Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [],
"is_fork": true,
"size_kb": 42845,
"has_wiki": true,
"homepage": "https://httpcloak.dev",
"languages": {
"C#": 256609,
"Go": 1507234,
"Shell": 11100,
"Python": 208016,
"Makefile": 3318,
"JavaScript": 161183
},
"pushed_at": "2026-07-18T07:33:40Z",
"created_at": "2026-07-18T07:23:03Z",
"owner_type": "User",
"updated_at": "2026-07-18T07:23:04Z",
"description": "Go HTTP client with browser-identical TLS/HTTP2 fingerprinting. Bypass bot detection by perfectly mimicking Chrome, Firefox, and Safari at the cryptographic level (JA3/JA4, Akamai fingerprint, header order). Supports HTTP/1.1, HTTP/2, HTTP/3, sessions, cookies, and proxies.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go",
"C#"
]
},
"owner": {
"blog": null,
"name": "Anson",
"type": "User",
"login": "10",
"company": null,
"location": "San Francisco",
"followers": 35,
"avatar_url": "https://avatars.githubusercontent.com/u/48256568?v=4",
"created_at": "2019-03-05T17:46:02Z",
"is_verified": null,
"public_repos": 18,
"account_age_days": 2697
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "v1.6.8",
"kind": "patch",
"published_at": "2026-07-12T22:40:08Z"
},
{
"tag": "v1.6.8-beta.1",
"kind": "prerelease",
"published_at": "2026-06-05T18:26:39Z"
},
{
"tag": "v1.6.7",
"kind": "patch",
"published_at": "2026-06-03T10:28:00Z"
},
{
"tag": "v1.6.6",
"kind": "patch",
"published_at": "2026-05-09T14:55:26Z"
},
{
"tag": "v1.6.5",
"kind": "patch",
"published_at": "2026-04-30T18:29:37Z"
},
{
"tag": "v1.6.1",
"kind": "patch",
"published_at": "2026-03-15T22:49:19Z"
},
{
"tag": "v1.6.1-beta.3",
"kind": "prerelease",
"published_at": "2026-03-08T09:56:20Z"
},
{
"tag": "v1.6.1-beta.2",
"kind": "prerelease",
"published_at": "2026-02-22T20:37:40Z"
},
{
"tag": "v1.6.1-beta.1",
"kind": "prerelease",
"published_at": "2026-02-22T17:13:36Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2026-02-22T00:31:02Z"
},
{
"tag": "v1.6.0-beta.13",
"kind": "prerelease",
"published_at": "2026-02-12T20:31:28Z"
},
{
"tag": "v1.6.0-beta.12",
"kind": "prerelease",
"published_at": "2026-02-12T20:04:49Z"
},
{
"tag": "v1.6.0-beta.11",
"kind": "prerelease",
"published_at": "2026-02-11T14:12:12Z"
},
{
"tag": "v1.6.0-beta.10",
"kind": "prerelease",
"published_at": "2026-02-11T13:58:48Z"
},
{
"tag": "v1.6.0-beta.9",
"kind": "prerelease",
"published_at": "2026-02-11T12:06:38Z"
},
{
"tag": "v1.6.0-beta.8",
"kind": "prerelease",
"published_at": "2026-02-11T11:25:17Z"
},
{
"tag": "v1.6.0-beta.7",
"kind": "prerelease",
"published_at": "2026-02-10T22:37:40Z"
},
{
"tag": "v1.6.0-beta.6",
"kind": "prerelease",
"published_at": "2026-02-10T21:56:02Z"
},
{
"tag": "v1.6.0-beta.5",
"kind": "prerelease",
"published_at": "2026-02-10T21:54:49Z"
},
{
"tag": "v1.6.0-beta.4",
"kind": "prerelease",
"published_at": "2026-02-10T20:29:02Z"
},
{
"tag": "v1.6.0-beta.3",
"kind": "prerelease",
"published_at": "2026-02-08T14:31:47Z"
},
{
"tag": "v1.6.0-beta.2",
"kind": "prerelease",
"published_at": "2026-02-07T12:04:26Z"
},
{
"tag": "v1.6.0-beta.1",
"kind": "prerelease",
"published_at": "2026-02-07T10:35:56Z"
},
{
"tag": "v1.5.10",
"kind": "patch",
"published_at": "2026-01-30T11:56:42Z"
},
{
"tag": "v1.5.9",
"kind": "patch",
"published_at": "2026-01-22T16:30:00Z"
},
{
"tag": "v1.5.8",
"kind": "patch",
"published_at": "2026-01-22T15:26:01Z"
},
{
"tag": "v1.5.7",
"kind": "patch",
"published_at": "2026-01-17T10:03:49Z"
},
{
"tag": "v1.5.6",
"kind": "patch",
"published_at": "2026-01-12T00:10:06Z"
},
{
"tag": "v1.5.5",
"kind": "patch",
"published_at": "2026-01-11T22:45:05Z"
},
{
"tag": "v1.5.3",
"kind": "patch",
"published_at": "2026-01-10T21:36:14Z"
},
{
"tag": "v1.5.2",
"kind": "patch",
"published_at": "2026-01-09T21:30:48Z"
},
{
"tag": "v1.5.1",
"kind": "patch",
"published_at": "2026-01-08T22:39:41Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-01-08T02:02:35Z"
},
{
"tag": "v1.1.4",
"kind": "patch",
"published_at": "2026-01-08T01:56:09Z"
},
{
"tag": "v1.1.2",
"kind": "patch",
"published_at": "2026-01-07T21:57:45Z"
},
{
"tag": "v1.1.1",
"kind": "patch",
"published_at": "2026-01-07T18:02:39Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-01-07T16:43:21Z"
},
{
"tag": "v1.0.12",
"kind": "patch",
"published_at": "2026-01-07T12:44:38Z"
},
{
"tag": "v1.0.11",
"kind": "patch",
"published_at": "2026-01-07T12:33:20Z"
},
{
"tag": "v1.0.10",
"kind": "patch",
"published_at": "2026-01-07T07:43:26Z"
},
{
"tag": "v1.0.9",
"kind": "patch",
"published_at": "2026-01-07T00:19:19Z"
},
{
"tag": "v1.0.8",
"kind": "patch",
"published_at": "2026-01-07T00:15:33Z"
},
{
"tag": "v1.0.7",
"kind": "patch",
"published_at": "2026-01-07T00:05:29Z"
},
{
"tag": "v1.0.6",
"kind": "patch",
"published_at": "2026-01-06T23:51:03Z"
},
{
"tag": "v1.0.5",
"kind": "patch",
"published_at": "2026-01-06T22:06:15Z"
},
{
"tag": "v1.0.3",
"kind": "patch",
"published_at": "2026-01-06T18:11:09Z"
},
{
"tag": "v1.0.2",
"kind": "patch",
"published_at": "2026-01-06T18:02:55Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2026-01-06T16:44:03Z"
}
],
"recent_commits": [
{
"oid": "257363f29c0d74729979d4140f34a13d5ad769b6",
"body": null,
"is_bot": false,
"headline": "chore(release): bump version to 1.6.8, cut CHANGELOG [1.6.8]",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T22:40:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1de9350d085d3953ffc2d96b6a29e25af830121e",
"body": "Adds chrome-150-android, completing the Chrome 150 platform matrix. Android\nChrome runs the same Chromium/BoringSSL stack as desktop (only iOS is the WebKit\nexception), and the Android TLS base is HelloChrome_146_Linux — identical to\ndesktop Linux — so this preset carries the SAME ML-DSA signature_a\n[…]\ns\nassumed to match desktop and will be confirmed against a real Android 150\ncapture. Regression lock guards ML-DSA-on-TCP/none-on-QUIC plus the mobile\nidentity (sec-ch-ua-mobile ?1, platform Android).",
"is_bot": false,
"headline": "feat(fingerprint): Chrome 150 Android preset (chrome-150-android)",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T20:28:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe0841ea9a3b797a745ba022f49bdf9abfad025b",
"body": "Adds chrome-150-ios as a pure header/UA bump over the chrome-148 iOS base\n(User-Agent: iOS 26_5_0, CriOS/150.0.7871.51). iOS Chrome is forced onto\nSafari/WebKit's TLS stack (HelloIOS_18), so the wire fingerprint is inherited\nbyte-exact and, unlike the desktop chrome-150 line, carries NO ML-DSA\nsigna\n[…]\nde729e78a9f0ebd1dd099314a7. chrome-latest-ios now tracks 150; Android\nstays on 148 pending a fresh capture. Regression lock guards the UA/header bump,\nthe Safari TLS base, and the no-ML-DSA invariant.",
"is_bot": false,
"headline": "feat(fingerprint): Chrome 150 iOS preset (chrome-150-ios)",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T20:15:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "59b67271b5be61c2682311c935fde41ba9767c64",
"body": "…er handshake\n\nIn HTTP/3-only mode there is no protocol fallback, so a QUIC connection that\ncompletes its handshake but then blackholes application data (classically an\nIPv6 PMTU black hole: keepalives keep the connection \"alive\" while the response\nnever arrives) left doHTTP3 blocked on RoundTrip un\n[…]\ning); healthy paths still return immediately;\nprefer_ipv4 body reads intact; -race clean. Adds regression coverage for the\nstall classifier, the IPv4-first override wiring, and the stall-window bound.",
"is_bot": false,
"headline": "fix(transport): forced-H3 no longer hangs when a QUIC path stalls aft…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T20:07:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cfe1b24dd98df5ea906b4f568da4ba8f03754c37",
"body": "Add chrome-150 (windows/linux/macos) and point chrome-latest at it. Chrome 150\nadvertises the three ML-DSA signature schemes (0x0904-0x0906 = ML-DSA-44/65/87,\ndraft-ietf-tls-mldsa, TLS 1.3-only) in its TCP ClientHello signature_algorithms,\non top of the Chrome 146 base — but NOT over QUIC, where ant\n[…]\ns pure JSON (based_on chrome-149 + the sig-algs list + the captured\n UA and sec-ch-ua brand rotation); no Go hardcoding.\n\nStatic lock (chrome150_test.go) guards ML-DSA on TCP and its absence on QUIC.",
"is_bot": false,
"headline": "feat(fingerprint): Chrome 150 preset with ML-DSA post-quantum signatures",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T17:25:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c95ccc2d7713ec60877a92512de3ff4a851e427f",
"body": "…print (#79)\n\nHttpCloakHandler proxied https:// requests via HttpClient's CONNECT tunnel, so\nHttpClient performed its OWN end-to-end TLS handshake and the target saw .NET's\nTLS + HTTP/1.1 fingerprint (ja4 t13d1112..., HTTP/1.1) instead of the browser\npreset. That diverged from Session, which applies\n[…]\ndpoint: the Handler now matches Session\n(ja4 t13d1516h2..., h2, same Akamai H2 hash and cipher list). The localhost hop\nstays plaintext; the fingerprinted TLS is between the LocalProxy and the target.",
"is_bot": false,
"headline": "fix(dotnet): route HttpCloakHandler https requests through the finger…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T10:25:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a45770f08f933f4bfa43080e9e989402b2e61388",
"body": "…he stream.go rework\n\nPR #77 (thanks marioparaschiv) added the streaming H1 fallback for servers that\nnegotiate http/1.1. This branch had already reworked stream.go (per-request\nsnapshot, connection-establishment timeout bounding, Lines() leak fix) and carried\nthe same fix folded in (#75) with per-h\n[…]\nesolved stream.go to the reworked superset; #77's tests are kept as\nregression locks and pass against it. Also merges #80's Python free-threading\nchanges (auto-merged with the cache-callback UAF fix).",
"is_bot": false,
"headline": "Merge origin/main: reconcile #77 (streaming HTTP/1.1 fallback) with t…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-12T09:52:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3446969e77c2795c2b5732642ec195438b267bfa",
"body": "* Fallback to HTTP/1 for ALPN mismatch in streaming\n\n* Test forced HTTP/2 stream rejects HTTP/1 fallback",
"is_bot": false,
"headline": "Fix streaming fallback for HTTP/1-only servers (#77)",
"author_name": "Mario P.",
"author_login": "marioparaschiv",
"committed_at": "2026-07-12T09:51:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f8e7fef10ee3a65b6fbb44d5933f07098ad6119b",
"body": "…#73)\n\nThe Linux window handling requested SO_RCVBUF = WindowSize/2, which produced an\nadvertised initial receive window of only ~WindowSize/2 (e.g. 32120 for a Windows\nfingerprint's 64240). Request a buffer comfortably larger than WindowSize so the\nwindow reaches WindowSize; TCP_WINDOW_CLAMP still \n[…]\nced to 0 by the window clamp, and capped by\nnet.core.rmem_max, so fp.WindowScale cannot be matched to an arbitrary browser\nvalue (e.g. wscale 8) via setsockopt on Linux without kernel-level rewriting.",
"is_bot": false,
"headline": "fix(transport): advertise the full fingerprint window size on Linux (…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T12:27:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c483ade30bd943d8c47116c35815ab451b5cfd73",
"body": "applyTCPFingerprint only set IP_TTL (IPPROTO_IP), which is a no-op on an IPv6\nsocket, so IPv6 SYNs carried the kernel default hop limit (64) regardless of the\nfingerprint. Set both IP_TTL and IPV6_UNICAST_HOPS (the mismatched family fails\nharmlessly as ENOPROTOOPT; only a failure of both is an error\n[…]\no longer\nabort an IPv6 dial when a Windows fingerprint sets DFBit. Applied on Linux, macOS,\nand Windows. Verified: IPv6 hop limit now matches the fingerprint TTL (128 for\nWindows), IPv4 TTL unchanged.",
"is_bot": false,
"headline": "fix(transport): set the IPv6 hop limit in the TCP/IP fingerprint (#81)",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T12:21:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ffa57868a6587b8a86aced849d22efed80d95c7",
"body": "…1.1 (#75)\n\nrequest_stream failed with \"Failed to start streaming request\" on any host that\nspeaks only http/1.1: the streaming auto path had no H1 fallback and re-tried H2\ninto the same ALPN mismatch. Add doStreamHTTP2OrHTTP1 and route the auto,\ncached-decision, and probe ALPN-mismatch paths through it so streaming falls back\nto HTTP/1.1 like the buffered path does, caching the H1 decision per host. Forced\nHTTP/2 stays strict. Mirrors the approach in #77.",
"is_bot": false,
"headline": "fix(transport): stream over HTTP/1.1 when the server negotiates http/…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:18:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "829dce7c5cdee1521fbec39ef7b8eab40c86f246",
"body": "- clib: recover-guard every export (including the fast-path exports) so a panic\n can't cross the cgo boundary; store and cancel the streaming context on close.\n- python: add async per-request timeout, deep-copy request headers, and retain\n cache-callback buffers so a shared backend can't hit a use-after-free.\n- dotnet: fix the binary-request timeout unit and async NUL-body handling.",
"is_bot": false,
"headline": "fix(bindings): crash-safety, memory-safety, timeout correctness",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:11:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e57c06342af9669c2a203b6ab0a03622356b5d49",
"body": "…rent hint prep\n\n- Derive one request deadline (per-request timeout, else session timeout) so a\n configured timeout bounds the whole logical request across redirects/retries.\n- Route client-hint application through a shared prepare step for buffered and\n streaming paths with deterministic override.",
"is_bot": false,
"headline": "fix(session): bound the whole request by the configured timeout, cohe…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:11:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "40944d801b57b63d7904847e5a3dd5df5d46d0b6",
"body": "…nnel, ECH degradation (#74)\n\n- Guard the unified Transport's sub-transport and config pointers with a mutex;\n snapshot them once per request so SetProxy/SetPreset can't race dispatch.\n- Establish one overall request deadline so redirects and retries share the\n timeout budget instead of stacking i\n[…]\ns stall the handshake, cascading to a\n slow fallback. Time-box the ECH attempt, retry once without ECH, and cache the\n incompatibility so later connections skip it. ECH-capable hosts are unaffected.",
"is_bot": false,
"headline": "fix(transport): concurrency, timeouts, happy-eyeballs, lazy SOCKS5 tu…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:11:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "252917e1bbd3772a85a2c79df8e533dbf6cf0630",
"body": "…tion\n\n- Add the high-entropy sec-ch-ua-* set and conditional-cache validators to the\n H2/H3 and H1 header-order tables so session-injected hints emit in a stable,\n grouped order instead of random map-iteration order.\n- H1 honors preset JA3 and the h2/h3 protocol keys.",
"is_bot": false,
"headline": "fix(fingerprint): deterministic client-hint header order, JA3 applica…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:11:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb75a478415ab4f1d419c13223aae73cc62a838c",
"body": "…kets\n\n- SOCKS5/HTTP-CONNECT/MASQUE try every resolved address (IPv4 first) with\n per-address timeouts so an unreachable address can't stall the dial.\n- SOCKS5 handshake reads honor the caller deadline (fallback to dialer timeout).\n- MASQUE: key the tunnel by target host+port, reset on Refresh, gua\n[…]\n, and open a fresh UDP socket per dial attempt so\n a failed attempt's transport can't swallow the fallback's handshake packets.\n- Add dialutil helpers (IPv4-first ordering, first-reachable TCP dial).",
"is_bot": false,
"headline": "fix(proxy): multi-address dial, MASQUE tunnel keying, per-attempt soc…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:11:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9aa41464291408029b1db848823cace51ea668ea",
"body": "…ility cache\n\n- Resolve() dedups concurrent lookups via singleflight DoChan; each caller\n selects on its own context so a cancelled leader can't fail healthy joiners.\n The shared lookup runs under a detached, deadline-bounded context.\n- Honor a short default TTL with negative caching and error cla\n[…]\nECHIncompatible/IsECHIncompatible: remember targets that stall or\n reject an ECH handshake so later connections skip ECH (10m TTL, self-heals).\n- Bound the ECH config cache and sweep expired entries.",
"is_bot": false,
"headline": "fix(dns): TTL + negative caching, singleflight DoChan, ECH incompatib…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-07-08T10:11:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "223b1acf094ce47853f7a6c8a26b4e4c9a3850b5",
"body": "* Prepare python binding for free-threaded\n\n* Optional faster json decoding via msgspec\n\n* Revert json changes",
"is_bot": false,
"headline": "Support Python 3.14t (Free-Threaded / No-GIL) (#80)",
"author_name": "Shinon",
"author_login": "Ristellise",
"committed_at": "2026-07-08T07:35:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "165b7124f3d5173f1d0085e0c059916a46c43b45",
"body": "Keep the repo free of newly-added test files per project preference. The\nclient-hint coherence + opt-out behaviour was verified before release; the\nlibrary build is unaffected (test-only removal).",
"is_bot": false,
"headline": "chore: drop added client-hint test files from the tree",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-05T18:31:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2e52267b6e2c9968d5934c84d5759ca7baa97bc5",
"body": "…ta.1]\n\nBeta of the UA client-hints coherence + opt-out work. Python uses the\nPEP 440 form (1.6.8b1); npm/.NET/clib use 1.6.8-beta.1.",
"is_bot": false,
"headline": "chore(release): bump version to 1.6.8-beta.1, cut CHANGELOG [1.6.8-be…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-05T18:26:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ada52f8fc89e41d9a9b215fd2fdfc56c16aac7ac",
"body": "High-entropy client hints (sec-ch-ua-full-version-list, -arch,\n-platform-version, -bitness, -model) were built from a stale hardcoded\ntable in session.getPlatform that capped at Chrome 145 with its own GREASE\nbrand token, independent of the per-version token the presets carry. So\nonce a host adverti\n[…]\neeps the trio. Both with runtime toggles.\n- Locks: fingerprint coherence test across every preset, session\n end-to-end tests for coherence, both opt-outs, streaming parity and\n override determinism.",
"is_bot": false,
"headline": "fix(fingerprint,session): coherent UA client hints + opt-out knobs",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-05T18:24:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "48c5e7c183ef8c47649861e85292f6ba9f172221",
"body": "…(1.6.7)\n\n- Preset reference + fingerprinting chapters + llms.txt/llms-full.txt: desktop\n chrome-latest aliases now resolve to chrome-149 (mobile stays 148); added\n chrome-149-{windows,linux,macos} rows (UA 149.0.0.0, sec-ch-ua brand rotation,\n TLS/H2 hashes identical to 148); reworded the 'when \n[…]\nd in\n all three bindings.\n- python binding chapter: ctor signature block now lists without_conditional_cache\n and disable_http3.\nAll verified against binding source; no docs/build artifacts touched.",
"is_bot": false,
"headline": "docs: pre-release sweep — Chrome 149 currency + binding API accuracy …",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-03T10:28:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "37c20949eb60198acf1d3a38088fee0a5f1debfd",
"body": "…de all(), CHANGELOG truth\n\nFrom the 1.6.7 pre-release audit:\n- Python streaming methods (get/put/delete/patch/request_stream) now accept and\n forward allow_redirects + disable_conditional_cache, matching post_stream and\n the Node binding. The clib RequestConfig/RequestOptions already carry both\n \n[…]\n end to end' to match the committed table-driven test plus the\n local e2e check; added the new top-level Go wrappers (NewManager/Manager,\n ValidateSessionFile, SetKeyLogWriter) to the Added section.",
"is_bot": false,
"headline": "fix(bindings,changelog): pre-release sweep — Python stream kwargs, No…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-03T10:28:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d8f5cd3f799d31f25de38309bfb0ffaf9d7ece4b",
"body": "Bumps all binding manifests + the clib version() string to 1.6.7\n(nodejs package.json + optionalDependencies + npm/* platform packages,\npython pyproject.toml + __init__.py, dotnet csproj, clib httpcloak.go) and\nrenames CHANGELOG [Unreleased] -> [1.6.7] - 2026-06-03 with a fresh empty\n[Unreleased] on\n[…]\n timeouts, #68 proxy H3/H2 racing, #70 redirect\nReferer) plus the Chrome 149 desktop preset and the previously-unreleased\nbinding work. No tag/push here; the native libraries are rebuilt by CI on tag.",
"is_bot": false,
"headline": "chore(release): bump version to 1.6.7, cut CHANGELOG [1.6.7]",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-03T09:45:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb4d6bc94edd7c72582893360b833ded7c55a634",
"body": "…atest\n\nChrome 149 stable. Verified on the wire (tls.peet.ws/api/all over H2) that 149's\nTLS + HTTP/2 fingerprint is byte-identical to 148: same JA4\n(t13d1516h2_8daaf6152771_d8a2da3f94cd), same peetprint, same Akamai H2. The only\nchange is two headers:\n - User-Agent -> Chrome/149.0.0.0\n - sec-ch-u\n[…]\n\nVerified: fingerprint suite green; on-the-wire check (temp) confirmed\nchrome-149-windows and chrome-latest send the 149 headers with the 148 JA4/\npeetprint/Akamai. No version bump or tag (prep only).",
"is_bot": false,
"headline": "feat(fingerprint): add Chrome 149 preset (desktop) + make it chrome-l…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-03T09:31:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52582ca7ac2575fc5d5222c995df3346bcfad3da",
"body": "…efault port (#70)",
"is_bot": false,
"headline": "docs(changelog): note Referer strips fragment/credentials and drops d…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-02T13:26:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a782ae28740972bba4bf5842a9bad4d6d683caf",
"body": "…versarial review\n\nPost-merge adversarial review of the #70 (4286f19) and #68 (1d2728a) work\nsurfaced three real issues in the committed code; all fixed here.\n\n1. (#70, high) Same-origin redirect Referer leaked the URL fragment and any\n userinfo credentials, and kept a redundant default port. redi\n[…]\n else unified URL), matching how the H3 transport is constructed.\n Removed the now-dead effectiveProxyURL.\n\nBuild + vet clean; session + transport suites green incl. -race; 14/14 referer\ncases pass.",
"is_bot": false,
"headline": "fix(redirect,transport): harden #70 Referer + #68 proxy paths from ad…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-02T13:26:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1d2728a7b58ee4155e0389ca67ecebaab59a08a8",
"body": "…st; proxy-aware H3 probe (#68)\n\nIn auto mode over a SOCKS5/MASQUE proxy, Do() tried HTTP/3 first and waited for\nthe QUIC handshake before considering HTTP/2. When the proxy accepts UDP\nASSOCIATE but does not relay QUIC datagrams (common with residential/mobile\nproxies), the H3 dial idled out (~5s) \n[…]\nrelay (tunneled, no direct dial). Regression-locked:\n neutering the connectViaProxy branch makes it fail with \"real-IP leak\".\n- Full transport suite green incl. -race; vet clean; session suite green.",
"is_bot": false,
"headline": "fix(transport): race H3/H2 over UDP-capable proxies instead of H3-fir…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-02T09:48:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4286f19fb646564e54bd1678a9b4894eb5e87f8c",
"body": "…#70)\n\nA session that followed a redirect carried whatever Referer was already on\nthe request (usually none) and only stripped it on an https->http\ndowngrade; it never synthesized a Referer from the previous URL the way a\nbrowser does. A server inspecting the Referer across a redirect chain could\nte\n[…]\nes Chrome today.\n\nVerified: 7-case unit test for the policy (session/redirect_referer_test.go)\nplus an end-to-end check against a redirecting server confirming the hop\nreceives Referer=<previous URL>.",
"is_bot": false,
"headline": "fix(redirect): synthesize browser-like Referer on each redirect hop (…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-06-02T09:30:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "37bf1fe27eab9420e9ea458c796da019ac314f67",
"body": "…ound the whole request\n\nA request through a proxy that accepts the tunnel but whose upstream never\nresponds (a stalled/dead residential IP, a slow CONNECT, a blackholed peer)\ncould ignore the caller's timeout and hang up to the transport's hardcoded 30s\ndefault before failing. Reproduced with a sta\n[…]\n, cookie, and ECH fixes still pass; cgo lib builds.\n\nFollow-up (separate): surface the already-typed Go transport errors across the\ncgo boundary so callers classify failures by kind instead of timing.",
"is_bot": false,
"headline": "fix(timeout): honor request + session timeouts on connection setup; b…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-31T21:58:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c9f1839c3e261efa8286d0c31f68ee8d7e24aa00",
"body": "A session kept alive for many hours could suddenly fail every HTTP/3\nrequest to a host with illegal_parameter rejections or handshake timeouts,\nall at the same minute across independent servers, recoverable only by a\nprocess restart.\n\nRoot cause: getECHConfig cached the per-host ECH config on the tr\n[…]\ncurrency race test stays race-clean; cgo lib builds. Separate from the\nalready-fixed H3 shared-spec race, which is the concurrent-corruption\ncontributor for callers sharing one session across workers.",
"is_bot": false,
"headline": "fix(transport): stop pinning stale ECH config on long-lived H3 sessions",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-31T21:19:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ae71ebc6f67d59df02c3fe9e20a2f69cbc17eab",
"body": "…er concurrency\n\nConcurrent requests on one Session with H3 enabled (the default) could drop\nPOST bodies, cancel, or hang. Reproduced with `go test -race`: the H3\ntransport cached one *utls.ClientHelloSpec on HTTP3Transport and handed that\nsame pointer to every QUIC dial. utls ApplyPreset mutates th\n[…]\n shipping regression locks: transport/http3_spec_test.go (structural:\ndistinct objects + order stability) and transport/http3_concurrency_test.go\n(local concurrent Connect, locked by `go test -race`).",
"is_bot": false,
"headline": "fix(transport): eliminate HTTP/3 shared-ClientHelloSpec data race und…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-31T17:56:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6e10ebd7700e49181dd530a3a8f002fc95c1b91e",
"body": "…n H2 and H3\n\nTwo independent users reported it and they were right: real Chrome and\nFirefox split the Cookie request header into one \"cookie\" field per\ncookie-pair on the wire (HPACK on H2, QPACK on H3) for compression\nefficiency, per RFC 9113 8.2.3. Confirmed directly from live\nChromium/QUICHE mai\n[…]\nome 3 / Firefox 3 / Safari 1 on both H2 and H3. Edge note: the H2\nencoder strips all spaces after ';' while Chrome strips exactly one;\nirrelevant for jar cookies (single space), logged as a follow-up.",
"is_bot": false,
"headline": "fix(fingerprint): crumble Cookie header per-pair for Chrome/Firefox o…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-31T17:35:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb6d40e301c5020a510b4b13262ef4e7c0a08ab8",
"body": "… + StreamResponse symmetry + CHANGELOG\n\nThree small but visible polish items closing out the per-binding gap audit.\n\ncgo\n- SessionConfig.DisableHTTP3 bool wired (json:\"disable_http3\"). Maps to\n httpcloak.WithDisableHTTP3() in the option pipeline.\n\nBindings\n- Python: ctor param disable_http3=False\n\n[…]\nll surface including SessionCacheBackend wiring + binary POST +\nchunked upload + stream history. All green. docs build green. em-dash\nsweep clean. go vet clean. .NET builds clean across net6/7/8/9/10.",
"is_bot": false,
"headline": "feat(bindings): explicit disable_http3 + .NET AOT-safe SetHeaderOrder…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T10:06:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2370906839916768fc9147645ea520cbe8387544",
"body": "Python has had stream_upload since the 5-entry upload state machine\nlanded in cgo; Node and .NET had no managed wrapper, so anyone uploading\na multi-GB file from those two bindings had to either fall back to\nin-memory byte[] / Buffer (defeating the point of streaming) or open a\nLocalProxy and pipe t\n[…]\n0..0xFF (4096 bytes total):\n- Node: status 200, sha256 round-trip match\n- .NET: status 200, sha256 round-trip match\nPython's existing stream_upload smoke-tested in the earlier async\nbinary fix commit.",
"is_bot": false,
"headline": "feat(bindings): chunked upload (Node uploadStream, .NET UploadStream)",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T09:54:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d625b8056b5ae9f655009b2e54717d359a7e18a7",
"body": "…erywhere\n\nThe observability chapter explicitly marked these four as Go-only across\nevery binding. The Go top-level had them at httpcloak.go:1011-1026 since\nforever; only the cgo plumbing was missing. Without these, anyone running\na long-lived session pool in Python / Node / .NET had no way to ask \"\n[…]\n false after\nclose/dispose. Docs updated: observability.md table reflects the new\nreality; intro prose corrected to call out GetTransport as the only\nremaining Go-only method (by design, not absence).",
"is_bot": false,
"headline": "feat(bindings): expose Session.Stats / IdleTime / IsActive / Touch ev…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T09:50:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "120bd79deb42765bf0819af50d8bf55f2362b7bc",
"body": "…sion)\n\nThe audit flagged LocalProxy.GetSession + ListSessions as Go-only with no\nC-API export, so every binding was missing session enumeration on the\nproxy registry. The use case is operational: \"what's registered right\nnow, which IDs are stale, garbage-collect dead entries on a long-running\nproxy\n[…]\nings: registered alpha + beta,\nlisted, probed nope == false, unregistered alpha, re-listed (just beta),\nre-probed alpha == false. cgo rebuild + copy done; .NET still builds\nclean across net6/7/8/9/10.",
"is_bot": false,
"headline": "feat(bindings): LocalProxy session enumeration (listSessions / hasSes…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T08:37:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb7bca7ea40e049d81d5c0c31e2e915a0772f2fc",
"body": "The .NET binding had zero managed surface for the distributed TLS session\ncache that Python and Node have shipped for months. Anyone running a\nmulti-process .NET deployment that wanted Redis-backed TLS resumption had\nto spin up a Go-side LocalProxy and route traffic through it; the doc\nexplicitly di\n[…]\nected\nfrom \"not exposed today\" to the real surface; the stale \"Presets lags\nthe registry\" claim replaced with the actual current shape now that\nChromeLatest / Chrome148 etc. are first-class constants.",
"is_bot": false,
"headline": "feat(dotnet): add SessionCacheBackend managed wrapper",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T08:31:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27344574b8e125991a5ad40789d69cc698e48363",
"body": "…de AbortSignal\n\nThe cgo lib has exposed httpcloak_cancel_request since 2026-01 but neither\nthe Python nor Node bindings hooked it up. Result: asyncio.wait_for would\nmark the Python Future as cancelled while the Go-side goroutine kept\nrunning (still doing DNS / TCP / TLS / HTTP work) and the respons\n[…]\norg/delay/5 cancels at\n 1.00s with the supplied reason; no teardown crash; session usable for a\n fresh GET after.\n\n.NET already had this wired (CancellationToken in Session.cs:104-115);\nnot touched.",
"is_bot": false,
"headline": "feat(bindings): wire httpcloak_cancel_request for Python asyncio + No…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T08:24:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee9667c2d769fad7ba73b5f4ebaf010c0ff8b4b0",
"body": "…ers expect\n\nThe .NET binding's async surface had a glaring hole: PostAsync, PutAsync\nand PatchAsync only accepted string body, while the sync surface had\nbyte[] and Stream overloads. Anyone uploading a file or any non-UTF-8\nbinary via PostAsync had to either lossy-convert to a string at the call\nsi\n[…]\nchoed back identical bytes)\n- WarmupAsync → completed\n\nBuilds clean across net6 / net7 / net8 / net9 / net10. Documented in the\n.NET binding chapter as the canonical async pattern for binary payloads.",
"is_bot": false,
"headline": "feat(dotnet): add the binary/Stream/multipart async overloads .NET us…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T08:18:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b9c308bdc6fce4c30b2cc8110308e275e45be3f",
"body": "…st, Firefox 148/latest, Safari latest\n\nThe Preset / Presets class in each binding lagged the runtime registry by\ntwo majors. Python topped out at CHROME_146 and FIREFOX_133; .NET at\nChrome146 and Firefox133; Node at CHROME_146 and FIREFOX_133. Anyone\nwanting chrome-148 or chrome-latest had to bypas\n[…]\n-side available_presets() registry. Backwards-compat aliases\n(IOS_CHROME_148, ANDROID_CHROME_LATEST, IOS_SAFARI_LATEST, etc.) added so\nthe old \"ios-chrome\" / \"android-chrome\" naming continues to work.",
"is_bot": false,
"headline": "feat(bindings): refresh Preset constants to cover Chrome 147/148/late…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T08:14:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ecce385585895a81de01c7a2782a042affdb03e",
"body": "Seven independent P0 issues across Python, Node and .NET, each caught by\nthe per-binding gap audit and verified end-to-end with binary-payload\nsmoke tests against httpbin (post + multipart, sha256 round-trip match).\n\nNode\n- setSessionIdentifier was an instant runtime crash: the JS method called\n th\n[…]\nss net6/7/8/9/10; docusaurus build green; smoke tests for both\nsync json POST + async json POST + async binary POST + async multipart\nall pass with 200 and byte-for-byte sha256 match where applicable.",
"is_bot": false,
"headline": "fix(bindings): kill the P0 silent bugs from the gap audit",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T08:10:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dcb1f0156bae84d625945fc2de75c7464f9a65fc",
"body": "Doc-audit pass against actual source. Every claim verified by grep before\nthe edit landed.\n\n.NET binding chapter\n- Ctor signature block at dotnet.md:39-72 was missing withoutConditionalCache\n even though Session.cs:46 has it. Added.\n- FastResponse signatures at dotnet.md:148-152 documented a string\n[…]\n declared so TS callers stop needing\n the (httpcloak as any).describePreset cast.\n\nBuild verified green. Em-dash sweep clean. No orphan references to the\nremoved lies remain anywhere under docs/docs.",
"is_bot": false,
"headline": "docs+typings: fix every documented-but-fabricated binding claim",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-12T07:57:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cdca097b92d42db02d9b7adef66bbce4db58368f",
"body": "… binding chapter\n\nThe feature shipped across all four bindings but the per-binding chapters\nonly documented the constructor option and an old `allowRedirects` ctor\narg. Each chapter now spells out the full surface: per-request kwargs on\nevery method, runtime mutators, and the WithoutConditionalCach\n[…]\ntable.\n - Adds runtime-toggle line under WithoutRedirects / WithRedirects so\n readers know the same controls also exist as runtime mutators.\n\nVerified: Docusaurus build green, em-dash sweep clean.",
"is_bot": false,
"headline": "docs(bindings): wire conditional-cache + redirect controls into every…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-11T08:19:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "533485e63c50e78f92dec7cee9c2d94270b48fab",
"body": "Missed by the prior commit. Other Python methods (get, put, delete, patch,\nhead, options, request, *_async) had the kwargs threaded through; post was\nthe lone gap. Caught by a runtime smoke test across every method.\n\nAdds the two kwargs to the post signature, forwards them when the timeout\npath dele\n[…]\nuest, and wires them into the options JSON when\nthe direct httpcloak_post_raw path runs.\n\nVerified end-to-end: 27/27 cases pass across sync + async on all 8 method\nfamilies against a local httpserver.",
"is_bot": false,
"headline": "python: wire allow_redirects + disable_conditional_cache on Session.post",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-11T07:51:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3bcb14153e9060ed99b07406aa82eeacb79fab4",
"body": "…on every method\n\nExtends the per-request override surface to every public request method in\nevery binding, not just Request / RequestAsync. The wire-format fields and\nsession-layer wiring already shipped in the prior commit; this round\nexposes them on the convenience methods so callers don't have t\n[…]\nthrough cgo as expected.\n- .NET dotnet build: 0 warnings, 0 errors across net6/7/8/9/10.\n- Go vet clean across full lib; Go feature tests still pass.\n- Docusaurus build green; no em-dashes introduced.",
"is_bot": false,
"headline": "feat(bindings): per-request allowRedirects + disableConditionalCache …",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-11T06:56:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e229fe9abb1a2acdc9c90464735a7cafecba6e1b",
"body": "Closes a long-standing gap reported by a C# user: the session unconditionally\ninjects If-None-Match / If-Modified-Since from a per-URL cache map, and the\nfollow-redirects flag was set-once at construction time. There was no way to\ntoggle either short of dropping the session. Adds three control surfa\n[…]\ntime mutators round-trip through cgo\n cleanly.\n- Node smoke test: same.\n- .NET dotnet build: 0 warnings, 0 errors across net6/7/8/9/10.\n- go vet clean on every core package.\n- Docusaurus build green.",
"is_bot": false,
"headline": "feat: per-request and runtime control for conditional cache + redirects",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-11T06:36:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "77347062c349897fe00f8435b54320096aae12d2",
"body": "…-status claims\n\nSix Opus agents re-audited the docs against source after the phase 9 fix\nsweep. They surfaced regressions introduced by phase 10 itself plus a few\nitems the earlier passes missed. Every claim below is verified against\nthe live source line referenced in the parenthetical citation.\n\nP\n[…]\ntruncated; the orphan \"Neither set\" row is back where it belongs\n inside the table.\n- reference/architecture.md: `proxy/masque.go` joins `proxy/socks5_*.go`\n in the internal/advanced classification.",
"is_bot": false,
"headline": "docs: phase 11 audit fixes — kill phase 10 fabrications, sync release…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T19:05:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "64617e9099d96932b9489de1980e49fdc04f5c2c",
"body": "…yLogWriter\n\nThree thin re-exports so the documented entry point matches the API\ncallers actually reach for:\n\n- httpcloak.Manager (type alias) and httpcloak.NewManager() wrap the\n session.Manager in-process registry. Worker pools and multi-tenant\n scrapers can now stay on the top-level package wit\n[…]\n multipart uploader, in-memory bytes.Buffer for tests, or\n anything else that isn't a file path.\n\nNo behaviour change; everything delegates to the existing implementations\nin session/ and transport/.",
"is_bot": false,
"headline": "httpcloak: top-level wrappers for Manager, ValidateSessionFile, SetKe…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T18:04:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9aaaaa334ce2835429c8c5fc1a31f3130d0371b6",
"body": "Mismatch fixes (verified against source before each edit):\n- reference/architecture.md: drop the daemon claim, fix the priority-table\n pointer to custom_preset.go, and rewrite the bindings line. The same\n stale \"daemon over stdin/stdout JSON\" docstring in protocol/types.go\n is also rewritten now \n[…]\n tcpDf on SessionOptions and update\nrefresh() to declare the optional switchProtocol arg that already\nworks at runtime.\n\nsidebars.ts: register dns-cache and session-manager under\nConnection Lifecycle.",
"is_bot": false,
"headline": "docs: phase 9 mismatch sweep + new tier 1/2 coverage chapters",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T18:04:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "953025ecb3925e37fe1a4008dc43d8c1a85151cb",
"body": "…aces\n\nSweep across the docs to fix code examples where Python / Node.js / .NET\nsnippets referenced kwargs, properties, types, or class names that don't\nmatch the actual binding (e.g. r.http_version → r.protocol, force_http2\n→ http_version=\"h2\", new SessionOptions{} → named-param ctor, ech_from\n→ ec\n[…]\nsion as thin delegations to the\ninner session.Session, so the observability chapter examples compile\nagainst the documented top-level entrypoint instead of forcing readers\ninto the session subpackage.",
"is_bot": false,
"headline": "docs: align cross-language code samples with the shipped binding surf…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T15:52:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e0710180d0af2ce0deb2f9c5ceb03f5522dae7b5",
"body": "…ntation section)",
"is_bot": false,
"headline": "readme: link to httpcloak.dev docs site (top-of-page pointer + Docume…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T14:15:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5505fbcf2bbe066694d9c2b0fd762d8cb65b475e",
"body": "… standard)",
"is_bot": false,
"headline": "docs: dry-clear voice rewrite across all sections (LocalProxy as gold…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T14:14:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "33315d9bfd97e9999238a1934b48e2e1bfbd5c53",
"body": "…r next pass)",
"is_bot": false,
"headline": "docs: rewrite local-proxy-server in dry-clear style (gold standard fo…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T07:31:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a1c40041e1b7b2f8fadc3c6d7d3e56da819d6a2",
"body": "…ller, real voice)",
"is_bot": false,
"headline": "docs: punch up local-proxy-server prose (kill 'Undici and friends' fi…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T06:51:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6579f3c5d70e4b2a57727268b6f15fdb50f0d25f",
"body": "…i story, special headers, session cache, multi-proxy)",
"is_bot": false,
"headline": "docs: rewrite local-proxy-server (4-lang server tabs, TLSOnly + Undic…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-10T06:44:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b404813b2cfb9b79f789fdefb853ea799f1d1433",
"body": "…ents\n\nNew chapters:\n- /connection-lifecycle/fork: Session.Fork(n) sibling sessions\n- /advanced-tls/cert-pinning: SPKI / cert-hash pinning, CertPinner API\n- /requests-and-responses/auth: BasicAuth / BearerAuth / DigestAuth\n- /requests-and-responses/hooks: PreRequest + PostResponse middleware\n- /reci\n[…]\nl.txt\n(67 concatenated chapters, ~430KB, no MDX overhead) follow the\nllmstxt.org convention so AI agents can crawl docs without rendering.\n\nSidebar updated with all 5 new chapters. Build passes clean.",
"is_bot": false,
"headline": "docs: add 5 audit-gap chapters + llms.txt and llms-full.txt for AI ag…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T22:34:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a69d21fb52f5e974ccba28face37fec45878c266",
"body": "…shes, contractions, punchy)",
"is_bot": false,
"headline": "docs: rewrite all 48 chapters in human, conversational tone (no em-da…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T22:27:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eabbefa1f7fd652bd2ba1aa0a215bb70e1c05048",
"body": "…in proper tone",
"is_bot": false,
"headline": "docs: strip em-dashes site-wide + rewrite TLS fingerprinting chapter …",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T22:17:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "524e7674b88d353f072d34a106267a82319132cc",
"body": null,
"is_bot": false,
"headline": "internal: keep root-level _test.go files local instead of shipping",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T22:10:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4b5b801f099a67c149ae648bf70147c32220b3b",
"body": "Every section moved from skeleton placeholders to real content with\n4-language code tabs (Go, Python, Node.js, .NET) where applicable.\nExamples tested against tls.peet.ws, httpbin.org, example.com from\neach binding. All 31 With* options enumerated in the reference table.\n\nBug findings during writing tracked in internal_docs/latest_bugs.md\nfor separate review (not fixed in this commit).",
"is_bot": false,
"headline": "docs: fill 48 chapters across 11 topic sections",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T21:38:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d623d8773a5b37c7f5af94b79dcac48c97ab5f9",
"body": null,
"is_bot": false,
"headline": "docs: drop future.v4 flag so .md files keep MDX (admonitions + tabs)",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T21:31:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "abda9a2b4906614cf3f861d41cbf8c1a68f8b90d",
"body": null,
"is_bot": false,
"headline": "docs: restructure to topic-grouped layout with 12 sections",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T21:10:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0549ab863c19ff33abd46b9c3fd2fe527141d48d",
"body": "Two compile-breaking bugs in the homepage Go example shipped with the\nscaffold commit:\n\n - httpcloak.NewSession takes a preset NAME (string), not a *Preset\n value, and returns *Session not (*Session, error). Was calling\n NewSession(fingerprint.Chrome148()) and assigning to (s, _).\n - Session\n[…]\nGet takes (ctx, url) — only two args. Was calling\n s.Get(ctx, url, nil).\n\nVerified by compiling the snippet against the local module — clean\nbuild. Python / Node.js / .NET examples already correct.",
"is_bot": false,
"headline": "docs: fix Go quickstart — wrong NewSession + Get signatures",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T20:01:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb9e62e3603cb3525ffaa152f3febfb3799ccd89",
"body": "Sets up the public docs site at docs/ ready for Vercel deploy at\nhttpcloak.dev. Single-version, no blog, four sections (concepts,\nreference, how-to, tutorial), homepage is a categorized feature\ncatalog linking to placeholder sections that will be filled in\nfollow-up commits.\n\nDemo Docusaurus content\n[…]\n run build` — zero errors, zero\nbroken-link warnings.\n\nInternal AI-context docs (the previous docs/ contents) were\nrelocated to internal_docs/codebase_reference/ in a prior step\nand remain gitignored.",
"is_bot": false,
"headline": "docs: Docusaurus scaffold with feature-catalog homepage",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T19:59:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e57405dfa969227355897667aad1c47370a5a1ca",
"body": "Documents the win32-arm64 optionalDependency drop — the entry was\nmismatched with CI's actual publish matrix, broke yarn classic\ninstalls across all platforms, and gave Windows-ARM64 users an\nobscure ENOENT-from-npm at install time instead of a clear runtime\nerror.",
"is_bot": false,
"headline": "changelog: note win32-arm64 npm cleanup in 1.6.6",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:55:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47565b6febd76fa5e9feac98a30fec3d186b799e",
"body": "…arn classic\n\nIssue surfaced after v1.6.5: the main npm package's optionalDependencies\nlisted @httpcloak/win32-arm64, but CI's npm-platform matrix only built\n[linux-x64, linux-arm64, darwin-x64, darwin-arm64, win32-x64] — so the\n@httpcloak/win32-arm64 package was never actually published to npm. The\n[…]\n64 to the CI matrix (needs an\naarch64-w64-mingw32-gcc cross-compiler runner or a native ARM64\nWindows GitHub-hosted runner), this commit can be reverted in one\nline and the npm/ subdirectory restored.",
"is_bot": false,
"headline": "bindings(nodejs): drop @httpcloak/win32-arm64 — never built, breaks y…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:55:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6a1715dd5fe4aecaade7a55ea363dff65ead9f1",
"body": "Bumps every binding / package version string to 1.6.6:\n\n - bindings/python/pyproject.toml + httpcloak/__init__.py\n - bindings/nodejs/package.json (+ optionalDependencies)\n - bindings/nodejs/npm/{linux,darwin,win32}-{x64,arm64}/package.json\n - bindings/dotnet/HttpCloak/HttpCloak.csproj\n - bindin\n[…]\nes.\n - WithLocalAddrIP(net.IP) ergonomic alias.\n - client.Client.DoStream cookie jar parity with Do.\n - IP_FREEBIND sockopt actually wired (was promised in the doc\n comment for years; now real).",
"is_bot": false,
"headline": "release: 1.6.6",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:49:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7309a3d081784c18ecad69b4323b7422f5967e0",
"body": "Promotes the [Unreleased] block to [1.6.6] - 2026-05-09 and folds\nin the v1.6.6 work:\n\n Added:\n - chrome-148-windows / -linux / -macos / -android presets;\n chrome-latest aliases bumped to 148; iOS already at 148 from v1.6.5\n - WithoutCookieJar() across all 4 bindings (Go / Python / Node \n[…]\nower-level client API were affected)\n - IP_FREEBIND is actually applied now when WithLocalAddress is\n set — the doc comment had been claiming it for years but\n the sockopt was never wired",
"is_bot": false,
"headline": "changelog: 1.6.6 — chrome-148, WithoutCookieJar, H3 PRIORITY_UPDATE fix",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:48:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c8fb2fc0604c5637e48d2ef58110e71e09214b6c",
"body": "Adds bool withoutCookieJar = false parameter to the Session\nconstructor, plus a SessionConfig.WithoutCookieJar property tagged\nwith JsonPropertyName(\"without_cookie_jar\") and\nJsonIgnore(WhenWritingDefault) so the JSON config stays clean for\nthe default-false case. XML doc updated.\n\nVerified live aga\n[…]\ne: GetCookies().Count == 1, server saw cookie\n - jar disabled: GetCookies().Count == 0, server saw {}\n - jar disabled + headers Dictionary with \"Cookie\" key:\n server saw {\"manual\": \"passthrough\"}",
"is_bot": false,
"headline": "bindings(dotnet): withoutCookieJar parameter on Session ctor",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:48:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "965f9be88c4dd6960712172abc04cd99f0f4fb94",
"body": "Adds withoutCookieJar?: boolean option to SessionOptions, forwarded\nto clib config as without_cookie_jar=true. JSDoc + .d.ts type\ndeclaration both updated. Caller-provided Cookie headers still\npass through regardless of this flag.\n\nVerified live against httpbin.org/cookies/set:\n\n - default mode: ge\n[…]\nngth == 1, server saw cookie\n - jar disabled: getCookies().length == 0, server saw {}\n - jar disabled + manual { headers: { Cookie: \"manual=passthrough\" } }:\n server saw {\"manual\": \"passthrough\"}",
"is_bot": false,
"headline": "bindings(nodejs): withoutCookieJar option on new Session()",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:48:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a9e0c67f0d20226b414c21c0add6931ff7c9277e",
"body": "Adds without_cookie_jar: bool = False keyword to Session.__init__,\nforwarded to the clib config as without_cookie_jar=true. Caller-\nprovided Cookie headers still pass through regardless of this flag.\n\nVerified live against httpbin.org/cookies/set:\n\n - default mode: jar size 1, server saw injected cookie on next req\n - jar disabled: jar size 0, server saw {} on next req\n - jar disabled + manual headers={\"Cookie\": \"manual=passthrough\"}:\n server saw {\"manual\": \"passthrough\"}",
"is_bot": false,
"headline": "bindings(python): without_cookie_jar=True kwarg on Session",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:48:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3df66b5caa90b21ecee9c2c0677a788bff4c6b4f",
"body": "Adds WithoutCookieJar bool field to the clib SessionConfig with JSON\nname \"without_cookie_jar\". When true, httpcloak_session_new appends\nhttpcloak.WithoutCookieJar() to the option chain so the lower layers\nskip the internal cookie jar entirely. Mirrors the existing pattern\nused for switch_protocol / enable_speculative_tls.\n\nThis is the binding-traversal layer for the WithoutCookieJar feature;\nlanguage-specific bindings (Python / Node.js / .NET) follow as\nseparate commits.",
"is_bot": false,
"headline": "clib: WithoutCookieJar plumbed via without_cookie_jar JSON config field",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:47:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fd8f4e7994b40250f157ce137b875ef291154efb",
"body": "Some applications maintain their own cookie store (database, shared\ncache across sessions, custom jar implementation) and want the lib\nto stay byte-transparent: the response's Set-Cookie headers should\nNOT auto-populate an internal jar, and the request's Cookie header\nshould NOT be auto-augmented wi\n[…]\nloak\n(based on gkopp13's original patch). Surface is identical;\nimplementation expanded to also guard the Set-Cookie storage\npaths in addition to the inject-on-request path the original\npatch covered.",
"is_bot": false,
"headline": "options: WithoutCookieJar() — disable internal cookie jar entirely",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:47:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "306d492f310121c489d5a347866d6671de9d4b15",
"body": "Picks up the H3 PRIORITY_UPDATE-on-control-stream fix:\n\n - prioritized_stream_id is now the actual request stream ID\n (typically 4 — Chrome's first request stream after the 0-RTT\n probe burns stream 0), not the hardcoded 0 that H3 fingerprint-\n ers silently dropped as malformed.\n\n - Prior\n[…]\num. Verified clean build and live-match against\nquic.browserleaks.com for chrome-148-{windows,linux,macos,android}\nand chrome-147-windows (h3_hash = ba909fc3dc419ea5c5b26c6323ac1879\nacross the board).",
"is_bot": false,
"headline": "deps: bump sardanioss/quic-go to v1.2.25",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:47:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "976e3454f6ef71e1af1ededd1a9128dfcfed09ca",
"body": "Captured against tls.peet.ws/api/all from real Chrome 148 on Windows\nand Android. Wire-level diff vs chrome-147 is just two header values:\n\n - User-Agent version: Chrome/147.0.0.0 → Chrome/148.0.0.0\n - sec-ch-ua brand list rotation:\n from: \"Google Chrome\";v=\"147\", \"Not.A/Brand\";v=\"8\", \"Chromi\n[…]\nst-linux /\n chrome-latest-macos / chrome-latest-android / android-\n chrome-latest now point to the 148 variants (was 147).\n - chrome-latest-ios stays at 148 (already pointed there from v1.6.5).",
"is_bot": false,
"headline": "fingerprint: chrome-148 desktop + android presets",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-09T14:47:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c54e6c5075d1f5d0e1dad73dcda2b6e071868f7",
"body": "… for next release\n\nThree Unreleased entries covering the work since v1.6.5:\n\n - Added: WithLocalAddrIP(net.IP) ergonomic alias for the existing\n WithLocalAddress(string) option.\n - Fixed: client.Client.DoStream now applies cookies from the jar\n and stores Set-Cookie from streamed responses \n[…]\nets IP_FREEBIND /\n IPV6_FREEBIND on Linux as the docs have always claimed —\n binding to non-local IPv6 addresses from a routed prefix works\n without CAP_NET_ADMIN or a global sysctl override.",
"is_bot": false,
"headline": "changelog: queue source-IP binding hardening + DoStream cookie parity…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-05T05:27:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "136bcc6e9839648c83afca8fb95a2875dcdf2439",
"body": "WithLocalAddress(addr) has been documented as \"Works with IP_FREEBIND\non Linux\" since v1.5.x, but the codebase never actually set the\nsockopt — only kernels with net.ipv4.ip_nonlocal_bind=1 globally\nenabled (or processes running with CAP_NET_ADMIN) ever picked up the\nbehaviour. Everyone else trying \n[…]\nttpcloak.go doc comment updated to describe what we actually do\nnow (\"freebind is automatically applied\") instead of the prior\n\"Works with IP_FREEBIND\" phrasing that pushed the work onto the\noperator.",
"is_bot": false,
"headline": "transport: actually wire IP_FREEBIND for non-local IPv6 source binding",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-05T05:27:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5491c85b60223c656579279245468e1324d7f56e",
"body": "Drop-in net.IP-typed sibling for WithLocalAddress(string). Exists so\ncallers who already hold a parsed net.IP (rotating from a pool, or\nreturned by some upstream IP-allocator) don't have to .String() →\nre-parse round-trip just to satisfy our string signature.\n\nSame internal storage (c.localAddr), so\n[…]\ns pin both the parity-with-string-form\nproperty (IPv4, IPv6, IPv4-mapped IPv6) and the nil-is-no-op\ncontract.\n\nAsked for in a v1.7.0 feature request, paired with the freebind\nsockopt fix that follows.",
"is_bot": false,
"headline": "options: WithLocalAddrIP(net.IP) ergonomic alias",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-05T05:26:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e3acf960b937a43c0098cd712f14ba2b94ec8b36",
"body": "The lower-level client.Client.DoStream skipped both halves of cookie\nhandling that client.Client.Do has done since the cookie jar shipped:\n\n - Apply cookies from the jar to the outgoing request (Do path:\n client.go:788-794) — without this, a session that authenticated\n via Do() and then issue\n[…]\n.NewTLSServer\ndoesn't speak HTTP/2 by default; the cookie behaviour is\nprotocol-independent. Verified the test catches the regression by\nreverting client/stream.go and confirming both assertions fail.",
"is_bot": false,
"headline": "client: DoStream cookie jar parity with Do",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-05-05T05:26:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a229c0351824713cda073bd6c4076d404831091f",
"body": "The repo go.mod has been carrying a leaked\n`replace github.com/sardanioss/quic-go => /home/saksham/own_tools/quic-go`\nsince 4c9fb5f (Mar 17) — added during local QUIC development and\nnever removed. Two consequences:\n\n 1. Public `go install github.com/sardanioss/httpcloak@vX.Y.Z` would\n fail for\n[…]\nd quic-go indirectly through the `replace ... => ../..`\nback to this module).\n\nSame precedent set by f25fbf8 (Bump sardanioss/udpbara to v1.1.0,\nremove local replace directive) when udpbara graduated.",
"is_bot": false,
"headline": "deps: bump sardanioss/quic-go to v1.2.24, drop local replace directive",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T18:29:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "038f7dd22ad5d8fefd15ae937155eece5d8eb7d3",
"body": "…rthand fix\n\nThree new entries under the [1.6.5] block:\n\n- Breaking Changes: get_cookies / get_cookie now return Cookie\n objects (Python: List[Cookie] / Optional[Cookie]; Node.js:\n Cookie[] / Cookie|null; .NET: List<Cookie> / Cookie?). Closes\n the v1.6.1 deprecation cycle. Migration snippets incl\n[…]\nits.\n\nThe 1.6.5 release was already a breaking refactor of the custom-\npreset internals via the fingerprint-importer rewrite, so the\ncookie close-out lands in this version rather than waiting for\n2.0.",
"is_bot": false,
"headline": "changelog: 1.6.5 — cookie API close-out, loader hardening, akamai sho…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T18:00:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c1b7b8eb1d33a5237c2cd4d126f91613a10a39a",
"body": "…ride\n\nTwo related custom-preset bugs from the v1.6.5 fingerprint-importer\nwork, both surfacing through the documented describe -> edit JSON ->\nload_preset_from_json workflow.\n\n1. JSON loader hardening (registry.go, custom_preset.go, clib).\n\n Three failure modes a user-supplied preset could hit si\n[…]\nnheritance loop) and on\nthe akamai overlay against a captured Chrome 147 fingerprint:\nWINDOW_UPDATE went from 15663105 (parent default) to 10485760\n(captured) and pseudo-order from m,a,s,p to m,p,a,s.",
"is_bot": false,
"headline": "fingerprint: harden JSON loader + akamai shorthand authoritative over…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T18:00:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a3e617f1801b00da7d16039f96a86393aac5815",
"body": "…cts with metadata\n\nCloses the v1.6.1 deprecation cycle on the flat {name: value} cookie\nreturn shape. The deprecation warning we shipped told callers to expect\nthis break in \"a future release\" — that release is 1.6.5 because the\nfingerprint-importer rewrite is already a breaking refactor of the\ncus\n[…]\n -> cookies.FirstOrDefault(c => c.Name == \"foo\")?.Value\n\nThe *_detailed variants stay as no-op aliases for source-compat; new\ncode should call the plain variants since they now return the same\nthing.",
"is_bot": false,
"headline": "bindings: cookie API close-out — get_cookies / get_cookie return obje…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T17:59:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ebf89d21280bded6b9469f21a53bedf5b4a06bfd",
"body": "Cuts the [Unreleased] block on 2026-04-30 and bumps every binding /\npackage version string to 1.6.5:\n\n - bindings/python/pyproject.toml + httpcloak/__init__.py\n - bindings/nodejs/package.json (+ optionalDependencies)\n - bindings/nodejs/npm/{linux,darwin,win32}-{x64,arm64}/package.json\n - binding\n[…]\nks), #53 (fetch_mode), #51 (.NET\n cookie MaxAge int64), #42 (binary response bodies), the\n X25519MLKEM768 hybrid-PQ JA3 handshake fix, and the QUIC\n google_connection_options ORIG correction.",
"is_bot": false,
"headline": "release: 1.6.5",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T17:08:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d7a3f8d4c61c19f9a9f58c71b0a803e834d24b7a",
"body": "Two README occurrences (~line 280 in the ECH feature section, ~line 813\nin the Session API summary) showed `ech_from=\"cloudflare.com\"`. Both\nwrong:\n\n - The actual Python kwarg is `ech_config_domain` (Session.__init__).\n - The value should be `cloudflare-ech.com`, the dedicated ECH config\n domai\n[…]\nrified after the fix: 3/3 attempts return `sni=encrypted` from\nthe Cloudflare trace endpoint, and the ECH ClientHello extension grows\nfrom the 186-byte GREASE size to 250 bytes of real config payload.",
"is_bot": false,
"headline": "docs: fix ECH example in README — correct kwarg name and config domain",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T16:59:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dcd8a5290c315cf6de07457d87f51e663240bd1b",
"body": "…entries\n\nREADME\n\n Add a new flagship Features entry \"Build Any Browser Fingerprint From\n JSON\" that walks through the capture -> JSON spec -> register -> use\n pattern in three steps with a runnable Python snippet, plus a\n per-binding API table for describe / load / unregister. The previous\n \"T\n[…]\nhe per-request timeout fix (Python /\n Node.js / .NET / clib) and the cache-control HPACK position\n regression. Update the tweak-fingerprint examples entry to point at\n the new README section names.",
"is_bot": false,
"headline": "docs: README adds Build Any Browser Fingerprint From JSON; CHANGELOG …",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T16:44:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8eeae39b58b9dbee8d376652e92d3bfc9018df32",
"body": "Four-recipe demonstration of the describe -> edit JSON -> load_preset_from_json\nworkflow:\n\n 1. Bump per-resource-type H2 stream priority (image: u=2 -> u=1).\n 2. Customize HPACK header order (insert x-tracking-id before priority).\n 3. Build a fresh preset from an externally-captured JA3 + Akamai pair.\n 4. Clean up registered presets via unregister_preset.\n\nEach example runs standalone, prints wire weights / header order / JA3\nhash matches as it goes, and exits cleanly.",
"is_bot": false,
"headline": "examples: tweak-fingerprint walkthrough across Python, Node.js, .NET",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T16:44:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "79d74b7f08bc646178c1bbff96ec8bf08d85c8c4",
"body": "…de.js, .NET\n\nThree coordinated bugs from one root cause: the clib request paths use\ndifferent timeout units (sync = milliseconds, async = seconds) but the\npublic binding API documents seconds everywhere.\n\n 1. Python Session.get(url, timeout=30) routed through Session.request()\n which forwarded\n[…]\nis now uniformly seconds, matching\nSession(timeout=). Verified end-to-end: s.get(url, timeout=30) returns\n200 promptly; s.get(url, timeout=1) against a 2-second-sleep endpoint\nfast-fails in ~1 second.",
"is_bot": false,
"headline": "bindings: per-request timeout now uniformly seconds across Python, No…",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T16:44:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44f74fb2cb1ae068bce3b540df73413bd7bddd9e",
"body": "Two intertwined wire-fingerprint corrections.\n\n1. Per-dest H2 stream priority (Issue #56). Real Chrome 147 emits a\n different RFC 7540 stream weight per Sec-Fetch-Dest, driven by an\n internal RFC 9218 urgency table. New PriorityTable map on\n H2FingerprintConfig carries {Urgency, Incremental, E\n[…]\n Safari/iOS variants, concurrent stream stress under -race, and a\nTestUserSuppliedCacheControl_RespectsHPACKPosition regression that\npins cache-control's slot relative to :path / sec-ch-ua / priority.",
"is_bot": false,
"headline": "fingerprint: per-resource-type H2 priority + correct HPACK header order",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T16:44:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6b46fd98b8acabd3c3cb994a165e859b8eb49f81",
"body": null,
"is_bot": false,
"headline": "gitignore: ignore custom-fingerprint and streaming scratch binaries",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-30T16:43:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1ed131554d58837bcfc7a832b04283ca33520aa",
"body": "Python and Node.js bindings silently enabled 3 retries on 5xx for\ncallers that never asked for them. Result was 4 requests per failed\ncall (1 + 3 retries on the default [429, 500, 502, 503, 504] list),\nfiring on POST/PUT/PATCH the same as GET — a real idempotency hazard\nbeyond just unexpected traffi\n[…]\nxplicit \"pass retry=3\nexplicitly for old behavior\" note. Other 5 places in Python that say\nretry=3 are docstring examples showing how to opt-in — they're now\ncorrectly illustrative of the new pattern.",
"is_bot": false,
"headline": "Fix #57: Python and Node.js retry now defaults to 0 (was 3)",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T09:25:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52bfc363d66cdf39dfc7c2425da1d15b0fc8d56f",
"body": "Replace specific vendor and target references with neutral phrasing\nacross both the Unreleased block and prior release notes:\n\n- Removed mentions of specific WAF / anti-bot vendor names — replaced\n with generic terms (\"passive H2 fingerprinters\", \"protocol mismatch\n signals\", etc.)\n- Removed menti\n[…]\ned surface and behavior\nonly. Forensic detail (target-site repros, vendor-attributable detection\nmechanisms, fingerprint hashes used during validation) lives in commit\nmessages and internal docs only.",
"is_bot": false,
"headline": "changelog: scrub vendor / target / tool names across all releases",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T09:08:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c0882c0c343888133955928cd407f041823296a",
"body": "Strip the per-platform \"byte-validated against …\" sourcing and the\ninline H2/H3 wire diffs from the Chrome 147 family and chrome-148-ios\nentries. Release-note prose now describes shipped surface only — what\nthe preset is, what alias resolves to it — without disclosing which\nfingerprinting endpoints \n[…]\norms were captured vs extrapolated, or\ninternal struct paths.\n\nSame applies to the Describe entry remaining content — kept neutral.\n\nThe detailed audits live in commit messages and internal docs only.",
"is_bot": false,
"headline": "changelog: trim Chrome 147 / 148-ios entries — drop validation forensics",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T09:04:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8bcd3aaf19db5de4e4d5c1dcc360dfadae7faa70",
"body": "Audited the shipped chrome-147-android preset against a live\ntls.peet.ws/api/all capture from real Chrome 147 on Android 10.\nAll wire bytes match: same JA4 as Chrome 147 Windows\n(t13d1516h2_8daaf6152771_d8a2da3f94cd), identical Akamai H2 fp hash,\nmatching sec-ch-ua brand string and User-Agent litera\n[…]\n wire is OS-independent on Chrome's network stack, so the\nAndroid extrapolation came out byte-correct by construction; this\ncommit just captures that the validation actually happened.\n\nNo code change.",
"is_bot": false,
"headline": "changelog: note chrome-147-android capture validation",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T09:00:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0bdb3075f4a8704efe36f6c773f0051bdcdc493",
"body": "Chrome 148 ships on iOS first this cycle (Apple's release cadence),\nand the diff vs chrome-146-ios is bigger than the Windows 146→147 bump:\nHTTP/2 SettingsOrder reorders + drops MAX_FRAME_SIZE, pseudo-order\nswaps p↔a, ConnectionWindowUpdate changes, navigation header set adds\npriority + drops sec-fe\n[…]\nome-148-ios.\n\nTests: TestEmbedded_AllJSONsParseAndBuild + TestEmbedded_RoundTripDescribe\nboth extend to chrome-148-ios. 63/63 presets pass strict Describe\nround-trip in Python + Node.js binding tests.",
"is_bot": false,
"headline": "fingerprint: add chrome-148-ios with Safari-reduced QUIC flow control",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T05:51:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ef267650cb2a55ef762f504e78d06e59ac48779c",
"body": "Adds Chrome 147 JSON presets for the remaining four platforms and wires\nthe *-latest aliases through to them.\n\n- chrome-147-linux + chrome-147-macos: same pattern as Windows — UA OS\n string + sec-ch-ua-platform swap, identical sec-ch-ua brand string\n (Chrome's brand list is browser-internal, OS-in\n[…]\n.\n\nWire smoke-check via Get(): chrome-latest on Linux returns\nchrome-147-linux with the captured Chrome 147 sec-ch-ua bytes; iOS\ncorrectly emits empty sec-ch-ua (WebKit limitation inherited from 146).",
"is_bot": false,
"headline": "fingerprint: complete Chrome 147 family + bump all chrome-latest aliases",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T05:32:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "616c234aa93943236068c0b34bce6887c6a2e462",
"body": "Adds //go:embed-driven preset registry: any JSON file dropped in\nfingerprint/embedded/ is auto-registered at package init via the standard\nLoadPresetFromJSON + BuildPreset path. Failures (malformed JSON, unknown\nbased_on, etc.) are logged and skipped so a single bad file can never\nprevent the librar\n[…]\ne-147-windows emits the captured\nsec-ch-ua bytes on the wire with Chrome 146 TLS underneath.\n\nLinux/macOS variants and chrome-latest alias bump pending — will\nfollow once those captures are confirmed.",
"is_bot": false,
"headline": "fingerprint: ship embedded JSON registry + chrome-147-windows",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T05:21:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b95f1bae5177e1811470c4ebcf08192f0bf679b",
"body": "Single Unreleased entry covering the full Describe rollout:\n- fingerprint.Describe(name) → flat JSON with strict byte-equal\n round-trip contract (Phase 1.1, 1.2, 1.3)\n- ClientHelloIDName inverse lookup with -auto-alias precedence\n- httpcloak_describe_preset clib export with httpcloak_free_string\n \n[…]\nl\n 53 built-in presets in each language\n\nEmbedded JSON registry (Phase 3) and Chrome 147 (Phase 4) deferred\nto a follow-up release; will be added when the user provides the\nChrome 147 H2 + H3 preset.",
"is_bot": false,
"headline": "changelog: document Describe API across Go, clib, and all bindings",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T05:11:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8578560539b0ee8ce45064b21a0c5a563b6bb38e",
"body": "Adds the .NET surface for httpcloak_describe_preset alongside the\nexisting CustomPresets.{LoadFromFile,LoadFromJson,Unregister} statics.\n\nImplementation marshals the C string via Native.PtrToStringAndFree\n(same pattern as LoadFromJson) and validates the result with\nJsonDocument.Parse. The error enve\n[…]\nd via internal_tests/dotnet/TestDescribePreset.csproj:\n53/53 presets round-trip byte-equal through Describe → LoadFromJson →\nDescribe.\n\nBuilds clean across net6.0/net7.0/net8.0/net9.0/net10.0 targets.",
"is_bot": false,
"headline": "dotnet: add CustomPresets.Describe static method",
"author_name": "Saksham Solanki",
"author_login": "sardanioss",
"committed_at": "2026-04-28T05:08:07Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 48,
"commits_last_year": 671,
"latest_release_at": "2026-07-12T22:40:08Z",
"latest_release_tag": "v1.6.8",
"releases_from_tags": true,
"days_since_last_push": 5,
"active_weeks_last_year": 20,
"days_since_latest_release": 10,
"mean_days_between_releases": 15.7
},
"community": {
"has_readme": false,
"has_license": false,
"has_description": false,
"has_contributing": false,
"health_percentage": null,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/sardanioss/httpcloak",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": false,
"registry_url": "https://pkg.go.dev/github.com/sardanioss/httpcloak",
"is_deprecated": false,
"latest_version": "v1.6.8",
"repository_url": "https://github.com/sardanioss/httpcloak",
"versions_count": 53,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-12T22:40:08Z",
"latest_version_yanked": null,
"days_since_latest_publish": 10
},
{
"name": "httpcloak",
"exists": true,
"license": "MIT",
"keywords": [
"http",
"http2",
"http3",
"quic",
"tls",
"fingerprint",
"browser",
"scraping",
"bot-detection"
],
"ecosystem": "npm",
"matches_repo": false,
"registry_url": "https://www.npmjs.com/package/httpcloak",
"is_deprecated": false,
"latest_version": "1.6.8",
"repository_url": "https://github.com/sardanioss/httpcloak",
"versions_count": 44,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 5573,
"first_published_at": "2026-01-06T13:02:09.729000Z",
"latest_published_at": "2026-07-12T22:46:35.950000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 10
},
{
"name": "httpcloak",
"exists": true,
"license": "MIT",
"keywords": [
"http",
"http2",
"http3",
"quic",
"tls",
"fingerprint",
"browser",
"scraping",
"Development Status :: 4 - Beta",
"Intended Audience :: Developers",
"License :: OSI Approved :: MIT License",
"Operating System :: OS Independent",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.8",
"Programming Language :: Python :: 3.9",
"Topic :: Internet :: WWW/HTTP",
"Topic :: Software Development :: Libraries :: Python Modules"
],
"ecosystem": "pypi",
"matches_repo": false,
"registry_url": "https://pypi.org/project/httpcloak/",
"is_deprecated": false,
"latest_version": "1.6.8",
"repository_url": "https://github.com/sardanioss/httpcloak",
"versions_count": 46,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 36087,
"first_published_at": "2026-01-06T13:01:57.637043Z",
"latest_published_at": "2026-07-12T22:46:27.121064Z",
"latest_version_yanked": null,
"days_since_latest_publish": 10
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples",
"recipes"
],
"has_llms_txt": true,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"bindings/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"docs/tsconfig.json"
],
"toolchain_manifests": [
"bindings/clib/go.mod",
"bindings/dotnet/HttpCloak.Tests/HttpCloak.Tests.csproj",
"bindings/dotnet/HttpCloak/HttpCloak.csproj",
"go.mod"
],
"largest_source_bytes": 200051,
"source_files_sampled": 188,
"oversized_source_files": 9,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"docs/package.json",
"go.mod"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/andybalholm/brotli",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.0"
},
{
"name": "github.com/klauspost/compress",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.18.2"
},
{
"name": "github.com/miekg/dns",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.69"
},
{
"name": "github.com/sardanioss/http",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.0"
},
{
"name": "github.com/sardanioss/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.6"
},
{
"name": "github.com/sardanioss/quic-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.25"
},
{
"name": "github.com/sardanioss/udpbara",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/sardanioss/utls",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.3"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.48.0"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.19.0"
},
{
"name": "github.com/sardanioss/httpcloak",
"manifest": "bindings/clib/go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.4"
},
{
"name": "koffi",
"manifest": "bindings/nodejs/package.json",
"ecosystem": "npm",
"version_constraint": "^2.9.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "sardanioss",
"commits": 667,
"avatar_url": "https://avatars.githubusercontent.com/u/66795395?v=4"
},
{
"type": "User",
"login": "headnode-ai",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/243331759?v=4"
},
{
"type": "User",
"login": "marioparaschiv",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/98427312?v=4"
},
{
"type": "User",
"login": "Ristellise",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/7894419?v=4"
}
],
"contributors_sampled": 4,
"top_contributor_share": 0.994
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"bindings.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "internal error: Client.Actions.ListWorkflowRunsByFileName: internal error: ListWorkflowRunsByFileName: GET https://api.github.com/repos/10/httpcloak/actions/workflows/bindings.yml/runs?status=success: 404 Not Found []",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "49 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "257363f29c0d74729979d4140f34a13d5ad769b6",
"ran_at": "2026-07-23T18:24:33Z",
"aggregate_score": 2.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": null,
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": null,
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/10/httpcloak",
"host": "github.com",
"name": "httpcloak",
"owner": "10"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 39,
"inputs": {
"security": 22,
"vitality": 76,
"community": 12,
"governance": 22,
"engineering": 56
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 76,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"commits_last_year": 671,
"human_commit_share": 1,
"days_since_last_push": 5,
"active_weeks_last_year": 20
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "20/52 weeks with commits",
"points": 13.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 20
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "671 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 671
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 88,
"inputs": {
"releases_count": 48,
"latest_release_tag": "v1.6.8",
"releases_from_tags": true,
"days_since_latest_release": 10,
"mean_days_between_releases": 15.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "48 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 48
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 10 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 10
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~15.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 15.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 12,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_readme": false,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "critical",
"name": "Sustainability & Governance",
"value": 22,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 14,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 4,
"top_contributor_share": 0.994
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 99% of commits",
"points": 0.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 99
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "4 contributors",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 4
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 53,
"inputs": {
"followers": 35,
"owner_type": "User",
"is_verified": null,
"owner_login": "10",
"public_repos": 18,
"account_age_days": 2697
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "35 followers of 10",
"points": 11.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 35,
"login": "10"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "18 public repos, account ~7 yr old",
"points": 21.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 18
}
},
{
"code": "account_age_years",
"params": {
"years": 7
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 56,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://httpcloak.dev",
"has_readme": false,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://httpcloak.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "critical",
"name": "Security",
"value": 22,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 22,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 2.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "internal error: Client.Actions.ListWorkflowRunsByFileName: internal error: ListWorkflowRunsByFileName: GET https://api.github.com/repos/10/httpcloak/actions/workflows/bindings.yml/runs?status=success: 404 Not Found []",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "49 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 61,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "moderate",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"has_llms_txt": true,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": "llms.txt present",
"points": 15,
"status": "met",
"details": [
{
"code": "llms_txt_present",
"params": {}
}
],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"bindings/Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"docs/tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [
"bindings/clib/go.mod",
"bindings/dotnet/HttpCloak.Tests/HttpCloak.Tests.csproj",
"bindings/dotnet/HttpCloak/HttpCloak.csproj",
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "bindings/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "bindings/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "docs/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 97,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 200051,
"source_files_sampled": 188,
"oversized_source_files": 9
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "9/188 source files over 60KB",
"points": 52.4,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 188,
"oversized": 9
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples",
"recipes"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples, recipes",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples, recipes"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Community profile unavailable",
"go package 'github.com/sardanioss/httpcloak' points at a different repository (https://github.com/sardanioss/httpcloak); excluded from ecosystem scoring",
"npm package 'httpcloak' points at a different repository (https://github.com/sardanioss/httpcloak); excluded from ecosystem scoring",
"pypi package 'httpcloak' points at a different repository (https://github.com/sardanioss/httpcloak); excluded from ecosystem scoring",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"deps.dev does not index npm:httpcloak@1.6.8; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-23T18:24:39.194657Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/1/10/httpcloak.svg",
"full_name": "10/httpcloak",
"license_state": "standard",
"license_spdx": "MIT"
}