Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-30 06:10 UTC

AlexanderMattTurner / agent-sanitizer

Strip common prompt injection surfaces.

JavaScript · PythonApache-2.0★ 2 stars⑂ 1 forksince Jun 2026View on GitHub ↗

AlexanderMattTurner/agent-sanitizer holds a health index of 58 out of 100, placing it in the Moderate band. It scores highest on AI Readiness (78/100) and lowest on Community & Adoption (39/100). It was last updated today. A single contributor accounts for most of its recent work.

58
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

58
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

4 followers13 public repossince Jun 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

70Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
4.2/36Commit cadence — 6/52 weeks with commits
18/18Commit volume — 606 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year606
human_commit_share0.8
days_since_last_push0
active_weeks_last_year6
How it's scored
16.2/27Ships releases — 63 version tags (no GitHub releases)
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~0.2 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count63
latest_release_tagv2.5.0
releases_from_tagsyes
days_since_latest_release0
mean_days_between_releases0.2
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

39At risk · 18% of overall
How it's scored
0/60Stars — 2 stars
0/25Forks — 1 forks
0/15Watchers — 0 watchers
Inputs used
forks1
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateyes
How it's scored
38.7/80Monthly downloads — 797 downloads/month across npm, pypi
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesagent-sanitizer, agent-sanitizer
dependents
ecosystemsnpm, pypi
total_downloads
monthly_downloads797
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

49At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
7.3/22.5Commit distribution — top contributor authored 68% of commits
2.7/13.5Contributor breadth — 2 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.676
How it's scored
11.7/46.8Issue resolution — 25% of issues closed
35.3/38.3PR acceptance — 167/181 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/14 approved changesets -- score normalized to 0
Inputs used
merged_prs167
open_issues6
closed_issues2
issue_closed_ratio0.25
closed_unmerged_prs14
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
5/25Owner reach — 4 followers of AlexanderMattTurner
8.7/25Track record — 13 public repos, account ~0 yr old
Inputs used
followers4
owner_typeOrganization
is_verified
owner_loginAlexanderMattTurner
public_repos13
account_age_days58
How it's scored
25/25Published & resolvable — 2 package(s) on npm, pypi
35/35Publish recency — latest publish 0 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesagent-sanitizer, agent-sanitizer
ecosystemsnpm, pypi
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

72Good · 20% of overall
How it's scored
24/24CI workflows — 37 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.mjs
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes

Documentation

40At risk
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

56Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/14 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.5
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages473
unassessed_packages1
affected_by_severitymoderate 1
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 473 resolved dependencies against OSV. 1 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

78Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 78 of 80 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.975
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes17,470
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.mjs
11/11Static type checking — tsconfig.json
10/10Reproducible environment — lockfile
4/10Demonstrated agent practice — 2 of the last 100 commits agent-authored or agent-credited
5/8Automated maintenance — dependency automation configured, none observed in the sampled commits
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Inputs used
has_nixno
has_testsyes
lockfilespnpm-lock.yaml, uv.lock
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configstsconfig.json
agent_commit_share0.02
toolchain_manifests
dependency_bot_commit_share0
How it's scored
27/45Type-checkable code — JavaScript with type-check config (tsconfig.json)
53.5/55Manageable file sizes — 5/178 source files over 60KB
Inputs used
primary_languageJavaScript
largest_source_bytes91,158
source_files_sampled178
oversized_source_files5

Key facts

2GitHub stars
2contributors
606commits, last 12 months
0days since last push
63releases
1bus factor
6open issues
npm, PyPIpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index npm:agent-sanitizer@2.5.0; advisories assessed against the repository dependency graph instead

More detail

OpenSSF Scorecard 4.5 / 10
4.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-30 06:10 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/14 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 9
RegistryPackageVersion constraintManifest
npmagent-control-plane-core0.2.13package.json
npmnamespace-guard0.20.0package.json
npmcss-tree^3.2.1package.json
npmrehype-parse9.0.1package.json
npmremark-gfm4.0.1package.json
npmremark-parse11.0.0package.json
npmstyle-to-object1.0.14package.json
npmunified11.0.5package.json
npmunist-util-visit5.1.0package.json
All dependencies 474

Full resolved dependency set from the GitHub dependency graph: 9 direct and 465 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npmagent-control-plane-core0.2.13direct
npmcss-tree3.2.1direct
npmnamespace-guard0.20.0direct
npmrehype-parse9.0.1direct
npmremark-gfm4.0.1direct
npmremark-parse11.0.0direct
npmstyle-to-object1.0.14direct
npmunified11.0.5direct
npmunist-util-visit5.1.0direct
npm@babel/code-frame7.29.7indirect
npm@babel/compat-data7.29.7indirect
npm@babel/core7.29.7indirect
npm@babel/generator7.29.7indirect
npm@babel/helper-annotate-as-pure7.29.7indirect
npm@babel/helper-compilation-targets7.29.7indirect
npm@babel/helper-create-class-features-plugin7.29.7indirect
npm@babel/helper-globals7.29.7indirect
npm@babel/helper-member-expression-to-functions7.29.7indirect
npm@babel/helper-module-imports7.29.7indirect
npm@babel/helper-module-transforms7.29.7indirect
npm@babel/helper-optimise-call-expression7.29.7indirect
npm@babel/helper-plugin-utils7.29.7indirect
npm@babel/helper-replace-supers7.29.7indirect
npm@babel/helper-skip-transparent-expression-wrappers7.29.7indirect
npm@babel/helper-string-parser7.29.7indirect
npm@babel/helper-validator-identifier7.29.7indirect
npm@babel/helper-validator-option7.29.7indirect
npm@babel/helpers7.29.7indirect
npm@babel/parser7.29.7indirect
npm@babel/plugin-proposal-decorators7.29.7indirect
npm@babel/plugin-syntax-decorators7.29.7indirect
npm@babel/plugin-syntax-jsx7.29.7indirect
npm@babel/plugin-syntax-typescript7.29.7indirect
npm@babel/plugin-transform-destructuring7.29.7indirect
npm@babel/plugin-transform-explicit-resource-management7.29.7indirect
npm@babel/plugin-transform-modules-commonjs7.29.7indirect
npm@babel/plugin-transform-typescript7.29.7indirect
npm@babel/preset-typescript7.28.5indirect
npm@babel/template7.29.7indirect
npm@babel/traverse7.29.7indirect
npm@babel/types7.29.7indirect
npm@bcoe/v8-coverage1.0.2indirect
npm@commitlint/cli21.2.1indirect
npm@commitlint/config-conventional21.2.0indirect
npm@commitlint/config-validator21.2.0indirect
npm@commitlint/ensure21.2.0indirect
npm@commitlint/execute-rule21.0.1indirect
npm@commitlint/format21.2.0indirect
npm@commitlint/is-ignored21.2.0indirect
npm@commitlint/lint21.2.0indirect
npm@commitlint/load21.2.0indirect
npm@commitlint/message21.2.0indirect
npm@commitlint/parse21.2.0indirect
npm@commitlint/read21.2.1indirect
npm@commitlint/resolve-extends21.2.0indirect
npm@commitlint/rules21.2.0indirect
npm@commitlint/to-lines21.0.1indirect
npm@commitlint/top-level21.2.0indirect
npm@commitlint/types21.2.0indirect
npm@conventional-changelog/git-client3.1.0indirect
npm@conventional-changelog/template1.2.1indirect
npm@esbuild/aix-ppc640.28.1indirect
npm@esbuild/android-arm0.28.1indirect
npm@esbuild/android-arm640.28.1indirect
npm@esbuild/android-x640.28.1indirect
npm@esbuild/darwin-arm640.28.1indirect
npm@esbuild/darwin-x640.28.1indirect
npm@esbuild/freebsd-arm640.28.1indirect
npm@esbuild/freebsd-x640.28.1indirect
npm@esbuild/linux-arm0.28.1indirect
npm@esbuild/linux-arm640.28.1indirect
npm@esbuild/linux-ia320.28.1indirect
npm@esbuild/linux-loong640.28.1indirect
npm@esbuild/linux-mips64el0.28.1indirect
npm@esbuild/linux-ppc640.28.1indirect
npm@esbuild/linux-riscv640.28.1indirect
npm@esbuild/linux-s390x0.28.1indirect
npm@esbuild/linux-x640.28.1indirect
npm@esbuild/netbsd-arm640.28.1indirect
npm@esbuild/netbsd-x640.28.1indirect
npm@esbuild/openbsd-arm640.28.1indirect
npm@esbuild/openbsd-x640.28.1indirect
npm@esbuild/openharmony-arm640.28.1indirect
npm@esbuild/sunos-x640.28.1indirect
npm@esbuild/win32-arm640.28.1indirect
npm@esbuild/win32-ia320.28.1indirect
npm@esbuild/win32-x640.28.1indirect
npm@eslint-community/eslint-utils4.10.1indirect
npm@eslint-community/regexpp4.12.2indirect
npm@eslint/config-array0.23.5indirect
npm@eslint/config-helpers0.6.0indirect
npm@eslint/core1.2.1indirect
npm@eslint/js10.0.1indirect
npm@eslint/object-schema3.0.5indirect
npm@eslint/plugin-kit0.7.2indirect
npm@humanfs/core0.19.2indirect
npm@humanfs/node0.16.8indirect
npm@humanfs/types0.15.0indirect
npm@humanwhocodes/module-importer1.0.1indirect
npm@humanwhocodes/retry0.4.3indirect
npm@inquirer/ansi2.0.7indirect
npm@inquirer/checkbox5.2.1indirect
npm@inquirer/confirm6.1.1indirect
npm@inquirer/core11.2.1indirect
npm@inquirer/editor5.2.2indirect
npm@inquirer/expand5.1.1indirect
npm@inquirer/external-editor3.0.3indirect
npm@inquirer/figures2.0.7indirect
npm@inquirer/input5.1.2indirect
npm@inquirer/number4.1.1indirect
npm@inquirer/password5.1.1indirect
npm@inquirer/prompts8.5.2indirect
npm@inquirer/rawlist5.3.1indirect
npm@inquirer/search4.2.1indirect
npm@inquirer/select5.2.1indirect
npm@inquirer/type4.0.7indirect
npm@istanbuljs/schema0.1.6indirect
npm@jridgewell/gen-mapping0.3.13indirect
npm@jridgewell/remapping2.3.5indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@sec-ant/readable-stream0.4.1indirect
npm@simple-libs/child-process-utils2.0.0indirect
npm@simple-libs/stream-utils2.0.0indirect
npm@sindresorhus/merge-streams4.0.0indirect
npm@stryker-mutator/api9.6.1indirect
npm@stryker-mutator/core9.6.1indirect
npm@stryker-mutator/instrumenter9.6.1indirect
npm@stryker-mutator/tap-runner9.6.1indirect
npm@stryker-mutator/util9.6.1indirect
npm@types/debug4.1.13indirect
npm@types/esrecurse4.3.1indirect
npm@types/estree1.0.9indirect
npm@types/hast3.0.5indirect
npm@types/istanbul-lib-coverage2.0.6indirect
npm@types/json-schema7.0.15indirect
npm@types/mdast4.0.4indirect
npm@types/ms2.1.0indirect
npm@types/node25.9.1indirect
npm@types/unist3.0.3indirect
npm@typescript-eslint/eslint-plugin8.61.0indirect
npm@typescript-eslint/parser8.61.0indirect
npm@typescript-eslint/project-service8.61.0indirect
npm@typescript-eslint/scope-manager8.61.0indirect
npm@typescript-eslint/tsconfig-utils8.61.0indirect
npm@typescript-eslint/type-utils8.61.0indirect
npm@typescript-eslint/types8.61.0indirect
npm@typescript-eslint/typescript-estree8.61.0indirect
npm@typescript-eslint/utils8.61.0indirect
npm@typescript-eslint/visitor-keys8.61.0indirect
npmacorn8.18.0indirect
npmacorn-jsx5.3.2indirect
npmagent-sanitizer2.1.0indirect
npmajv6.15.0indirect
npmajv8.18.0indirect
npmajv8.20.0indirect
npmangular-html-parser10.4.0indirect
npmansi-regex5.0.1indirect
npmansi-regex6.2.2indirect
npmansi-styles4.3.0indirect
npmansi-styles6.2.3indirect
npmargparse2.0.1indirect
npmargue-cli3.1.0indirect
npmbail2.0.2indirect
npmbalanced-match4.0.4indirect
npmbaseline-browser-mapping2.11.6indirect
npmbrace-expansion5.0.8indirect
npmbrowserslist4.28.7indirect
npmc811.0.0indirect
npmcall-bind-apply-helpers1.0.2indirect
npmcall-bound1.0.4indirect
npmcallsites3.1.0indirect
npmcaniuse-lite1.0.30001806indirect
npmccount2.0.1indirect
npmchalk5.6.2indirect
npmcharacter-entities2.0.2indirect
npmchardet2.2.0indirect
npmcli-width4.1.0indirect
npmcliui8.0.1indirect
npmcliui9.0.1indirect
npmcolor-convert2.0.1indirect
npmcolor-name1.1.4indirect
npmcomma-separated-tokens2.0.3indirect
npmcommander14.0.3indirect
npmconventional-changelog-angular9.2.1indirect
npmconventional-changelog-conventionalcommits10.2.1indirect
npmconventional-commits-parser7.1.1indirect
npmconvert-source-map2.0.0indirect
npmcosmiconfig9.0.2indirect
npmcosmiconfig-typescript-loader6.3.0indirect
npmcross-spawn7.0.6indirect
npmdebug4.4.3indirect
npmdecode-named-character-reference1.3.0indirect
npmdeep-is0.1.4indirect
npmdequal2.0.3indirect
npmdes.js1.1.0indirect
npmdevlop1.1.0indirect
npmdiff-match-patch1.0.5indirect
npmdunder-proto1.0.1indirect
npmelectron-to-chromium1.5.398indirect
npmemoji-regex10.6.0indirect
npmemoji-regex8.0.0indirect
npmentities6.0.1indirect
npmenv-paths2.2.1indirect
npmerror-ex1.3.4indirect
npmes-define-property1.0.1indirect
npmes-errors1.3.0indirect
npmes-object-atoms1.1.2indirect
npmes-toolkit1.50.0indirect
npmesbuild0.28.1indirect
npmescalade3.2.0indirect
npmescape-string-regexp4.0.0indirect
npmescape-string-regexp5.0.0indirect
npmeslint10.4.0indirect
npmeslint-scope9.1.2indirect
npmeslint-visitor-keys3.4.3indirect
npmeslint-visitor-keys5.0.1indirect
npmespree11.2.0indirect
npmesquery1.7.0indirect
npmesrecurse4.3.0indirect
npmestraverse5.3.0indirect
npmesutils2.0.3indirect
npmevents-to-array2.0.3indirect
npmexeca9.6.1indirect
npmextend3.0.2indirect
npmfast-check4.8.0indirect
npmfast-deep-equal3.1.3indirect
npmfast-json-stable-stringify2.1.0indirect
npmfast-levenshtein2.0.6indirect
npmfast-string-truncated-width3.0.3indirect
npmfast-string-width3.0.2indirect
npmfast-uri3.1.4indirect
npmfast-wrap-ansi0.2.2indirect
npmfdir6.5.0indirect
npmfigures6.1.0indirect
npmfile-entry-cache8.0.0indirect
npmfind-up5.0.0indirect
npmflat-cache4.0.1indirect
npmflatted3.4.3indirect
npmforeground-child3.3.1indirect
npmfunction-bind1.1.2indirect
npmgensync1.0.0-beta.2indirect
npmget-caller-file2.0.5indirect
npmget-east-asian-width1.6.0indirect
npmget-intrinsic1.3.0indirect
npmget-proto1.0.1indirect
npmget-stream9.0.1indirect
npmglob13.0.6indirect
npmglob-parent6.0.2indirect
npmglobal-directory5.0.0indirect
npmglobals17.6.0indirect
npmgopd1.2.0indirect
npmhas-flag4.0.0indirect
npmhas-symbols1.1.0indirect
npmhasown2.0.4indirect
npmhast-util-from-html2.0.3indirect
npmhast-util-from-parse58.0.3indirect
npmhast-util-parse-selector4.0.0indirect
npmhastscript9.0.1indirect
npmhtml-escaper2.0.2indirect
npmhuman-signals8.0.1indirect
npmiconv-lite0.7.3indirect
npmignore5.3.2indirect
npmignore7.0.6indirect
npmimport-fresh3.3.1indirect
npmimurmurhash0.1.4indirect
npminherits2.0.4indirect
npmini6.0.0indirect
npminline-style-parser0.2.7indirect
npmis-arrayish0.2.1indirect
npmis-extglob2.1.1indirect
npmis-fullwidth-code-point3.0.0indirect
npmis-glob4.0.3indirect
npmis-plain-obj4.1.0indirect
npmis-stream4.0.1indirect
npmis-unicode-supported2.1.0indirect
npmisexe2.0.0indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-reports3.2.0indirect
npmjiti2.6.1indirect
npmjs-md40.3.2indirect
npmjs-tokens4.0.0indirect
npmjs-yaml4.3.0indirect
npmjsesc3.1.0indirect
npmjson-buffer3.0.1indirect
npmjson-parse-even-better-errors2.3.1indirect
npmjson-rpc-2.01.7.1indirect
npmjson-schema-traverse0.4.1indirect
npmjson-schema-traverse1.0.0indirect
npmjson-stable-stringify-without-jsonify1.0.1indirect
npmjson52.2.3indirect
npmkeyv4.5.4indirect
npmlevn0.4.1indirect
npmlines-and-columns1.2.4indirect
npmlint-staged17.2.0indirect
npmlocate-path6.0.0indirect
npmlodash.groupby4.6.0indirect
npmlongest-streak3.1.0indirect
npmlru-cache11.5.2indirect
npmlru-cache5.1.1indirect
npmmake-dir4.0.0indirect
npmmarkdown-table3.0.4indirect
npmmath-intrinsics1.1.0indirect
npmmdast-util-find-and-replace3.0.2indirect
npmmdast-util-from-markdown2.0.3indirect
npmmdast-util-gfm3.1.0indirect
npmmdast-util-gfm-autolink-literal2.0.1indirect
npmmdast-util-gfm-footnote2.1.0indirect
npmmdast-util-gfm-strikethrough2.0.0indirect
npmmdast-util-gfm-table2.0.0indirect
npmmdast-util-gfm-task-list-item2.0.0indirect
npmmdast-util-phrasing4.1.0indirect
npmmdast-util-to-markdown2.1.2indirect
npmmdast-util-to-string4.0.0indirect
npmmdn-data2.27.1indirect
npmmicromark4.0.2indirect
npmmicromark-core-commonmark2.0.3indirect
npmmicromark-extension-gfm3.0.0indirect
npmmicromark-extension-gfm-autolink-literal2.1.0indirect
npmmicromark-extension-gfm-footnote2.1.0indirect
npmmicromark-extension-gfm-strikethrough2.1.0indirect
npmmicromark-extension-gfm-table2.1.1indirect
npmmicromark-extension-gfm-tagfilter2.0.0indirect
npmmicromark-extension-gfm-task-list-item2.1.0indirect
npmmicromark-factory-destination2.0.1indirect
npmmicromark-factory-label2.0.1indirect
npmmicromark-factory-space2.0.1indirect
npmmicromark-factory-title2.0.1indirect
npmmicromark-factory-whitespace2.0.1indirect
npmmicromark-util-character2.1.1indirect
npmmicromark-util-chunked2.0.1indirect
npmmicromark-util-classify-character2.0.1indirect
npmmicromark-util-combine-extensions2.0.1indirect
npmmicromark-util-decode-numeric-character-reference2.0.2indirect
npmmicromark-util-decode-string2.0.1indirect
npmmicromark-util-encode2.0.1indirect
npmmicromark-util-html-tag-name2.0.1indirect
npmmicromark-util-normalize-identifier2.0.1indirect
npmmicromark-util-resolve-all2.0.1indirect
npmmicromark-util-sanitize-uri2.0.1indirect
npmmicromark-util-subtokenize2.1.0indirect
npmmicromark-util-symbol2.0.1indirect
npmmicromark-util-types2.0.2indirect
npmminimalistic-assert1.0.1indirect
npmminimatch10.2.6indirect
npmminipass7.1.3indirect
npmms2.1.3indirect
npmmutation-server-protocol0.4.1indirect
npmmutation-testing-elements3.7.3indirect
npmmutation-testing-metrics3.7.3indirect
npmmutation-testing-report-schema3.7.3indirect
npmmute-stream3.0.0indirect
npmnatural-compare1.4.0indirect
npmnode-releases2.0.51indirect
npmnpm-run-path6.0.0indirect
npmobject-inspect1.13.4indirect
npmoptionator0.9.4indirect
npmp-limit3.1.0indirect
npmp-locate5.0.0indirect
npmparent-module1.0.1indirect
npmparse-json5.2.0indirect
npmparse-ms4.0.0indirect
npmparse57.3.0indirect
npmpath-exists4.0.0indirect
npmpath-key3.1.1indirect
npmpath-key4.0.0indirect
npmpath-scurry2.0.2indirect
npmpicocolors1.1.1indirect
npmpicomatch4.0.5indirect
npmprelude-ls1.2.1indirect
npmprettier3.9.6indirect
npmpretty-ms9.3.0indirect
npmprogress2.0.3indirect
npmproperty-information7.2.0indirect
npmpunycode2.3.1indirect
npmpure-rand8.4.2indirect
npmqs6.15.1indirect
npmremark-stringify11.0.0indirect
npmrequire-directory2.1.1indirect
npmrequire-from-string2.0.2indirect
npmresolve-from4.0.0indirect
npmresolve-from5.0.0indirect
npmrxjs7.8.2indirect
npmsafer-buffer2.1.2indirect
npmsemver6.3.1indirect
npmsemver7.7.4indirect
npmsemver7.8.5indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmside-channel1.1.1indirect
npmside-channel-list1.0.1indirect
npmside-channel-map1.0.1indirect
npmside-channel-weakmap1.0.2indirect
npmsignal-exit4.1.0indirect
npmsource-map0.7.6indirect
npmsource-map-js1.2.1indirect
npmspace-separated-tokens2.0.2indirect
npmstring-argv0.3.2indirect
npmstring-width4.2.3indirect
npmstring-width7.2.0indirect
npmstring-width8.2.2indirect
npmstrip-ansi6.0.1indirect
npmstrip-ansi7.2.0indirect
npmstrip-final-newline4.0.0indirect
npmsupports-color7.2.0indirect
npmtap-parser17.0.0indirect
npmtap-yaml3.0.0indirect
npmtest-exclude8.0.0indirect
npmtinyexec1.2.4indirect
npmtinyglobby0.2.17indirect
npmtree-kill1.2.2indirect
npmtrough2.2.0indirect
npmts-api-utils2.5.0indirect
npmtslib2.8.1indirect
npmtunnel0.0.6indirect
npmtype-check0.4.0indirect
npmtyped-inject5.0.0indirect
npmtyped-rest-client2.3.1indirect
npmtypescript6.0.3indirect
npmtypescript-eslint8.61.0indirect
npmunderscore1.13.8indirect
npmundici-types7.24.6indirect
npmunicorn-magic0.3.0indirect
npmunist-util-is6.0.1indirect
npmunist-util-stringify-position4.0.0indirect
npmunist-util-visit-parents6.0.2indirect
npmupdate-browserslist-db1.2.3indirect
npmuri-js4.4.1indirect
npmv8-to-istanbul9.3.0indirect
npmvfile6.0.3indirect
npmvfile-location5.0.3indirect
npmvfile-message4.0.3indirect
npmweapon-regex1.3.6indirect
npmweb-namespaces2.0.1indirect
npmwhich2.0.2indirect
npmword-wrap1.2.5indirect
npmwrap-ansi7.0.0indirect
npmwrap-ansi9.0.2indirect
npmy18n5.0.8indirect
npmyallist3.1.1indirect
npmyaml2.9.0indirect
npmyaml-types0.3.0indirect
npmyargs17.7.3indirect
npmyargs18.1.0indirect
npmyargs-parser21.1.1indirect
npmyargs-parser22.0.0indirect
npmyocto-queue0.1.0indirect
npmyoctocolors2.2.0indirect
npmzod4.4.3indirect
npmzwitch2.0.4indirect
PyPIagent-sanitizer0.0.0indirect
PyPIagent-sanitizer2.1.0indirect
PyPIcertifi2026.6.17indirect
PyPIcharset-normalizer3.4.7indirect
PyPIcolorama0.4.6indirect
PyPIdetect-secretsindirect
PyPIdetect-secrets1.5.0indirect
PyPIexceptiongroup1.3.1indirect
PyPIhypothesis6.155.7indirect
PyPIidna3.18indirect
PyPIiniconfig2.3.0indirect
PyPIpackaging26.2indirect
PyPIpluggy1.6.0indirect
PyPIpygments2.20.0indirect
PyPIpytest9.0.3indirect
PyPIpyyaml6.0.3indirect
PyPIregexploit1.0.0indirect
PyPIrequests2.34.2indirect
PyPIsortedcontainers2.4.0indirect
PyPItomli2.4.1indirect
PyPItyping-extensions4.15.0indirect
PyPIurllib32.7.0indirect
Dependency advisories 1

This repository publishes no package the index resolves, so its own dependency graph was assessed — 473 packages, which also include development and test pins that never ship: 1 carry known advisories, of which 0 are direct. 1 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
qs6.15.1indirectmoderate16.15.2

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 3628,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Shell": 42546,
        "Python": 386020,
        "JavaScript": 1397607,
        "TypeScript": 12060
      },
      "pushed_at": "2026-07-30T06:08:45Z",
      "created_at": "2026-06-21T18:28:59Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-30T06:08:56Z",
      "description": "Strip common prompt injection surfaces.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript",
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "AlexanderMattTurner",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/289737770?v=4",
      "created_at": "2026-06-01T15:25:24Z",
      "is_verified": null,
      "public_repos": 13,
      "account_age_days": 58
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-30T06:08:32Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-07-30T05:33:54Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-30T05:24:50Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-07-30T04:45:38Z"
        },
        {
          "tag": "v2.2.2",
          "kind": "patch",
          "published_at": "2026-07-30T03:47:26Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2026-07-30T01:53:26Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-07-30T01:05:22Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-07-29T18:27:36Z"
        },
        {
          "tag": "v2.0.3",
          "kind": "patch",
          "published_at": "2026-07-28T22:30:16Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-07-28T21:11:53Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-07-27T22:03:59Z"
        },
        {
          "tag": "v1.47.14",
          "kind": "patch",
          "published_at": "2026-07-23T20:31:27Z"
        },
        {
          "tag": "v1.47.11",
          "kind": "patch",
          "published_at": "2026-07-23T06:40:19Z"
        },
        {
          "tag": "v1.47.10",
          "kind": "patch",
          "published_at": "2026-07-22T23:53:59Z"
        },
        {
          "tag": "v1.47.9",
          "kind": "patch",
          "published_at": "2026-07-21T16:32:49Z"
        },
        {
          "tag": "v1.47.8",
          "kind": "patch",
          "published_at": "2026-07-21T16:29:49Z"
        },
        {
          "tag": "v1.47.7",
          "kind": "patch",
          "published_at": "2026-07-21T15:47:32Z"
        },
        {
          "tag": "v1.47.6",
          "kind": "patch",
          "published_at": "2026-07-21T14:08:32Z"
        },
        {
          "tag": "v1.47.5",
          "kind": "patch",
          "published_at": "2026-07-21T07:37:48Z"
        },
        {
          "tag": "v1.47.4",
          "kind": "patch",
          "published_at": "2026-07-21T06:57:11Z"
        },
        {
          "tag": "v1.47.3",
          "kind": "patch",
          "published_at": "2026-07-21T06:36:07Z"
        },
        {
          "tag": "v1.47.2",
          "kind": "patch",
          "published_at": "2026-07-21T03:18:48Z"
        },
        {
          "tag": "v1.47.0",
          "kind": "minor",
          "published_at": "2026-07-21T02:43:34Z"
        },
        {
          "tag": "v1.46.0",
          "kind": "minor",
          "published_at": "2026-07-19T21:37:28Z"
        },
        {
          "tag": "v1.6.4",
          "kind": "patch",
          "published_at": "2026-07-01T04:52:56Z"
        },
        {
          "tag": "v1.6.3",
          "kind": "patch",
          "published_at": "2026-07-01T04:16:38Z"
        },
        {
          "tag": "v1.6.2",
          "kind": "patch",
          "published_at": "2026-07-01T04:15:04Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2026-07-01T03:52:49Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-06-30T18:01:49Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-06-30T17:19:09Z"
        },
        {
          "tag": "v1.4.10",
          "kind": "patch",
          "published_at": "2026-06-30T06:31:06Z"
        },
        {
          "tag": "v1.4.9",
          "kind": "patch",
          "published_at": "2026-06-30T05:35:03Z"
        },
        {
          "tag": "v1.4.8",
          "kind": "patch",
          "published_at": "2026-06-30T05:21:49Z"
        },
        {
          "tag": "v1.4.7",
          "kind": "patch",
          "published_at": "2026-06-30T05:09:11Z"
        },
        {
          "tag": "v1.4.6",
          "kind": "patch",
          "published_at": "2026-06-30T05:08:09Z"
        },
        {
          "tag": "v1.4.5",
          "kind": "patch",
          "published_at": "2026-06-30T04:50:02Z"
        },
        {
          "tag": "v1.4.4",
          "kind": "patch",
          "published_at": "2026-06-30T04:24:13Z"
        },
        {
          "tag": "v1.4.3",
          "kind": "patch",
          "published_at": "2026-06-30T03:43:56Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2026-06-29T22:42:04Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-06-29T19:20:17Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-06-29T14:28:26Z"
        },
        {
          "tag": "v1.3.5",
          "kind": "patch",
          "published_at": "2026-06-29T06:44:14Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2026-06-29T02:11:19Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-06-29T00:52:35Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-06-29T00:51:48Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-06-29T00:23:34Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-06-29T00:21:54Z"
        },
        {
          "tag": "v1.2.16",
          "kind": "patch",
          "published_at": "2026-06-29T00:19:36Z"
        },
        {
          "tag": "v1.2.15",
          "kind": "patch",
          "published_at": "2026-06-29T00:11:24Z"
        },
        {
          "tag": "v1.2.10",
          "kind": "patch",
          "published_at": "2026-06-29T00:05:51Z"
        },
        {
          "tag": "v1.2.8",
          "kind": "patch",
          "published_at": "2026-06-28T23:20:34Z"
        },
        {
          "tag": "v1.2.6",
          "kind": "patch",
          "published_at": "2026-06-28T22:17:35Z"
        },
        {
          "tag": "v1.2.5",
          "kind": "patch",
          "published_at": "2026-06-28T21:53:16Z"
        },
        {
          "tag": "v1.2.4",
          "kind": "patch",
          "published_at": "2026-06-28T21:28:16Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-06-28T21:24:03Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-06-28T20:47:28Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-06-23T20:46:34Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2026-06-23T20:02:12Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-06-23T18:47:12Z"
        },
        {
          "tag": "v1.0.4",
          "kind": "patch",
          "published_at": "2026-06-23T04:49:53Z"
        },
        {
          "tag": "v1.0.3",
          "kind": "patch",
          "published_at": "2026-06-23T03:18:21Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-06-23T02:59:27Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-06-22T07:23:41Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e0db8b2353b7756013582ee766bb6ff23cea40e9",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.5.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T06:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e5b383c1760661a0d5b5cc3ade5654ba08b0cc5",
          "body": "…er-exports-lutkzd\n\nfeat: publish the claude-hooks composition surface as typed subpaths",
          "is_bot": false,
          "headline": "Merge pull request #190 from AlexanderMattTurner/claude/agent-sanitiz…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T06:07:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59779bfa4b3e26dd7304888fbc467539bc08dd61",
          "body": "2.4.1 shipped the four Claude Code hooks and their nine shared libs in the\ntarball behind a single `\"./claude-hooks\"` exports entry pointing at\nplugin-hooks.mjs, whose only export is the `--hook=` CLI dispatcher. Every\ncomposable piece — sanitizeText, evaluateToolOutput, composeContext, the whole\nho\n[…]\ner had.\n\nA pattern rather than a hand-listed set: `files` already ships the whole\nclaude-hooks tree, and a per-module allowlist would leave the next lib\nunreachable until someone remembered to add it.",
          "is_bot": false,
          "headline": "feat: publish the claude-hooks composition surface as typed subpaths",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T05:55:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b570839ebb0681afc9603e3512d85032b26520eb",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.4.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T05:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ba401da7c2dd41c02d9fac2f62d9ecd12c3038e",
          "body": "…gin-migration-v68rdg\n\ndocs(readme): cut the README by a quarter and unbury the examples",
          "is_bot": false,
          "headline": "Merge pull request #189 from AlexanderMattTurner/claude/sanitizer-plu…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T05:33:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f49171d92c6226b67760b79d9c6f682b29f0e1",
          "body": "345 -> 263 lines. The Claude Code section spelled the same settings.json\nentry four times (60 lines of JSON) where one entry plus an event ->\n--hook= table says it; the comparison and Python sections restated their\ntables in prose; and the API examples sat under '## How this compares',\nwhich is not what they compare. Examples is now its own section.\n\nNo content dropped: every entry point, code, command, env var and link\nsurvives.",
          "is_bot": false,
          "headline": "docs(readme): cut the README by a quarter and unbury the examples",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T05:28:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ad245af82ec7cac9086afd9510f950f445bc1e5",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.4.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T05:24:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6c7f141e86b9e0d34f62e669c4f666f9b242923",
          "body": "…gin-migration-v68rdg\n\nfeat: publish the Claude Code hooks as agent-sanitizer/claude-hooks",
          "is_bot": false,
          "headline": "Merge pull request #188 from AlexanderMattTurner/claude/sanitizer-plu…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T05:24:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a50596bef33d4e46bf6944cfe0423816b4a368eb",
          "body": "…its stated reason\n\nThe floor claimed to ratchet against deleting the un-bundled entry tests.\nDeleting all three of them leaves coverage identical at 95/3297 lines, so\nit never observed them: `plugin-hooks.mjs` measures 0% while three tests\nspawn it, and the 95 covered lines are scattered import-tim\n[…]\n is worth less than nothing. The behavioural gates hold this code:\nthe degraded-verdict matrix, the env-var coverage enumeration, the egress\npin, the new fail-closed peer test and the live-engine job.",
          "is_bot": false,
          "headline": "fix(ci): drop the claude-hooks coverage floor, which cannot fail for …",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T05:05:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74219c2db293ae713bc2c1de7ebae3961bada051",
          "body": "The four hooks were reachable only by installing the marketplace plugin.\nThis exports the un-bundled sources so a project can wire them into its\nown settings.json against the npm package, with the plugin remaining the\nzero-config path.\n\n`agent-control-plane-core` and `namespace-guard` move to depend\n[…]\ned guards instead. Observed: with agent-control-plane-core\nremoved from a consumer install, sanitize-output emitted\n`[SANITIZATION FAILED …]` and the AWS key did not survive; before, stdout\nwas empty.",
          "is_bot": false,
          "headline": "feat: publish the Claude Code hooks as agent-sanitizer/claude-hooks",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T04:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d280f7cb1a30398cb87d95dc44131450dd9069f",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.3.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T04:45:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42e8804a5ca98ceefe9840a8307b53239b9db898",
          "body": "…er-plugin-26isvp\n\nfeat(plugin): ship the Claude Code plugin from this repo",
          "is_bot": false,
          "headline": "Merge pull request #184 from AlexanderMattTurner/claude/agent-sanitiz…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T04:45:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f31c90b49fa144678062ace54d5b473a749127f3",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.2.2 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T03:47:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91fe81758ead6f6dae0bd876fe132b739ce91900",
          "body": "…action-false-positive-glvldl\n\nfix(secrets): stop a lone PEM header from redacting the rest of the file",
          "is_bot": false,
          "headline": "Merge pull request #187 from AlexanderMattTurner/claude/edit-tool-red…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T03:46:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0481df6ed6a75ae325e7fc8c0e747c648448fa37",
          "body": "PEM_BLOCK_RE ended an unterminated block at end-of-string, so a bare\n\"-----BEGIN PRIVATE KEY-----\" (a test fixture, a doc example) collapsed\nevery byte after it into one [REDACTED: Private Key] placeholder. In a 98 kB\nfile that hid 13 kB of unrelated source from the model's view, and made\nrehydrateR\n[…]\n line.\n\nThe R1 intrusion deny now reports both byte ranges it compared, so a caller can\ntell a true overlap from a mis-sized redaction instead of re-reading text the\nmessage wrongly implies is hidden.",
          "is_bot": false,
          "headline": "fix(secrets): stop a lone PEM header from redacting the rest of the file",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T02:59:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5002fc375bd76bd931f523b08bbc8bced74fe1e",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.2.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T01:53:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a037cfb78471abf894244952fe6532e72619ad3",
          "body": "…gin-migration-v68rdg\n\ndocs(skills): require PR bodies to state the current head, never their own history",
          "is_bot": false,
          "headline": "Merge pull request #186 from AlexanderMattTurner/claude/sanitizer-plu…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T01:52:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b4d40dbd21249e70589ec764741d52c57daf9d3",
          "body": "…ts skeleton",
          "is_bot": false,
          "headline": "docs(skills): carry the current-head rule into the update-after-commi…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:49:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bfeef192400eee037a176b5c8d991a891d55bfb",
          "body": null,
          "is_bot": false,
          "headline": "docs(skills): trim the current-head rule to substitutions, not additions",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ccee07190a36960c9cc90e803b4b97509b9bb53",
          "body": "…r own history\n\nThe body template asked for 'what you ran and the outcome', which in\npractice licenses session chronology, and nothing banned a body from\nnarrating its own earlier claims. Align with the current-state rule:\n'How it was tested' is claims about the CURRENT head paired with the\ncommands\n[…]\nt falsify them now; a false claim in an earlier body version\nis replaced, never corrected in place; evidence cycles appear as the\ncurrent-state fact they established, not the runs that established it.",
          "is_bot": false,
          "headline": "docs(skills): require PR bodies to state the current head, never thei…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:42:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8a7a426090da15a378de21495e1cb5c9bbe30c6",
          "body": "The trace module's contract is that every defense layer announces it\nRAN, and sanitize-user-prompt was the one stdin hook that never did — a\nsilently disabled prompt gate was invisible on the channel. The trace\ntest now derives per-hook coverage: all three stdin hooks must emit\nhook_ran.",
          "is_bot": false,
          "headline": "feat(plugin): announce prompt-gate engagement on the trace channel",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:25:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8d40d22fa98eef25488de308ddb6524a0505cc9",
          "body": "The wiring kill test is complete: node-tests-passed went red on the\ncorrupted head (run 30505171252), so the plugin suite is proven wired\ninto the required check, not presumed.\n\nAlso isolates the live-engine corpus onto a per-run socket. The echo-stub\nkill test caught the corpus trusting the DEFAULT\n[…]\n the stub\nreds two corpus checks (secret survives, no REDACTED marker) and the\nreal engine passes all seven; the credential-var check also gains a\npositive control so silence cannot pass as redaction.",
          "is_bot": false,
          "headline": "test(plugin): revert the deliberate red; isolate the live-engine socket",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:20:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b254c85b7d3fbbb30e0e9f0e51df715ab8e0bf9",
          "body": "Wiring kill test: a suite whose CI-redness has never been observed is\npresumed unwired. Reverted in the next commit.",
          "is_bot": false,
          "headline": "test(plugin): deliberate red to observe node-tests-passed fail",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:16:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a18ef34ecc54bb4f41c22c7f48f5c15fc22ff869",
          "body": "The JS side is one committed bundle, but the Python redactor still\nrequired a SessionStart PyPI install: no venv (or no network) meant\nsanitize-output failed closed on every tool call. plugin/dist/redactor/\ndaemon.pyz closes that hole — a self-contained, platform-independent\nzipapp of the pinned age\n[…]\ne committed\nartifact is tracked, pure-Python, and actually redacts.\n\nAlso adds the degraded-posture completeness test: every wired hook must\nsit in exactly one posture table (fail-closed or advisory).",
          "is_bot": false,
          "headline": "feat(plugin): ship the redaction engine as a committed zipapp",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T01:15:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "409e7e8e93d970a9a2ea2204dc7948c7bcb73878",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.2.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T01:05:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15498063ac3a37493f05122f4bc0b8640447f8ec",
          "body": "…ential-vocabulary-7t86vy\n\nfeat(secrets): publish the credential-noun vocabulary as a shared export",
          "is_bot": false,
          "headline": "Merge pull request #185 from AlexanderMattTurner/claude/upstream-cred…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-30T01:04:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f83f74520f982f2e6c1ce2ecaad61d8b6284c8",
          "body": null,
          "is_bot": true,
          "headline": "chore(plugin): regenerate dist for the pinned engine",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T00:58:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94a1cd58c5c2cf036df14df24a55d4128374a197",
          "body": "Kill test for the plugin-suite CI wiring. The previous attempt also touched a\nbuild input, so plugin-dist-autofix healed it before the required check could\nreport. plugin/dist is not in that workflow's paths, so this one stands.",
          "is_bot": false,
          "headline": "test(plugin): dist-only corruption to observe node-tests-passed go red",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:57:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7194aa4e99ad7af4795d287deddc8cc9e359d54a",
          "body": null,
          "is_bot": true,
          "headline": "chore(plugin): regenerate dist for the pinned engine",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-30T00:52:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "031f4368133eb839cec476d9d10503a2a2300329",
          "body": "Kill test for the plugin-suite CI wiring. Reverted in the next commit.\nA suite whose redness has never been observed is presumed unwired.",
          "is_bot": false,
          "headline": "test(plugin): corrupt the bundle to observe node-tests-passed go red",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:51:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67b1e85b3c7ae4a01cbba69507a6fe8e618bd6db",
          "body": "The name claimed an ordering assertion the test does not make.",
          "is_bot": false,
          "headline": "test(secrets): name the dedup test for what it asserts",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a4338ea23a26c49a5a63eb2fd9333e8993e971",
          "body": "Layer 2 was dead in the shipped plugin. css-tree pulls its CSS syntax\ntables through `createRequire(import.meta.url)(\"../data/patch.json\")`;\nesbuild inlines the surrounding JS but leaves that require, which then\nresolves against the BUNDLE's directory. An installed plugin has no\n`plugin/dist/data/`,\n[…]\nmerated\n  from the sources so a new one cannot ship unexercised\n- a degraded-verdict matrix derived from hooks.json\n- an egress pin: the artifact's only outbound surface is the local\n  redactor socket",
          "is_bot": false,
          "headline": "fix(plugin): inline the JSON data css-tree requires at runtime",
          "author_name": "t",
          "author_login": null,
          "committed_at": "2026-07-30T00:50:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a237d3814dd62ee50c4e5ede4fb5947480939ca",
          "body": "The words that make an identifier name a secret existed twice with no link\nbetween them: as regex fragments in the engine's `_FIELD_NAMES`, and as an\nenv-var-name segment list in a downstream consumer. A newly recognized noun had\nto be added in both trees by hand, and a noun added to one side only l\n[…]\nly rather than\nthrough a conditions object (so the new export would have been unguarded), and\nit parsed npm's stdout whole, reddening when pnpm's deps check wrote a\n\"Progress:\" line ahead of the JSON.",
          "is_bot": false,
          "headline": "feat(secrets): publish the credential-noun vocabulary as a shared export",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:37:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0ef2c9381e7b361444bc37327a30e465a5b0179",
          "body": "…s on\n\nThe plugin ships a committed esbuild bundle that inlines 69 third-party\npackages, and `committed bundle matches a fresh build` runs inside the\nRequired node-tests check. With pnpm-lock.yaml gitignored, CI resolved\nthose packages fresh on every run across 695 ranged dependency edges, so\nthe ne\n[…]\nand\npack-smoke, mutation, hook-lifecycle and plugin-dist-autofix all list it\nas a trigger path. It also restores setup-node's `cache: pnpm`, which\nthe removed comment named as the cost of ignoring it.",
          "is_bot": false,
          "headline": "fix(ci): commit the lockfile the bundle's reproducibility gate depend…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-30T00:19:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f11463741b6ead8c9fa6c6e775595ceaa820dab0",
          "body": "`dist/` in .gitignore matched plugin/dist/, so `git add -A` silently skipped\nthe one file the plugin cannot work without. Every local assertion still passed\nbecause the build had just written it as an untracked file; only a fresh clone\nsaw the truth, which is what CI reported (12 red).\n\nRe-include t\n[…]\nt that catches the class: ask `git ls-files` what is\nTRACKED rather than the filesystem what exists, so an ignore rule that swallows\na shipped artifact reds a test instead of shipping an empty plugin.",
          "is_bot": false,
          "headline": "fix(plugin): commit the bundle the .gitignore was swallowing",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:40:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "219bfec7a5e6f9a7f28d79108fd5ea37cb272975",
          "body": "The repo's check-json pre-commit hook parses every .json with a strict decoder,\nso a tsconfig carrying JS comments fails the push.",
          "is_bot": false,
          "headline": "fix(plugin): drop JSONC comments from tsconfig.hooks.json",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:34:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "006d1d8813ee00b422df0d7363734feb4c52cd79",
          "body": "…equired\n\nThe hook modules are loaded by the bundle entry (or by `node <path>` for the\nbuild script), never executed as `./path`, so a shebang without the executable\nbit is the mismatch the tier-1 check flags. The dist-autofix workflow pushes an\nartifact onto the PR branch rather than reporting a status, so its paths filter\nstrands no required check.",
          "is_bot": false,
          "headline": "chore(plugin): drop unused shebangs and mark the dist autofix never-r…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:33:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1575c628abc4067fdd1d24502c9c0f32d9331aea",
          "body": "Port the sanitizer plugin out of agent-glovebox and into the engine's own\nrepo, bundled against the PUBLISHED npm package rather than sibling workspace\nsources. The plugin's committed bundle therefore only moves when the engine pin\nmoves, which is what kills the perpetual merge-conflict churn that m\n[…]\nLOVEBOX_* env var. The three redactor configs are\nimported as JSON modules instead of read from disk by __dirname arithmetic, so\nesbuild inlines them and the bundle has no config directory to resolve.",
          "is_bot": false,
          "headline": "chore(plugin): ship the Claude Code plugin from this repo",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-29T23:26:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55e6566f5cdbf62d8a447e428a6eb232c1fa760a",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.1.0 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-29T18:27:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45651cc636a4fc0d9e4e754a0c62d0bce6046fbd",
          "body": "…lockfile-conflicts-xefa1t\n\nfeat(ci): auto-regenerate conflicted lockfiles in auto-resolve instead of handing off",
          "is_bot": false,
          "headline": "Merge pull request #183 from AlexanderMattTurner/claude/auto-resolve-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-29T18:26:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "665d3a8d737bc936a3d3f5f7551128d3b58a2e66",
          "body": "The absent-tool test filtered PATH by dirname(command -v pnpm), which names\nonly the FIRST match — a runner carrying a second pnpm elsewhere on PATH kept\nthe tool reachable, so the lockfile took the deferred-regen branch and the test\npassed on the wrong branch until needs_commit tripped it in CI.\n\nF\n[…]\ntly: pnpm\nunreachable, git and dirname still reachable. Losing dirname would make\nlockfile_tool decline the path and route it to the LLM — a third wrong branch\nthat also satisfies the first assertion.",
          "is_bot": false,
          "headline": "test(ci): strip every pnpm from PATH and assert the absent-tool premise",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:36:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2075e4087835d6487a75c30bc92cdb024c34d2fb",
          "body": "…entials\n\nReview of the deferred-lockfile stage surfaced a silent wrong-resolution path\nand a privilege leak:\n\n- Seed regeneration from --theirs (base), not --ours (PR head). Every lockfile\n  tool preserves the resolutions it finds on disk, so seeding from the PR's own\n  lockfile regenerated it byte\n[…]\nmanifest branches, and assert the tool's argv,\nseeded content, and scrubbed environment so each rail is load-bearing. Wire\nthe auto-resolve suites into CI, which node --test's default discovery skips.",
          "is_bot": false,
          "headline": "fix(ci): seed lockfile regeneration from the base side and scrub cred…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:31:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f719de0ff63242270902a9f818fc76e5e0c54693",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.0.3 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-28T22:30:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "718c5f3a10b7d7bb2d63038ec4326211c3fabcd9",
          "body": "…er-180-146rqc\n\nfix(release): skip re-runs against an already-released SHA",
          "is_bot": false,
          "headline": "Merge pull request #181 from AlexanderMattTurner/claude/agent-sanitiz…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T22:29:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2e6f2c7cc6a4dda9e125877928b8522a74bf425",
          "body": "…ry API\n\nThe known-vulnerable-actions audit only fires when GH_TOKEN is visible, so it\nran in agent sessions and nowhere else; there the advisories endpoint is 403 and\nzizmor aborts, making every .github/ change unpushable. Run offline audits only\nin the hook; CI is the place to restore online coverage with a token.",
          "is_bot": false,
          "headline": "fix(ci): stop the zizmor hook failing closed on an unreachable adviso…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:20:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18f8117ffc5315b5c1a9f0e166ae9486bd02f2be",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): restore the executable bit on version-bump.sh",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:13:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf496b742e107563e656c67143c66db9fb7a0564",
          "body": null,
          "is_bot": false,
          "headline": "style(ci): apply shfmt case-indent formatting to auto-resolve-lib",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:10:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22027ad21f9dd19050877ce9396d50c7b320d359",
          "body": "Auto-resolve previously classified any conflicted lockfile as unresolvable\nand handed off to a human, even though the fix is purely mechanical. Prepare\nnow defers lockfiles with a known owning tool (pnpm-lock.yaml,\npackage-lock.json, uv.lock) to a new deferred_lock class; finalize re-runs\nthe owning\n[…]\nved manifests and stages the result. Only\nbinaries and unsupported lockfiles still hand off — and the handoff now\nlabels the PR auto-resolve-blocked so base pushes stop retrying into the\nsame refusal.",
          "is_bot": false,
          "headline": "feat(ci): auto-regenerate conflicted lockfiles instead of refusing them",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T22:09:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d5b7faf1cb2c66e5acdceacfe849fb636f2ee19",
          "body": "The lowest v-tag containing HEAD is the release that shipped it; a descending\nsort named the newest release instead, misdirecting anyone reading the log.\nAlso correct the tagging comment, which still claimed a re-trigger sees\nHEAD == tag SHA — the false premise the already-released guard exists to fix.",
          "is_bot": false,
          "headline": "fix(release): name the tag that actually released HEAD when skipping",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T22:08:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af10c30fc9cdb2f0ad9c90693ccae851dafc65be",
          "body": null,
          "is_bot": false,
          "headline": "test(release): cover a re-run against an already-released SHA",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T21:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3948579198524d7c6fad3a01167cd0eafe6ce01",
          "body": "The release tag lands on the release-docs commit, a child of the SHA that\nwas published, so a re-run against that published SHA saw only ancestor\ntags: `git describe` reported the previous release and the run re-cut the\nsame commit range under a fresh version number, publishing a byte-identical\nduplicate. Exit early when `git tag --contains HEAD` finds a release tag.\n\nCloses #180",
          "is_bot": false,
          "headline": "fix(release): skip re-runs against an already-released SHA",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T21:57:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a5ec9d6f698c411053751eb820ddb1048331ae6",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 2.0.1 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-28T21:11:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8a193945a4910239f7601f5e501115c2a2f9b7b",
          "body": "…p-edges-uqdwzh\n\nfix(secrets): make unknown assignment operators fail wholesale, never partially match",
          "is_bot": false,
          "headline": "Merge pull request #179 from AlexanderMattTurner/claude/gh-audit-shar…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T20:50:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4793e3ab7eb99e5c3bd9d5677d98ed43719d45ab",
          "body": "… partially match\n\nA multi-char operator the field-value alternation doesn't know (===, =~) had\nits first byte matched by the one-byte arm, gluing the rest onto the captured\nvalue where the stray byte defeats every fullmatch-anchored value-shape skip\nat once — the class behind both shipped false pos\n[…]\nroduces a false negative instead, and === is\nexplicit. An operator x skip-shape grid test pins every combination, with a\npositive redaction marker per operator so the benign half can't pass\nvacuously.",
          "is_bot": false,
          "headline": "fix(secrets): make unknown assignment operators fail wholesale, never…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T20:47:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d0ad21df25568316fa5d6228c20b968e65cdf3f",
          "body": "…and-pin\n\nfix(hooks): stop tag pushes from rebuilding the whole pre-commit suite",
          "is_bot": false,
          "headline": "Merge pull request #175 from AlexanderMattTurner/claude/pre-push-tag-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T20:29:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c14b5502cb42394261188c9e69388dd1e5d43d1",
          "body": "…p-edges-uqdwzh\n\nfix(secrets): stop redacting shell parameter-expansion defaults and secret-location fields",
          "is_bot": false,
          "headline": "Merge pull request #178 from AlexanderMattTurner/claude/gh-audit-shar…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T20:29:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff7e64f47d95e03cfa5ccde511b5bbaa7b35070a",
          "body": "…ecret-location fields\n\nThe field-value regex treated the : in ${SECRET_FILE:-/etc/app/secret} as a\none-byte assignment, gluing the -/+/? operator byte onto the captured value so\nevery value-shape skip (filesystem path, env reference, placeholder) stopped\nmatching and an ordinary shell default was m\n[…]\no adds path/file to the metadata-field suffixes: secret_path / key_file\nfields name where a secret lives, and their variable-rooted or relative values\nescape the absolute-path and env-reference skips.",
          "is_bot": false,
          "headline": "fix(secrets): stop redacting shell parameter-expansion defaults and s…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T20:16:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "038b49a79435ddea18faeed11376c429c237dd16",
          "body": "ci: print PyPI's rejection reason on publish failures",
          "is_bot": false,
          "headline": "Merge pull request #176 from AlexanderMattTurner/claude/pypi-verbose",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T07:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87f4f0d16aa94a6bc49be110807132c33a4161f6",
          "body": "The break-glass publish died with a bare \"HTTPError: 400 Bad Request\" —\ntwine only prints the registry's response body (which names the offending\nmetadata field or publisher mismatch) under --verbose, so the failed run\ncarries no diagnosis. Both publish steps now pass verbose: true.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01MNEMrPimpPVH8HUAGqzEMu",
          "is_bot": false,
          "headline": "ci: print PyPI's rejection reason on publish failures",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T06:11:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ae4d2365e2914e0aba91d02a1f1f5ec74d72f3af",
          "body": "`git push origin <tag>` fed the pushed-range check a tag ref, which has no\nupstream to diff against, so it fell through to the new-branch fallback and\nswept the merge base with origin/HEAD — a stale branch on this clone. Skip tag\nrefs: a tag adds no commits, and the tagged commit was already checked\n[…]\n this very file. Use exit code 3 instead: pre-commit maps hook failures to 1\n  and everything else, including a failed environment install, to 3.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): stop tag pushes from rebuilding the whole pre-commit suite",
          "author_name": "Alexander Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T05:21:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9be965ad0a1bf3c2cb8d0da3b7bb10d439ecfc84",
          "body": "fix(ci): give the conflict resolver uvx so the pre-push hook can run",
          "is_bot": false,
          "headline": "Merge pull request #174 from AlexanderMattTurner/claude/resolver-uvx",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-28T00:49:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d7d8f1c6920c504c7ed30ef2eb0f1273c5e7907",
          "body": "The resolution push executes the checked-out PR head's .hooks/pre-push,\nwhich runs the pushed-range pre-commit suite through uvx. The resolver\njob never installed uv, so the hook degraded on every run — and a PR\nhead carrying an older hook revision fails closed, rejecting the\nresolution push with \"required tool 'pre-commit' not found\" (PR #169).\nWith uv present the hook checks the range for real on any branch\nvintage.",
          "is_bot": false,
          "headline": "fix(ci): give the conflict resolver uvx so the pre-push hook can run",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-28T00:46:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "655b7fb5471fc14476270e08a0835461ab680fc4",
          "body": "ci: source the org PAT (TEMPLATE_SYNC_TOKEN_ORG) in every workflow",
          "is_bot": false,
          "headline": "Merge pull request #172 from AlexanderMattTurner/claude/org-pat-sweep",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-27T22:34:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f35dcf52fac8a7b015c9eac64f72a739b681f4e",
          "body": "…xandermattturner/agent-input-sanitizer into claude/org-pat-sweep",
          "is_bot": false,
          "headline": "Merge branch 'claude/org-pat-sweep' of http://127.0.0.1:41729/git/ale…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T22:19:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d26b9cec451d01c3212b61be9854e2566a664173",
          "body": "GitHub rejects approving reviews minted with the Actions GITHUB_TOKEN\n(\"GitHub Actions is not permitted to approve pull requests\"), so the\npush-time approve step and the hourly sweep both source\nTEMPLATE_SYNC_TOKEN_ORG, falling back to GITHUB_TOKEN which fails loud\non the approve when the PAT is unset. Explicitly user-directed.",
          "is_bot": false,
          "headline": "ci: approve with the org PAT in the reviewer-hold clear paths",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T22:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf84535e652f6336ea3011fd11011d5081199d35",
          "body": null,
          "is_bot": true,
          "headline": "style: apply prettier",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-27T22:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "021d6a16b05457213ab68a3bd541473fc05aac0c",
          "body": "The four workflows still reading the cross-account TEMPLATE_SYNC_TOKEN\njoin auto-version and template-sync on the org-level PAT, which is the\ntoken actually authorized on this repo (version-bump.test.mjs pins the\ndistinction). Operator-facing messages and the auto-resolve env plumbing\nfollow the secret's name so remediation instructions point at the secret\nthat exists. The PR-approval step is untouched and stays on the Actions\nGITHUB_TOKEN.",
          "is_bot": false,
          "headline": "ci: source the org PAT (TEMPLATE_SYNC_TOKEN_ORG) in every workflow",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T22:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e653e479ed6732a611033a7393d09714c0db317b",
          "body": "…sanitizer\n\nfeat!: rename the package to agent-sanitizer",
          "is_bot": false,
          "headline": "Merge pull request #170 from AlexanderMattTurner/claude/rename-agent-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-27T22:03:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6450a51a7ad08716fc03d7cdb297b3caa728ecb9",
          "body": "The pinned 1.38.0 was only ever published under the old package name, so\nunder agent-sanitizer it can never resolve and the install step would 404\nevery review workflow on first run after merge. 2.0.0 is the version the\nrename's feat! merge makes auto-version cut from the 1.47.x line — the\nfirst release that will exist under the new name.",
          "is_bot": false,
          "headline": "fix(ci): pin the review-pipeline sanitizer install to 2.0.0",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T21:17:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b49ead8b9e83ea37f0bee8e5e56567649399a6f",
          "body": null,
          "is_bot": true,
          "headline": "style: apply prettier",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-27T21:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adc05fac55b65a2b440088fd42c1a9f7b65aae98",
          "body": "BREAKING CHANGE: the npm package, the PyPI distribution, and the Python\nimport package are now `agent-sanitizer` / `agent_sanitizer` (previously\n`agent-input-sanitizer` / `agent_input_sanitizer`), with no compatibility\nalias. The tool sanitizes an agent's whole content surface — tool output,\nuser pr\n[…]\n-referential GitHub URLs move to the renamed repo;\nnpm provenance validates repository.url against the publishing repo, so\nthe GitHub repo rename must land before the first release under the new\nname.",
          "is_bot": false,
          "headline": "feat!: rename the package to agent-sanitizer",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-27T21:09:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "77d78aa01191547927050d35c439178d7e746fdf",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.14 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T20:31:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51535335d0e05334319a12b14b8aa6f35d5b7398",
          "body": "…h-workflow-1pff2b\n\nfix(ci): rebase release-docs push when main advances mid-run",
          "is_bot": false,
          "headline": "Merge pull request #167 from AlexanderMattTurner/claude/python-publis…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T20:30:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0a5eb2a2b9d1b1a96e8cf3d316c00ceda4bac80",
          "body": "…notate rebase marker\n\nTwo CI-red fixes:\n\n- The release-docs race test spawns the real version-bump.sh, which reads\n  GITHUB_REF_NAME as the push target. Under Actions that names the PR merge\n  ref (167/merge), so the run targeted the wrong branch and the\n  rebase-on-reject path never fired — the te\n[…]\n to inline-only\n  workflow guards. Add its documented allow-externalized-marker opt-out with\n  a truthful reason: auto-version.yaml checks out fetch-depth: 0, the exact\n  invariant the guard protects.",
          "is_bot": false,
          "headline": "test(ci): stop leaking GITHUB_REF_NAME into the release-race test, an…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T20:26:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e31a12ebf58ef8efbbe2ba616394f03ff10476d3",
          "body": "The template ships its own version-bump.test.mjs, and template-sync landed\nit at .github/scripts/version-bump.test.mjs. It tests the template's release\ndesign (plain-string npm view, GITHUB_TOKEN-only push) against this repo's\nhardened live script (npm view --json, TEMPLATE_SYNC_TOKEN_ORG push), so it\nfails 5/6 and is red on main. scripts/version-bump.test.mjs already covers the\nlive script and passes; extend its SSOT contract test to assert the template\nduplicate stays gone.",
          "is_bot": false,
          "headline": "test(ci): drop incompatible template-synced version-bump test",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T20:11:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d83625e050a477d66b854fc3aac409dd04518ab",
          "body": "In a restricted-egress sandbox, pre-commit can't download a linter's\nbinary (shellcheck/shfmt fetch from GitHub releases -> HTTP 403) and\nhard-fails the environment install before running anything. That is not a\nlint failure, but it aborted every 'git push' from such an environment.\n\nCapture pre-com\n[…]\nthe existing 'skip loudly when uvx is absent' path. A\ngenuine lint/format failure from a hook that actually ran still aborts the\npush. CI (pre-commit.yaml) re-runs the full suite on the PR regardless.",
          "is_bot": false,
          "headline": "ci: skip pushed-range pre-commit run when a hook can't be provisioned",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T19:40:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9ae63d5a537db238d61431041cc3ba67f7f43e9",
          "body": "The main-merge auto-resolver garbled the version-bump.sh conflict: it\ndropped the RELEASE_DOCS_PUSH_FAILED=0 initialization (leaving a set -u\nunbound-variable crash right after the release-docs push, before tagging)\nand mangled the push call into the nonsensical\n`retry_cmd push_with_rebase \"HEAD:$DE\n[…]\nutostash on non-fast-forward so a racing merge can't strand the\nrelease), and set RELEASE_DOCS_PUSH_FAILED on failure so the tag is skipped\nwhen docs did not land. The race regression test now passes.",
          "is_bot": false,
          "headline": "fix(ci): repair botched auto-merge of release-docs push logic",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T19:33:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5419a32e41a6813ca5c948931aaf2257b53d2049",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into claude/python-publish-workflow-1pff2b",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T19:20:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1040443e88e2488346f66b1e853a2d8de6cc9a0b",
          "body": "The auto-version concurrency group serializes the workflow, but main can\nstill advance via an ordinary PR merge while a release run is in flight.\nThe run then holds a stale tip and its `git push HEAD:main` is rejected\nnon-fast-forward; the old retry_cmd just re-ran the identical push, which\ncan neve\n[…]\navioral test that runs the real script against a bare remote which\nadvances out from under it, asserting the release-docs commit and tag land\non top of the concurrent commit (never force-pushed away).",
          "is_bot": false,
          "headline": "fix(ci): rebase release-docs push when main advances mid-run",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T17:20:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84cf21d49fa22914598c55111c3e52550b2583ca",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.13 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T16:36:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffc62986c85078db8c4f77eb72a7839e35a2d527",
          "body": "chore: sync from template repository",
          "is_bot": false,
          "headline": "Merge pull request #163 from AlexanderMattTurner/template-sync",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T16:35:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1471d2a6c15b9eadff1ad3b312933b253556a82",
          "body": "Finalize PR #163 (sync from template f2b22de) by resolving the 12 conflicted\nfiles, keeping project-specific customizations and adopting genuine template\nimprovements:\n\n- pre-push-check.sh: take template's ruff runner (local's string form is broken\n  against the `\"$@\"` run_check).\n- session-setup.sh\n[…]\ns at three jq sites (added matcher-content check), and\nmatchers must be tool-name filters (real settings.json already uses `Bash` + an\n`if` field), so the fixture's command-content matcher is updated.",
          "is_bot": false,
          "headline": "chore: resolve template-sync merge conflicts",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T15:55:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "671bc5b4f34bd4a598d84ed06b46d6518db983be",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.11 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-23T06:40:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96e834030c46d55c29f1b519d6e4668dddcd2e38",
          "body": "…anitizer-py310-cjqrie\n\nfix(python): lower requires-python to 3.10 by removing 3.11-only regex",
          "is_bot": false,
          "headline": "Merge pull request #165 from AlexanderMattTurner/claude/agent-input-s…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T06:31:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9053a7f1dea05197860bf3f7b14a4713529e745",
          "body": "Run pytest only on Python 3.10 (the package's declared floor) in validate-config\ninstead of also on 3.11. Running the floor immediately surfaced a real gap:\ntests/test_gitleaks_allowlist.py imported the stdlib `tomllib`, which only exists\non 3.11+, so the guard could never have run on 3.10. Fall back to `tomli` (a\nmarker-gated dev dependency, installed only below 3.11) so the allowlist guard\nruns on the floor with real TOML parsing rather than a hand-rolled approximation.",
          "is_bot": false,
          "headline": "test(python): make the suite run on the 3.10 floor in CI",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T06:29:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "014de1e13b137e6441f65e66eed1d97ffe0b6bec",
          "body": "The published wheel declared `requires-python = \">=3.11\"` and the secrets\nredaction engine used a possessive quantifier (`*+`) in `_ENV_REFERENCE_RE`,\na regex feature `re` only gained in Python 3.11. Downstream bases on Python\n3.10 (e.g. Ubuntu 22.04 / 3.10.6) therefore had no installable wheel, eve\n[…]\npy.\n\nRun the pytest suite on both 3.10 (the floor) and 3.11 in CI, so a future\n3.11-only construct can no longer slip in unnoticed — the gap that let the\npossessive quantifier land in the first place.",
          "is_bot": false,
          "headline": "fix(python): lower requires-python to 3.10 by removing 3.11-only regex",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-23T06:15:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebde9617ceacbb8f4118fbec2a086e5f262675a9",
          "body": null,
          "is_bot": false,
          "headline": "chore: sync from template repository (f2b22de)",
          "author_name": "alexander-turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-23T05:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa5ec791a7ac5d97d817b7c74ccb4f25ef9d045b",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.10 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-22T23:53:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d322cb0e15919649059b08319aaf56442f68e518",
          "body": "…t-sanitizer-control-plane-syat46\n\nfix(sanitizer): hidden-text false positives, scale-collapse miss, base64url beacon, lone-surrogate re-redact",
          "is_bot": false,
          "headline": "Merge pull request #164 from AlexanderMattTurner/claude/parallel-audi…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-22T23:53:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e27b4b681f462ec85e612a8d3aa3611fa9cfa38b",
          "body": "Same template-synced file, same pre-existing drift as the control-plane repo:\nruff-format wants two blank lines before the top-level\ntest_survives_self_overwrite_with_longer_file def. Surfaced by pre-commit\nrun --all-files; fixing to get the PR's pre-commit check green.",
          "is_bot": false,
          "headline": "style: satisfy ruff-format blank-line rule in test_template_sync",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:45:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71cdb9f96d230a45ea8dba782fee6cf1e53b0881",
          "body": "…e branches\n\nThe strict c8 100% gate (lines/branches/functions) rejected three\nnewly-uncovered spots:\n\n- html.mjs isTextPaintedVisible re-checked -webkit-text-fill-color, but the\n  same-color/transparent branches now resolve the EFFECTIVE fill BEFORE calling\n  it, so a concrete fill keeps effectiveC\n[…]\nunder a 100% gate) and the atomicReplaceFile\n  rename-catch cleanup (a LOW temp-leak nit that would need a new public seam +\n  two branch tests to cover). The CLI cwd validation and docblock fix stay.",
          "is_bot": false,
          "headline": "fix(coverage): restore 100% — drop dead fill check, revert unreachabl…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:42:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f05ae55a427152b8e771c06b444c3f1ba68218f",
          "body": "…y tail\n\ncheckExfilUrl measured the long-query length from a raw indexOf(\"?\"), which can\nmatch a \"?\" inside the FRAGMENT — leaving parsed.search empty so allParamsBenign\nruns [].every(...) and vacuously suppresses the flag. Measure from parsed.search\n(the fragment is length-checked separately). No o\n[…]\n target and is a legal\nquery sub-delimiter WITHIN it, so a ?a=1;data=<blob> exfil tail was dropped. A\nquoted value now runs to its closing quote; an unquoted value stops only at\nwhitespace or a quote.",
          "is_bot": false,
          "headline": "fix(html): measure query from parsed.search; keep meta-refresh ;-quer…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:25:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "addaf3f4caf2b00e2da0518de00d1eff5b8ecaee",
          "body": "…, CLI cwd\n\ncleanFile now returns the documented null (not true) when scanText flagged a\npayload but stripInvisible removed nothing — a preserved-payload signal, so a\ncaller is never told a preserved run was cleaned. @returns corrected to\nboolean|null. The path is currently unreachable (every scan-f\n[…]\ntionFiles now fails loud on a present-but-non-string cwd\ninstead of silently dropping it and scanning process.cwd() (wrong scope). Stale\none-shot docblock corrected to say \"one-line reason on stderr\".",
          "is_bot": false,
          "headline": "fix(instructions): cleanFile null signal, temp cleanup on rename fail…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:21:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "742c1b50162d2b0cfbfb5a9d41e0b62043a73359",
          "body": "…omment\n\nisSgrColorOnly's second conjunct re-tested the SGR-stripped prompt against the\nsame C1 introducer class isSgrOnly already checks, so it was dead code, and its\ncomment falsely claimed isSgrOnly is blind to the C1 OSC introducer U+009D.\nisSgrOnly's control-introducer class already covers the whole C1 block\n(U+0080 through U+009F), U+009D included, plus 7-bit ESC. Behavior is unchanged;\nthe misleading comment is corrected so a future editor does not re-add a\nredundant OSC check.",
          "is_bot": false,
          "headline": "refactor(prompt): drop dead SGR-only conjunct and correct its false c…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T23:01:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f2c4019c7fbe802a77a8600018777c7c85066a8",
          "body": "Layer-5 span deletion can splice two kept regions across a lone UTF-16 surrogate\n(e.g. deleting one half of a surrogate pair), both reconstituting a secret the\nfirst redaction pass never saw intact AND leaving a lone surrogate the redactor\nreads as U+FFFD — so the reconstituted secret survives the r\n[…]\ne layer1.mjs docstring, which claimed applyLayer1\nnormalizes lone surrogates — it does not; LONE_SURROGATE_RE is exported for\nconsumers to apply at the redactor/HTML boundary, which is what this does.",
          "is_bot": false,
          "headline": "fix(output): normalize lone surrogates on the Layer-5 re-redact path",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T22:54:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55c9d087c3ea71cbf77c82444f69050f8321af13",
          "body": "… base64url beacon\n\nHidden-text detection: collapse the same-color/transparent branches onto one\neffective-fill-color and a centralized hasImageLayer() guard. The background-color\nLONGHAND path ignored a co-declared background-image, splicing text painted over\nan image; the same-color branch compare\n[…]\n word-slug shows neither. Raises recall\non scattered-separator beacons while keeping slugs benign (precision-first).\n\nRegression rows added to the hidden-style SSOT table and checkExfilUrl unit suite.",
          "is_bot": false,
          "headline": "fix(html): kill same-color false positives, multi-arg scale collapse,…",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-22T22:51:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f1009e0d9bbd084336b4c5315f29f634035bb4f",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.9 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T16:32:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2c17cc218cecea211301439cfe82a0c954ae9dc",
          "body": "…force-merge-qtv3bi\n\nci: use TEMPLATE_SYNC_TOKEN_ORG as the primary template-sync token",
          "is_bot": false,
          "headline": "Merge pull request #162 from AlexanderMattTurner/claude/templatesync-…",
          "author_name": "Alex Turner",
          "author_login": "alexander-turner",
          "committed_at": "2026-07-21T16:32:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fcd5977be397412d1ff52e67585ecf7df41bef4",
          "body": null,
          "is_bot": false,
          "headline": "ci: use TEMPLATE_SYNC_TOKEN_ORG as the primary template-sync token",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-07-21T16:31:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00612cedff99ca89b2b2e484a0121ed37d446e25",
          "body": null,
          "is_bot": true,
          "headline": "docs: release 1.47.8 [skip ci]",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-21T16:29:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 63,
      "commits_last_year": 606,
      "latest_release_at": "2026-07-30T06:08:32Z",
      "latest_release_tag": "v2.5.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "agent-sanitizer",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "llm",
            "prompt-injection",
            "sanitize",
            "unicode",
            "invisible-characters",
            "ansi",
            "exfiltration",
            "rag",
            "agent",
            "security",
            "homoglyph",
            "confusables",
            "redaction",
            "tool-output",
            "edit-repair"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/agent-sanitizer",
          "is_deprecated": false,
          "latest_version": "2.5.0",
          "repository_url": "https://github.com/AlexanderMattTurner/agent-sanitizer",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 797,
          "first_published_at": "2026-07-28T00:49:03.964000Z",
          "latest_published_at": "2026-07-30T06:08:31.970000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "agent-sanitizer",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ansi",
            "prompt-injection",
            "sanitizer",
            "security",
            "unicode",
            "License :: OSI Approved :: Apache Software License"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/agent-sanitizer/",
          "is_deprecated": false,
          "latest_version": "2.5.0",
          "repository_url": "https://github.com/AlexanderMattTurner/agent-sanitizer",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-07-28T15:58:16.326054Z",
          "latest_published_at": "2026-07-30T06:09:06.106909Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-04",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 91158,
      "source_files_sampled": 178,
      "oversized_source_files": 5,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 17470
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "plugin/requirements.txt",
        "pyproject.toml",
        "python/pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.1",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-q8mj-m7cp-5q26"
            ],
            "fixed_version": "6.15.2",
            "advisory_count": 1,
            "oldest_advisory_days": 68
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 473,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 1,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "agent-control-plane-core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.2.13"
        },
        {
          "name": "namespace-guard",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.20.0"
        },
        {
          "name": "css-tree",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.2.1"
        },
        {
          "name": "rehype-parse",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "9.0.1"
        },
        {
          "name": "remark-gfm",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "4.0.1"
        },
        {
          "name": "remark-parse",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "11.0.0"
        },
        {
          "name": "style-to-object",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "1.0.14"
        },
        {
          "name": "unified",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "11.0.5"
        },
        {
          "name": "unist-util-visit",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "5.1.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "agent-control-plane-core",
            "direct": true,
            "version": "0.2.13",
            "ecosystem": "npm"
          },
          {
            "name": "css-tree",
            "direct": true,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "namespace-guard",
            "direct": true,
            "version": "0.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "rehype-parse",
            "direct": true,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-gfm",
            "direct": true,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-parse",
            "direct": true,
            "version": "11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "style-to-object",
            "direct": true,
            "version": "1.0.14",
            "ecosystem": "npm"
          },
          {
            "name": "unified",
            "direct": true,
            "version": "11.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-visit",
            "direct": true,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-annotate-as-pure",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-create-class-features-plugin",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-member-expression-to-functions",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-optimise-call-expression",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-replace-supers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-skip-transparent-expression-wrappers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-proposal-decorators",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-decorators",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-jsx",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-typescript",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-destructuring",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-explicit-resource-management",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-modules-commonjs",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-typescript",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/preset-typescript",
            "direct": false,
            "version": "7.28.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/cli",
            "direct": false,
            "version": "21.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/config-conventional",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/config-validator",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/ensure",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/execute-rule",
            "direct": false,
            "version": "21.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/format",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/is-ignored",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/lint",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/load",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/message",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/parse",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/read",
            "direct": false,
            "version": "21.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/resolve-extends",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/rules",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/to-lines",
            "direct": false,
            "version": "21.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/top-level",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@commitlint/types",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@conventional-changelog/git-client",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@conventional-changelog/template",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.23.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/ansi",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/checkbox",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/confirm",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/core",
            "direct": false,
            "version": "11.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/editor",
            "direct": false,
            "version": "5.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/expand",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/external-editor",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/figures",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/input",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/number",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/password",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/prompts",
            "direct": false,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/rawlist",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/search",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/select",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/type",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@sec-ant/readable-stream",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@simple-libs/child-process-utils",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@simple-libs/stream-utils",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sindresorhus/merge-streams",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/api",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/core",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/instrumenter",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/tap-runner",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@stryker-mutator/util",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/debug",
            "direct": false,
            "version": "4.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "@types/esrecurse",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/hast",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-coverage",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/mdast",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/ms",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/unist",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "agent-sanitizer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "angular-html-parser",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "argue-cli",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "bail",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.11.6",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.7",
            "ecosystem": "npm"
          },
          {
            "name": "c8",
            "direct": false,
            "version": "11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001806",
            "ecosystem": "npm"
          },
          {
            "name": "ccount",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "5.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "character-entities",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "chardet",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-width",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "comma-separated-tokens",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "14.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "conventional-changelog-angular",
            "direct": false,
            "version": "9.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "conventional-changelog-conventionalcommits",
            "direct": false,
            "version": "10.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "conventional-commits-parser",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cosmiconfig",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "cosmiconfig-typescript-loader",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decode-named-character-reference",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "dequal",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "des.js",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "devlop",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff-match-patch",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.398",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "env-paths",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-toolkit",
            "direct": false,
            "version": "1.50.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "9.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "11.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "events-to-array",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "extend",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "4.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-truncated-width",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-width",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "fast-wrap-ansi",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "figures",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "13.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "global-directory",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "17.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "hast-util-from-html",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "hast-util-from-parse5",
            "direct": false,
            "version": "8.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "hast-util-parse-selector",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "hastscript",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "inline-style-parser",
            "direct": false,
            "version": "0.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-obj",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jiti",
            "direct": false,
            "version": "2.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-md4",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-even-better-errors",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-rpc-2.0",
            "direct": false,
            "version": "1.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "lint-staged",
            "direct": false,
            "version": "17.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.groupby",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "longest-streak",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "markdown-table",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-find-and-replace",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-from-markdown",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-autolink-literal",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-footnote",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-strikethrough",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-table",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-gfm-task-list-item",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-phrasing",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-to-markdown",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "mdast-util-to-string",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdn-data",
            "direct": false,
            "version": "2.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-core-commonmark",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-autolink-literal",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-footnote",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-strikethrough",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-table",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-tagfilter",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-extension-gfm-task-list-item",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-destination",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-label",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-space",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-title",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-factory-whitespace",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-character",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-chunked",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-classify-character",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-combine-extensions",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-decode-numeric-character-reference",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-decode-string",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-encode",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-html-tag-name",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-normalize-identifier",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-resolve-all",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-sanitize-uri",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-subtokenize",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-symbol",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromark-util-types",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimalistic-assert",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-server-protocol",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-testing-elements",
            "direct": false,
            "version": "3.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-testing-metrics",
            "direct": false,
            "version": "3.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "mutation-testing-report-schema",
            "direct": false,
            "version": "3.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "mute-stream",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.51",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse-ms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.9.6",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-ms",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "progress",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "property-information",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.1",
            "ecosystem": "npm"
          },
          {
            "name": "remark-stringify",
            "direct": false,
            "version": "11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "rxjs",
            "direct": false,
            "version": "7.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "space-separated-tokens",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-argv",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "8.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tap-parser",
            "direct": false,
            "version": "17.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tap-yaml",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tree-kill",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "trough",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tunnel",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-inject",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-rest-client",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "underscore",
            "direct": false,
            "version": "1.13.8",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "unicorn-magic",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-is",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-stringify-position",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "unist-util-visit-parents",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-to-istanbul",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "vfile",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "vfile-location",
            "direct": false,
            "version": "5.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "vfile-message",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "weapon-regex",
            "direct": false,
            "version": "1.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "web-namespaces",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml-types",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "18.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "22.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yoctocolors",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zwitch",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "agent-sanitizer",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "agent-sanitizer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2026.6.17",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.7",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "detect-secrets",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "detect-secrets",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "exceptiongroup",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis",
            "direct": false,
            "version": "6.155.7",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.18",
            "ecosystem": "pypi"
          },
          {
            "name": "iniconfig",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "9.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "pypi"
          },
          {
            "name": "regexploit",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.2",
            "ecosystem": "pypi"
          },
          {
            "name": "sortedcontainers",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 474,
        "direct_count": 9,
        "indirect_count": 465
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 167,
        "open_issues": 6,
        "closed_ratio": 0.25,
        "closed_issues": 2,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "claude",
          "commits": 382,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "alexander-turner",
          "commits": 183,
          "avatar_url": "https://avatars.githubusercontent.com/u/3458070?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.676
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "auto-resolve-conflicts.yaml",
        "auto-version.yaml",
        "build-publish-notify.yaml",
        "cancel-on-pr-close.yaml",
        "ci-failure-notify.yaml",
        "claude-merge-delta-review.yaml",
        "claude-pr-review.yaml",
        "claude-review-thread-resolve.yaml",
        "claude-reviewer-hold-clear.yaml",
        "claude.yaml",
        "decide-reusable.yaml",
        "dependabot-auto-merge.yaml",
        "format-autofix.yaml",
        "format-check.yaml",
        "fuzz-nightly.yaml",
        "gitleaks.yaml",
        "history-integrity.yaml",
        "hook-lifecycle.yaml",
        "lint.yaml",
        "merge-conflict-labeler.yaml",
        "mutation.yaml",
        "node-tests.yaml",
        "pack-smoke.yaml",
        "phone-home.yaml",
        "plugin-dist-autofix.yaml",
        "pr-desc-accuracy.yaml",
        "pr-review-advisory-comment.yaml",
        "pr-review-advisory.yaml",
        "pre-commit.yaml",
        "publish-python.yaml",
        "release-canary.yaml",
        "remerge-diff-report.yaml",
        "security-vulnerability-scan.yaml",
        "sync-required-checks.yaml",
        "template-sync.yaml",
        "validate-config.yaml",
        "zizmor.yaml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/14 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e0db8b2353b7756013582ee766bb6ff23cea40e9",
        "ran_at": "2026-07-30T06:10:36Z",
        "aggregate_score": 4.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-30T06:09:58Z",
      "oldest_open_prs": [
        {
          "number": 169,
          "created_at": "2026-07-24T10:52:52Z",
          "last_comment_at": "2026-07-29T11:13:52Z",
          "last_comment_author": "alexander-turner"
        }
      ],
      "last_merged_pr_at": "2026-07-30T06:07:47Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 166,
          "created_at": "2026-07-23T16:37:24Z",
          "last_comment_at": "2026-07-28T21:26:29Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 168,
          "created_at": "2026-07-24T08:42:14Z",
          "last_comment_at": "2026-07-29T09:08:19Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 171,
          "created_at": "2026-07-27T21:53:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 173,
          "created_at": "2026-07-27T22:36:17Z",
          "last_comment_at": "2026-07-28T20:52:36Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 177,
          "created_at": "2026-07-28T07:08:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 182,
          "created_at": "2026-07-28T22:08:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/AlexanderMattTurner/agent-sanitizer",
    "host": "github.com",
    "name": "agent-sanitizer",
    "owner": "AlexanderMattTurner"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 56,
        "vitality": 70,
        "community": 39,
        "governance": 49,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 606,
              "human_commit_share": 0.8,
              "days_since_last_push": 0,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "606 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 606
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 63,
              "latest_release_tag": "v2.5.0",
              "releases_from_tags": true,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "63 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 63
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 39,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "packages": [
                "agent-sanitizer",
                "agent-sanitizer"
              ],
              "dependents": null,
              "ecosystems": "npm, pypi",
              "total_downloads": null,
              "monthly_downloads": 797
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "797 downloads/month across npm, pypi",
                "points": 38.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 797,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.676
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 68% of commits",
                "points": 7.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 68
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "merged_prs": 167,
              "open_issues": 6,
              "closed_issues": 2,
              "issue_closed_ratio": 0.25,
              "closed_unmerged_prs": 14
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "25% of issues closed",
                "points": 11.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 25
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "167/181 decided PRs merged",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 167,
                      "decided": 181
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/14 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "AlexanderMattTurner",
              "public_repos": 13,
              "account_age_days": 58
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of AlexanderMattTurner",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "AlexanderMattTurner"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "13 public repos, account ~0 yr old",
                "points": 8.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 13
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "agent-sanitizer",
                "agent-sanitizer"
              ],
              "ecosystems": "npm, pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm, pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "37 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 45,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/14 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 473 resolved dependencies against OSV; 1 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 473
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 1
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 473,
              "unassessed_packages": 1,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 473,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 78,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.975,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 17470
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "78 of 80 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 78,
                      "sampled": 80
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml",
                "uv.lock"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 91158,
              "source_files_sampled": 178,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/178 source files over 60KB",
                "points": 53.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 178,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index npm:agent-sanitizer@2.5.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T06:10:51.422009Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/AlexanderMattTurner/agent-sanitizer.svg",
  "full_name": "AlexanderMattTurner/agent-sanitizer",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm, PyPI.