Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 99999,
"has_wiki": false,
"homepage": "https://www.useatlas.dev",
"languages": {
"CSS": 41037,
"MDX": 2692397,
"HTML": 137557,
"Shell": 290001,
"PLpgSQL": 94877,
"Dockerfile": 37544,
"JavaScript": 3712576,
"TypeScript": 42492708
},
"pushed_at": "2026-07-25T21:00:48Z",
"created_at": "2026-03-05T12:44:30Z",
"owner_type": "Organization",
"updated_at": "2026-07-24T22:00:55Z",
"description": null,
"is_archived": false,
"is_disabled": false,
"license_spdx": "AGPL-3.0",
"default_branch": "main",
"license_spdx_raw": "AGPL-3.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "Organization",
"login": "AtlasDevHQ",
"company": null,
"location": null,
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/264680315?v=4",
"created_at": "2026-02-28T19:12:52Z",
"is_verified": null,
"public_repos": 4,
"account_age_days": 147
},
"license": {
"state": "standard",
"spdx_id": "AGPL-3.0",
"raw_spdx": "AGPL-3.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-07-24T18:52:28Z"
},
{
"tag": "v0.0.67",
"kind": "patch",
"published_at": "2026-07-23T00:27:02Z"
},
{
"tag": "v0.0.66",
"kind": "patch",
"published_at": "2026-07-19T23:37:28Z"
},
{
"tag": "v0.0.65",
"kind": "patch",
"published_at": "2026-07-19T23:12:14Z"
},
{
"tag": "v0.0.64",
"kind": "patch",
"published_at": "2026-07-19T22:39:41Z"
},
{
"tag": "v0.0.63",
"kind": "patch",
"published_at": "2026-07-19T22:26:24Z"
},
{
"tag": "v0.0.62",
"kind": "patch",
"published_at": "2026-07-19T21:06:54Z"
},
{
"tag": "v0.0.61",
"kind": "patch",
"published_at": "2026-07-19T19:53:01Z"
},
{
"tag": "v0.0.60",
"kind": "patch",
"published_at": "2026-07-19T18:55:35Z"
},
{
"tag": "v0.0.59",
"kind": "patch",
"published_at": "2026-07-19T16:06:15Z"
},
{
"tag": "v0.0.58",
"kind": "patch",
"published_at": "2026-07-18T21:32:36Z"
},
{
"tag": "v0.0.57",
"kind": "patch",
"published_at": "2026-07-18T18:31:06Z"
},
{
"tag": "v0.0.56",
"kind": "patch",
"published_at": "2026-07-18T17:32:31Z"
},
{
"tag": "v0.0.55",
"kind": "patch",
"published_at": "2026-07-17T19:28:57Z"
},
{
"tag": "v0.0.54",
"kind": "patch",
"published_at": "2026-07-13T20:44:20Z"
},
{
"tag": "v0.0.53",
"kind": "patch",
"published_at": "2026-07-13T20:00:57Z"
},
{
"tag": "v0.0.52",
"kind": "patch",
"published_at": "2026-07-13T18:22:04Z"
},
{
"tag": "v0.0.51",
"kind": "patch",
"published_at": "2026-07-13T15:13:58Z"
},
{
"tag": "v0.0.50",
"kind": "patch",
"published_at": "2026-07-13T14:01:15Z"
},
{
"tag": "v0.0.49",
"kind": "patch",
"published_at": "2026-07-12T13:39:30Z"
},
{
"tag": "v0.0.48",
"kind": "patch",
"published_at": "2026-07-12T03:16:56Z"
},
{
"tag": "v0.0.47",
"kind": "patch",
"published_at": "2026-07-11T01:40:49Z"
},
{
"tag": "v0.0.46",
"kind": "patch",
"published_at": "2026-07-10T22:01:44Z"
},
{
"tag": "v0.0.45",
"kind": "patch",
"published_at": "2026-07-10T22:01:43Z"
},
{
"tag": "v0.0.44",
"kind": "patch",
"published_at": "2026-07-05T15:51:11Z"
},
{
"tag": "v0.0.43",
"kind": "patch",
"published_at": "2026-07-04T22:37:32Z"
},
{
"tag": "v0.0.42",
"kind": "patch",
"published_at": "2026-07-04T01:20:07Z"
},
{
"tag": "v0.0.41",
"kind": "patch",
"published_at": "2026-07-03T17:15:18Z"
},
{
"tag": "v0.0.40",
"kind": "patch",
"published_at": "2026-07-02T19:07:08Z"
},
{
"tag": "v0.0.39",
"kind": "patch",
"published_at": "2026-07-02T01:17:13Z"
},
{
"tag": "v0.0.38",
"kind": "patch",
"published_at": "2026-07-01T21:30:00Z"
},
{
"tag": "v0.0.37",
"kind": "patch",
"published_at": "2026-07-01T17:39:47Z"
},
{
"tag": "v0.0.36",
"kind": "patch",
"published_at": "2026-07-01T12:44:22Z"
},
{
"tag": "v0.0.35",
"kind": "patch",
"published_at": "2026-06-29T17:57:02Z"
},
{
"tag": "v0.0.34",
"kind": "patch",
"published_at": "2026-06-29T01:45:27Z"
},
{
"tag": "v0.0.33",
"kind": "patch",
"published_at": "2026-06-28T21:21:39Z"
},
{
"tag": "v0.0.32",
"kind": "patch",
"published_at": "2026-06-27T02:01:03Z"
},
{
"tag": "v0.0.31",
"kind": "patch",
"published_at": "2026-06-26T23:33:59Z"
},
{
"tag": "v0.0.30",
"kind": "patch",
"published_at": "2026-06-26T16:40:37Z"
},
{
"tag": "v0.0.29",
"kind": "patch",
"published_at": "2026-06-25T17:52:33Z"
},
{
"tag": "v0.0.28",
"kind": "patch",
"published_at": "2026-06-25T15:17:33Z"
},
{
"tag": "v0.0.27",
"kind": "patch",
"published_at": "2026-06-25T11:34:59Z"
},
{
"tag": "v0.0.26",
"kind": "patch",
"published_at": "2026-06-24T16:41:55Z"
},
{
"tag": "v0.0.25",
"kind": "patch",
"published_at": "2026-06-23T19:41:23Z"
},
{
"tag": "v0.0.24",
"kind": "patch",
"published_at": "2026-06-23T18:11:43Z"
},
{
"tag": "v0.0.23",
"kind": "patch",
"published_at": "2026-06-23T13:38:31Z"
},
{
"tag": "v0.0.22",
"kind": "patch",
"published_at": "2026-06-23T12:00:26Z"
},
{
"tag": "v0.0.21",
"kind": "patch",
"published_at": "2026-06-22T18:00:07Z"
},
{
"tag": "v0.0.20",
"kind": "patch",
"published_at": "2026-06-20T20:38:04Z"
},
{
"tag": "v0.0.19",
"kind": "patch",
"published_at": "2026-06-19T14:47:32Z"
},
{
"tag": "v0.0.18",
"kind": "patch",
"published_at": "2026-06-18T20:27:21Z"
},
{
"tag": "v0.0.17",
"kind": "patch",
"published_at": "2026-06-17T16:56:54Z"
},
{
"tag": "v0.0.16",
"kind": "patch",
"published_at": "2026-06-15T20:55:52Z"
},
{
"tag": "v0.0.15",
"kind": "patch",
"published_at": "2026-06-14T21:14:11Z"
},
{
"tag": "v0.0.14",
"kind": "patch",
"published_at": "2026-06-13T15:51:50Z"
},
{
"tag": "v0.0.13",
"kind": "patch",
"published_at": "2026-06-12T15:07:05Z"
},
{
"tag": "v0.0.12",
"kind": "patch",
"published_at": "2026-06-06T22:29:39Z"
},
{
"tag": "v0.0.11",
"kind": "patch",
"published_at": "2026-06-06T01:12:58Z"
},
{
"tag": "v0.0.10",
"kind": "patch",
"published_at": "2026-06-05T19:41:52Z"
},
{
"tag": "v0.0.9",
"kind": "patch",
"published_at": "2026-06-05T00:55:36Z"
},
{
"tag": "v0.0.8",
"kind": "patch",
"published_at": "2026-06-03T21:14:51Z"
},
{
"tag": "v0.0.7",
"kind": "patch",
"published_at": "2026-06-03T14:59:50Z"
},
{
"tag": "v0.0.6",
"kind": "patch",
"published_at": "2026-06-03T00:34:16Z"
},
{
"tag": "v0.0.5",
"kind": "patch",
"published_at": "2026-06-02T15:53:26Z"
},
{
"tag": "v0.0.4",
"kind": "patch",
"published_at": "2026-06-02T00:50:32Z"
},
{
"tag": "v0.0.3",
"kind": "patch",
"published_at": "2026-06-01T00:03:31Z"
},
{
"tag": "v0.0.2",
"kind": "patch",
"published_at": "2026-05-31T15:08:47Z"
},
{
"tag": "v0.0.1",
"kind": "patch",
"published_at": "2026-05-29T03:29:21Z"
}
],
"recent_commits": [
{
"oid": "ae4b7320a8571d52b0be6b1857da0eaa8dd18538",
"body": "…mode (#4795)\n\nBrain M1 (milestone #91, issues #4767-#4775) is a nine-issue vertical slice\nthat should not reach main half-built while the v0.1.0 tag is still uncut.\nIt will accumulate on `milestone/v0.2.0-brain-m1` and land as one merge.\n\nWithout this, a PR stacked onto that branch runs ZERO requir\n[…]\ne,\n and merges into it are discipline-gated, not protection-gated.\n\nNo untrusted input reaches any run: block; fork PRs arrive as pull_request,\nnever push, so the push filter adds no trigger surface.",
"is_bot": false,
"headline": "ci: gate milestone/** integration branches; add ship-issue milestone …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T22:00:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4703ed877156e992c77ef9796cfb3b23fa305c9",
"body": "…on' (#4788)\n\nWalks back the chat-availability wording merged in #4787, which was\nwritten on a wrong premise ('only Slack is live'). Verified against\nplugins/chat/src/adapter-registry.ts + the static-bot install handlers\nand deploy/api/atlas.config.ts (no overrideImplementationStatus):\n\n Slack — on\n[…]\n'installable today, Google Chat coming soon'. Region + /security fixes\nfrom #4787 are correct and unaffected. Blog announcing-atlas left\nuntouched (its 'Eight integrations' line was already accurate).",
"is_bot": false,
"headline": "www/docs: correct chat-reach copy — installable today, not 'coming so…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T17:48:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4aa9a583b08e7d70241dae6d80a4c1275167bc7",
"body": "- Regions → area-level (US/EU/APAC), dropping city/country pins so copy\n stays true as physical regions move. Resolves the EU www-vs-docs\n mismatch (www: Netherlands/Eemshaven, docs: Ireland). Real Railway EU\n region is europe-west4 (Netherlands); genericized rather than pinned.\n- /security: rewo\n[…]\nnding comparison: add '(Slack live; Google Chat coming soon)' caveat.\n- NOT touched: DPA Ireland governing-law/forum (legal jurisdiction);\n blog/announcing-atlas (launch content, flagged separately).",
"is_bot": false,
"headline": "www/docs: fix accuracy drifts from /www-audit (#4787)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T16:52:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d13cb3ffffec94f44edc134c4a7b85c40671a71b",
"body": "…tus decision closed",
"is_bot": false,
"headline": "docs(roadmap): v0.1.0 milestone fully clear — security pass + OpenSta…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T14:11:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ae60d79c84c8c14adfda12e5600100c1b332e7b",
"body": null,
"is_bot": false,
"headline": "docs(roadmap): bank the #4785 explore/sandbox hardening ship (PR #4786)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T14:00:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4179888be55967d648988f5565913f01c624ecd2",
"body": "…ainment docs (#4785) (#4786)\n\nDefense-in-depth residue from the #3351 live security pass:\n\n- explore/nsjail output truncation is now surfaced from a byte-accurate flag\n (readLimited -> { text, truncated }, threaded onto ExecResult, marked at the\n tool seam via markCappedStream) instead of re-deri\n[…]\ns reword).\n- Documented that the vercel-sandbox deny-all policy does not block the\n link-local Firecracker MMDS (provider-controlled, not app-blockable) rather\n than shipping a non-functional block.",
"is_bot": false,
"headline": "fix(sandbox): byte-accurate explore truncation signal + accurate cont…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T13:59:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8bf15aeae66a019c421ce3bb6f08e89fa2c9a720",
"body": "…4779/#4780/#4781); #3351 findings closed",
"is_bot": false,
"headline": "docs(roadmap): tidy — bank the 2026-07-24 security-pass ship-batch (#…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T13:25:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e5a9e561ffc4ec626e272e8c5b1c7bd5e7a9670",
"body": "…#4779) (#4784)\n\n* fix(security): DNS-aware egress guard closes hostname→internal SSRF (#4779)\n\nisSafeExternalUrl is synchronous (it backs a Zod refine) so a public\nhostname that RESOLVES to an internal IP (e.g. 127.0.0.1.nip.io, cloud\nmetadata via wildcard DNS, or a live DNS-rebind record) passed t\n[…]\nk proving\n getModelFromWorkspaceConfig installs createGuardedFetch() on the custom\n provider (captures the fetch option; a literal internal IP is rejected by the\n guard's sync first pass — no DNS).",
"is_bot": false,
"headline": "fix(security): DNS-aware egress guard closes hostname→internal SSRF (…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T13:19:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "31ac41450f5ac44698d765f2d318eb2e24231d24",
"body": "…#4781) (#4783)\n\nThe /api/v1/explore endpoint + agent-facing tool description advertised a\npath-jail ('read-only, path-traversal-protected access scoped to semantic/;\nwrites, shell escapes, and traversal outside the semantic directory are\nrejected') that the sandbox backend does not enforce. On SaaS\n[…]\negenerated openapi.json + api-reference MDX.\n\nDoc-first accuracy fix; the optional defense-in-depth items (block link-local\n169.254.0.0/16 egress; add a truncated flag to capped output) are split out.",
"is_bot": false,
"headline": "docs(explore): reword containment claims to match enforced behavior (…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T12:59:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0793899c5d57b1c3e0243f4e59f49f0f58f9d4f1",
"body": "…t (#4780) (#4782)\n\nTwo authenticated DoS levers via unbounded parser inputs, from the #3351 live pass:\n\n- validate-sql accepted a 2 MB `sql` body (no cap) while execute-sql capped at\n 100k; both feed the same node-sql-parser on the API event loop. Hoist\n `MAX_SQL_LEN` into lib/tools/sql.ts (the p\n[…]\n22 (never reaches parse/persist) and at-cap ->\naccepted, for both caps. Pure input-bound hardening; no behavior change for\nlegitimate inputs. openapi.json regenerated for the two new maxLength bounds.",
"is_bot": false,
"headline": "fix(api): cap parser-fed inputs — validate-sql sql + admin yamlConten…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T12:53:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed5d6fbfdaaa013c251093b0946ffbae69476273",
"body": "… ride next tag (#4778)\n\nv0.0.67 (Seam Consolidation & Aggregate-Review Hardening) tagged @ 343215486\n2026-07-22 but was still framed as unreleased. Bank it to History, update the\nlatest-tag pointer, and reframe Next: the query soft-deadline (#4741) shipped\nin v0.0.67; per-tier KB caps (#4235) + tool-span coverage (#4464) ride v0.0.68.",
"is_bot": false,
"headline": "docs(roadmap): tidy — bank v0.0.67 into History; KB caps + tool-spans…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T02:33:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e9f9c2bfa6ab0a59ad8a9521b09464daf06cd16",
"body": "Road-to-launch note covering the month since the beta recap: making\nAtlas Cloud's promises mechanical (self-verifying backups, executing\nresidency deletion, an honest sandbox carve-out) and six MCP fixes\nforced by real AI clients. Wires the post into POSTS (sitemap auto-derives).",
"is_bot": false,
"headline": "feat(www): add \"The last mile\" blog post (#4777)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T02:24:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9505978e01e61654c11f238b5ca97856b82d6d33",
"body": "…7–#4775 (#4776)\n\nAdds the v0.2.0 — Brain M1: Thin Wedge Slice planned-tag entry (ADR-0036\nmilestone cut, parked until v0.1.0 ships per the re-aim guide).\n\nClaude-Session: https://claude.ai/code/session_01SBCZPiF95TDTLqfnzENRXn",
"is_bot": false,
"headline": "docs(roadmap): bank the Brain M1 kickoff — milestone #91, issues #476…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T01:34:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d5afec03675512085b98965e4149b3fe11686803",
"body": "…#4755) (#4766)\n\nThe synthesis/handoff ADR for the \"Atlas as the company brain\" wayfinder\nmap (#4755, all ten decision tickets closed). Each section is one locked\ndecision (T2-T10); T1's landscape research grounds the Context section\nand lands alongside as .claude/research/4756-company-brain-landsca\n[…]\nefault) are folded in. Per T10's disposition, ADR-0028/\n0020/0030 are deliberately untouched; the 0028 amendment lands with M1.\n\nClaude-Session: https://claude.ai/code/session_01SBCZPiF95TDTLqfnzENRXn",
"is_bot": false,
"headline": "docs(adr): ADR-0036 — Atlas becomes the data-grounded company brain (…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-24T01:19:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2634b5b7ec9fb286c36ebbdd2aff77b4d572d5fe",
"body": null,
"is_bot": false,
"headline": "docs(roadmap): tidy — bank the tool-span coverage ship (#4464)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-23T18:27:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63433c2d3905b4eeb5069aa0de3cc25fc0872465",
"body": null,
"is_bot": false,
"headline": "docs(roadmap): bank the per-tier KB caps ship (#4235)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-23T18:11:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6184cf69b2848a08ee92107c3dd501ad1e309f05",
"body": "* feat(billing): per-tier Knowledge Base caps as a SaaS entitlement lever (#4235)\n\nKB ingest caps shipped platform-scoped only (`ATLAS_KNOWLEDGE_INGEST_*`), so\non SaaS the only lever for an enterprise customer's 100 MB knowledge base was\nraising the cap for every tenant in the region. KB size is sto\n[…]\nthe getWorkspaceDetails-null coupling.\n- Drop a duplicate assertion; fix two indentation nits.\n\n* fix(test): correct api-test-mocks alias + add maxKnowledgeCollections to billing wire fixtures (#4235)",
"is_bot": false,
"headline": "feat: per-tier Knowledge Base caps as a SaaS entitlement lever (#4754)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-23T18:08:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d77f7821bbc60e42420d82e8fe04755ae7cb3f1a",
"body": "…64) (#4753)\n\n`searchKnowledge`, `createDashboard`, `executeRestOperation` and the action\ntools carried no `atlas.*` span of their own — only the tools that remembered\nto self-instrument did — so latency couldn't be attributed within a turn from\nthe `atlas.`-prefixed views. The registry had no span \n[…]\nthe grandfathered off-prefix names, which are documented\nrather than renamed since renames break live dashboards. The operator-facing\nobservability page is updated for the new hierarchy.\n\nCloses #4464",
"is_bot": false,
"headline": "feat(telemetry): trace every agent tool at the ToolRegistry seam (#44…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-23T16:31:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f96ddb33a5c46863f5c5383fa19de97282f9b743",
"body": "…ening",
"is_bot": false,
"headline": "docs(changelog): v0.0.67 — Seam Consolidation & Aggregate-Review Hard…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-23T00:27:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3432154863e6a984286e4b635006f83b528c8687",
"body": "…ardown no-op, doc drift (#4751) (#4752)\n\n* fix(plugins,docs): aggregate-review residue — restore tenant-isolation guard, close silent credential-teardown no-op (#4751)\n\n* fix(review): .js import extension, tighten deadline comment, cover S3 endpoint field (#4751)",
"is_bot": false,
"headline": "fix: aggregate-review residue — tenant-isolation guard, credential-te…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-23T00:16:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0055ac396a12d5b7abab3fb994e8d2c3883e9c38",
"body": null,
"is_bot": false,
"headline": "docs(roadmap): tidy — bank the 2026-07-22 ship-batch runs (9 issues)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T23:38:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e619dd92b2c9101a02136b69cc8490a60a83057f",
"body": "…eOrgContext (#4356) (#4748)\n\n* refactor(api): migrate inline org-context null checks onto requireOrgContext (#4356)\n\n`requireOrgContext()` is the canonical org-context seam, but ~53 handlers\nhand-rolled the identical check inline and the copies had drifted into 5\ndifferent messages and 4 different \n[…]\nno_organization` / `org_required` codes stay the onboarding contract.\nRecorded in the `noActiveOrgBody` doc comment.\n\n* docs(api): note admin-model-config in the noActiveOrgBody carve-out list (#4356)",
"is_bot": false,
"headline": "refactor(api): migrate the inline org-context null checks onto requir…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T23:17:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9fc33d3b6d61b1c51a98ea6cb8f2df5b6c328bcf",
"body": "…#4750)\n\n* refactor(api): give conversation scope a first-class module (#4351)\n\nConversation scope (SQL routing + REST scope + reach + voice, ADR-0011 /\nADR-0022) was a loose column bag: five byte-identical-bar-the-column\nwriters, an 11-column INSERT hand-copied per id-branch, and five parallel\ndecl\n[…]\nity note: the SET list is built from\n the closed `CONVERSATION_SCOPE_COLUMNS` constant, never caller input; every\n value is bound.\n- Comment fix: five axes ⇒ up to five independent writes, not four.",
"is_bot": false,
"headline": "refactor(api): give conversation scope a first-class module (#4351) (…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T23:07:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb3b5eda1ee8491f7d84a6f4a9b8e38839098f22",
"body": "…ll shim into tearDownWorkspaceInstall (#4353) (#4749)\n\n* refactor(plugins): one teardown contract — fold the hook-only uninstall shim into tearDownWorkspaceInstall (#4353)\n\n`invokeOnUninstallHookForInstallRow` resolved `(catalog_id, slug)` from an\ninstallation id and then ran the `onUninstall` hook\n[…]\nat shape.\n\nDeliberately NOT re-derived from the DELETE's RETURNING tuple: that second\npath is exactly what this issue removes, and post-DELETE the hook could no\nlonger authenticate to revoke anything.",
"is_bot": false,
"headline": "refactor(plugins): one teardown contract — fold the hook-only uninsta…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T23:01:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ac79ae0091d2e6addf777a20ac9c90083d3ed46b",
"body": "…dsAtFrom (#4354) (#4747)\n\n* refactor(billing): route every trial-clock stamper through fullTrialEndsAtFrom (#4354)\n\nThe rule \"a full trial clock = now + TRIAL_DAYS\" lived in four places: the\ncanonical stamper `fullTrialEndsAtFrom` (one caller), the reader\n`effectiveTrialEndsAt` which independently \n[…]\nds are what actually catch a re-inlined stamper;\n- correct the DST wording (the table straddles a US spring-forward and sits\n on the edge of an EU fall-back) and note TZ-invariance of the assertions.",
"is_bot": false,
"headline": "refactor(billing): route all trial-clock stampers through fullTrialEn…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T22:53:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a397877bb3e2deb7d16bebaa101cb59fd4292cc",
"body": "…e (ADR-0035) (#4746)\n\n* refactor(notebook): phase-2 — DROP COLUMN conversations.notebook_state (ADR-0035)\n\nContract half of the two-phase drop staged by #4587 (phase 1, shipped in\nv0.0.47): migration 0179 drops `conversations.notebook_state`, and the\nDrizzle mirror is removed in the same commit so \n[…]\ndy removed in #4587 and migration\n0169 converted the remaining rows to `'web'` — no wire-type work remains.\n\nCloses #4588\n\n* style(schema): separate the notebook tombstone from the org-scoping comment",
"is_bot": false,
"headline": "refactor(notebook): phase-2 — DROP COLUMN conversations.notebook_stat…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T22:51:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b6724e46ea776feaf69f197c2fe06602a84fd930",
"body": "…path (#4745)\n\n* feat(backups): abort stale incomplete multipart uploads in the purge path (#4727)\n\nA failed S3 backup upload deliberately never finalizes — finalizing would\nproduce a truncated object that could pass a header-only verify. The parts\nalready uploaded therefore linger as an incomplete \n[…]\n\n\n* docs(backups): correct the degradation-level note after the 403 carve-out\n\nThe module header still claimed every unsupported response no-ops at debug\nlevel; a 403 now warns with the grants to add.",
"is_bot": false,
"headline": "feat(backups): abort stale incomplete multipart uploads in the purge …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T21:24:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4de4d679cb10f02e52c79eae4337e7360cbe30a",
"body": "… checkout (#4655) (#4744)\n\nThe dual-write sync layer persists per-org YAML under\n`{getSemanticRoot()}/.orgs/<orgId>/`, and `getSemanticRoot()` defaults to\n`{cwd}/semantic`. Every suite exercising the real write path (the `-pg`\namendment / connection-profile family, the wizard, `importFromDisk`) the\n[…]\nor the env override.\n- New `src/__tests__/semantic-root-sandbox.test.ts` pins the contract, including\n an end-to-end `syncEntityToDisk` that asserts `{cwd}/semantic` is never\n created.\n\nCloses #4655",
"is_bot": false,
"headline": "fix(test): sandbox the semantic root so -pg suites stop littering the…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T21:20:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e95f4b31a37734446f23b869c09d17b6cb2f3c37",
"body": "… (#4462) (#4743)\n\n* fix(settings): lock RESEND_API_KEY + ATLAS_PROVIDER as SaaS-immutable (#4462)\n\nBoth keys are validated by a SaaS boot guard yet were freely mutable at\nruntime. Deleting a registry-only RESEND_API_KEY override post-boot\nsilently flips the platform email transport to the ATLAS_SMT\n[…]\n\"live cache\" read as the internal `_liveCache`; say what\nactually happens (setSetting updates the in-process cache getSetting /\ngetSettingAuto read). Name the 409 envelope explicitly in the admin doc.",
"is_bot": false,
"headline": "fix(settings): lock RESEND_API_KEY + ATLAS_PROVIDER as SaaS-immutable…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T21:14:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4672d268c89eef1a6a6471635e97ff8fa3fd996",
"body": "* test(mcp): stub the billing agent-gate in smoke.test.ts (#4370)\n\n`smoke.test.ts` was the only MCP test that did not stub\n`@atlas/api/lib/billing/agent-gate`, so its `executeSQL` dispatch ran the\nreal billing enforcement gate. That gate reads the internal DB\n(`organization` / `settings`) and fails \n[…]\niew panel: the codebase numbers the billing gate as gate 0\n(datasource-tools.ts, dispatch-gate.ts) — action-policy is gate 1,\nmcp:write is gate 2, RBAC is gate 3. The new stub's comment said\n\"Gate-2\".",
"is_bot": false,
"headline": "test(mcp): stub the billing agent-gate in smoke.test.ts (#4742)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T21:07:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f391e7fb990b8a4d660b5491ecff3cd196506561",
"body": "ROADMAP's History stopped at v0.0.57 while nine tags shipped (the backups +\nresidency wave, then the eight-tag hosted-MCP fix train). Adds one line per\ntag, collapses the now-tagged v0.0.58 bullet out of Planned tags, and points\nthe \"latest tag\" statements at v0.0.66 with the #4741 soft-deadline follow-on\nnoted as riding the next tag.",
"is_bot": false,
"headline": "docs(roadmap): tidy — bank v0.0.58 through v0.0.66 into History",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T19:57:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1783bc0407d1ef0bbb931a0b3f6310c6f11fae8a",
"body": "…velope (#4734) (#4741)\n\n* fix(mcp): cap the query agent run with a soft deadline + query_timeout envelope (#4734)\n\nCorrected root cause (verified live against prod): the >120s drop is NOT a\nRailway edge idle-timeout the server can defeat — it's the MCP CLIENT's own\nrequest-timeout ceiling (~120s), \n[…]\nthe resolve path too and share one envelope builder\nacross both exits. Docs + the `AtlasMcpToolErrorCode` comment described\n`query_timeout` as statement_timeout only; both now cover the agent-run cap.",
"is_bot": false,
"headline": "fix(mcp): cap query agent run with a soft deadline + query_timeout en…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-22T19:52:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5dc1b3fb4b118e416c96046b53b01597266fb08c",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.66 — Hosted-MCP Query Keepalive",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T23:37:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a8105484d907c7461dd817c61ce5603b49e0f273",
"body": "…#4734) (#4740)\n\nVerified live against prod: a >120s query STILL dropped the transport after the\nprogress-heartbeat fix, because the heartbeat only puts bytes on the wire when\nthe client sent a progressToken — and the reporting client (and this Claude Code\nMCP client) doesn't. The heartbeat was a no\n[…]\nytes naturally suppress the keepalive.\n\nTests: stream-liveness.test.ts — keepalive injected during idle gaps with data\nintact + in order; no keepalive when keepaliveMs omitted (GET streams unchanged).",
"is_bot": false,
"headline": "fix(mcp): transport-agnostic SSE keepalive on POST tool-call stream (…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T23:36:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "063f1de0574e3af394c6eba7088970c8d7ffbcb7",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.65 — describeEntity Display-Name Fix",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T23:12:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cbfdfe73953289ab416ba3d8d88e65c0258a44d6",
"body": "… too (#4733 follow-up) (#4739)\n\nVerified live against hosted prod after the first #4733 fix: describing a\ngroup-scoped entity by its TABLE worked, but by the NAME listEntities advertises\nstill 404'd — the exact reported symptom (describeEntity({name:\"Conversation\"})\n=> unknown_entity) was still liv\n[…]\nsly conflated the name column with the YAML name, so\nit passed while prod failed. Fixture now models all three identifiers distinctly\n(column=stem, name=display, table) and asserts resolution by each.",
"is_bot": false,
"headline": "fix(mcp): describeEntity resolves entities by their YAML display name…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T23:11:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8658344ae3d1ae2bc587519975a808e102aaa020",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.64 — Hosted-MCP Deploy Fix",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T22:39:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "20548b52013e536505eb7655e3f219a097ec7a89",
"body": "…eploy (#4737)\n\nThe api service (all 3 regions) serves the hosted MCP — it depends on\n@atlas/mcp (workspace:*) and bundles packages/mcp into its image. But\ndeploy/api*/railway.json watchPatterns omitted packages/mcp/**, so a change\nconfined to packages/mcp produced skippedReason:'No changes to watch\n[…]\nson copies, covered by packages/**/package.json); the broad 'COPY . .'\nthat bundles mcp source is invisible to it. Broader watchPatterns-vs-workspace-dep\naudit + gate extension tracked as a follow-up.",
"is_bot": false,
"headline": "fix(deploy): watch packages/mcp in api services so hosted-MCP fixes d…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T22:38:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9ed0095bd79af9d7745f4694ee70fc3351ca41a8",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.63 — Hosted-MCP Tool Fixes",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T22:26:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ab3c04b30c09a5ac26d23a6fa5606ae630f5dc0",
"body": "…t drop transport (#4734) (#4736)\n\nThe query POST response is a Streamable-HTTP text/event-stream that emits zero\napplication bytes during the server-side agent run, so an intermediary\nidle-timeout (Railway edge/LB, ~120s) closes it before a long run finishes →\nclient sees 'transport dropped'.\n\nAdd \n[…]\n.test.ts (heartbeat helper — monotonic <1, stop clears timer,\nend-to-end monotonicity through the wrapper), query-tool.test.ts (interim\nprogress fires during a >interval run; timer cleared on settle).",
"is_bot": false,
"headline": "fix(mcp): keepalive heartbeat on hosted query tool so >120s runs don'…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T22:21:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "99afdbaa696ea12ff4333b997d1e7f46500a6f2d",
"body": "…d DB path (#4733) (#4735)\n\ndescribeEntity called the disk-only getEntityByName while listEntities reads\nthe org-scoped semantic_entities DB. On SaaS (entities are DB-only) every\ndescribe of a group-scoped entity missed → unknown_entity, even for names\nlistEntities returns.\n\nRoute describeEntity thr\n[…]\nti-group → validation_failed);\nthe no-DB disk path stays covered by lookups.test.ts + the canonical MCP eval.\ntelemetry.test.ts gains the AmbiguousEntityError re-export + a hermetic\nadmin-source mock.",
"is_bot": false,
"headline": "fix(mcp): describeEntity resolves group-scoped entities via org-scope…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T22:14:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "890aa157a250e04e9c0b4d7d7555f8802d86db90",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.62 — Hosted-MCP Transport Fix",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T21:07:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "227eb0db81b700997bfb232ea9088845268b3624",
"body": "…across installer, SDK, wizard, docs (#4732)\n\nHosted MCP clients that followed Atlas's own setup surfaces got a config\nspeaking the deprecated HTTP+SSE transport against a Streamable-HTTP-only\nendpoint: OAuth completed, then the first request 400'd. Root cause was a\n`/sse` connect URL plus a missing\n[…]\n JSON example; SDK + load-test docs. Self-hosted --transport sse\n (standalone server's own listener) and legacy-alias notes left intact.\n\nDependency refs stay pinned; publish tags follow after merge.",
"is_bot": false,
"headline": "fix(mcp): emit canonical Streamable-HTTP config (type:http, no /sse) …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T20:51:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5a890ea6aa90b26dc4d713e4a7527739b74e22b5",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.61 — Scheduled-Backup Hang Fix",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T19:53:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cfadbeab4d540c4b47aab3045e87992001f8bf86",
"body": "… await (#4731)\n\nScheduled backups have never once succeeded in prod: every region sat with a\nsingle backup row stuck `in_progress` (no error, no size), so no `verified`\nbackup ever existed and /health reported `backups: degraded` in all 3 regions.\n\nRoot cause is an event-ordering bug in `performBac\n[…]\n— it times out against the old\nordering and passes with the latch. The existing engine.test.ts mocks\nre-fire `close` on every listener attach and resolve put instantly, so they\ncould never catch this.",
"is_bot": false,
"headline": "fix(backups): register pg_dump exit-code listener before the pipeline…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T19:52:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a4ec5a65237948d68458dc57571b44e0960d883",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.60 — MCP OAuth Consent Fix",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T18:56:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "228dcfc4158c4430017f67f0557ebc3d74058b56",
"body": "…4) (#4730)\n\nAdmin-merge rationale: all required checks green (ci, api-tests 1-4, Deploy Validation, Symlink Stub Build) plus the full non-required battery; the required 'Analyze (javascript-typescript)' (CodeQL) gate never triggered on this non-fork PR — no workflow run, queue, or check-run on the head SHA after ~30min, while it fired promptly for #4725/#4726/#4729. Judged a GitHub default-setup miss (not a failure); owner-authorized admin merge.",
"is_bot": false,
"headline": "fix(mcp): pin OAuth login/consent pages to the web origin (consent 40…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T18:47:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fde17b68a9faf967add17934eae21a510e271edc",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.59 — Backup Engine & Residency Cleanup",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T16:06:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dd3ec725ae8bc3682818059a81fef57745be39d6",
"body": "… get refresh tokens (#4728) (#4729)\n\n* fix(mcp): advertise offline_access in scopes_supported so DCR clients get refresh tokens (#4728)\n\nDCR clients (Claude Code among them) register with exactly the\nprotected-resource metadata's advertised scope list, and\n@better-auth/oauth-provider validates auth\n[…]\nurfaces the compile-time satisfies can't reach.\n\nNegative test (renaming offline_access in the union) confirmed all three\ncompile-time tethers fail the build; new fixture tests cover the runtime gate.",
"is_bot": false,
"headline": "fix(mcp): advertise offline_access in scopes_supported so DCR clients…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T14:51:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f03da89c9377074fdc6af8b16ef329051d4209fa",
"body": "…the backup engine (#4457) (#4726)\n\nThe scheduled-backup engine shipped in #4723 spawns pg_dump/psql, but the\napi runner image never installed a postgres client — every backup cycle\nwould fail with spawn ENOENT (surfacing as the /health backups tripwire's\ndegraded state, boot-green-but-broken exactl\n[…]\n\ndefault client is insufficient.\n\nVerified against the exact pinned base image digest:\ndocker run oven/bun:1.3.13@sha256:87416c... + this RUN block\n-> pg_dump (PostgreSQL) 18.4, psql (PostgreSQL) 18.4",
"is_bot": false,
"headline": "fix(deploy): install PostgreSQL 18 client tools in the api image for …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T02:19:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "798cceec1244b0e2982565281ce259731de7f002",
"body": "…utes (#4458) (#4725)\n\n* fix(residency): region-migration Phase 4 source cleanup actually executes (#4458)\n\nThe destructive half of migration Phase 4: a new\nregion_migration_source_cleanup periodic fiber (hourly) consumes the\npreviously-unconsumed getCleanupDueMigrations and deletes a migrated\nworks\n[…]\nts\n\nThe compile-time CleanupScopedTable derivation reads\nBUNDLE_TABLE_DECISIONS directly; EXPORTED_TABLES/STAYS_TABLES are\nconsumed only by the tripwire test (github-code-quality finding on\nPR #4725).",
"is_bot": false,
"headline": "fix(residency): region-migration Phase 4 source cleanup actually exec…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T01:58:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "866a8b87be6c8b5964b71d428cb0ce48fc2dd95b",
"body": "…iber, S3 storage driver, health tripwire (#4457) (#4723)\n\n* fix(backups): wire the scheduled-backup automation for real — cadence-window fiber, S3 storage driver, health tripwire (#4457)\n\nstartScheduler was dead code: zero production callers, so the sold/promised\nautomated-backup feature never ran,\n[…]\nd (#4723 review)\n\ngithub-code-quality[bot]: 'backupsComponent' always evaluates to true —\nboth the try and catch arms assign it. Encode that in the declaration\n(no undefined arm) and pass it directly.",
"is_bot": false,
"headline": "fix(backups): wire the scheduled-backup automation — cadence-window f…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T01:07:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f2e57a9979bb2395c8188a774dfcbb07a31ab5d",
"body": "…2 bundle + drift tripwire) (#4724)\n\n* fix(residency): close the region-migration export bundle scope drift (#4460)\n\nThe export bundle covered only the four original pillars (conversations,\nsemantic entities, learned patterns, settings); everything shipped since —\ndashboards, knowledge documents, sc\n[…]\nonse-shape guard now covers all four sections the cast claims\n- Owner re-shares phrasing in the two remaining spots\n\n* docs(roadmap): bank #4460 — region-migration export bundle scope drift (PR #4724)",
"is_bot": false,
"headline": "fix(residency): region-migration export bundle covers every pillar (v…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-19T00:55:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "68b6eb3bf8e023031dd5a5ad6bf75e88ea37297b",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.58 — Dashboard & Sharing Residue",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T21:32:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "188a6db7ec60fea676001728bd0e1e179a675628",
"body": "…(milestone #90 closed; 3 issues, PRs #4720/#4721/#4722)",
"is_bot": false,
"headline": "docs(roadmap): v0.0.58 — Dashboard & Sharing Residue shipped to main …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T21:21:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f71a3701f76d547d45ae51a01d3cbd8693d38be1",
"body": "….58 closeout)",
"is_bot": false,
"headline": "docs(guides): SameSite scope caveat for org-scoped share embeds (v0.0…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T21:21:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "761cb7306729b7db205475b7b8cfdb1035350463",
"body": "…ard share pattern (#4719) (#4722)\n\n* fix(web): shared conversation surface parity with the hardened dashboard share pattern (#4719)\n\n- no-store + React cache() intra-render dedup replaces revalidate:60 — a\n revoked/expired share link dies immediately\n- token-hash-only logging (#4317 discipline) — \n[…]\nm ADR-0024 §5 refs\n- tests: token-echo redaction (SSR + client), messages:[null] -> server-error,\n page-seam hand-off tests for page + embed, draftMode added to next/headers\n mocks (all three sites)",
"is_bot": false,
"headline": "fix(web): shared conversation surface parity with the hardened dashbo…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T21:18:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "17e5f25255b8c3a1db8a63e60021f3ecda6d8014",
"body": "…of silently writing published cache (#4720)\n\n* fix(dashboards): draft Refresh-all surfaces 503 on a thrown draft load instead of silently writing the published cache (#4685)\n\nloadDraft collapsed both \"no draft exists\" and \"the load threw\" to null.\nThe bulk draft Refresh-all branch (a WRITE path, #4\n[…]\n Log label 'loadDraft failed' -> 'dashboard draft load failed' (the\n catch now lives in loadDraftChecked; caller-agnostic label).\n- Test comment made name-agnostic; assert loadDraftChecked call args.",
"is_bot": false,
"headline": "fix(dashboards): draft Refresh-all 503s on thrown draft load instead …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T20:55:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53ccfcbe5605cc8b4d38ca032c0b83aeea23657f",
"body": "…e viewer session client-side (#4718) (#4721)\n\n* fix(dashboards): resolve org-scoped shares client-side when SSR hits the auth wall (#4718)\n\nUnder ADR-0024 the SaaS session cookie is host-only on the per-region API\ndomain, so the shared page's RSC cookie forward is structurally empty\ncross-origin — \n[…]\nody cast\n- tests: isAuthWallReason exhaustive pin, resolveAuthReason direct pins,\n mapper-totality + no-values-in-log pins, embed login-required split,\n full use-dark-mode mock, mockResolve teardown",
"is_bot": false,
"headline": "fix(dashboards): org-scoped shares dead-end cross-origin — resolve th…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T20:39:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92a9ceb64bcc7ca9e2a443fefb9b869948bc44d3",
"body": "…one #90: #4685 + #4718 + #4719)",
"is_bot": false,
"headline": "docs(roadmap): kick off v0.0.58 — Dashboard & Sharing Residue (milest…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T20:02:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a128589b8d521c6fcc6f72984c313769900fd372",
"body": "…v0.0.56 detail, fix latest-tag drift)",
"is_bot": false,
"headline": "docs: tidy — bank tags v0.0.56/v0.0.57 (collapse to History, archive …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T19:48:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71832104c58dbe4eab47c22c1cf25f9e9d23af08",
"body": "…OST allowlist, PR #4717) + #4669 (platform-tier settings console, PR #4716); unblocks agents-repo #203/#204/#205",
"is_bot": false,
"headline": "docs(roadmap): Agent Auth cluster residue closed — #4707 (read-safe P…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T19:42:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8e41dff26c8d29286453593e4ed99c6c695b4c29",
"body": "…lore/metrics/validate-sql) into the capability surface (#4707) (#4717)\n\n* feat(agent-auth): admit a curated read-safe POST allowlist into the capability surface (#4707)\n\nREAD_SAFE_OPERATIONS admits the four analyst read actions (POST /api/v1/query,\n/explore, /metrics/{id}/run, /validate-sql) into t\n[…]\nAttribute auto-LIMIT/statement-timeout to execution, not validateSQL\n- Soften the isWriteOperation param note (same default, not 'can never diverge')\n- querySalesforce grouped as a read, not an action",
"is_bot": false,
"headline": "feat(agent-auth): admit a curated read-safe POST allowlist (query/exp…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T19:40:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1fb1cdf9c9d036ad882269e8575721273e7f8e48",
"body": "…the platform console (#4669) (#4716)\n\n* feat(admin): explicit platform-tier write path for workspace-scoped settings (#4669)\n\n- PUT/DELETE /api/v1/admin/settings/{key}?tier=platform targets the\n global (org_id IS NULL) row explicitly — never inferred from the\n session org — gated to platform_admi\n[…]\nboth verbs, pin no-default platformValue\n shape, complete the partial settings mock (mock-all-exports)\n\n* review-panel round 2 polish (#4669): comment accuracy + DELETE workspace-tier audit assertion",
"is_bot": false,
"headline": "feat(admin): platform-tier writes for workspace-scoped settings from …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T19:31:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5048720dc348ec632858574cd839c95e90015c53",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.57 — Two-Phase Drop Cleanup",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T18:31:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c4b2b5dc1d6978208f3a2e95323218294b525e6",
"body": "… drop",
"is_bot": false,
"headline": "docs(roadmap): record #4561 → PR #4714 merged alongside #4551 phase-2…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T18:16:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8bfa46c73875e3ba47fb64b5519beb92a316140c",
"body": "…1) (#4714)\n\nPhase 2 of the two-phase drop (parent #4553, ADR-0034): phase 1 (#4555,\nshipped v0.0.55) removed every reader/writer, so migration 0176 drops the\ntable. The Drizzle mirror in schema.ts is removed in the same commit per\nthe drop-table discipline; migrate test counts/lists bumped, and the\n0083 real-PG shape/CHECK/cascade tests are replaced by a drop assertion.",
"is_bot": false,
"headline": "chore(db): drop dashboard_stage_changes — stage tracker phase 2 (#456…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T18:14:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a5e6f6b31f538e87c68590ac1afd2f9397ee132",
"body": "…ides the next tag",
"is_bot": false,
"headline": "docs(roadmap): bank #4551 config-block removal phase 2 (PR #4713) — r…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T18:14:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "577d9a143b8a0b991d38cb38daaad1a7782bfbde",
"body": "… the sole Query Cache surface (#4551) (#4713)\n\n* feat(config): remove the `cache:` config block — settings registry is the sole Query Cache surface (#4551)\n\nPhase 2 of the two-phase config-block drop (PRD #4544, ADR-0033). Phase 1\n(#4545, ignored-with-boot-warning) shipped in tag v0.0.56; this land\n[…]\nk's removal\n- multi-tenancy.mdx: qualify ATLAS_CACHE_* / atlas.config.ts sentences as\n self-hosted (audience-invariant-leak class from the v0.0.42 audit);\n Admin-page sentence stays audience-neutral",
"is_bot": false,
"headline": "feat(config): remove the `cache:` config block — settings registry is…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T18:12:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2d22c297e366722c517b74acf2352b045dd26922",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.56 — Admin Cache Elevation",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T17:32:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53dc3755b101ede0ab0733ba9ea19a0dbcf8f58e",
"body": "… (#4712)\n\n* docs(cache): v0.0.56 closeout reconciliation — catch guides up to the shipped contracts\n\nguides/caching.mdx predated the milestone's admin-API rework:\n- cache key is five components post-ADR-0033 (#4547): resolved RLS config\n joins the material, so an RLS change orphans pre-change entr\n[…]\n cache page (PR #4711), closeout docs\nreconciliation. #4551 graduates to the next tag per two-phase drop\ndiscipline. Planned-tags bullet updated: all three 2026-07-10 elevate\nclusters are now shipped.",
"is_bot": false,
"headline": "docs: v0.0.56 closeout — cache guide reconciliation + ROADMAP banking…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T17:20:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b75112825a8ea434e3f40829841080aad9e76d0",
"body": "Presentation-only fixes from a design/a11y audit of the reworked cache\npage (#4549/#4550); wire schemas untouched:\n\n- Fill stat renders an honest em dash (no gauge) when entryCount/maxSize\n are unreported by the cache backend, instead of a confident 0.0%\n- disabled Flush button is the tooltip trigg\n[…]\nical to the empty state\n- hit-rate readout row wraps on narrow viewports\n- TTL input: aria-invalid + inline error for unsaveable values, live\n human-units preview while dirty, aria-describedby wiring",
"is_bot": false,
"headline": "polish(admin): impeccable audit pass on the Query Cache page (#4711)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T16:53:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "895cb7d18524f9121b88dc74b88c1b645ce972f3",
"body": "…Rs #4705/#4706/#4708/#4709) (#4710)",
"is_bot": false,
"headline": "docs(roadmap): bank shipped v0.0.56 slices #4545/#4546/#4549/#4550 (P…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T16:09:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "182b1a1fc04683661fe5522e594db442a17a5c36",
"body": "… on the admin cache page (#4550) (#4709)\n\n* feat(cache): entry inspection table + org-authorized per-entry delete on the admin cache page (#4550)\n\n- CacheEntry gains sqlPreview (~200-char cap, stamped at the sql.ts write\n site from the same post-beforeQuery SQL that built the key — no full-SQL\n r\n[…]\nenant audit shape; managed-no-org\n 400s on all four routes; caller-vs-target enabled gate pinned\n\n* fix(cache): void the fire-and-forget refetch in the 404-delete recovery path (no-floating-promises)",
"is_bot": false,
"headline": "feat(cache): entry inspection table + org-authorized per-entry delete…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T16:02:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "766c6f72103844b0bf7c3f9f9ddee26fee18683d",
"body": "…through the cockpit (#4549) (#4708)\n\n* feat(cache): org-scoped flush contract + org-bucketed windowed stats through the cockpit (#4549)\n\n- New module-level org stats registry (lib/cache/stats-registry.ts): per-org\n hit/miss buckets with a since-labeled lifetime rate plus a last-hour rate\n via two\n[…]\nuded) in sql-cache-elevation; fanout per-leg accounting\n pinned; no-org (single-tenant) stats+flush branches; plugin-backend\n stats/flush/audit behavior; LRU self-heal; de-vacuumed the 422 assertion",
"is_bot": false,
"headline": "feat(cache): org-scoped flush contract + org-bucketed windowed stats …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T15:23:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0537361054eb2fd726f1c0f1e89a1548e534c7ed",
"body": "…ntrols, config-block deprecation (#4545) (#4706)\n\n* feat(cache): Query Cache knobs → settings registry, inline cockpit controls, config-block deprecation (phase 1)\n\nMove the Query Cache's three knobs into the settings registry so they are\nruntime-controllable end-to-end with no redeploy (#4545):\n- \n[…]\nning split per deploy mode, restart caveat removed, three audit\n ride-alongs (L8/L10/L14).\n\nCloses #4545\n\n* docs(cache): correct getCacheMaxSize comment — getSettingAuto delegates to getSetting today",
"is_bot": false,
"headline": "feat(cache): Query Cache knobs → settings registry, inline cockpit co…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T14:24:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "007fe7012d5b8f002b4ede5646e1402580c11709",
"body": "…cuteSQL seam (#4546) (#4705)\n\nA Query Cache hit stops being invisible staleness. Slice 2 of v0.0.56\n(milestone #89), building on the async CacheBackend contract from #4548.\n\n- Hit responses carry `cacheAgeMs` (now minus the entry's write timestamp,\n clamped at 0; omitted when `cachedAt` is non-fin\n[…]\n-hit, clock-skew clamp, bypass read-skip/write-keep, refreshed-entry\nre-hit, all-hit vs mixed vs partial-failure fanout propagation, merger per-leg\npropagation, and web formatCacheAge/render branches.",
"is_bot": false,
"headline": "feat(cache): surface hit age + governance-safe bypassCache at the exe…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T14:08:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3489519a69dc7a828a016080de0f8b634af1077f",
"body": null,
"is_bot": false,
"headline": "docs(roadmap): bank shipped v0.0.56 slices #4547/#4548 (PRs #4703/#4704)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T14:07:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fffe75be683e9e61adbfbff60283cbb2b02796ba",
"body": "… before the cache check (#4547) (#4703)\n\nThe cache key captures every row-determining input (ADR-0033): resolved RLS config hashed into the key (closes H3), beforeQuery dispatch + re-validation moved above the cache check (closes M11 governance half), afterQuery/metrics live-only, single RLS-config snapshot threaded to key+injector, L9 invariant + custom-validator fingerprint gate.",
"is_bot": false,
"headline": "feat(cache): ADR-0033 governance — RLS config in the key, beforeQuery…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T01:51:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1204f1db14765dd53c69bf3e0b13e86fb4d432ca",
"body": "…l-plugin validation (#4548) (#4704)\n\n* feat(cache): async CacheBackend contract with scope tags, org index, fail-plugin validation (#4548)\n\n- CacheBackend fully async (get/set/delete/flush/flushByOrg/stats return Promise);\n kills the phantom-hit failure mode (unawaited Promise read as a truthy hit\n[…]\nen path (delete still completes + warning);\n admin-workspace cache mock gains validateCacheBackend (mock-all-exports).\n- lru.ts: correct the flushByOrg copy-first comment to describe the real reason.",
"is_bot": false,
"headline": "feat(cache): async CacheBackend contract — scope tags, org index, fai…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T01:26:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "84dd58e94d82ca3d4ab75463a6afcbc5cd2229f8",
"body": null,
"is_bot": false,
"headline": "docs(roadmap): kickoff v0.0.56 — Admin Cache Elevation (milestone #89)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T00:30:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63d5cf2ba8e5c50abdfe0db34414bd69847b680a",
"body": "…2/#4533/#4700)",
"is_bot": false,
"headline": "docs: tidy — bank the 2026-07-17 /next batch (5 PRs: #4461/#4463/#453…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T00:05:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9c88a6c493eb43d2048cd96819ee70798ce9c4a",
"body": "…1) (#4702)\n\nSaaS pins `sandbox.priority: [\"vercel-sandbox\"]` (deny-all, no fallback)\nbut nothing asserted the Vercel Sandbox credentials at boot. A region\nwith a missing/mis-stamped per-service VERCEL_TOKEN (Railway shared vars\ndon't auto-inherit) booted green, /health stayed green, and every\nexplo\n[…]\ny keys mutable via setSetting;\n VERCEL_TOKEN is a pure env secret (matches TURNSTILE_SECRET_KEY /\n AI_GATEWAY_API_KEY precedent).\n- Boot-smoke fixture populates VERCEL_TOKEN.\n\nv0.1.0 launch blocker.",
"is_bot": false,
"headline": "fix(api): SaaS boot guard for pinned vercel-sandbox credentials (#446…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-18T00:04:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3b37860fd066702dd57d0dae7c2e000c9d8f87b7",
"body": "…age test passes (#4700) (#4701)\n\nThe 'every ChatErrorCode is classified' invariant in errors.test.ts drifted\nwhen subscription_required was added to CHAT_ERROR_CODES but never added to\nthe test's retryable/non-retryable arrays, leaving the whole file red on main.\n\nsubscription_required is a billing\n[…]\n_MAP already pins it to false) — a permanent, non-retryable code.\nAdd it to nonRetryableCodes, and to the parallel parseChatError permanent-codes\nlist to keep the two classification arrays consistent.",
"is_bot": false,
"headline": "fix(types): classify subscription_required so the ChatErrorCode cover…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T23:54:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b7b4e10fe7d9998abacc4a5867fc6b4c2017f29d",
"body": "…ils fast (#4463) (#4699)\n\nNo pg pool (analytics or internal) set connectionTimeoutMillis, and no mysql2\npool set connectTimeout. pg defaults to 0 (no timeout), so a saturated pool\nqueued pool.connect() indefinitely and an unreachable-but-routable DB stalled\nevery request for the OS TCP keepalive wi\n[…]\ncomment: the internal pool now bounds the acquire,\n so the 5s audit-write cap is tighter/independent rather than the only guard.\n- Document ATLAS_CONNECT_TIMEOUT in .env.example + env-vars reference.",
"is_bot": false,
"headline": "fix(api): bound connectionTimeoutMillis on all pg pools so acquire fa…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T23:53:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3472485c59c99f53fcd5b88b97c501c800f6799d",
"body": "…laims discriminate keys (#4532) (#4698)\n\nbuildCacheKey serialized auth claims with JSON.stringify(claims,\nObject.keys(claims).sort()). A replacer array is applied at every nesting\nlevel, so a nested claim like { app_metadata: { org_id: \"org-42\" } }\nserialized to {\"app_metadata\":{}} and the discrimi\n[…]\n invariant\nhonestly for the undefined-orgId / nested-claims cases.\n\nAdds regression tests: two claims differing only at a nested path produce\ndifferent keys; nested key order does not affect the hash.",
"is_bot": false,
"headline": "fix(cache): deep-canonicalize claims in buildCacheKey so nested RLS c…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T23:52:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3bcadec5dd28389e5f44a492b199ebedca8f308",
"body": "…#4697)\n\nThe cache-flush route's own docblock declares that, because flush is\nprocess-global across every workspace on the runtime, attribution is the\nsecurity control. But the handler logged that row via fire-and-forget\nlogAdminAction, whose insert is swallowed by a circuit breaker — during a\ncircu\n[…]\n a silent 200, and the flush never runs.\n\nTests pin both invariants: the audit row commits before the flush, and a\nfailing audit write does not silently succeed (500, flush not called).\n\nSecurity fix.",
"is_bot": false,
"headline": "fix(cache): await the flush attribution row before flushing (#4533) (…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T23:52:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cab793ee9a2c2c40560a546828c2c2af2fcf94d5",
"body": "…detail",
"is_bot": false,
"headline": "docs(roadmap): close out v0.0.55 — collapse to History, archive full …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T19:47:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c996d84deec941a632934cf97d4bb24e790dc68",
"body": null,
"is_bot": false,
"headline": "docs(changelog): v0.0.55 — Dashboard Second Elevation",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T19:29:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a8c24cf8ac36cdbdbfef0f6a5abffcb14c1f7c65",
"body": "…ass (#4691)\n\n* test(dashboards): pin seedDraftCards batch concurrency contract\n\nThe existing wall-clock-budget test (one fast + one 200ms-slow card under a\n10ms budget) resolves identically whether seedDraftCards executes cards\nconcurrently or serially, so it did not actually pin the concurrency co\n[…]\nd accept/discard ghost-overlay staging model (ADR-0034 replaced\n it with the inline-undo single-edit mechanism).\n\nNo behavior change beyond copy/markup/responsive layout; 304 affected\nweb tests pass.",
"is_bot": false,
"headline": "polish(dashboards): design-review nits from the v0.0.55 pre-release p…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T19:04:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c175177fc8c6962953c7c4fea4d706177d4fe446",
"body": null,
"is_bot": false,
"headline": "docs: tidy — bank v0.0.55 design-review polish slice (#4686–#4690)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T18:53:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27bfa904a12ed3feef3aa20519922ff32e680302",
"body": "…N_H (#4687) (#4696)\n\n* fix(dashboards): text section-header tiles floor at a shorter TEXT_MIN_H (#4687)\n\nA markdown text / section-header card inherited the shared grid MIN_H=4\nfloor, so a one-line `## Section` header rendered as a ~180px empty box\ninstead of a tight banner over the charts grouped \n[…]\nundo request-body layout schemas now\nvalidate against TextCardLayoutSchema (h minimum 2, not 4), so the\ngenerated OpenAPI spec's layout.h minimum drops accordingly. Keeps\ncheck-openapi-drift.sh green.",
"is_bot": false,
"headline": "fix(dashboards): text section-header tiles floor at a shorter TEXT_MI…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T18:01:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ccaf6b8bd35847abb8b5c703954e720da133b071",
"body": "…k control (#4686) (#4695)\n\n* fix(dashboards): embed ?theme= themes charts too + discoverable light/dark control (#4686)\n\nThe share dialog's Embed tab forced theme only via a .dark wrapper: chrome\nthemed but tile charts read useDarkMode() (visitor's documentElement /\nprefers-color-scheme), so a forc\n[…]\nhange deselect comment.\n- tile.test.tsx: make the unforced-path test load-bearing — flip the mocked\n visitor system to dark and assert the chart follows it, so it can't pass on a\n hardcoded default.",
"is_bot": false,
"headline": "fix(dashboards): embed ?theme= themes charts + discoverable light/dar…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T17:54:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ee83426d1c1c4df27799dde9d0c0ff178f0748b",
"body": "… to card type (#4688) (#4694)\n\n* fix(dashboards): dashboard tiles render ResultChart plot-only, pinned to the card's type (#4688)\n\nDashboard chart tiles reuse the chat ResultChart, which carried its own caption\nbar + Line/Area/Bar type toggle and auto-detected its type from the data. Inside\na title\n[…]\nt and\n makes a typo'd member a compile error.\n- Clarify the chartType JSDoc (it pins regardless of embedded; intended paired).\n- Harden the shared-tile async flush against the two-hop dynamic loader.",
"is_bot": false,
"headline": "fix(dashboards): dashboard tiles render ResultChart plot-only, pinned…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T17:41:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "25f9a116c54797fb14e9c589e8ae639b151f6c08",
"body": "…4690) (#4693)\n\n* fix(dashboards): distinguish 401 from 403 on shared-view auth wall (#4690)\n\nShared-dashboard fetch collapsed 401 (no session) and 403 (authenticated,\nwrong org) into a single 'auth-required' reason, so a logged-in member of the\nwrong org dead-ended on a 'Log in' CTA they had alread\n[…]\nThe malformed-403 mock's json returns Promise<never>, which tsgo's stricter\ntsconfig.test-check rejected as a direct `as Response` cast (TS2352). Cast via\nunknown, matching the outer stubFetch helper.",
"is_bot": false,
"headline": "fix(dashboards): distinguish 401 from 403 on shared-view auth wall (#…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T17:34:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "42fa613755b75ac1341b1672daeec97b4e5f1bc9",
"body": "…ignal (#4689) (#4692)\n\nThe View/Edit toggle + 'drag tiles' help were gated on a coarse-pointer\nmedia query, while the grid degrades to a non-draggable single-column\nstack on measured width < MOBILE_BREAKPOINT. On a narrow-but-mouse-driven\nwindow (fine pointer, <640px) the chrome advertised drag/res\n[…]\none signal, so advertised == deliverable.\nThe narrow-desktop hint reads 'Widen the window to edit' rather than the\nfalse 'Editing is desktop-only'. Coarse-pointer (touch) path unchanged.\n\nCloses #4689",
"is_bot": false,
"headline": "fix(dashboards): gate topbar Edit affordances on the grid's stacked s…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T17:30:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a128d67415053fbd2dc3e27c27963a4efbabd08",
"body": "The existing wall-clock-budget test (one fast + one 200ms-slow card under a\n10ms budget) resolves identically whether seedDraftCards executes cards\nconcurrently or serially, so it did not actually pin the concurrency contract\nADR-0034 Decision 1 makes load-bearing: the budget bounds the WHOLE batch\n\n[…]\nbudget elapses, flipping it to\n`unseeded` and failing the assertion. Verified red under a for/await refactor,\ngreen under the shipped Promise.all.\n\nSurfaced by the v0.0.55 milestone-wide review panel.",
"is_bot": false,
"headline": "test(dashboards): pin seedDraftCards batch concurrency contract (#4684)",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T17:00:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb259488d36a82be2918ffbb6242d12d471b8294",
"body": "…on (#4683)\n\n* docs(dashboards): document the shared-view Embed tab / framable /embed route (#4564)\n\n* docs: reconcile ROADMAP v0.0.55 — all 18 issues merged, milestone closed",
"is_bot": false,
"headline": "docs: v0.0.55 closeout — dashboard embed guide + ROADMAP reconciliati…",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T16:36:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b79cc217b231d4f830e70d730d341125a75160af",
"body": "…Edit; scoped shortcuts (#4560) (#4682)\n\nView mode offers only non-mutating tile affordances (refresh, fullscreen, CSV, drilldown); Rename/Duplicate/Remove and drag are Edit-only. The tile-actions menu renders only when it holds an item (editing or an export handler), never an empty dropdown.\n\nScope\n[…]\nafts row.\n\nTests: View/Edit affordance-set gating on the tile, RGL drag/resize gating in both modes, the shortcut predicate, and the non-forking route seam.\n\nADR-0034 / CONTEXT.md § Dashboard editing.",
"is_bot": false,
"headline": "feat(dashboards): View is read-only — mutating tile controls move to …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T16:26:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "191d58b8ec2a2481efbcd05a7ae1214d5f6dffe0",
"body": "…in the draft with inline undo (#4555) (#4681)\n\n* feat(dashboards): single edit mechanism — destructive bound ops land in the draft with inline undo (#4555)\n\nRetire the stage tracker (ADR-0034 Decision 2, reverses #2365). The bound\neditor's removeCard / updateCardSql now apply straight to the caller\n[…]\ntagedChange/Stage* wire types from @useatlas/types\n- fix stale stage-tracker comments in dashboard-versioning.ts + bound-dashboard.ts\n\n* test: cover the undo route's cross-org getDashboard guard (404)",
"is_bot": false,
"headline": "feat(dashboards): single edit mechanism — destructive bound ops land …",
"author_name": "Matt Sywulak",
"author_login": "msywulak",
"committed_at": "2026-07-17T16:21:00Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 68,
"commits_last_year": 3439,
"latest_release_at": "2026-07-24T18:52:28Z",
"latest_release_tag": "v0.1.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 21,
"days_since_latest_release": 1,
"mean_days_between_releases": 0.6
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": false,
"has_contributing": true,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "create-atlas-agent",
"exists": true,
"license": "MIT",
"keywords": [
"atlas",
"text-to-sql",
"data-analyst",
"agent",
"semantic-layer",
"bun",
"hono"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/create-atlas-agent",
"is_deprecated": false,
"latest_version": "0.3.3",
"repository_url": "https://github.com/AtlasDevHQ/atlas",
"versions_count": 7,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 49,
"first_published_at": "2026-02-24T20:29:37.499000Z",
"latest_published_at": "2026-05-03T19:55:39.385000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 83
},
{
"name": "create-atlas-plugin",
"exists": true,
"license": "Apache-2.0",
"keywords": [
"atlas",
"text-to-sql",
"plugin",
"scaffold",
"bun"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/create-atlas-plugin",
"is_deprecated": false,
"latest_version": "0.1.1",
"repository_url": "https://github.com/AtlasDevHQ/atlas",
"versions_count": 2,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 22,
"first_published_at": "2026-05-03T19:29:52.974000Z",
"latest_published_at": "2026-05-03T19:34:06.439000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 83
}
]
},
"popularity": {
"forks": 3,
"stars": 1,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-06-18",
"count": 1
},
{
"date": "2026-06-29",
"count": 1
},
{
"date": "2026-07-07",
"count": 1
}
],
"complete": true,
"collected": 3,
"total_forks": 3
},
"star_history": null,
"open_issues_and_prs": 37
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": true,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [
"apps/docs/openapi.json"
],
"has_devcontainer": false,
"typecheck_configs": [
"apps/docs/tsconfig.json",
"apps/www/tsconfig.json",
"create-atlas/templates/docker/tsconfig.json",
"create-atlas/templates/nextjs-standalone/tsconfig.json",
"ee/tsconfig.json",
"examples/embedded-mcp-onboarding/tsconfig.json",
"examples/nextjs-standalone/tsconfig.json",
"packages/api/tsconfig.json",
"packages/cli/tsconfig.json",
"packages/mcp/tsconfig.json",
"packages/oauth-helper/tsconfig.json",
"packages/plugin-sdk/tsconfig.json",
"packages/react/tsconfig.json",
"packages/schemas/tsconfig.json",
"packages/sdk/tsconfig.json",
"packages/types/tsconfig.json",
"packages/web/tsconfig.json",
"packages/webhook-publisher/tsconfig.json",
"plugins/bigquery/tsconfig.json",
"plugins/chat/tsconfig.json",
"plugins/clickhouse/tsconfig.json",
"plugins/duckdb/tsconfig.json",
"plugins/elasticsearch/tsconfig.json",
"plugins/email-digest/tsconfig.json",
"plugins/email/tsconfig.json",
"plugins/jira/tsconfig.json",
"plugins/mcp/tsconfig.json",
"plugins/mysql/tsconfig.json",
"plugins/obsidian-reader/tsconfig.json",
"plugins/obsidian/tsconfig.json",
"plugins/salesforce/tsconfig.json",
"plugins/snowflake/tsconfig.json",
"plugins/teams/tsconfig.json",
"plugins/twenty/tsconfig.json",
"plugins/webhook-action/tsconfig.json",
"plugins/webhook/tsconfig.json",
"plugins/yaml-context/tsconfig.json",
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 438644,
"source_files_sampled": 3784,
"oversized_source_files": 74,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 46249
},
"dependencies": {
"manifests": [
"create-atlas-plugin/package.json",
"create-atlas/package.json",
"ee/package.json",
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 7,
"malicious_count": 0,
"assessed_package": "npm:create-atlas-agent@0.3.3",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@clack/prompts",
"manifest": "create-atlas-plugin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.0"
},
{
"name": "picocolors",
"manifest": "create-atlas-plugin/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.1"
},
{
"name": "@clack/prompts",
"manifest": "create-atlas/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.0"
},
{
"name": "picocolors",
"manifest": "create-atlas/package.json",
"ecosystem": "npm",
"version_constraint": "^1.1.1"
},
{
"name": "@atlas/api",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@useatlas/chat",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@useatlas/twenty",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@useatlas/types",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@useatlas/webhook-publisher",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "effect",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "^3.14.8"
},
{
"name": "ipaddr.js",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "^2.3.0"
},
{
"name": "node-sql-parser",
"manifest": "ee/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.0"
},
{
"name": "@ai-sdk/amazon-bedrock",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.119"
},
{
"name": "@ai-sdk/anthropic",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.85"
},
{
"name": "@ai-sdk/gateway",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.133"
},
{
"name": "@ai-sdk/openai",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.74"
},
{
"name": "@ai-sdk/provider",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.10"
},
{
"name": "@ai-sdk/react",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.210"
},
{
"name": "@aws-sdk/client-bedrock",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.1075.0"
},
{
"name": "@better-auth/api-key",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.20"
},
{
"name": "@better-auth/oauth-provider",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.20"
},
{
"name": "@better-auth/passkey",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.20"
},
{
"name": "@better-auth/scim",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.20"
},
{
"name": "@better-auth/stripe",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.20"
},
{
"name": "@clack/prompts",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.0"
},
{
"name": "@clickhouse/client",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.22.0"
},
{
"name": "@effect/ai",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.36.0"
},
{
"name": "@effect/ai-anthropic",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.26.0"
},
{
"name": "@effect/ai-openai",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.39.2"
},
{
"name": "@effect/platform",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.96.2"
},
{
"name": "@effect/sql",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.51.1"
},
{
"name": "@hono/zod-openapi",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.4.0"
},
{
"name": "@hookform/resolvers",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.0"
},
{
"name": "@opentelemetry/exporter-metrics-otlp-http",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.218.0"
},
{
"name": "@opentelemetry/exporter-trace-otlp-http",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.218.0"
},
{
"name": "@opentelemetry/resources",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.0"
},
{
"name": "@opentelemetry/sdk-metrics",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.0"
},
{
"name": "@opentelemetry/sdk-node",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.218.0"
},
{
"name": "@opentelemetry/semantic-conventions",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.41.1"
},
{
"name": "@radix-ui/react-slot",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.3.0"
},
{
"name": "@shikijs/transformers",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.2.0"
},
{
"name": "@tailwindcss/cli",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.1"
},
{
"name": "@tailwindcss/postcss",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.1"
},
{
"name": "@tanstack/react-query",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.101.1"
},
{
"name": "@tanstack/react-query-devtools",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.101.1"
},
{
"name": "@types/nodemailer",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^8.0.1"
},
{
"name": "ai",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.208"
},
{
"name": "better-auth",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.20"
},
{
"name": "date-fns",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.4.0"
},
{
"name": "effect",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.21.4"
},
{
"name": "fumadocs-core",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "~16.9.3"
},
{
"name": "fumadocs-openapi",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^10.9.1"
},
{
"name": "fumadocs-ui",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "~16.9.3"
},
{
"name": "happy-dom",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^20.10.6"
},
{
"name": "hono",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.12.27"
},
{
"name": "ipaddr.js",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.4.0"
},
{
"name": "js-yaml",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.1.0"
},
{
"name": "jsforce",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.10.16"
},
{
"name": "lucide-react",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.21.0"
},
{
"name": "mysql2",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.22.4"
},
{
"name": "nanoid",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.1.15"
},
{
"name": "next",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^16.2.9"
},
{
"name": "nodemailer",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^9.0.1"
},
{
"name": "obsidian",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.13.1"
},
{
"name": "radix-ui",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.6.0"
},
{
"name": "react-dom",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^19.2.6"
},
{
"name": "react-hook-form",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^7.80.0"
},
{
"name": "react-resizable-panels",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4"
},
{
"name": "snowflake-sdk",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.4.3"
},
{
"name": "tailwindcss",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.3.1"
},
{
"name": "zustand",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.0.14"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@ai-sdk/amazon-bedrock",
"direct": true,
"version": "^4.0.119",
"ecosystem": "npm"
},
{
"name": "@ai-sdk/anthropic",
"direct": true,
"version": "^3.0.85",
"ecosystem": "npm"
},
{
"name": "@ai-sdk/gateway",
"direct": true,
"version": "^3.0.133",
"ecosystem": "npm"
},
{
"name": "@ai-sdk/openai",
"direct": true,
"version": "^3.0.74",
"ecosystem": "npm"
},
{
"name": "@ai-sdk/provider",
"direct": true,
"version": "^3.0.10",
"ecosystem": "npm"
},
{
"name": "@ai-sdk/react",
"direct": true,
"version": "^3.0.210",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/client-bedrock",
"direct": true,
"version": "^3.1075.0",
"ecosystem": "npm"
},
{
"name": "@better-auth/api-key",
"direct": true,
"version": "^1.6.20",
"ecosystem": "npm"
},
{
"name": "@better-auth/oauth-provider",
"direct": true,
"version": "^1.6.20",
"ecosystem": "npm"
},
{
"name": "@better-auth/passkey",
"direct": true,
"version": "^1.6.20",
"ecosystem": "npm"
},
{
"name": "@better-auth/scim",
"direct": true,
"version": "^1.6.20",
"ecosystem": "npm"
},
{
"name": "@better-auth/stripe",
"direct": true,
"version": "^1.6.20",
"ecosystem": "npm"
},
{
"name": "@clack/prompts",
"direct": true,
"version": "^1.1.0",
"ecosystem": "npm"
},
{
"name": "@clack/prompts",
"direct": true,
"version": "^1.6.0",
"ecosystem": "npm"
},
{
"name": "@clickhouse/client",
"direct": true,
"version": "^1.22.0",
"ecosystem": "npm"
},
{
"name": "@effect/ai",
"direct": true,
"version": "^0.36.0",
"ecosystem": "npm"
},
{
"name": "@effect/ai-anthropic",
"direct": true,
"version": "^0.26.0",
"ecosystem": "npm"
},
{
"name": "@effect/ai-openai",
"direct": true,
"version": "^0.39.2",
"ecosystem": "npm"
},
{
"name": "@effect/platform",
"direct": true,
"version": "^0.96.2",
"ecosystem": "npm"
},
{
"name": "@effect/sql",
"direct": true,
"version": "^0.51.1",
"ecosystem": "npm"
},
{
"name": "@hono/zod-openapi",
"direct": true,
"version": "^1.4.0",
"ecosystem": "npm"
},
{
"name": "@hookform/resolvers",
"direct": true,
"version": "^5.4.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/exporter-metrics-otlp-http",
"direct": true,
"version": "^0.218.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/exporter-trace-otlp-http",
"direct": true,
"version": "^0.218.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/resources",
"direct": true,
"version": "^2.8.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/sdk-metrics",
"direct": true,
"version": "^2.8.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/sdk-node",
"direct": true,
"version": "^0.218.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/semantic-conventions",
"direct": true,
"version": "^1.41.1",
"ecosystem": "npm"
},
{
"name": "@radix-ui/react-slot",
"direct": true,
"version": "^1.3.0",
"ecosystem": "npm"
},
{
"name": "@shikijs/transformers",
"direct": true,
"version": "^4.2.0",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/cli",
"direct": true,
"version": "^4.3.1",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/postcss",
"direct": true,
"version": "^4.3.1",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-query",
"direct": true,
"version": "^5.101.1",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-query-devtools",
"direct": true,
"version": "^5.101.1",
"ecosystem": "npm"
},
{
"name": "@types/nodemailer",
"direct": true,
"version": "^8.0.1",
"ecosystem": "npm"
},
{
"name": "@useatlas/twenty",
"direct": true,
"version": "^0.0.6",
"ecosystem": "npm"
},
{
"name": "@useatlas/types",
"direct": true,
"version": "^0.1.0",
"ecosystem": "npm"
},
{
"name": "@useatlas/types",
"direct": true,
"version": "^0.5.0",
"ecosystem": "npm"
},
{
"name": "@useatlas/webhook-publisher",
"direct": true,
"version": "^0.0.1",
"ecosystem": "npm"
},
{
"name": "ai",
"direct": true,
"version": "^6.0.208",
"ecosystem": "npm"
},
{
"name": "better-auth",
"direct": true,
"version": "^1.6.16",
"ecosystem": "npm"
},
{
"name": "better-auth",
"direct": true,
"version": "^1.6.20",
"ecosystem": "npm"
},
{
"name": "date-fns",
"direct": true,
"version": "^4.4.0",
"ecosystem": "npm"
},
{
"name": "effect",
"direct": true,
"version": "^3.14.8",
"ecosystem": "npm"
},
{
"name": "effect",
"direct": true,
"version": "^3.21.4",
"ecosystem": "npm"
},
{
"name": "fumadocs-core",
"direct": true,
"version": "~16.9.3",
"ecosystem": "npm"
},
{
"name": "fumadocs-openapi",
"direct": true,
"version": "^10.9.1",
"ecosystem": "npm"
},
{
"name": "fumadocs-ui",
"direct": true,
"version": "~16.9.3",
"ecosystem": "npm"
},
{
"name": "happy-dom",
"direct": true,
"version": "^20.10.6",
"ecosystem": "npm"
},
{
"name": "hono",
"direct": true,
"version": "^4.12.27",
"ecosystem": "npm"
},
{
"name": "ipaddr.js",
"direct": true,
"version": "^2.3.0",
"ecosystem": "npm"
},
{
"name": "ipaddr.js",
"direct": true,
"version": "^2.4.0",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": true,
"version": "^5.1.0",
"ecosystem": "npm"
},
{
"name": "jsforce",
"direct": true,
"version": "^3.10.16",
"ecosystem": "npm"
},
{
"name": "lucide-react",
"direct": true,
"version": "^1.21.0",
"ecosystem": "npm"
},
{
"name": "mysql2",
"direct": true,
"version": "^3.22.4",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": true,
"version": "^5.1.15",
"ecosystem": "npm"
},
{
"name": "next",
"direct": true,
"version": "^16.2.1",
"ecosystem": "npm"
},
{
"name": "next",
"direct": true,
"version": "^16.2.9",
"ecosystem": "npm"
},
{
"name": "node-sql-parser",
"direct": true,
"version": "^5.4.0",
"ecosystem": "npm"
},
{
"name": "nodemailer",
"direct": true,
"version": "^9.0.1",
"ecosystem": "npm"
},
{
"name": "obsidian",
"direct": true,
"version": "^1.13.1",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": true,
"version": "^1.1.1",
"ecosystem": "npm"
},
{
"name": "radix-ui",
"direct": true,
"version": "^1.6.0",
"ecosystem": "npm"
},
{
"name": "react-dom",
"direct": true,
"version": "^19.2.4",
"ecosystem": "npm"
},
{
"name": "react-dom",
"direct": true,
"version": "^19.2.6",
"ecosystem": "npm"
},
{
"name": "react-hook-form",
"direct": true,
"version": "^7.80.0",
"ecosystem": "npm"
},
{
"name": "react-resizable-panels",
"direct": true,
"version": "^4",
"ecosystem": "npm"
},
{
"name": "snowflake-sdk",
"direct": true,
"version": "^2.4.3",
"ecosystem": "npm"
},
{
"name": "tailwindcss",
"direct": true,
"version": "^4.3.1",
"ecosystem": "npm"
},
{
"name": "zustand",
"direct": true,
"version": "^5.0.14",
"ecosystem": "npm"
},
{
"name": "@axe-core/playwright",
"direct": false,
"version": "^4.11.3",
"ecosystem": "npm"
},
{
"name": "@better-auth/agent-auth",
"direct": false,
"version": "0.6.2",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/discord",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/gchat",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/github",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/linear",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/slack",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/state-memory",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/teams",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/telegram",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@chat-adapter/whatsapp",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "@daytonaio/sdk",
"direct": false,
"version": "^0.185.0",
"ecosystem": "npm"
},
{
"name": "@dnd-kit/core",
"direct": false,
"version": "^6.3.1",
"ecosystem": "npm"
},
{
"name": "@dnd-kit/modifiers",
"direct": false,
"version": "^9.0.0",
"ecosystem": "npm"
},
{
"name": "@dnd-kit/sortable",
"direct": false,
"version": "^10.0.0",
"ecosystem": "npm"
},
{
"name": "@dnd-kit/utilities",
"direct": false,
"version": "^3.2.2",
"ecosystem": "npm"
},
{
"name": "@duckdb/node-api",
"direct": false,
"version": "^1.5.3-r.3",
"ecosystem": "npm"
},
{
"name": "@effect/experimental",
"direct": false,
"version": "^0.60.0",
"ecosystem": "npm"
},
{
"name": "@effect/sql-mysql2",
"direct": false,
"version": "^0.52.0",
"ecosystem": "npm"
},
{
"name": "@effect/sql-pg",
"direct": false,
"version": "^0.52.1",
"ecosystem": "npm"
},
{
"name": "@modelcontextprotocol/sdk",
"direct": false,
"version": "^1.29.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/api",
"direct": false,
"version": "^1.9.1",
"ecosystem": "npm"
},
{
"name": "@playwright/test",
"direct": false,
"version": "^1.60.0",
"ecosystem": "npm"
},
{
"name": "@tanstack/react-table",
"direct": false,
"version": "^8.21.3",
"ecosystem": "npm"
},
{
"name": "@testing-library/dom",
"direct": false,
"version": "^10.4.1",
"ecosystem": "npm"
},
{
"name": "@testing-library/react",
"direct": false,
"version": "^16.3.2",
"ecosystem": "npm"
},
{
"name": "@types/bun",
"direct": false,
"version": "^1.3.14",
"ecosystem": "npm"
},
{
"name": "@types/diff",
"direct": false,
"version": "^8.0.0",
"ecosystem": "npm"
},
{
"name": "@types/json-schema",
"direct": false,
"version": "^7.0.15",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "^25.9.4",
"ecosystem": "npm"
},
{
"name": "@types/pg",
"direct": false,
"version": "^8.20.0",
"ecosystem": "npm"
},
{
"name": "@types/react",
"direct": false,
"version": "^19.2.14",
"ecosystem": "npm"
},
{
"name": "@types/react",
"direct": false,
"version": "^19.2.15",
"ecosystem": "npm"
},
{
"name": "@types/react-dom",
"direct": false,
"version": "^19.2.3",
"ecosystem": "npm"
},
{
"name": "@types/react-syntax-highlighter",
"direct": false,
"version": "^15.5.13",
"ecosystem": "npm"
},
{
"name": "@typescript/native-preview",
"direct": false,
"version": "^7.0.0-dev.20260623.1",
"ecosystem": "npm"
},
{
"name": "@useatlas/react",
"direct": false,
"version": "^0.2.0",
"ecosystem": "npm"
},
{
"name": "@useatlas/sdk",
"direct": false,
"version": "^0.1.0",
"ecosystem": "npm"
},
{
"name": "@vercel/og",
"direct": false,
"version": "0.11.1",
"ecosystem": "npm"
},
{
"name": "@vercel/sandbox",
"direct": false,
"version": "^2",
"ecosystem": "npm"
},
{
"name": "@vercel/sandbox",
"direct": false,
"version": "^2.2.1",
"ecosystem": "npm"
},
{
"name": "babel-plugin-react-compiler",
"direct": false,
"version": "^1.0.0",
"ecosystem": "npm"
},
{
"name": "better-auth-harmony",
"direct": false,
"version": "^1.3.2",
"ecosystem": "npm"
},
{
"name": "chat",
"direct": false,
"version": "4.23.0",
"ecosystem": "npm"
},
{
"name": "class-variance-authority",
"direct": false,
"version": "^0.7.1",
"ecosystem": "npm"
},
{
"name": "clsx",
"direct": false,
"version": "^2.1.1",
"ecosystem": "npm"
},
{
"name": "cmdk",
"direct": false,
"version": "^1.1.1",
"ecosystem": "npm"
},
{
"name": "croner",
"direct": false,
"version": "^10.0.1",
"ecosystem": "npm"
},
{
"name": "diff",
"direct": false,
"version": "^9.0.0",
"ecosystem": "npm"
},
{
"name": "domhandler",
"direct": false,
"version": "^5.0.3",
"ecosystem": "npm"
},
{
"name": "drizzle-kit",
"direct": false,
"version": "^0.31.10",
"ecosystem": "npm"
},
{
"name": "drizzle-orm",
"direct": false,
"version": "^0.45.2",
"ecosystem": "npm"
},
{
"name": "e2b",
"direct": false,
"version": "^2.28.2",
"ecosystem": "npm"
},
{
"name": "entities",
"direct": false,
"version": "^4.5.0",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "^0.28.1",
"ecosystem": "npm"
},
{
"name": "exceljs",
"direct": false,
"version": "^4.4.0",
"ecosystem": "npm"
},
{
"name": "fflate",
"direct": false,
"version": "^0.8.2",
"ecosystem": "npm"
},
{
"name": "fumadocs-mdx",
"direct": false,
"version": "^15.0.12",
"ecosystem": "npm"
},
{
"name": "github-slugger",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "htmlparser2",
"direct": false,
"version": "^9.1.0",
"ecosystem": "npm"
},
{
"name": "input-otp",
"direct": false,
"version": "^1.4.2",
"ecosystem": "npm"
},
{
"name": "jose",
"direct": false,
"version": "^6.2.3",
"ecosystem": "npm"
},
{
"name": "just-bash",
"direct": false,
"version": "^3.0.2",
"ecosystem": "npm"
},
{
"name": "next-themes",
"direct": false,
"version": "^0.4.6",
"ecosystem": "npm"
},
{
"name": "nuqs",
"direct": false,
"version": "^2.8.9",
"ecosystem": "npm"
},
{
"name": "oxlint",
"direct": false,
"version": "^1.72.0",
"ecosystem": "npm"
},
{
"name": "oxlint-plugin-eslint",
"direct": false,
"version": "^1.72.0",
"ecosystem": "npm"
},
{
"name": "oxlint-tsgolint",
"direct": false,
"version": "^0.24.0",
"ecosystem": "npm"
},
{
"name": "pg",
"direct": false,
"version": "^8.22.0",
"ecosystem": "npm"
},
{
"name": "pg-mem",
"direct": false,
"version": "^3.0.14",
"ecosystem": "npm"
},
{
"name": "pino",
"direct": false,
"version": "^10.3.1",
"ecosystem": "npm"
},
{
"name": "pino-pretty",
"direct": false,
"version": "^13.1.3",
"ecosystem": "npm"
},
{
"name": "react",
"direct": false,
"version": "^19.2.4",
"ecosystem": "npm"
},
{
"name": "react",
"direct": false,
"version": "^19.2.6",
"ecosystem": "npm"
},
{
"name": "react-day-picker",
"direct": false,
"version": "^10.0.1",
"ecosystem": "npm"
},
{
"name": "react-grid-layout",
"direct": false,
"version": "^2.2.3",
"ecosystem": "npm"
},
{
"name": "react-markdown",
"direct": false,
"version": "^10.1.0",
"ecosystem": "npm"
},
{
"name": "react-syntax-highlighter",
"direct": false,
"version": "^16.1.1",
"ecosystem": "npm"
},
{
"name": "recharts",
"direct": false,
"version": "^3.8.1",
"ecosystem": "npm"
},
{
"name": "remark-gfm",
"direct": false,
"version": "^4.0.1",
"ecosystem": "npm"
},
{
"name": "shadcn",
"direct": false,
"version": "^4.11.0",
"ecosystem": "npm"
},
{
"name": "sonner",
"direct": false,
"version": "^2.0.7",
"ecosystem": "npm"
},
{
"name": "stripe",
"direct": false,
"version": "^22.2.3",
"ecosystem": "npm"
},
{
"name": "syncpack",
"direct": false,
"version": "^15.3.2",
"ecosystem": "npm"
},
{
"name": "tailwind-merge",
"direct": false,
"version": "^3.5.0",
"ecosystem": "npm"
},
{
"name": "tsup",
"direct": false,
"version": "^8.5.1",
"ecosystem": "npm"
},
{
"name": "tw-animate-css",
"direct": false,
"version": "^1.4.0",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^6.0.2",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^6.0.3",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": false,
"version": "^4.4.3",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 161,
"direct_count": 71,
"indirect_count": 90
}
},
"maintainership": {
"issues": {
"open_prs": 6,
"merged_prs": 2326,
"open_issues": 31,
"closed_ratio": 0.987,
"closed_issues": 2401,
"closed_unmerged_prs": 36
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "msywulak",
"commits": 3382,
"avatar_url": "https://avatars.githubusercontent.com/u/51167140?v=4"
},
{
"type": "User",
"login": "claude",
"commits": 54,
"avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
},
{
"type": "User",
"login": "jstar0",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/54024410?v=4"
}
],
"contributors_sampled": 3,
"top_contributor_share": 0.984
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"claude.yml",
"deploy-validation.yml",
"eval.yml",
"fork-pr-gate.yml",
"lighthouse.yml",
"load-test-mcp.yml",
"mcp-registry.yml",
"model-freshness.yml",
"publish.yml",
"staging-smoke.yml",
"sync-starters.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 8,
"reason": "dependency not pinned by hash detected -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "78 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "ae4b7320a8571d52b0be6b1857da0eaa8dd18538",
"ran_at": "2026-07-25T21:03:13Z",
"aggregate_score": 6.3,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T21:01:22Z",
"oldest_open_prs": [
{
"number": 4789,
"created_at": "2026-07-24T18:43:59Z",
"last_comment_at": "2026-07-24T18:50:24Z",
"last_comment_author": "github-actions"
},
{
"number": 4790,
"created_at": "2026-07-24T18:44:01Z",
"last_comment_at": "2026-07-24T18:50:49Z",
"last_comment_author": "github-actions"
},
{
"number": 4791,
"created_at": "2026-07-24T18:44:03Z",
"last_comment_at": "2026-07-24T18:53:26Z",
"last_comment_author": "github-actions"
},
{
"number": 4792,
"created_at": "2026-07-24T18:44:05Z",
"last_comment_at": "2026-07-24T18:52:13Z",
"last_comment_author": "github-actions"
},
{
"number": 4793,
"created_at": "2026-07-24T18:44:07Z",
"last_comment_at": "2026-07-24T18:53:27Z",
"last_comment_author": "github-actions"
},
{
"number": 4794,
"created_at": "2026-07-24T18:53:31Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-25T21:00:47Z",
"ci_last_conclusion": "SKIPPED",
"oldest_open_issues": [
{
"number": 1922,
"created_at": "2026-04-27T00:06:44Z",
"last_comment_at": "2026-07-10T00:27:28Z",
"last_comment_author": "msywulak"
},
{
"number": 1928,
"created_at": "2026-04-27T00:50:25Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2055,
"created_at": "2026-05-04T03:31:45Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2109,
"created_at": "2026-05-06T02:55:19Z",
"last_comment_at": "2026-05-09T14:20:19Z",
"last_comment_author": "msywulak"
},
{
"number": 2200,
"created_at": "2026-05-08T22:35:27Z",
"last_comment_at": "2026-06-21T11:18:37Z",
"last_comment_author": "msywulak"
},
{
"number": 2802,
"created_at": "2026-05-25T02:26:03Z",
"last_comment_at": "2026-06-13T16:01:38Z",
"last_comment_author": "msywulak"
},
{
"number": 2919,
"created_at": "2026-05-28T14:58:39Z",
"last_comment_at": "2026-06-24T17:48:16Z",
"last_comment_author": "msywulak"
},
{
"number": 3368,
"created_at": "2026-06-10T16:02:40Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 3414,
"created_at": "2026-06-12T06:37:20Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 3765,
"created_at": "2026-06-17T20:17:37Z",
"last_comment_at": "2026-06-18T18:04:15Z",
"last_comment_author": "msywulak"
},
{
"number": 3766,
"created_at": "2026-06-17T20:24:03Z",
"last_comment_at": "2026-06-23T01:10:41Z",
"last_comment_author": "msywulak"
},
{
"number": 3777,
"created_at": "2026-06-18T08:06:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 3870,
"created_at": "2026-06-22T11:12:11Z",
"last_comment_at": "2026-07-09T21:13:32Z",
"last_comment_author": "msywulak"
},
{
"number": 4099,
"created_at": "2026-06-29T04:05:51Z",
"last_comment_at": "2026-07-02T00:56:52Z",
"last_comment_author": "msywulak"
},
{
"number": 4379,
"created_at": "2026-07-06T01:06:04Z",
"last_comment_at": "2026-07-10T13:17:13Z",
"last_comment_author": "msywulak"
},
{
"number": 4402,
"created_at": "2026-07-07T03:11:16Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 4403,
"created_at": "2026-07-07T03:11:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 4404,
"created_at": "2026-07-07T03:11:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 4416,
"created_at": "2026-07-07T22:49:03Z",
"last_comment_at": "2026-07-08T17:19:07Z",
"last_comment_author": "msywulak"
},
{
"number": 4438,
"created_at": "2026-07-09T15:54:44Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/AtlasDevHQ/atlas",
"host": "github.com",
"name": "atlas",
"owner": "AtlasDevHQ"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"security": 70,
"vitality": 87,
"community": 36,
"governance": 55,
"engineering": 69
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 87,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"commits_last_year": 3439,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 21
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "21/52 weeks with commits",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 21
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "3439 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 3439
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 68,
"latest_release_tag": "v0.1.0",
"releases_from_tags": false,
"days_since_latest_release": 1,
"mean_days_between_releases": 0.6
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "68 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 68
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.6 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.6
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 36,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 2,
"inputs": {
"forks": 3,
"stars": 1,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "1 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 1
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "3 forks",
"points": 2.5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 3
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (AGPL-3.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "AGPL-3.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "at_risk",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 31,
"inputs": {
"packages": [
"create-atlas-agent",
"create-atlas-plugin"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 71
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "71 downloads/month across npm",
"points": 24.8,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 71,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 55,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 16,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 3,
"top_contributor_share": 0.984
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 98% of commits",
"points": 0.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 98
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "3 contributors",
"points": 4.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 3
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"merged_prs": 2326,
"open_issues": 31,
"closed_issues": 2401,
"issue_closed_ratio": 0.987,
"closed_unmerged_prs": 36
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "99% of issues closed",
"points": 46.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 99
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "2326/2362 decided PRs merged",
"points": 37.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 2326,
"decided": 2362
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 36,
"inputs": {
"followers": 0,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "AtlasDevHQ",
"public_repos": 4,
"account_age_days": 147
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of AtlasDevHQ",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "AtlasDevHQ"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "4 public repos, account ~0 yr old",
"points": 5.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 4
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"create-atlas-agent",
"create-atlas-plugin"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 83
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 83 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 83
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "7 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 7
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 69,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "12 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 12
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": "https://www.useatlas.dev",
"has_readme": true,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.useatlas.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 70,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 63,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 6.3
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 4,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "78 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:create-atlas-agent@0.3.3 runtime dependency closure — what installing the published package pulls in — 7 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:create-atlas-agent@0.3.3",
"assessed": 7
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 7,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 7,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 77,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"has_llms_txt": true,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 46249
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": "llms.txt present",
"points": 15,
"status": "met",
"details": [
{
"code": "llms_txt_present",
"params": {}
}
],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 51,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"apps/docs/tsconfig.json",
"apps/www/tsconfig.json",
"create-atlas/templates/docker/tsconfig.json",
"create-atlas/templates/nextjs-standalone/tsconfig.json",
"ee/tsconfig.json",
"examples/embedded-mcp-onboarding/tsconfig.json",
"examples/nextjs-standalone/tsconfig.json",
"packages/api/tsconfig.json",
"packages/cli/tsconfig.json",
"packages/mcp/tsconfig.json",
"packages/oauth-helper/tsconfig.json",
"packages/plugin-sdk/tsconfig.json",
"packages/react/tsconfig.json",
"packages/schemas/tsconfig.json",
"packages/sdk/tsconfig.json",
"packages/types/tsconfig.json",
"packages/web/tsconfig.json",
"packages/webhook-publisher/tsconfig.json",
"plugins/bigquery/tsconfig.json",
"plugins/chat/tsconfig.json",
"plugins/clickhouse/tsconfig.json",
"plugins/duckdb/tsconfig.json",
"plugins/elasticsearch/tsconfig.json",
"plugins/email-digest/tsconfig.json",
"plugins/email/tsconfig.json",
"plugins/jira/tsconfig.json",
"plugins/mcp/tsconfig.json",
"plugins/mysql/tsconfig.json",
"plugins/obsidian-reader/tsconfig.json",
"plugins/obsidian/tsconfig.json",
"plugins/salesforce/tsconfig.json",
"plugins/snowflake/tsconfig.json",
"plugins/teams/tsconfig.json",
"plugins/twenty/tsconfig.json",
"plugins/webhook-action/tsconfig.json",
"plugins/webhook/tsconfig.json",
"plugins/yaml-context/tsconfig.json",
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "apps/docs/tsconfig.json, apps/www/tsconfig.json, create-atlas/templates/docker/tsconfig.json, create-atlas/templates/nextjs-standalone/tsconfig.json, ee/tsconfig.json, examples/embedded-mcp-onboarding/tsconfig.json, examples/nextjs-standalone/tsconfig.json, packages/api/tsconfig.json, packages/cli/tsconfig.json, packages/mcp/tsconfig.json, packages/oauth-helper/tsconfig.json, packages/plugin-sdk/tsconfig.json, packages/react/tsconfig.json, packages/schemas/tsconfig.json, packages/sdk/tsconfig.json, packages/types/tsconfig.json, packages/web/tsconfig.json, packages/webhook-publisher/tsconfig.json, plugins/bigquery/tsconfig.json, plugins/chat/tsconfig.json, plugins/clickhouse/tsconfig.json, plugins/duckdb/tsconfig.json, plugins/elasticsearch/tsconfig.json, plugins/email-digest/tsconfig.json, plugins/email/tsconfig.json, plugins/jira/tsconfig.json, plugins/mcp/tsconfig.json, plugins/mysql/tsconfig.json, plugins/obsidian-reader/tsconfig.json, plugins/obsidian/tsconfig.json, plugins/salesforce/tsconfig.json, plugins/snowflake/tsconfig.json, plugins/teams/tsconfig.json, plugins/twenty/tsconfig.json, plugins/webhook-action/tsconfig.json, plugins/webhook/tsconfig.json, plugins/yaml-context/tsconfig.json, tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "apps/docs/tsconfig.json, apps/www/tsconfig.json, create-atlas/templates/docker/tsconfig.json, create-atlas/templates/nextjs-standalone/tsconfig.json, ee/tsconfig.json, examples/embedded-mcp-onboarding/tsconfig.json, examples/nextjs-standalone/tsconfig.json, packages/api/tsconfig.json, packages/cli/tsconfig.json, packages/mcp/tsconfig.json, packages/oauth-helper/tsconfig.json, packages/plugin-sdk/tsconfig.json, packages/react/tsconfig.json, packages/schemas/tsconfig.json, packages/sdk/tsconfig.json, packages/types/tsconfig.json, packages/web/tsconfig.json, packages/webhook-publisher/tsconfig.json, plugins/bigquery/tsconfig.json, plugins/chat/tsconfig.json, plugins/clickhouse/tsconfig.json, plugins/duckdb/tsconfig.json, plugins/elasticsearch/tsconfig.json, plugins/email-digest/tsconfig.json, plugins/email/tsconfig.json, plugins/jira/tsconfig.json, plugins/mcp/tsconfig.json, plugins/mysql/tsconfig.json, plugins/obsidian-reader/tsconfig.json, plugins/obsidian/tsconfig.json, plugins/salesforce/tsconfig.json, plugins/snowflake/tsconfig.json, plugins/teams/tsconfig.json, plugins/twenty/tsconfig.json, plugins/webhook-action/tsconfig.json, plugins/webhook/tsconfig.json, plugins/yaml-context/tsconfig.json, tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 8",
"points": 8,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 438644,
"source_files_sampled": 3784,
"oversized_source_files": 74
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "74/3784 source files over 60KB",
"points": 53.9,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 3784,
"oversized": 74
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": [
"apps/docs/openapi.json"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "apps/docs/openapi.json",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "apps/docs/openapi.json"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-25T21:03:36.517084Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/AtlasDevHQ/atlas.svg",
"full_name": "AtlasDevHQ/atlas",
"license_state": "standard",
"license_spdx": "AGPL-3.0"
}