Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"a11y",
"accessibility",
"automated-testing",
"playwright",
"regression-testing",
"security-audit",
"seo",
"testing",
"web-crawler",
"web-testing"
],
"is_fork": false,
"size_kb": 211,
"has_wiki": true,
"homepage": "https://aegisrunner.com",
"languages": {
"Dockerfile": 3695,
"JavaScript": 703616
},
"pushed_at": "2026-07-20T04:38:31Z",
"created_at": "2026-02-18T06:55:02Z",
"owner_type": "User",
"updated_at": "2026-07-20T04:38:34Z",
"description": "AegisRunner crawls any website from a single URL, discovers every page, form, and interaction, then uses AI to generate a complete Playwright test suite. Also runs accessibility, SEO, security, and performance audits on every page — no recording, no scripting, no setup.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "JavaScript",
"significant_languages": [
"JavaScript"
]
},
"owner": {
"blog": "https://aegisrunner.com",
"name": "Aegis Runner",
"type": "User",
"login": "Aegis-Runner",
"company": "AegisRunner",
"location": null,
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/262282406?v=4",
"created_at": "2026-02-18T06:53:06Z",
"is_verified": null,
"public_repos": 2,
"account_age_days": 157
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "cli-v1.0.28",
"kind": "other",
"published_at": "2026-07-19T17:45:59Z"
},
{
"tag": "cli-v1.0.27",
"kind": "other",
"published_at": "2026-07-19T11:57:57Z"
},
{
"tag": "next-v0.4.2",
"kind": "other",
"published_at": "2026-07-19T09:56:37Z"
},
{
"tag": "nuxt-v0.4.3",
"kind": "other",
"published_at": "2026-07-19T09:56:37Z"
},
{
"tag": "vite-v0.4.2",
"kind": "other",
"published_at": "2026-07-19T09:56:34Z"
},
{
"tag": "cli-v1.0.26",
"kind": "other",
"published_at": "2026-07-19T08:07:57Z"
},
{
"tag": "cli-v1.0.25",
"kind": "other",
"published_at": "2026-07-19T03:37:21Z"
},
{
"tag": "vite-v0.4.1",
"kind": "other",
"published_at": "2026-07-19T03:37:19Z"
},
{
"tag": "cli-v1.0.24",
"kind": "other",
"published_at": "2026-07-18T05:15:39Z"
},
{
"tag": "cli-v1.0.23",
"kind": "other",
"published_at": "2026-07-18T04:41:43Z"
},
{
"tag": "nuxt-v0.4.2",
"kind": "other",
"published_at": "2026-07-18T04:41:39Z"
},
{
"tag": "cli-v1.0.22",
"kind": "other",
"published_at": "2026-07-18T04:29:03Z"
},
{
"tag": "next-v0.4.1",
"kind": "other",
"published_at": "2026-07-17T14:52:26Z"
},
{
"tag": "next-v0.4.0",
"kind": "other",
"published_at": "2026-07-17T13:58:43Z"
},
{
"tag": "nuxt-v0.4.0",
"kind": "other",
"published_at": "2026-07-17T13:58:43Z"
},
{
"tag": "vite-v0.4.0",
"kind": "other",
"published_at": "2026-07-17T13:58:41Z"
},
{
"tag": "cli-v1.0.21",
"kind": "other",
"published_at": "2026-07-17T13:57:48Z"
},
{
"tag": "next-v0.3.0",
"kind": "other",
"published_at": "2026-07-17T12:31:57Z"
},
{
"tag": "nuxt-v0.3.0",
"kind": "other",
"published_at": "2026-07-17T12:19:45Z"
},
{
"tag": "vite-v0.3.0",
"kind": "other",
"published_at": "2026-07-17T12:19:39Z"
},
{
"tag": "cli-v1.0.20",
"kind": "other",
"published_at": "2026-07-17T12:18:29Z"
},
{
"tag": "cli-v1.0.19",
"kind": "other",
"published_at": "2026-07-17T11:55:04Z"
},
{
"tag": "cli-v1.0.18",
"kind": "other",
"published_at": "2026-07-17T09:13:56Z"
},
{
"tag": "cli-v1.0.17",
"kind": "other",
"published_at": "2026-07-16T09:13:48Z"
},
{
"tag": "next-v0.2.2",
"kind": "other",
"published_at": "2026-07-16T07:47:39Z"
},
{
"tag": "cli-v1.0.16",
"kind": "other",
"published_at": "2026-07-16T07:46:42Z"
},
{
"tag": "nuxt-v0.2.1",
"kind": "other",
"published_at": "2026-07-16T06:15:43Z"
},
{
"tag": "next-v0.2.1",
"kind": "other",
"published_at": "2026-07-16T06:15:43Z"
},
{
"tag": "vite-v0.2.1",
"kind": "other",
"published_at": "2026-07-16T06:15:41Z"
},
{
"tag": "cli-v1.0.15",
"kind": "other",
"published_at": "2026-07-16T06:15:01Z"
},
{
"tag": "cli-v1.0.14",
"kind": "other",
"published_at": "2026-07-16T04:51:31Z"
},
{
"tag": "cli-v1.0.13",
"kind": "other",
"published_at": "2026-07-15T17:29:52Z"
},
{
"tag": "next-v0.2.0",
"kind": "other",
"published_at": "2026-07-15T10:06:17Z"
},
{
"tag": "vite-v0.2.0",
"kind": "other",
"published_at": "2026-07-15T10:06:15Z"
},
{
"tag": "nuxt-v0.2.0",
"kind": "other",
"published_at": "2026-07-15T10:06:15Z"
},
{
"tag": "cli-v1.0.12",
"kind": "other",
"published_at": "2026-07-15T10:02:21Z"
},
{
"tag": "cli-v1.0.11",
"kind": "other",
"published_at": "2026-07-15T09:40:29Z"
},
{
"tag": "next-v0.1.0",
"kind": "other",
"published_at": "2026-07-15T09:12:48Z"
},
{
"tag": "nuxt-v0.1.0",
"kind": "other",
"published_at": "2026-07-15T08:46:24Z"
},
{
"tag": "vite-v0.1.0",
"kind": "other",
"published_at": "2026-07-15T08:14:34Z"
},
{
"tag": "cli-v1.0.10",
"kind": "other",
"published_at": "2026-07-15T08:05:40Z"
},
{
"tag": "cli-v1.0.9",
"kind": "other",
"published_at": "2026-07-15T04:52:37Z"
},
{
"tag": "cli-v1.0.8",
"kind": "other",
"published_at": "2026-07-14T17:17:19Z"
},
{
"tag": "cli-v1.0.7",
"kind": "other",
"published_at": "2026-07-14T15:06:04Z"
}
],
"recent_commits": [
{
"oid": "21f7f836bf214983c901657c78bd1c2964802907",
"body": "…backticks)\n\nThe run: line was a plain YAML scalar containing ': ' (Please switch: npx) which\nbroke parsing, so GitHub never registered the workflow_dispatch trigger (dispatch\n422'd; push events failed with 'workflow file issue'). Also the notice had\nbackticks inside a double-quoted shell string -> \n[…]\nand substitution. Switch to\na block scalar and a backtick-free message.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QZk25Y6jd2KBsMZWqLtoxQ",
"is_bot": false,
"headline": "fix(ci): make deprecate-scan-runner workflow valid (block scalar, no …",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-20T04:38:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "24f5f976219211845d99a1c2aacc9cc4c4da96ef",
"body": "…progress bridge\n\n- Widget: the running scope button now stays highlighted (full-opacity cyan ring)\n while others dim, instead of the static primary button always looking active.\n- Rename 'Crawling · N pages' -> 'Scanning · N pages' to match the web app.\n- Bridge the post-crawl gap: show 'Scan comp\n[…]\n1-2 min\n the AI goal pipeline spends turning the scan into test cases.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QZk25Y6jd2KBsMZWqLtoxQ",
"is_bot": false,
"headline": "cli 1.0.28: widget active-scope highlight + Scanning copy + test-gen …",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-19T17:45:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "930a93e3bbfc0d84b394ecbfed10f38339709a7a",
"body": "…he pinning a broken runner)\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "cli 1.0.27: widget spawns @aegisrunner/runner@latest (avoid stale-cac…",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-19T11:57:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0e172f5ba3c52154048a4b31ba18bcd38152439e",
"body": "@aegisrunner/runner/runnerExecutor.mjs imports @axe-core/playwright, pixelmatch,\npngjs and sharp, but package.json only declared playwright — so a fresh\n`npx @aegisrunner/runner` (the framework widget's local runner) crashed on\nstartup with ERR_MODULE_NOT_FOUND '@axe-core/playwright' and exited befo\n[…]\nited before it came online'). The\nDocker image bundled them so only the npm path was affected. Added all four at\nthe crawler's versions.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "runner 1.2.1: declare the deps it actually imports (fixes npx crash)",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-19T11:53:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f59f2f3e27bea61b73820319b8326c0a7d3f05ef",
"body": "vite/nuxt/next READMEs now show `token: process.env.AEGIS_TOKEN` in the config\nexample and a 'Your token' section covering `aegis login` (recommended),\nAEGIS_TOKEN env, and the token option — with a don't-commit-the-literal warning.\nReact/Vue on Vite use @aegisrunner/vite; React on Next, Vue on Nuxt. Patch bumps\nto republish the READMEs to npm.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "docs: show the CI token in each plugin config + aegis login",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-19T09:56:00Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c781db22083b548e0dc83c67d79a8a636df80fd3",
"body": "The floating widget's shield used a near-black fill on the near-black button\nwith only a thin cyan outline — technically rendered but easy to miss. Now a\nsolid cyan shield with a dark check + svg{display:block}.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "cli 1.0.26: make the dev-widget shield icon clearly visible (solid cyan)",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-19T08:07:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "47130ee9f5710f8c9d56febe5a55b7481d1a2fe0",
"body": "…rts)\n\n- New lib/config.mjs resolves the token from --token > AEGIS_TOKEN > a saved\n config file (~/.config/aegis/config.json via 'aegis login', or a project\n .aegisrc/aegis.json). Every command AND the dev widget/plugins (devSession)\n read it, so the in-app widget works without exporting a token\n[…]\ned (flag/env still win).\n- vite 0.4.1: require @aegisrunner/cli ^1.0.25 so 'npm i @aegisrunner/vite@latest'\n delivers the token config.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
"is_bot": false,
"headline": "cli 1.0.25: aegis login (save CI token once, no more AEGIS_TOKEN expo…",
"author_name": "Aegis-Runner",
"author_login": null,
"committed_at": "2026-07-19T03:36:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "70704d96f8cf59da2f30c4a8eb5598c2c2ac4d48",
"body": "…unner/runner",
"is_bot": false,
"headline": "ci: one-shot workflow to deprecate @aegisrunner/scan-runner → @aegisr…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-18T05:16:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e981647fbb6a88dbc3e1c7196499d030cc4e9c53",
"body": "…sede scan-runner\n\n@aegisrunner/runner is the new canonical npm name for the local executor (runs\nboth `aegis scan --local` and `aegis run --local`). @aegisrunner/scan-runner is\nkept published + deprecated → it (non-breaking). CLI + plugins now spawn\n@aegisrunner/runner via npx (command names + the aegisrunner1/scan-runner Docker\nimage unchanged). release-runner.yml publishes it on runner-v* tags (npm-only).",
"is_bot": false,
"headline": "runner: publish @aegisrunner/runner (canonical local executor), super…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-18T05:14:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "704c9d5727a98462d2499f62167f951859c802c6",
"body": "The in-app shield gains a \"Run generated tests\" action alongside Test this page /\nTest whole site: it runs the latest generated suite (execute, not scan) — locally\non your machine in local mode, or via the tunnel otherwise — with live status and\na results link. cli 1.0.23 (devSession.runTests + /__aegis/run); nuxt 0.4.2 adds\nthe /__aegis/run dev handler. vite/next pick it up via createAegisControl.",
"is_bot": false,
"headline": "widget: \"Run generated tests\" button on the shield",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-18T04:41:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ce2917a882ee254d603a91aeb478989605f1066",
"body": "…unner\n\nRoutes the run to a connected local runner (browser on your machine) via the run\nbroker instead of the cloud crawler — for localhost/private apps. Credentials\ncome from the runner's env, never the cloud.",
"is_bot": false,
"headline": "cli 1.0.22: `aegis run --local` — execute a run on your self-hosted r…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-18T04:28:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ba446ca97682fe95c94e1c1eeeaa0e1e86fd6ab",
"body": "… suites\n\nThe local executor now claims BOTH scan jobs and RUN jobs: it ships the brain-free\nrun engine and executes generated suites on the customer's machine against\nlocalhost, streaming per-case results back. Verdicts are identical to a cloud run\n(validated: 0/6 mismatches incl. needs_review). Bundle is brain-free (no crawl AI)\nand holds no cloud secrets (0 @aws-sdk; credentials come from the runner's env).",
"is_bot": false,
"headline": "scan-runner 1.2.0: unified runner — also executes `aegis run --local`…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-18T04:28:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84a2abf402b29b75642b7c66b610bd5ec02ae45b",
"body": "Two real-world breakages in local mode (the plugin default):\n\n- @aegisrunner/scan-runner 1.1.1: the transitive Playwright postinstall can be\n skipped (npx cache reuse, --ignore-scripts) leaving the runner to crash on\n first scan with 'Executable doesn't exist … chrome-headless-shell'. bin.mjs now\n\n[…]\nfig key is present. The plugin now detects Turbopack\n and skips the webpack widget-injection (the /__aegis rewrite still serves the\n widget; documented one-line <script> fallback + a one-time hint).",
"is_bot": false,
"headline": "fix(local): scan-runner self-installs the browser; next guards Turbopack",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T14:52:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b891bcc0e863bc437299318cf31ee89aca39dbe6",
"body": "The vite/nuxt/next dev plugins now run the browser ON the developer's machine by\ndefault via @aegisrunner/scan-runner, scanning http://localhost directly with no\ntunnel and no cloud relay — the fastest, most reliable path for big apps, and the\napp + credentials never leave the machine. Tunnel mode s\n[…]\nd.\n- cli 1.0.21 (ships the two new libs); plugins 0.4.0 (cli dep ^1.0.21).\n\nRequires backend support to accept a localhost baseUrl on a local scan regardless\nof the project's public domain (deployed).",
"is_bot": false,
"headline": "plugins: local execution by default (runner:'local') — no tunnel",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T13:57:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3e97631ae713c0eb4960476c641311c5b2d6f533",
"body": "Next has no dev-middleware/head hook, so the plugin runs a tiny control server\n(deterministic per-project port), proxies /__aegis/* to it via a dev rewrite,\nand injects the widget into the client bundle via a webpack entry (with a\ndocumented <script> fallback). Same shared widget as vite/nuxt. cli dep ^1.0.20.",
"is_bot": false,
"headline": "next: in-app AegisRunner widget (test page/site/creds) — 0.3.0",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T12:31:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ced19e26de4cdfb82b4b8316395a2bb641bb780",
"body": "…/creds)\n\nA floating shield injected into the dev app opens a panel to Test this page,\nTest the whole site, or set login credentials — with live progress + a results\nlink, without leaving the browser. Shared widget + control protocol live in\n@aegisrunner/cli (lib/devWidget.mjs + lib/aegisWidget.client.js); the vite and\nnuxt plugins mount the control and inject the widget. cli 1.0.20; vite+nuxt 0.3.0.\n(Next keeps keypress — its config-wrapper has no dev-middleware/head hook.)",
"is_bot": false,
"headline": "dev widget: in-app AegisRunner shield for vite + nuxt (test page/site…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T12:18:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "14bfc5db4cfdc11c093ff40303313de2cc80a5ef",
"body": "Delegates to @aegisrunner/scan-runner via npx so the zero-dependency CLI stays\nlight while 'scan --local' gets a no-Docker runner: `aegis scan-runner`.",
"is_bot": false,
"headline": "cli: add 'aegis scan-runner' — Docker-free web executor (1.0.19)",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T11:54:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "576e689f6aed486ff795d8a9235c99dd2e204e38",
"body": "npx @aegisrunner/scan-runner runs the browser executor with a local Playwright\n(installed via npm, Chromium auto-downloaded) — no Docker needed. Same audited,\nbrain-free bundle as the image. The release workflow now publishes both the npm\npackage and the Docker image on a scan-runner-v* tag.",
"is_bot": false,
"headline": "scan-runner: add Docker-free npm package (@aegisrunner/scan-runner)",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T11:54:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0907d9a4fcc1d5cdc05979935121a79cdc915faa",
"body": "The browser executor customers run to scan localhost/private/firewalled apps.\nBuilt FROM the official Playwright image + only the audited executor bundle —\nno cloud brain in any layer, zero shared secrets. Tag scan-runner-v* to publish\naegisrunner1/scan-runner (Docker Hub + GHCR).",
"is_bot": false,
"headline": "scan-runner: publish workflow + brain-free image for aegis scan --local",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T11:19:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb4059f674d2b962b13af2c864ec9fb5b7de7968",
"body": "- aegis mobile-runner: run the device side of a local mobile scan on your box\n (claims jobs outbound, replays the cloud explorer's Appium calls against a\n local device; APK + device stay on your machine)\n- aegis mobile-scan --local --package: trigger a scan on your local device\n- aegis scan --local: run the browser on your own self-hosted runner\n- lib/mobileExecutor.mjs: the Appium relay executor",
"is_bot": false,
"headline": "cli: local mobile runner + web scan --local (1.0.18)",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-17T09:13:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "89f717a7dc83825b2815a8712d45cf471c19f493",
"body": "fetch() (undici) transparently DECOMPRESSES the response body, but the\ntunnel client was relaying the origin's `content-encoding: gzip` header\nalongside the now-plain bytes. Downstream the browser tries to gunzip\nplain JS → net::ERR_CONTENT_DECODING_FAILED and the asset never loads.\n\nNext.js/Turbopa\n[…]\ntale\ncontent-length (described the compressed body), and hop-by-hop framing\nheaders from the relayed response. Verified against a gzip origin: the\nrelayed body is now valid, decodable JS.\n\ncli 1.0.17.",
"is_bot": false,
"headline": "fix(tunnel): strip content-encoding so gzipped dev assets don't corrupt",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-16T09:13:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2730de1abea12dc28b562cf10359e9e440fe929c",
"body": "…der blank\n\nNext.js Pages Router hides <body> (display:none) until the client JS\nhydrates, and dev compiles those chunks on demand — so the scanner's\nfirst load races the compile: a chunk 404s, hydration never runs, and\nthe page screenshots blank. Vite (no hide-FOUC) and Nuxt (SSR content)\nwere unaf\n[…]\ne the scan loads the page.\nBest-effort and bounded: same-origin JS/CSS only, capped at 32, 15s per\nasset, never throws, never blocks the scan.\n\ncli 1.0.16; @aegisrunner/next 0.2.2 (cli floor ^1.0.16).",
"is_bot": false,
"headline": "fix(readiness): warm referenced JS chunks so Next dev scans don't ren…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-16T07:46:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0cfa803a41b7e9b6a4da758c40605cfc73e75976",
"body": "…scan\n\nThe dev-server 'listening'/'ready' hook fires when the port is bound, but Vite\ncompiles modules lazily on the first request (and Nuxt/Next warm up), so firing\nthe startup scan the instant the tunnel opened hit a not-yet-ready shell → blank\npages. Add waitForAppReady(host, port) to cli/lib/api\n[…]\ntartup' scan in\naegis dev and all three plugins (@aegisrunner/vite/nuxt/next). Best-effort with a\n60s cap so a quirky app never blocks the scan.\n\ncli 1.0.15; vite/nuxt/next 0.2.1 (cli dep -> ^1.0.15).",
"is_bot": false,
"headline": "fix(dev): wait for the app to actually be serving before the startup …",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-16T06:14:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8639d0def2d01513bf48790d27277dc7f9a7096c",
"body": "The tunnel poll now drains many queued requests per round-trip via ?batch=N\n(server returns an array), so a Vite dev server's module burst no longer needs\none poll round-trip per request. Pure HTTP, backward compatible with older\nservers, no new dependency. Effective concurrency is POLLERS x BATCH.",
"is_bot": false,
"headline": "cli 1.0.14: batch-drain tunnel poll for high-throughput scans",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-16T04:51:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9778156e9e8714264d03d612d69c8c71193ae607",
"body": "Replace the single serial tunnel poll loop with a pool of 8 concurrent pollers\nso a Vite dev server's module burst (dozens/hundreds of requests per load) no\nlonger outruns the tunnel and 504s into a blank page. Add a 30s poll-fetch\ntimeout, and auto-reconnect: on a lapsed registration, re-register reclaiming the\nsame tunnel id so the public URL and any in-flight scan survive a network blip.\nRequires server support for POST /tunnel/register?id= (id reclaim).",
"is_bot": false,
"headline": "cli 1.0.13: concurrent tunnel poller pool + auto-reconnect",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T17:29:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0c5df661f7df3debade1c73840305c0e47cefe37",
"body": null,
"is_bot": false,
"headline": "docs: label option + native DevTools panel (vite/nuxt/next 0.2.0)",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T10:05:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d814774cabb0d42313dee5f316e887a452e83ee7",
"body": "- cli/lib/label.mjs: deriveLabel + aegisTag (package name / basename / explicit).\n aegis dev gains --label; all logs tag '◆ aegis·<label>' so several tunnels in\n one terminal (turbo/monorepo) stay legible. CLI → 1.0.12.\n- @aegisrunner/{vite,nuxt,next} 0.2.0: same label option, tagged output.\n- @ae\n[…]\n is now a NATIVE inline panel served from a\n local /__aegis route (dashboard sets X-Frame-Options, so we render status +\n a 'Scan now' button ourselves; /__aegis/state + /__aegis/scan dev handlers).",
"is_bot": false,
"headline": "feat: monorepo tunnel labels + native Nuxt DevTools panel",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T10:01:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7e5434009d6becc15b0159d92999ce402e7c5d59",
"body": "`aegis hooks install` writes a pre-push hook that runs AegisRunner (default\n`aegis run --wait`) and blocks the push on failure; `uninstall` removes it.\nMarker-guarded, backs up any existing pre-push hook, restores it on uninstall.\nThe explicit form of the plugins' scanOn:'commit'. v1.0.11.",
"is_bot": false,
"headline": "cli: aegis hooks — opt-in git pre-push gate",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T09:40:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "377eadbe247c7bb0d5fdc3b6c2eea4ab2ca782ec",
"body": "New package. withAegisRunner(nextConfig, opts) opens a tunnel to the dev port in\nthe dev phase and scans localhost on [a]/startup. Next has no dev-listen hook and\nevaluates next.config in several processes, so it uses a cross-process atomic\nlockfile to open exactly one tunnel per `next dev`. Reuses @aegisrunner/cli.\nrelease-next workflow on next-v*. Validated end-to-end on Next 14. v0.1.0.",
"is_bot": false,
"headline": "next: add @aegisrunner/next — Next.js config wrapper",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T09:12:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "edc8bf82dbec235c92be74b73f70aa595a998799",
"body": "New package. A Nuxt module that hooks the dev server's 'listen' for the port,\nopens a tunnel, scans the localhost app on [a] (or scanOn:'startup'), and adds a\nDevTools tab (link-out; the dashboard sets X-Frame-Options). Reuses the tunnel +\ntrigger + live-progress from @aegisrunner/cli. release-nuxt workflow on nuxt-v*.\nValidated end-to-end against Nuxt 3.21. v0.1.0.",
"is_bot": false,
"headline": "nuxt: add @aegisrunner/nuxt — the flagship framework module",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T08:46:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09b08936d3b8a99bc4e0e3549e95ee99c59e5973",
"body": "New package. One line in vite.config opens a tunnel to the dev server on start\nand scans the localhost app on [a] (or scanOn:'startup'), reusing the tunnel +\ntrigger + live-progress from @aegisrunner/cli. Covers Vue/React/Svelte. Adds a\nrelease-vite workflow (vite-v* tags → npm). v0.1.0.",
"is_bot": false,
"headline": "vite: add @aegisrunner/vite — attach AegisRunner to the Vite dev server",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T08:14:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ac8d8b3e6c24bb119038044e1c151a306861c7e",
"body": "New `aegis dev -- <cmd>` wraps any dev command: starts it, opens a tunnel to the\nlocal port (given via --port or sniffed from output), holds it for the session,\nand offers a one-keypress scan ([a]) with live progress. --scan-on startup scans\nautomatically. The universal primitive the framework plugins wrap. v1.0.10.",
"is_bot": false,
"headline": "cli: aegis dev — run your dev server with a tunnel attached",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T08:05:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0dbfde984ea7ccbb636d16b21a2a0f96b25087b5",
"body": "The tunnel client's fetch to your local app had no timeout, so a slow or\nnon-responding route blocked until the cloud's ~45s relay cap — stalling the\nwhole scan. Add a 25s local-fetch timeout that posts a clean 504 back so the\ncrawler moves on instead of waiting. v1.0.9.",
"is_bot": false,
"headline": "cli: fail fast on a slow/hung local route through the tunnel",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-15T04:52:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7ca08daa89eb8af235f72d6c44180bda9085088",
"body": "aegis scan now forwards credentials to the cloud scanner so pages behind a\nlogin get crawled and tested. --username takes any identity (email / username /\nphone / …) and the scanner's AI maps it onto the login form; the password comes\nfrom stdin or AEGIS_PASSWORD (never a plain flag). --role scans as a saved role.\nWorks with --tunnel and --url. README + landing docs updated. v1.0.8.",
"is_bot": false,
"headline": "cli: scan behind a login (--username / --password-stdin / --role)",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T17:16:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d93ebd9e4f1fe98fee680549a7e956366cb9ce0d",
"body": "…roject default (v1.0.7)",
"is_bot": false,
"headline": "fix(cli): scan --url \"\" now errors instead of silently scanning the p…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T15:05:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cb483181acbeba93e34261e28cd7828f5100385",
"body": "…process (v1.0.6)\n\nOpens a tunnel to a local app, scans the subdomain URL it hands back, and\nstreams progress — all in one process, so the tunnel stays connected for the\nwhole scan (no two-terminal juggling, no dropped tunnel). Also: --watch now\nreconnects if the SSE stream drops before completion.",
"is_bot": false,
"headline": "feat(cli): aegis scan --tunnel --port — tunnel + scan + watch in one …",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T15:01:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a0c120b592c18f37dd3930440d94def3b9a92d9",
"body": null,
"is_bot": false,
"headline": "docs: mention 'aegis scan --watch' in the CLI section",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T12:03:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "501f5adb31aa09d834f95d124aaa1cb7973e47d1",
"body": "…SE (v1.0.5)",
"is_bot": false,
"headline": "feat(cli): aegis scan --watch — live crawl + test-gen progress over S…",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T11:33:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e9db14f64b39f1136a7c6d8c8a3121fd1fc268e",
"body": null,
"is_bot": false,
"headline": "docs(cli): CI trigger token requires Pro or Business (v1.0.4)",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T07:23:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93580965163f7590923af72cae4c439a7f5b47a1",
"body": "- cli/ — zero-dependency Node CLI (run, scan, mobile-scan, tunnel, runner)\n- .github/workflows/release-cli.yml — publish to npm + Docker Hub + GHCR on cli-v* tags\n- README: CLI & self-hosted runner section + badges; LICENSE (MIT)",
"is_bot": false,
"headline": "Add @aegisrunner/cli — self-hosted runner, tunnel, and release workflow",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-14T06:29:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "08195d67435726a908171199e4f4aa73a4015702",
"body": null,
"is_bot": false,
"headline": "Update README.md",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-07-10T12:17:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe2f748dd92d452b0050eb25edb88e9b62fd76b7",
"body": null,
"is_bot": false,
"headline": "Update README.md",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-03-23T14:14:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "decb03d558a7a200490e61085c416cbbd7fb1f19",
"body": null,
"is_bot": false,
"headline": "Update README.md",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-03-23T14:13:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f741a506effa3b7439bcfbb4e71209c7eb151ed",
"body": null,
"is_bot": false,
"headline": "Update README.md",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-02-18T13:31:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac43da2354ac98113fcd9dee5dd55b5d912c57fe",
"body": null,
"is_bot": false,
"headline": "Update README.md",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-02-18T13:23:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "680681270a07728e18105743d98654bbe22e77dc",
"body": null,
"is_bot": false,
"headline": "Initial commit",
"author_name": "Aegis-Runner",
"author_login": "Aegis-Runner",
"committed_at": "2026-02-18T06:55:03Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 44,
"commits_last_year": 46,
"latest_release_at": "2026-07-19T17:45:59Z",
"latest_release_tag": "cli-v1.0.28",
"releases_from_tags": false,
"days_since_last_push": 5,
"active_weeks_last_year": 5,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.2
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@aegisrunner/cli",
"exists": true,
"license": "MIT",
"keywords": [
"testing",
"ci",
"e2e",
"regression",
"junit",
"aegisrunner"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@aegisrunner/cli",
"is_deprecated": false,
"latest_version": "1.0.28",
"repository_url": "https://github.com/Aegis-Runner/AegisRunner",
"versions_count": 29,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 4787,
"first_published_at": "2026-07-14T05:45:05.189000Z",
"latest_published_at": "2026-07-19T17:45:52.980000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
},
{
"name": "@aegisrunner/next",
"exists": true,
"license": "MIT",
"keywords": [
"next",
"nextjs",
"testing",
"e2e",
"regression",
"ai-testing",
"aegisrunner",
"localhost"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@aegisrunner/next",
"is_deprecated": false,
"latest_version": "0.4.2",
"repository_url": "https://github.com/Aegis-Runner/AegisRunner",
"versions_count": 8,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1214,
"first_published_at": "2026-07-15T09:12:42.407000Z",
"latest_published_at": "2026-07-19T09:56:31.880000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@aegisrunner/nuxt",
"exists": true,
"license": "MIT",
"keywords": [
"nuxt",
"nuxt-module",
"testing",
"e2e",
"regression",
"ai-testing",
"aegisrunner",
"localhost"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@aegisrunner/nuxt",
"is_deprecated": false,
"latest_version": "0.4.3",
"repository_url": "https://github.com/Aegis-Runner/AegisRunner",
"versions_count": 7,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1052,
"first_published_at": "2026-07-15T08:46:18.214000Z",
"latest_published_at": "2026-07-19T09:56:31.622000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@aegisrunner/vite",
"exists": true,
"license": "MIT",
"keywords": [
"vite",
"vite-plugin",
"testing",
"e2e",
"regression",
"ai-testing",
"aegisrunner",
"localhost"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@aegisrunner/vite",
"is_deprecated": false,
"latest_version": "0.4.2",
"repository_url": "https://github.com/Aegis-Runner/AegisRunner",
"versions_count": 7,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1027,
"first_published_at": "2026-07-15T08:14:28.499000Z",
"latest_published_at": "2026-07-19T09:56:27.956000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@aegisrunner/runner",
"exists": true,
"license": "MIT",
"keywords": [
"aegisrunner",
"testing",
"playwright",
"scanner",
"self-hosted",
"localhost"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@aegisrunner/runner",
"is_deprecated": false,
"latest_version": "1.2.1",
"repository_url": "https://github.com/Aegis-Runner/AegisRunner",
"versions_count": 2,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 338,
"first_published_at": "2026-07-18T05:14:45.999000Z",
"latest_published_at": "2026-07-19T11:54:00.777000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@aegisrunner/scan-runner",
"exists": true,
"license": "MIT",
"keywords": [
"aegisrunner",
"testing",
"playwright",
"scanner",
"self-hosted",
"localhost"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@aegisrunner/scan-runner",
"is_deprecated": true,
"latest_version": "1.2.0",
"repository_url": "https://github.com/Aegis-Runner/AegisRunner",
"versions_count": 3,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": "Renamed to @aegisrunner/runner (same executor, clearer name -- it runs both scan --local AND run --local). Please switch to npx @aegisrunner/runner",
"maintainers_count": 1,
"monthly_downloads": 502,
"first_published_at": "2026-07-17T11:54:22.371000Z",
"latest_published_at": "2026-07-18T04:28:33.085000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 7
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 280693,
"source_files_sampled": 20,
"oversized_source_files": 2,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"cli/package.json",
"next/package.json",
"nuxt/package.json",
"runner/package.json",
"scan-runner/package.json",
"vite/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@aegisrunner/cli",
"manifest": "next/package.json",
"ecosystem": "npm",
"version_constraint": "^1.0.21"
},
{
"name": "@aegisrunner/cli",
"manifest": "nuxt/package.json",
"ecosystem": "npm",
"version_constraint": "^1.0.23"
},
{
"name": "@nuxt/kit",
"manifest": "nuxt/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.0"
},
{
"name": "playwright",
"manifest": "runner/package.json",
"ecosystem": "npm",
"version_constraint": "1.60.0"
},
{
"name": "@axe-core/playwright",
"manifest": "runner/package.json",
"ecosystem": "npm",
"version_constraint": "^4.11.3"
},
{
"name": "pixelmatch",
"manifest": "runner/package.json",
"ecosystem": "npm",
"version_constraint": "^7.2.0"
},
{
"name": "pngjs",
"manifest": "runner/package.json",
"ecosystem": "npm",
"version_constraint": "^7.0.0"
},
{
"name": "sharp",
"manifest": "runner/package.json",
"ecosystem": "npm",
"version_constraint": "^0.34.5"
},
{
"name": "playwright",
"manifest": "scan-runner/package.json",
"ecosystem": "npm",
"version_constraint": "1.60.0"
},
{
"name": "@aegisrunner/cli",
"manifest": "vite/package.json",
"ecosystem": "npm",
"version_constraint": "^1.0.25"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "Aegis-Runner",
"commits": 39,
"avatar_url": "https://avatars.githubusercontent.com/u/262282406?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": false,
"ci_workflows": [
"deprecate-scan-runner.yml",
"release-cli.yml",
"release-next.yml",
"release-nuxt.yml",
"release-runner.yml",
"release-scan-runner.yml",
"release-vite.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "21f7f836bf214983c901657c78bd1c2964802907",
"ran_at": "2026-07-25T16:37:21Z",
"aggregate_score": 4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-20T04:39:11Z",
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/Aegis-Runner/AegisRunner",
"host": "github.com",
"name": "AegisRunner",
"owner": "Aegis-Runner"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 44,
"inputs": {
"security": 40,
"vitality": 74,
"community": 34,
"governance": 25,
"engineering": 48
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 74,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"commits_last_year": 46,
"human_commit_share": 1,
"days_since_last_push": 5,
"active_weeks_last_year": 5
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "5/52 weeks with commits",
"points": 3.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 5
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "46 commits in the last year",
"points": 15,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 46
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 44,
"latest_release_tag": "cli-v1.0.28",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.2
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "44 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 44
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.2 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.2
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 34,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 66,
"inputs": {
"packages": [
"@aegisrunner/cli",
"@aegisrunner/next",
"@aegisrunner/nuxt",
"@aegisrunner/vite",
"@aegisrunner/runner",
"@aegisrunner/scan-runner"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 8920
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "8,920 downloads/month across npm",
"points": 52.7,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 8920,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "critical",
"name": "Sustainability & Governance",
"value": 25,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "critical",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 21,
"inputs": {
"followers": 1,
"owner_type": "User",
"is_verified": null,
"owner_login": "Aegis-Runner",
"public_repos": 2,
"account_age_days": 157
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of Aegis-Runner",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "Aegis-Runner"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "2 public repos, account ~0 yr old",
"points": 4.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 2
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "good",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"packages": [
"@aegisrunner/cli",
"@aegisrunner/next",
"@aegisrunner/nuxt",
"@aegisrunner/vite",
"@aegisrunner/runner",
"@aegisrunner/scan-runner"
],
"ecosystems": "npm",
"any_deprecated": true,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "6 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 6,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "29 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 29
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "@aegisrunner/scan-runner: Renamed to @aegisrunner/runner (same executor, clearer name -- it runs both scan --local AND run --local). Please switch to npx @aegisrunner/runner",
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "at_risk",
"name": "Engineering Quality",
"value": 48,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "at_risk",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 30,
"inputs": {
"has_ci": true,
"has_tests": false,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "7 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 7
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"a11y",
"accessibility",
"automated-testing",
"playwright",
"regression-testing",
"security-audit",
"seo",
"testing",
"web-crawler",
"web-testing"
],
"has_wiki": true,
"homepage": "https://aegisrunner.com",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://aegisrunner.com",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "10 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 10
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 40,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 40,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 32,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.87,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "40 of 46 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 40,
"sampled": 46
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "critical",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"has_nix": false,
"has_tests": false,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.152,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "7 of the last 46 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 7,
"sampled": 46
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"primary_language": "JavaScript",
"largest_source_bytes": 280693,
"source_files_sampled": 20,
"oversized_source_files": 2
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "JavaScript without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "JavaScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "2/20 source files over 60KB",
"points": 49.5,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 20,
"oversized": 2
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T16:37:26.459552Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/Aegis-Runner/AegisRunner.svg",
"full_name": "Aegis-Runner/AegisRunner",
"license_state": "standard",
"license_spdx": "MIT"
}