0 — scaffoldingFile accepts an absolute path",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T19:42:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "513b7149bf10021de42abfc9e96638153dc33a5a",
          "body": "… phases)\n\nreadScaffoldingSql + validateMigrationBlock accept an absolute scaffoldingFile\nso one shared helper file serves both the pre and post migration phases (which\nhave different migrationsDirs). Bare filenames unchanged (byte-identical to\nv2.1.0). Whole-branch reviewed clean (539 tests).",
          "is_bot": false,
          "headline": "Merge: scaffoldingFile accepts an absolute path (shared helper across…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T19:42:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdef8e580b8233f9de84d0ed1a554fe22728df9e",
          "body": "…elp + docs)",
          "is_bot": false,
          "headline": "feat(config): accept an absolute scaffoldingFile path (validation + h…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T19:05:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0867ed3d2b99f10d13f924660a6a997e20e3c733",
          "body": "…lper file across phases)",
          "is_bot": false,
          "headline": "feat(migrate): readScaffoldingSql accepts an absolute path (shared he…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T19:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f88626bbebbff1be1923cd53eca85534468a8613",
          "body": "…4006 fix)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VAKX3VyzPNUnpBNC1rqjea",
          "is_bot": false,
          "headline": "chore(release): v2.1.0 — migration scaffolding bounded-lifecycle (ER-…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T17:44:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "af5dbde93381274e4518b167378018c9256f630e",
          "body": "…he deploy phase to eliminate ER-4006\n\nScaffolding SQL (migration helpers) is applied at the start of each migration\nphase and every definer-carrying object the ephemeral migrate lease user creates\nis dropped after reconcile, so DROP USER on lease revoke never hits MySQL 8.4\nER-4006. scaffoldingFile\n[…]\nisting\nbehavior byte-identical. Whole-branch reviewed clean (533 tests).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VAKX3VyzPNUnpBNC1rqjea",
          "is_bot": false,
          "headline": "Merge: migration scaffolding bounded-lifecycle — bracket helpers to t…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T17:43:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "988aff70f27b814fab808980a78fb8ca6f82f6c0",
          "body": "…ship rule",
          "is_bot": false,
          "headline": "docs: migration scaffolding config + persistent-definer-object author…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T17:11:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61234387b79bb8626d1652f07106cb5a4f9302e0",
          "body": "…lease username",
          "is_bot": false,
          "headline": "feat(migrate): thread scaffoldingFile through to the runner with the …",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T17:05:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed56622676a397af2f5d9ad420e9cc8ec49dfadd",
          "body": "lockHeld() called lock.isHeld() (SELECT IS_USED_LOCK) unguarded from\nrun()'s scaffolding finally block. On a dead connection — killed\nsession or proxy reconnect, the exact scenario the guard exists for —\nthat SELECT can reject instead of resolving false. Since the call sat\nin a finally, an unswallow\n[…]\n lock-held check\nrejecting during cleanup (success and failure phases), and\ndropDefinerObjects itself throwing (success and failure phases) — both\nprove the primary phase result/error is never masked.",
          "is_bot": false,
          "headline": "fix(migrate): make scaffolding cleanup's lock-held check non-throwing",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T17:01:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6ac105aa2b16d3163c22e8d91c18e82e07965e2",
          "body": "…efiner objects after reconcile (unconditional)",
          "is_bot": false,
          "headline": "feat(migrate): bracket the phase — apply scaffolding at start, drop d…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:54:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c486b3a1dff964ea6c2c6590e0a2ab295c6941f2",
          "body": "…ery shape\n\nDb.query (src/migrate/db.ts) returns rows directly, already unwrapping the\nmysql2 [rows, fields] tuple internally — confirmed against existing callers\nmigration-lock.ts and schema-migrations-repo.ts, which both consume it as\nrows directly. dropDefinerObjects instead destructured\nconst [r\n[…]\ned a contract-pinning regression test that fakes Db.query exactly like\n  the real implementation (internal tuple unwrap, rows returned directly),\n  which would fail under the old tuple-destructure bug",
          "is_bot": false,
          "headline": "fix(migrate): dropDefinerObjects tuple-destructure against real Db.qu…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:46:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2abd1060a37ba310c40b1dac0c137684e6bb352f",
          "body": "…oc/func/trigger/event)",
          "is_bot": false,
          "headline": "feat(migrate): dropDefinerObjects — unconditional definer cleanup (pr…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:40:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6f3a4853bfc5cfb84b066476d85cd2356977292",
          "body": null,
          "is_bot": false,
          "headline": "test(config): cover migration.scaffoldingFile validation rule",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d310429f1f19371d5f872d201893782fc8f8cab6",
          "body": null,
          "is_bot": false,
          "headline": "feat(migrate): readScaffoldingSql — read + split the scaffolding file",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:35:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81203ce58c1d96f341123e08defe8284883cf391",
          "body": null,
          "is_bot": false,
          "headline": "feat(config): --scaffolding-file flag, validation, and show render",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:29:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69be4ba33eb4b70afccf046043935f290d6310b1",
          "body": "test/config-types.test.ts was meant to guard against scaffoldingFile\nbeing removed from MigrationConfig, but tsconfig.json excludes test/\nfrom tsc --noEmit and TS types erase at runtime, so the field could be\ndeleted and npm test would still pass.\n\nAdd a type-level assertion in src/cli/types.ts (which IS covered by\ntypecheck) that fails to compile if scaffoldingFile is removed or its\ntype widens. Documented the gap in the test file so it's not mistaken\nfor the real guard.",
          "is_bot": false,
          "headline": "fix(config): add compile-time regression guard for scaffoldingFile",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:25:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40044652f95bcb9cd6d600b09b397db004a1dd80",
          "body": null,
          "is_bot": false,
          "headline": "feat(config): add scaffoldingFile field to MigrationConfig",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-03T16:20:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "251558061cfb416a39940a4851cb4e1738718b70",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.0.1 — fix post-deploy migration OrphanTrackedRowError",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T20:15:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ec3cbad519340ba169f90b294e7cf116a709496",
          "body": "…phase\n\nThe pre/post migration split runs the migration engine twice against different\ndirs (pre/ then post/) sharing ONE schema_migrations history table. The planner's\nintegrity pass (migration-planner.ts) looked up every tracked row in a map built\nonly from the current phase's files — so the post \n[…]\ned against\nthe sibling file, siblingIntegrityDirs cases, and integrityDirs forwarding to\nmakeRunner. Full suite 510 pass / 0 fail.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(migrate): scope orphan-integrity check to pre∪post dirs, not one …",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T20:15:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8edc6b2cdd06da1d70c86f0392a6f6b70095cdc6",
          "body": "BREAKING: all commands move from 'znvault deploy …' to 'znvault payara …'\n(grouped by concern: payara deploy run/to/war, payara config, payara\nrestart/status/applications, payara tls). No 'deploy' alias. Deploy configs\nmove to ~/.znvault/payara/configs.json with a one-time non-destructive\nauto-migration. No deploy behavior change — namespace + config location only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.0.0 — CLI namespace deploy → payara",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:57:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b1e61464026ea41f2127b378209699c334599f64",
          "body": "…ording\n\nFinal-review cleanup: 3 code-comment/TSDoc references to the old 'deploy config'/\n'deploy run' paths → payara namespace (never printed, cosmetic); and correct the\nREADME to present 'run' as the primary command with 'to' as its alias (was\nbackwards).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(payara): fix stale command-path comments + README run/to alias w…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:56:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3f444d76fb5de5cfda0b2a335ab9c9b39101d92c",
          "body": "…elog",
          "is_bot": false,
          "headline": "docs(payara): update command paths to payara namespace + v2.0.0 chang…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:42:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "601131bbe417c8a00f9a61b8b5b6582186421ee2",
          "body": "…ace + config path\n\nIncludes test/cli.test.ts, a plan-gap file not in the original Task-5 list, re-rooted to the new payara tree.",
          "is_bot": false,
          "headline": "test(payara): re-root seam + integration + cli tests to payara namesp…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:31:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5333e540a35d3a0687baf4baf3d482deb6da6de3",
          "body": "…pace",
          "is_bot": false,
          "headline": "feat(payara): update user-facing command-path strings to payara names…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:22:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ab667c7e37f9f0376812e0a7f40af224122f140",
          "body": "…concern)",
          "is_bot": false,
          "headline": "feat(payara): rename top-level CLI group deploy → payara (grouped by …",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:17:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e22ffe306b887e22849fdec96ee3fc5c9abf9a86",
          "body": "…a/configs.json",
          "is_bot": false,
          "headline": "feat(payara): one-time non-destructive config auto-migration to payar…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:14:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6c442ddc8b58ed80d6cb079f84b8519ea3fcee5",
          "body": null,
          "is_bot": false,
          "headline": "feat(payara): per-deployer config path constants (payara/configs.json)",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T18:10:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5904a68b4c64f20a64b6ce93c9e859f96d475ad",
          "body": "…rn note\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v1.28.3 — dedup migration settings + point-of-no-retu…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T17:30:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "de1572a0c180b5800716a89a05baa513fc288a79",
          "body": "…te in config show\n\ndeploy config show polish:\n- when pre- and post-deploy phases share the same role + database, hoist the\n  shared settings under a common 'Migration:' header and nest Pre-deploy /\n  Post-deploy beneath (each showing only its own Dir + Bundle); phases with\n  differing role/db still\n[…]\nhanges; rollback to the previous app version\n  may no longer be possible\nREADME config-show example updated to match. 4 new tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(deploy): dedup shared migration settings + point-of-no-return no…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T17:30:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "77093dfa4af2c49ce471a7b126732b644d43b734",
          "body": "Patch: deploy config show execution plan now says 'Run pre-deploy schema\nmigrations' and labels the post routine step 're-applied post-deploy'\n(no longer implies a double execution). Display-only; no behavior change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v1.28.2 — clearer pre/post migration plan wording",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T17:17:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "391b15cb48943f13c6125e1ba3b07e58447e3bb2",
          "body": "…ases\n\ndeploy config show execution plan:\n- step 2 now reads 'Run pre-deploy schema migrations' (was bare 'Run schema\n  migrations')\n- pre routine step labeled '(pre-deploy, ...)' for consistency\n- post routine step now 'Apply routine bundle … (re-applied post-deploy before\n  post-deploy migrations)\n[…]\nrminology is explicitly pre-deploy/post-deploy throughout\nTests lock in the new strings + forbid the bare 'Run schema migrations'.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deploy): clarify execution-plan wording for pre/post migration ph…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T17:16:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98772a514bbca80a397952dca8ea18e4f5bf3d3d",
          "body": "Patch release: fixes stale --help descriptions for --migrations-only,\n--skip-migrations, and set-migration --clear after the v1.28.0 two-phase\nmigration feature. Help-text only; no behavior change. Also ships the\nCLAUDE.md/README documentation for the post-deploy migration phase.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v1.28.1 — correct migration CLI help text",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T16:57:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "732ea87787f2e7ba9eeb32686b626f383c5196c0",
          "body": "…hase\n\nCLI help was stale after v1.28.0:\n- --migrations-only help said 'run only the migration phase' → now runs BOTH\n- --skip-migrations help said 'the migration phase' (singular) → skips both\n- set-migration --clear help now notes it is --phase-scoped\nDocs:\n- CLAUDE.md: add 'Migration phases' sect\n[…]\ng show example, multi-class\n  cross-ref) + v1.27.0/v1.28.0 changelog entries\nTest updated for the new --skip-migrations help text.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs+fix(deploy): correct migration CLI help + document post-deploy p…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T16:32:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14fe894384076dc49b543d3d322d265807060e20",
          "body": "Adds a post-deploy schema-migration phase alongside the existing pre-deploy\nphase, so destructive migrations run only after a fully successful rollout\n(never while a host still serves the old WAR). Six flags control which phases\nrun: --skip-migrations/--skip-pre/--skip-post/--migrations-only/--pre-o\n[…]\npostMigration config block + set-migration --phase; two-phase\nconfig show. Full back-compat for existing single-migration configs.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v1.28.0 — post-deploy migration phase",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T16:14:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4b2f21c6816390732bdafe301fdab4177774de09",
          "body": null,
          "is_bot": false,
          "headline": "test(deploy): cover pre-only + no-rollout config show render",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T16:05:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b05f127665415269ef900ead105e64de3e85f3bc",
          "body": null,
          "is_bot": false,
          "headline": "docs(deploy): document post-deploy migration phase + six flags",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T16:05:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aec71040a8c9f983ebef3065e7293349937afd2f",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): config show renders both migration phases + plan",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T16:00:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d64af671a748c02df656b7f3fbd404ce304d4ad9",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): set-migration --phase pre|post",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T15:55:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3820a3f555e753345ab4b0e600d160f8949e7b56",
          "body": "…-run)\n\nPut per-class post-deploy coverage on the returned structure instead of a\nclosure side-map. runClass now resolves to { ctx, coverageOk };\nexecuteMultiClassDeployment copies coverageOk onto ClassOutcome, and the\ntail gate reads result.classes[i].coverageOk. This makes the DESTRUCTIVE\npost-dep\n[…]\nrage\nfalse). coverageOk = deployableHosts.length === preOverrideClassHostCount\n(captured before any per-class --host override shrinks rc.hosts, B1c);\nearly no-hosts/unreachable paths resolve to false.",
          "is_bot": false,
          "headline": "feat(deploy): multi-class post-deploy gate (coverage/worker/scope/dry…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T15:50:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c574295825efd33e973a11c5c5ee251a69f7689d",
          "body": null,
          "is_bot": false,
          "headline": "test(deploy): flat partial-coverage post-deploy skip integration test",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T15:32:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b454ed011cf2f354574ca1083c245f89c10e8cc",
          "body": "…cement",
          "is_bot": false,
          "headline": "feat(deploy): flat post-deploy gate (coverage/worker/scope) + pre pla…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T15:24:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75c7a9112927635f55411c5b3e0f63c2dc387829",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): six migration flags, plan resolution, no-rollout branch",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T15:15:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9197a420865539b9ac12b2f3c6f691a85c8ce30e",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): generalize runMigrationPhase (phase + run + skipReason)",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T15:01:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f682968bb13e1e3d6be1e6b98e203787555b3889",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): validate postMigration block + same-dir warning",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T14:55:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a513cd2af3824f12c4f7f019945ffa8e7f013a54",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): add postMigration block to DeployConfig",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T14:51:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df584d4fc1460bb81acdcc83fc4b68a9ecf15e0d",
          "body": "…ip-reason",
          "is_bot": false,
          "headline": "feat(deploy): post-gate helpers — noFailures/fullCoverage/isScoped/sk…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T14:48:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a4d36fd8b7de4351e9ae83df2db48e01544f630",
          "body": null,
          "is_bot": false,
          "headline": "feat(deploy): resolveDeployPlan — six-flag migration/rollout resolver",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T14:45:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7c2566ee8a69b2d3019fd1b1f3f464ec45a69e6",
          "body": "Deploy the WAR without running the schema-migration phase, even when the\nconfig declares one. Inverse of --migrations-only; the two are mutually\nexclusive. No-op when the config has no migration block. Skip takes\nprecedence over --dry-run.\n\nWired into both the flat and multi-class deploy paths via\nr\n[…]\nd by unit tests for the skip\nbehavior and CLI-wiring tests for flag registration + the mutual-exclusion\nguard (mutation-verified).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(deploy): add --skip-migrations flag to deploy run",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T10:47:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f0365b0e863a596569f8fafa3195ae18ade690a8",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v1.26.0 — deploy config show prints an execution plan",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-02T06:06:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6a450af45f0ffebccdf58b20f04fb46895f1060",
          "body": "Add an 'Execution plan' section to 'deploy config show' describing, in order,\nwhat 'deploy run' actually does: the migration phase (apply routine bundle → run\nmigrations, before any host) then each node class as an ordered phase with its\nstrategy batch breakdown (e.g. 1+R → '1 host first, then the r\n[…]\nrallel'),\nHAProxy drain note, and the blocking gate between phases. Reuses resolveClass +\nparseDeploymentStrategy so the plan matches real deploy behavior. Works for both\nmulti-class and flat configs.",
          "is_bot": false,
          "headline": "feat(deploy): config show prints an execution plan",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T16:34:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dcc1089937daed401e88098c25b808b32bd5519d",
          "body": "…onfig show classes/routines)",
          "is_bot": false,
          "headline": "chore(release): v1.25.1 — deploy fixes (--dry-run migration phase + c…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T16:17:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dba76e9fefd437ca9b281f0525691ac82000483d",
          "body": "'deploy config show' only understood the flat config shape: for a MULTI-CLASS\nconfig it printed 'Hosts (0): (none)', a top-level strategy, and 'HAProxy (not\nconfigured)' — rendering none of the actual classes (their hosts, strategy,\nblocking, haproxy drain, quiesce). It also omitted the migration.ro\n[…]\ner\nclass, shows the routines bundle in the Migration block, and points the flat\nHosts/Strategy/HAProxy lines to the per-class view instead of showing misleading\nempties. Flat configs render unchanged.",
          "is_bot": false,
          "headline": "fix(deploy): config show renders node classes + migration routines",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T16:16:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1f200bdbb9514abfc5f813dea5222bbfe3f68c2",
          "body": "runMigrationPhase ignored --dry-run: a dry-run of a config with a migration\nblock still applied the routine bundle, minted a real dynamic-secrets lease, and\nran migrations against the live DB (only the WAR rollout was skipped). The\nmulti-class path called runMigrationPhase unconditionally before its\n[…]\n dry-run\nprinter. Now runMigrationPhase takes { dryRun } and, when set, prints the plan\n(role/dir + routine bundle) and returns without side effects. Wired at both the\nmulti-class and flat call sites.",
          "is_bot": false,
          "headline": "fix(deploy): --dry-run no longer executes the migration phase",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T16:05:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7aaa82816fbef04465b36eef4a854fae618607b6",
          "body": "…ease + deploy-config selector)",
          "is_bot": false,
          "headline": "chore(release): v1.25.0 — routine-bundle provisioning (apply-before-l…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T15:28:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e07e6e6d6ac2c44cf3f7f87f59b9103f35851d5",
          "body": "…validation + pass-through)",
          "is_bot": false,
          "headline": "feat(plugin): deploy config routines selector (set-migration flags + …",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T13:55:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8f61f766e9dd1cbea420d5d3a8531e3e733e397",
          "body": "…abort deploy on failure)",
          "is_bot": false,
          "headline": "feat(plugin): apply routine bundle before minting the migrate lease (…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T13:48:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27fb2519535a0020c24a8e5eb3bf4c73a639ddd9",
          "body": "…ersion})",
          "is_bot": false,
          "headline": "feat(plugin): dynamic-secrets client applyRoutines(roleId, {bundle, v…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T13:41:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c647e36730b834584154b4e4a3872c779e43d5c",
          "body": "…ovisioned by vault routines bundle",
          "is_bot": false,
          "headline": "refactor(migrate): stop creating zn_* helpers per-run; helpers now pr…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T13:36:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09770b15171d01e8ba2fdb20d173c400e567f70b",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v1.24.3 — lease-revoke race fix + --migrations-only flag",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T09:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd02aa64761ac2fc7818b3ff29d14de7a8474ec0",
          "body": "…ions-only flag\n\n- fix: close the db.end()/revoke race that marked leases FAILED; surface the\n  real revoke error (was swallowed); stop retrying a non-revocable lease.\n- feat: --migrations-only runs the schema-migration phase then stops (skip\n  rollout) — a fast feedback loop for testing migrations without touching hosts.",
          "is_bot": false,
          "headline": "Merge fix/revoke-race-observability: lease-revoke race fix + --migrat…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T09:02:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff74e2700429e228e9941d09d90b98a85198d7da",
          "body": "…t the rollout\n\nAdds `znvault deploy to <config> --migrations-only`: mints a lease, runs\nschema migrations, revokes the lease, then stops — skipping the WAR rollout\nentirely. Works for both flat and multi-class config shapes.\n\nGuard: `--migrations-only` without a migration config block exits with a\nclear error before touching any host.\n\nAdds 3 new unit tests to deploy-run-migration-phase.test.ts covering the\nrunMigrationPhase contract that the early-return relies on.",
          "is_bot": false,
          "headline": "feat(deploy): add --migrations-only to run the migration phase withou…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T09:00:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7754a3ec6b479421448c52912e495e228543d6bc",
          "body": "…rror\n\nPart A: catch(e) in makeRevokeOnce so the actual vault error is included in\nthe WARN log on failure, and non-last retry attempts log attempt+error+delay.\n\nPart B: 1500ms settle delay after db.end() before revokeOnce() so the\nephemeral user's server-side session tears down before vault's KILL/\n[…]\nill get 3 attempts.\n\nTests: 5 new assertions covering error surfacing, retry logging, and\nnon-revocable fast-exit.  settleMs:0 in all harness/inline deps to keep\nfake-timer tests instant.  18/18 pass.",
          "is_bot": false,
          "headline": "fix(migrate): close the lease-revoke race + surface the real revoke e…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T08:52:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc1a7bbddd391de67b407b359db6723974fac43f",
          "body": "…ection",
          "is_bot": false,
          "headline": "chore(release): v1.24.2 — match Kotlin SSL semantics for prod DB conn…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T05:48:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6f88accc48bb870a789bb71c983c5c9052621b3",
          "body": "…IRED for prod SSL\n\nThe TS engine used mysql2 ssl:{} (rejectUnauthorized:true → verify cert vs system\nCAs), which failed against the prod MySQL's internal CA ('unable to verify the\nfirst certificate'). Kotlin's sslMode=REQUIRED encrypts WITHOUT verifying the cert;\nmatch it with ssl:{rejectUnauthorized:false}. Found by the live staging deploy.",
          "is_bot": false,
          "headline": "Merge fix/migration-tls-rejectunauthorized: match Kotlin sslMode=REQU…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T05:48:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fb07dd0c3a16e3a76169695cd97c864f13b3562",
          "body": "…ify) for prod SSL\n\nmysql2's `ssl: {}` defaults to rejectUnauthorized:true (full CA verification), which\nfails against the prod MySQL's internal CA with \"unable to verify the first certificate\".\nKotlin's ConnectionFactory uses sslMode=REQUIRED (encrypt but do NOT verify the cert),\nso the faithful ma\n[…]\nto undefined — no SSL).\n\nAdds db-ssl.unit.test.ts with two unit assertions (vi.mock intercept on mysql2) that\nlock in the ssl option contract: ssl:true→{rejectUnauthorized:false}, ssl:false→undefined.",
          "is_bot": false,
          "headline": "fix(migrate): match Kotlin sslMode=REQUIRED (encrypt without cert ver…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T05:47:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a34e20f4fba10c896292436e36ede3ce706a42c",
          "body": "…configs",
          "is_bot": false,
          "headline": "chore(release): v1.24.1 — run migration phase for multi-class deploy …",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T05:39:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf7d6fe9d74b1528edb85d510b2d223670d23eec",
          "body": "…lti-class configs\n\nThe schema-migration deploy phase was only wired into the flat-config deploy\npath; multi-class configs (the real prod/staging shape) silently skipped it.\nCaught by a live 'znvault deploy to staging' end-to-end test. Fix: call\nrunMigrationPhase once, before runMultiClassDeploy, so a migration failure aborts\nthe deploy before any host is touched (symmetric with the flat path).",
          "is_bot": false,
          "headline": "Merge fix/migration-phase-multi-class: run the migration phase for mu…",
          "author_name": "diegovidal",
          "author_login": "vidaldiego",
          "committed_at": "2026-07-01T05:39:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 84,
      "commits_last_year": 252,
      "latest_release_at": "2026-07-20T16:32:47Z",
      "latest_release_tag": "v2.7.0",
      "releases_from_tags": false,
      "days_since_last_push": 6,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 2
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@zincapp/znvault-plugin-payara",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "znvault",
            "payara",
            "glassfish",
            "war",
            "deployment",
            "plugin",
            "secrets",
            "vault"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@zincapp/znvault-plugin-payara",
          "is_deprecated": false,
          "latest_version": "2.7.0",
          "repository_url": "https://github.com/vidaldiego/znvault-plugin-payara",
          "versions_count": 86,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 5133,
          "first_published_at": "2026-01-09T08:49:15.334000Z",
          "latest_published_at": "2026-07-20T16:32:34.296000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 59403,
      "source_files_sampled": 87,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 13116
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "adm-zip",
            "direct": true,
            "version": "0.5.18",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-xcpc-8h2w-3j85"
            ],
            "fixed_version": "0.6.0",
            "advisory_count": 1,
            "oldest_advisory_days": 16
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 78,
        "malicious_count": 0,
        "assessed_package": "npm:@zincapp/znvault-plugin-payara@2.7.0",
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@zincapp/znvault-deploy-core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@zincapp/znvault-migrate",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.0"
        },
        {
          "name": "adm-zip",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.5.16"
        },
        {
          "name": "inquirer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.2.1"
        },
        {
          "name": "listr2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.0.0"
        },
        {
          "name": "mysql2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.16.1"
        },
        {
          "name": "pino",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.2.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "vidaldiego",
          "commits": 252,
          "avatar_url": "https://avatars.githubusercontent.com/u/2470562?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".eslintrc.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 5,
            "reason": "dependency not pinned by hash detected -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "35 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4fd704bd0853d4c6087b67433452fd1b81f7724a",
        "ran_at": "2026-07-27T05:31:17Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T16:32:49Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/vidaldiego/znvault-plugin-payara",
    "host": "github.com",
    "name": "znvault-plugin-payara",
    "owner": "vidaldiego"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 52,
      "inputs": {
        "security": 44,
        "vitality": 83,
        "community": 25,
        "governance": 35,
        "engineering": 68
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 252,
              "human_commit_share": 1,
              "days_since_last_push": 6,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "252 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 252
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 84,
              "latest_release_tag": "v2.7.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "84 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 84
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 6,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 6 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 25,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "@zincapp/znvault-plugin-payara"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 5133
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,133 downloads/month across npm",
                "points": 49.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5133,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 35,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "vidaldiego",
              "public_repos": 19,
              "account_age_days": 5045
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of vidaldiego",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "vidaldiego"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "19 public repos, account ~13 yr old",
                "points": 21.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 19
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@zincapp/znvault-plugin-payara"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "86 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 86
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 68,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".eslintrc.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 2.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "35 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the npm:@zincapp/znvault-plugin-payara@2.7.0 runtime dependency closure — what installing the published package pulls in — 78 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@zincapp/znvault-plugin-payara@2.7.0",
                  "assessed": 78
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 79,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 78,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: adm-zip 0.5.18 (high 7.5)",
                "points": 14,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "adm-zip 0.5.18 (high 7.5)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 78,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 80,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.96,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 13116
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.15,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".eslintrc.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "15 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 15,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 5,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 59403,
              "source_files_sampled": 87,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/87 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 87,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T05:31:22.632513Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/v/vidaldiego/znvault-plugin-payara.svg",
  "full_name": "vidaldiego/znvault-plugin-payara",
  "license_state": "absent",
  "license_spdx": null
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.27.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasnpm.