Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 12:18 UTC

EffortlessMetrics / cargo-allow

Repo Allowlist for Rust

RustApache-2.0★ 0 stars⑂ 2 forkssince May 2026View on GitHub ↗

EffortlessMetrics/cargo-allow holds a health index of 62 out of 100, placing it in the Moderate band. It scores highest on AI Readiness (80/100) and lowest on Community & Adoption (50/100). It was last updated today. A single contributor accounts for most of its recent work.

62
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

62
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

EffortlessMetricsOrganization
7 followers75 public repossince Mar 2024

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

76Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
6.2/36Commit cadence — 9/52 weeks with commits
18/18Commit volume — 2,295 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year2,295
human_commit_share0.87
days_since_last_push0
active_weeks_last_year9

Release discipline

100Excellent
How it's scored
27/27Ships releases — 5 releases published
36/36Release recency — latest release 7 days ago
27/27Release cadence — a release every ~8.8 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count5
latest_release_tagv0.1.11
releases_from_tagsno
days_since_latest_release7
mean_days_between_releases8.8
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

50Moderate · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 2 forks
0/15Watchers — 0 watchers
Inputs used
forks2
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
54.1/80Monthly downloads — 11,465 downloads/month across crates
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesallow-core, allow-diff, allow-rust, allow-files, allow-match, cargo-allow
dependents
ecosystemscrates
total_downloads34,397
monthly_downloads11,465
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

53Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
19.2/46.8Issue resolution — 41% of issues closed
37.5/38.3PR acceptance — 2,077/2,116 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/12 approved changesets -- score normalized to 0
Inputs used
merged_prs2,077
open_issues405
closed_issues281
issue_closed_ratio0.41
closed_unmerged_prs39
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
6.5/25Owner reach — 7 followers of EffortlessMetrics
17.7/25Track record — 75 public repos, account ~2 yr old
Inputs used
followers7
owner_typeOrganization
is_verified
owner_loginEffortlessMetrics
public_repos75
account_age_days852
How it's scored
25/25Published & resolvable — 6 package(s) on crates
35/35Publish recency — latest publish 7 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesallow-core, allow-diff, allow-rust, allow-files, allow-match, cargo-allow
ecosystemscrates
any_deprecatedno
min_days_since_publish7

Engineering Quality

Are baseline engineering and documentation practices in place?

74Good · 20% of overall
How it's scored
24/24CI workflows — 3 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configno
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

56Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/12 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.6
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

80Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 87 of 87 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes5,031
How it's scored
18/18One-command bootstrap — justfile
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Rust (statically typed)
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 48 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 13 of the last 100 commits are automated dependency updates
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Inputs used
has_nixno
has_testsyes
lockfilesCargo.lock
has_dockerfileno
typed_languageyes
bootstrap_filesjustfile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.48
toolchain_manifestsCargo.toml, crates/allow-core/Cargo.toml, crates/allow-diff/Cargo.toml, crates/allow-files/Cargo.toml, crates/allow-inventory/Cargo.toml, crates/allow-match/Cargo.toml, crates/allow-policy-legacy/Cargo.toml, crates/allow-policy/Cargo.toml, crates/allow-report/Cargo.toml, crates/allow-rust/Cargo.toml, crates/cargo-allow/Cargo.toml, crates/cargo-intent/Cargo.toml, crates/cargo-proof/Cargo.toml, crates/intent-edit/Cargo.toml, crates/intent-engine/Cargo.toml, crates/intent-model/Cargo.toml, crates/intent-protocol/Cargo.toml, crates/proof-adapter-cargo-allow/Cargo.toml, crates/proof-adapter-command/Cargo.toml, crates/proof-adapter-hawk/Cargo.toml, crates/proof-adapter-ripr/Cargo.toml, crates/proof-engine/Cargo.toml, crates/proof-protocol/Cargo.toml, crates/proof-provider-api/Cargo.toml, crates/repo-edit/Cargo.toml, crates/repo-protocol/Cargo.toml, crates/repo-snapshot/Cargo.toml, crates/rust-source-index/Cargo.toml
dependency_bot_commit_share0.13
How it's scored
45/45Type-checkable code — Rust (statically typed)
54.8/55Manageable file sizes — 4/1,010 source files over 60KB
Inputs used
primary_languageRust
largest_source_bytes229,120
source_files_sampled1,010
oversized_source_files4
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

0GitHub stars
1contributors
2,295commits, last 12 months
0days since last push
5releases
1bus factor
405open issues
crates.iopackage ecosystems

Data collection warnings

  • Could not fetch crates package 'cargo-proof' from its registry
  • Could not fetch crates package 'intent-edit' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 5.6 / 10
5.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 12:18 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/12 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 89
RegistryPackageVersion constraintManifest
crates.iosha2crates/allow-core/Cargo.toml
crates.ioallow-corecrates/allow-diff/Cargo.toml
crates.ioallow-filescrates/allow-diff/Cargo.toml
crates.ioallow-policy-legacycrates/allow-diff/Cargo.toml
crates.ioallow-policycrates/allow-diff/Cargo.toml
crates.ioallow-rustcrates/allow-diff/Cargo.toml
crates.iosha2crates/allow-diff/Cargo.toml
crates.ioallow-corecrates/allow-files/Cargo.toml
crates.ioallow-corecrates/allow-inventory/Cargo.toml
crates.ioallow-corecrates/allow-match/Cargo.toml
crates.ioallow-corecrates/allow-policy-legacy/Cargo.toml
crates.ioallow-policycrates/allow-policy-legacy/Cargo.toml
crates.iotomlcrates/allow-policy-legacy/Cargo.toml
crates.ioallow-corecrates/allow-policy/Cargo.toml
crates.ioserdecrates/allow-policy/Cargo.toml
crates.iotomlcrates/allow-policy/Cargo.toml
crates.ioallow-corecrates/allow-report/Cargo.toml
crates.ioallow-policy-legacycrates/allow-report/Cargo.toml
crates.ioserdecrates/allow-report/Cargo.toml
crates.ioserde_jsoncrates/allow-report/Cargo.toml
crates.ioallow-corecrates/allow-rust/Cargo.toml
crates.iotomlcrates/allow-rust/Cargo.toml
crates.iotree-sittercrates/allow-rust/Cargo.toml
crates.iotree-sitter-rustcrates/allow-rust/Cargo.toml
crates.ioallow-corecrates/cargo-allow/Cargo.toml
crates.ioallow-policycrates/cargo-allow/Cargo.toml
crates.ioallow-inventorycrates/cargo-allow/Cargo.toml
crates.ioallow-filescrates/cargo-allow/Cargo.toml
crates.ioallow-rustcrates/cargo-allow/Cargo.toml
crates.ioallow-matchcrates/cargo-allow/Cargo.toml
crates.ioallow-reportcrates/cargo-allow/Cargo.toml
crates.ioallow-diffcrates/cargo-allow/Cargo.toml
crates.ioallow-policy-legacycrates/cargo-allow/Cargo.toml
crates.iorepo-protocolcrates/cargo-allow/Cargo.toml
crates.iorepo-editcrates/cargo-allow/Cargo.toml
crates.ioclapcrates/cargo-allow/Cargo.toml
crates.iotomlcrates/cargo-allow/Cargo.toml
crates.ioserdecrates/cargo-allow/Cargo.toml
crates.ioserde_jsoncrates/cargo-allow/Cargo.toml
crates.ioclapcrates/cargo-intent/Cargo.toml
crates.iointent-enginecrates/cargo-intent/Cargo.toml
crates.iointent-protocolcrates/cargo-intent/Cargo.toml
crates.iorepo-protocolcrates/cargo-intent/Cargo.toml
crates.iorepo-snapshotcrates/cargo-intent/Cargo.toml
crates.ioserdecrates/cargo-intent/Cargo.toml
crates.ioserde_jsoncrates/cargo-intent/Cargo.toml
crates.iotomlcrates/cargo-intent/Cargo.toml
crates.ioclapcrates/cargo-proof/Cargo.toml
crates.ioproof-enginecrates/cargo-proof/Cargo.toml
crates.ioproof-protocolcrates/cargo-proof/Cargo.toml
crates.ioproof-provider-apicrates/cargo-proof/Cargo.toml
crates.ioserdecrates/cargo-proof/Cargo.toml
crates.ioserde_jsoncrates/cargo-proof/Cargo.toml
crates.iotomlcrates/cargo-proof/Cargo.toml
crates.iorepo-editcrates/intent-edit/Cargo.toml
crates.iorepo-protocolcrates/intent-edit/Cargo.toml
crates.ioserdecrates/intent-edit/Cargo.toml
crates.iotomlcrates/intent-edit/Cargo.toml
crates.ioserdecrates/intent-engine/Cargo.toml
crates.ioserde_jsoncrates/intent-engine/Cargo.toml
crates.iotomlcrates/intent-engine/Cargo.toml
crates.ioallow-corecrates/intent-model/Cargo.toml
crates.ioserdecrates/intent-model/Cargo.toml
crates.iotomlcrates/intent-model/Cargo.toml
crates.ioserdecrates/intent-protocol/Cargo.toml
crates.ioserde_jsoncrates/intent-protocol/Cargo.toml
crates.iotomlcrates/intent-protocol/Cargo.toml
crates.ioproof-adapter-commandcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-cargo-allow/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioserdecrates/proof-adapter-cargo-allow/Cargo.toml
crates.iosha2crates/proof-adapter-cargo-allow/Cargo.toml
crates.iotomlcrates/proof-adapter-cargo-allow/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-command/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-command/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-command/Cargo.toml
crates.ioserdecrates/proof-adapter-command/Cargo.toml
crates.iotomlcrates/proof-adapter-command/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-hawk/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-hawk/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-hawk/Cargo.toml
crates.ioserdecrates/proof-adapter-hawk/Cargo.toml
crates.iotomlcrates/proof-adapter-hawk/Cargo.toml
crates.ioproof-protocolcrates/proof-adapter-ripr/Cargo.toml
crates.ioproof-provider-apicrates/proof-adapter-ripr/Cargo.toml
crates.iorepo-protocolcrates/proof-adapter-ripr/Cargo.toml
crates.ioserdecrates/proof-adapter-ripr/Cargo.toml
crates.iotomlcrates/proof-adapter-ripr/Cargo.toml
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 7498,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Just": 1122,
        "Rust": 6577477,
        "Shell": 189890,
        "Python": 12830
      },
      "pushed_at": "2026-07-25T11:55:46Z",
      "created_at": "2026-05-26T00:18:24Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-25T11:39:35Z",
      "description": "Repo Allowlist for Rust",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "effortlesssteven.com",
      "name": "EffortlessMetrics",
      "type": "Organization",
      "login": "EffortlessMetrics",
      "company": null,
      "location": "Canada",
      "followers": 7,
      "avatar_url": "https://avatars.githubusercontent.com/u/164865351?v=4",
      "created_at": "2024-03-25T09:34:01Z",
      "is_verified": null,
      "public_repos": 75,
      "account_age_days": 852
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.11",
          "kind": "patch",
          "published_at": "2026-07-18T00:52:46Z"
        },
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-07-09T00:19:59Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-06-16T04:04:39Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-06-12T21:40:24Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-06-12T20:35:17Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3366897b078191bee344d03af2d27bf635e322fd",
          "body": "…#2804)\n\n* fix(scanner): surface tree-sitter parse errors in scan completeness\n\nTrack files_with_parse_errors in RustScanResult and fail closed in check --mode no-new when partial parses are present, matching the files_skipped precedent (#2658).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* st\n[…]\n only; stderr warnings break the quiet artifact-output contract in audit integration tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(scanner): surface tree-sitter parse errors in scan completeness (…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T11:39:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "886e268f6f5e140cd816f4ffd8c1f79ebb17591e",
          "body": "* deps: bump fs4 from 0.13.1 to 1.1.0\n\nBumps [fs4](https://github.com/al8n/fs4) from 0.13.1 to 1.1.0.\n- [Release notes](https://github.com/al8n/fs4/releases)\n- [Changelog](https://github.com/al8n/fs4/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/al8n/fs4/commits/1.1.0)\n\n---\nupdated-dependen\n[…]\nbot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Steven Zimmerman, CPA <15812269+EffortlessSteven@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump fs4 from 0.13.1 to 1.1.0 (#2769)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T11:36:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d820b2414f4fb37548cd9b2c61403e3e80ac99d",
          "body": "* feat(migrate): add bespoke-ledger importer adapter (xtask/ripr)\n\nIntroduce a read-only xtask-ripr bespoke ledger dialect importer and wire\nmigrate --from to detect dialect=xtask-ripr before legacy dispatch.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* style: apply rustfmt for bespoke importer lane\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(migrate): bespoke-ledger importer adapter (xtask/ripr) (#2803)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T10:51:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2ac2b669d5a2e4efd7d38bdcab2ffc8da9494eb6",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v5...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/checkout from 5 to 7 (#2767)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:37:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "780d6a0bdbe6b1b64a6c8ea508640f69fe71a9d4",
          "body": "Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 96b4a1ef7235a096b17240c259729fdd70c83d45 to e8998f949152b193b063cb0ec769d69d929409be.\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://github.com/actio\n[…]\n63cb0ec769d69d929409be\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/attest-build-provenance (#2766)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:34:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fea3c82cac4015c1713db7d785194b36f73f2726",
          "body": "Bumps [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) from 42dc69e1aa15d09112580998cf2ef0119e2e91ae to e18b497796c12c097a38f9edb9d0641fb99eee32.\n- [Release notes](https://github.com/swatinem/rust-cache/releases)\n- [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG\n[…]\n38f9edb9d0641fb99eee32\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump Swatinem/rust-cache (#2765)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:30:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7032bd0f0b690ce956077a6273ce04ca62da6ca2",
          "body": "Bumps [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) from c3bbe7e4e3f7baeee1a3dd9aec0a3b2aded580fb to 3c6349835b2b7b196a839186cb8b78e02f7b5f25.\n- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)\n- [Commits](https://github.com/embarks\n[…]\n839186cb8b78e02f7b5f25\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump EmbarkStudios/cargo-deny-action (#2764)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:25:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fdb165f56a8ba40ff27de95c741f3b6ea791183d",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 4650159d642e33fdc30954ca22638caf0df6cac8 to 18283e04ce6e62d37312384ff67231eb8fd56d24.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main\n[…]\n12384ff67231eb8fd56d24\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump codecov/codecov-action (#2763)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:20:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c885ff732e2749027cd2b9dd8543b35307786892",
          "body": "Bumps [EffortlessMetrics/ub-review](https://github.com/effortlessmetrics/ub-review) from f0620c358f4a9032d3f832fda92488fd198ab6e9 to a1e64c65e39aadf341f4e5cb14094b9a87f592ad.\n- [Release notes](https://github.com/effortlessmetrics/ub-review/releases)\n- [Changelog](https://github.com/EffortlessMetrics\n[…]\nf4e5cb14094b9a87f592ad\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump EffortlessMetrics/ub-review (#2762)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:12:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2106a2232cc7f7be062003784eb438d9c7b86a2",
          "body": "Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.25.10 to 0.26.11.\n- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)\n- [Commits](https://github.com/tree-sitter/tree-sitter/compare/v0.25.10...v0.26.11)\n\n---\nupdated-dependencies:\n- dependency-name: tree-sitte\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump tree-sitter from 0.25.10 to 0.26.11 (#2770)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T09:08:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c18f384b48da5f22af8f8f86c77dc7def0d9620d",
          "body": "…-test\n\ntest: add tool command integration test (#2795)",
          "is_bot": false,
          "headline": "Merge pull request #2798 from EffortlessMetrics/test/tool-integration…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T08:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0d582eeacb52991c49044b7a5242bbc8399d687",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T08:41:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b6f60b9c12f9531f3ebd6d5194a91b0b8304681",
          "body": null,
          "is_bot": false,
          "headline": "test: restore Command import in tool_output",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T08:29:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8890d7f0a5a0b07b2dc93f318ef98c47a2ea521",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T08:23:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07888aded693d59d4e46c2b01cc7d1e61e8f039e",
          "body": "Bumps the patch-updates group with 4 updates in the / directory: [serde](https://github.com/serde-rs/serde), [serde_json](https://github.com/serde-rs/json), [toml](https://github.com/toml-rs/toml) and [clap](https://github.com/clap-rs/clap).\n\n\nUpdates `serde` from 1.0.228 to 1.0.229\n- [Release notes\n[…]\nncy-version: 1.1.3+spec-1.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: patch-updates\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump the patch-updates group across 1 directory with 4 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T08:23:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1832bc3992190340d338971765ec61bdb9c94ae",
          "body": "Avoid compiling the shared support module in the tool_output integration test crate, which triggered clippy dead-code failures under -D warnings.",
          "is_bot": false,
          "headline": "test: inline cargo_allow_command helper in tool_output",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T08:14:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2279331382d7e67839fd33a64cfb50a73660d00",
          "body": "The `tool` subcommand had zero binary-level integration coverage despite\nhaving 10 unit tests. Its identity, digest, and capability-generation\noutput is security-relevant (used by pre-commit verification).\n\nAdd crates/cargo-allow/tests/tool_output.rs with two integration tests:\n- tool_identity_json_\n[…]\ns\n  cargo-allow and the schema_id\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2659 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "test: add tool command integration test (#2795)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T07:57:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63829a7e77a666d7cc5723146c53c695bdb96799",
          "body": "…-0.11.0\n\ndeps: bump sha2 from 0.10.9 to 0.11.0",
          "is_bot": false,
          "headline": "Merge pull request #2771 from EffortlessMetrics/dependabot/cargo/sha2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T07:48:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f003984049f4e2e876de045edae1f4c35f5d2e4",
          "body": "…h-updates-2b5d80e5f5\n\ndeps: bump the patch-updates group across 1 directory with 4 updates",
          "is_bot": false,
          "headline": "Merge pull request #2768 from EffortlessMetrics/dependabot/cargo/patc…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T07:30:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80ead5a1beb02a6f7671233e924018eea49441d7",
          "body": "… output (#2785) (#2793)\n\ncargo-allow prints a 600+ char claim boundary on every human-format run\nwith no way to suppress it short of --format json. CI logs are polluted.\n\nAdd a global --quiet/-q flag that:\n- Suppresses CLAIM_BOUNDARY_TEXT in check/audit human output\n- Suppresses CLAIM_BOUNDARY_TEXT\n[…]\n through every command signature.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2657 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "feat(ux): add --quiet/-q flag to suppress claim boundary and advisory…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T05:28:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad86d12c72a36bd03c1b474aca56aebeb79c65d2",
          "body": "Bumps the patch-updates group with 4 updates in the / directory: [serde](https://github.com/serde-rs/serde), [serde_json](https://github.com/serde-rs/json), [toml](https://github.com/toml-rs/toml) and [clap](https://github.com/clap-rs/clap).\n\n\nUpdates `serde` from 1.0.228 to 1.0.229\n- [Release notes\n[…]\nncy-version: 1.1.3+spec-1.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: patch-updates\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump the patch-updates group across 1 directory with 4 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T05:24:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "104c0e850300230239dd4345ebeff1a756994d1d",
          "body": "…(#2792)\n\ncargo-allow shipped with Cargo default release profile (no LTO, no strip,\nopt-level=3, full debug paths). For a CPU-bound CLI tool this left\nmeasurable binary size and runtime performance on the floor.\n\nAdd:\n- lto = 'thin' — cross-crate inlining without fat-LTO build cost\n- strip = true — \n[…]\nry\n- codegen-units = 1 — better optimization at cost of slower compile\n\nThese settings apply to all workspace binaries (cargo-allow, cargo-intent,\ncargo-proof).\n\nBuild-only change; no production code.",
          "is_bot": false,
          "headline": "perf: add [profile.release] with LTO, strip, codegen-units=1 (#2789) …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T05:21:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ab820bed5c4cd55324f709a847ae88f3f59cc17",
          "body": "…rectly (#2777, #2778) (#2783)\n\nTwo init.rs bugs:\n\n#2777: The non-force path used exists() + AtomicReplace, leaving a TOCTOU\nwindow between the existence check and the unconditional rename. An external\nprocess that creates the file in the window would be silently overwritten\nwithout --force. Fixed b\n[…]\nnd using the correct action word.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2656 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(init): use CreateNewOnly for non-force path; report overwrite cor…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T04:31:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5280a9a7bf8bf11860de65ea78071f249841a11d",
          "body": "…ctions (#2776) (#2782)\n\nThe wildcard branch of source_tree_path_matches_filter checked\nsource_tree_scope_has_wildcard(&item_path) — the file being filtered.\nReal file paths never contain wildcards, so the branch was dead code.\nA glob pattern in the filter_path (e.g. --path 'src/**/*.rs') never\nmatc\n[…]\no fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (616 pass + 1 pre-existing flaky Windows\ntemp-dir doctor test); cargo-allow check --mode no-new (status: passed).",
          "is_bot": false,
          "headline": "fix(core): source_tree_path_matches_filter supports glob in both dire…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T04:24:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c54ab10ac31463199ca0476d818666458e327524",
          "body": "* docs: add SECURITY.md for vulnerability reporting (#1884)\n\ncargo-allow is a supply-chain governance tool with no SECURITY.md —\nexternal users and security researchers had no private reporting path.\n\nAdd SECURITY.md with:\n- Private reporting via email and GitHub Security Advisories\n- Response timel\n[…]\nitives, upstream dependency CVEs)\n- Hardening measures inventory (cargo-deny, Dependabot, SHA-pinned\n  actions, OIDC Trusted Publishing, keyless attestation, Windows CI)\n\n* policy: receipt SECURITY.md",
          "is_bot": false,
          "headline": "docs: add SECURITY.md for vulnerability reporting (#1884) (#2775)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T03:17:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1634f535d3a2c82adf3c713a2ca2a9de7ce199fd",
          "body": "…1949) (#2774)\n\nThe issue reported that evidence references to directory targets were\ntreated as valid. Investigation found the bug was already fixed: the\nevidence_reference_diagnostic function catches directories at the\nmetadata level (Ok(_) => InvalidLocalPath 'exists but is not a file')\nbefore th\n[…]\nactor\ncannot silently regress it.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2656 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "test(evidence): pin directory-target rejection as InvalidLocalPath (#…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T02:57:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92c5c71f4098d3b2ce2bfe428dd1c73c65f24f83",
          "body": "…773)\n\nThe legacy unsafe-allowlist parser captured scope, justification, and\naudit_url fields but the converter silently dropped them because the\nLegacyUnsafeRule type had no fields for them and the converter had no\npreservation path. Compliance reviews lost provenance on migration.\n\nAdd scope, just\n[…]\non: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (615 pass + 1 pre-existing flaky init\ntest on Windows); cargo-allow check --mode no-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): preserve unsafe provenance fields via links (#1865) (#2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T00:17:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53cb843b6ddf7629824ccc503d38ac52e41f2bcd",
          "body": "…1870) (#2772)\n\nnormalize_legacy_expires only mapped 'permanent' → 'never'. Legacy\nledgers using RFC3339 timestamps with timezones (2025-12-01T00:00:00Z vs\n2025-12-01T00:00:00-05:00) produced non-deterministic, non-comparable\nLifecycle values — breaking reproducible-migration guarantees.\n\nAdd canoni\n[…]\n plus the plain-date passthrough.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2654 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): canonicalize legacy expires timestamps to YYYY-MM-DD (#…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-25T00:10:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cff1f439aafb0fb817c381526396181c68169e2",
          "body": "Remove RTK from the live agent contract and reusable PR and plan templates. Keep historical evidence and runtime compatibility behavior unchanged.",
          "is_bot": false,
          "headline": "chore: remove RTK command wrapper guidance (#2761)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T23:27:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9bc1d519eb6ae5be164b6139fe19e6cfdce2cd3",
          "body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n  dependency-version: 0.11.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T23:00:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2dc7c28d60351cec88e2a02097753ad2f091a8ff",
          "body": "* ci: add Dependabot for Rust deps and GitHub Actions (#1898)\n\ncargo-allow had no automated dependency update path. Combined with the\ncargo-deny supply-chain audit (#1897), Dependabot ensures advisories are\nboth caught (deny) and patched (Dependabot PRs).\n\nConfiguration:\n- cargo ecosystem: weekly, M\n[…]\nen PRs max, patch updates grouped\n- github-actions ecosystem: weekly, Monday, 5 open PRs max\n\nCI-only; no production code changes.\n\n* policy: receipt .github/dependabot.yml\n\n* chore: trigger CI re-run",
          "is_bot": false,
          "headline": "ci: add Dependabot for Rust deps and GitHub Actions (#1898) (#2758)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T22:58:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66ebd703a631a84292815e8da934c895d710a409",
          "body": "cargo-allow had no test coverage reporting and no automated way to track\ncoverage regressions. As a governance tool, coverage visibility matters.\n\nAdd a coverage job to ci.yml that runs cargo-tarpaulin on the full\nworkspace and uploads the Cobertura XML to Codecov. The job is separate\nfrom the main test job so tarpaulin's instrumentation overhead doesn't\nslow down PR feedback. fail_ci_if_error: false so coverage upload\nfailures don't block merges.\n\nCI-only; no production code changes.",
          "is_bot": false,
          "headline": "ci: add cargo-tarpaulin coverage reporting to Codecov (#1902) (#2760)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T22:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70abd9d51f34222152ae7af26426f18ae74e75d5",
          "body": "The release install-smoke job ran on ubuntu-latest only, so the published\nbinary was never tested on Windows — the repo's primary dev OS. A Windows\nbinary could ship broken without any CI signal.\n\nMatrix the install-smoke job across ubuntu-latest and windows-latest with\nfail-fast: false. Added expli\n[…]\nds the OS.\n\nThe smoke script (scripts/release-install-smoke.sh) already uses bash and\ncargo install, which work on Windows via Git Bash. No script changes needed.\n\nCI-only; no production code changes.",
          "is_bot": false,
          "headline": "ci: matrix release install-smoke across ubuntu+windows (#1904) (#2759)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T22:26:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfb47b5f1247680dfec0ee9e8ee5b47b1859d6f6",
          "body": "Enable repo-wide delegate_spec_system cutover, replace CI embedded audit with cutover receipt, and document honest fail-closed posture until cargo-intent audit vertical ships.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2568): retire embedded spec-system CI audit path (#2757)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T20:50:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dac02808a09a61e80b76aa8a15db7f286d4a0445",
          "body": "Wave 6 closeout: validate packaging, boundaries, support postures, forbidden production deps, dogfood/simplification prerequisites, and rollback documentation without authorizing physical repository extraction.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2559): add extraction readiness checklist receipt (#2756)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T20:32:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b287fabba89946dbda97319d2d2e6392e7589776",
          "body": "* feat(#2208): add simplification inventory and remove io shim\n\nClassify extraction abstractions with mandatory labels, fold cargo-allow io helpers into command_support, and add audit script plus closeout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2208): update move ledger after io sh\n[…]\n: Cursor <cursoragent@cursor.com>\n\n* fix(#2208): move re-exports before io_tests for clippy\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2208): add simplification inventory and remove io shim (#2755)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T20:22:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65df48a2c6080eb34ea4a1b8090e959597ade616",
          "body": "* feat(#2558): add three-product dogfood pipeline smoke\n\nRun one real source change through cargo-intent, bridged proof planning, stubbed RIPR/Hawk evidence, gates, and reconciliation with honest claim boundary; wire CI and closeout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2558): re\n[…]\nCursor <cursoragent@cursor.com>\n\n* fix(#2558): align stub fixture needles with parity files\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2558): add three-product dogfood pipeline smoke (#2754)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T19:55:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "505502bdd0b1c13bfc40bb107a6d3dcd6749079f",
          "body": "* feat(#2605): add exact-candidate interop smoke A-E\n\nRun packaged three-product interop journeys outside the monorepo with installed candidate binaries, negative scenario controls, CI wiring, and offline receipt characterization.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2605): corre\n[…]\ncursoragent@cursor.com>\n\n* fix(#2605): accept findings exit from cargo-intent change status\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2605): add exact-candidate interop smoke A-E (#2753)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T18:59:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c49efeaed59d6812eec55d11e59191be475c3ee",
          "body": "Introduce proof.hawk.v1 provider with analysis receipt validation, finding mapping, source-anchor resolution, and receipt currentness so Hawk liveness stays provider-owned while cargo-proof consumes snapshots.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2555): add proof-adapter-hawk analysis adapter (#2752)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T17:59:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3fd7fb3b2b9ecdf619ad7bed3726adf7092ebc91",
          "body": "Land RiprGripReceiptV1 validation, receipt currentness, requirement-grip comparison, and ProofProviderV1 wiring without RIPR or intent crate imports. Authored evidence purpose remains cargo-intent owned.",
          "is_bot": false,
          "headline": "feat(#2556): add proof-adapter-ripr grip adapter (#2751)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T17:42:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d28ac4b28515d4f60a9aaafd5ebbb6a3e0e37cd1",
          "body": "* feat(#2567/#2554): add proof-adapter-cargo-allow provider\n\nLand snapshot-bound read-only cargo-allow provider contract, public process discovery, dry-run argv compilation via proof-adapter-command, and ProofProviderV1 wiring without cargo-allow private imports.\n\n* fix(#2567): satisfy source-tree c\n[…]\nllow from package smoke\n\nUnpublished adapter depends on proof-adapter-command; keep it out of workspace package verification until #2604 publish posture.\n\n* fix(#2567): satisfy clippy on adapter crate",
          "is_bot": false,
          "headline": "feat(#2567/#2554): add proof-adapter-cargo-allow provider (#2750)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T17:21:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d5537123d98fc7908c12d05ebf9752a7686c51d",
          "body": "* feat(#2589-B): add thin cargo-proof CLI\n\nIntroduce cargo-proof product shell with identity, render, exit mapping, plan and dry-run commands wired to proof-engine, plus six-crate proof-candidate install smoke.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2589-B): allow-dirty package in proof-candidate-smoke\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2589-B): add thin cargo-proof CLI (#2749)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T16:02:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bf7ec4e014662e04b4b234ca1bd1236dc74517d5",
          "body": "* feat(#2589-A): scaffold proof-engine crate\n\nIntroduce provider registry, captured receipts, obligation planning, currentness, dry-run, explicit execution gates, cache, contradiction detection, and phase-gate evaluation.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2589-A): align proof-\n[…]\ning\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* chore: cargo fmt proof-engine tests\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2589-A): scaffold proof-engine crate (#2748)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T15:34:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d446a9ca82f23f20c3f8f31b8fa2948d5df16e9",
          "body": "Introduce reviewed command registry, structured argv compilation, dry-run reports, and receipt interpretation with prose-to-shell rejection.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2603-B): scaffold proof-adapter-command crate (#2747)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T15:07:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f95ce9a06e7d600ad5f6c1e8bb64582cbbb080f0",
          "body": "* feat(#2603-A): scaffold proof-provider-api crate\n\nAdd provider API trait, fake provider, conformance harness, and parity/ledger registration.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2603-A): satisfy package smoke and crate doc boundary\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2603-A): allow proof-provider-api manifest and fixture README\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2603-A): scaffold proof-provider-api crate (#2746)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T14:43:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "edcf65627ee8d2c625e02b81e485031b781343ab",
          "body": "* feat(#2588-B): add proof-protocol plan and receipt DTOs\n\nLand provider-neutral plan, capability, receipt, contradiction, and phase-gate transport with parity fixtures, ledger entries, and shims.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* chore(#2588-B): refresh lockfile for proof-protocol deps\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2588-B): add proof-protocol plan and receipt DTOs (#2745)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T14:20:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "549149ae17df7ff2989cf0d6d599fdc40585df36",
          "body": "Combine translation and recompile contract into a settlement plan with await-apply, await-recompile-proof, and await-currentness-refresh residual obligations.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-F): add intent-edit settlement plan (#2744)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T14:02:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4fe64f6733dc3574ae02255255fd81e2dd5c8cd0",
          "body": "* feat(#2613-E): compile recompile contract via intent-engine\n\nBind intent-edit translation output to intent-engine phase-obligation transport with parity fixture, ledger, and shim registration.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2613-E): use transport DTOs without intent-engin\n[…]\ncally and validate round-trip in dev tests. Fix parity path recursion and clippy dead-code.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-E): compile recompile contract via intent-engine (#2743)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:52:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9d0408c94d1793becf5d2e1d7c2fdce01eea473",
          "body": "…t-translation\n\nfeat(#2613-D): translate intent-edit plans to repo-edit",
          "is_bot": false,
          "headline": "Merge pull request #2742 from EffortlessMetrics/cursor/2613d-repo-edi…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:26:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "394efbcabd143366754e7c0e706974fe243cf45c",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2613-D): remove duplicate move-ledger key",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:14:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "76c888fb4507e028f6683b65c5716ba4b4c42070",
          "body": "Add repo-edit translation DTOs that map validated edit plans and approval envelopes into SingleTargetApplyMode requests without executing apply.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-D): translate intent-edit plans to repo-edit",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:02:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6fe67305273776ac77a84d056493e2a8b64d9913",
          "body": "…approval\n\nfeat(#2613-C): add dialect adapters and approval/currentness",
          "is_bot": false,
          "headline": "Merge pull request #2741 from EffortlessMetrics/cursor/2613c-dialect-…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T13:00:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1cf1e64f9c55857c0909b2fbaaf566a1dc4bd34",
          "body": "Land intent-edit dialect selector normalization and approval/currentness fail-closed envelopes with parity/ledger registration; repo-edit translation deferred to #2613-D.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-C): add dialect adapters and approval/currentness",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:48:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5d7217d1499f2f3d999067c917025dcc4883c30a",
          "body": "…otocol-scaffold\n\nfeat(#2588-A): scaffold proof-protocol crate and boundary",
          "is_bot": false,
          "headline": "Merge pull request #2740 from EffortlessMetrics/cursor/2588a-proof-pr…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:44:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63c597d4e52076c72be1c07ba48c89c2707c8f51",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2588-A): satisfy source-tree boundary rustdoc check",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:33:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43d8f30cdd3d8c5242c7a3cf528e46d2f1654113",
          "body": "Introduce proof-protocol with parity/ledger registration, ADR-0002 forbidden-edge tests, and policy surfaces without wiring cargo-allow to proof-protocol.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2588-A): scaffold proof-protocol crate and boundary",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:19:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9caa9d8d35933b434fe14709c29c4991c7783ad4",
          "body": "feat(#2613-B): add intent-edit plan and find-before-create",
          "is_bot": false,
          "headline": "Merge pull request #2739 from EffortlessMetrics/cursor/2613b-edit-plan",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:16:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d40197e20a92f2ea54836431e1a67c24142f0b6",
          "body": "Land edit-plan transport with stable action IDs, find-before-create validation, parity fixture, and ledger registration without repo-edit translation yet.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-B): add intent-edit plan and find-before-create",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:03:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5e356dd094bf18a1ff22cd56f1e804b8c6dd331e",
          "body": "…dit-scaffold\n\nfeat(#2613-A): scaffold intent-edit crate and boundary topology",
          "is_bot": false,
          "headline": "Merge pull request #2738 from EffortlessMetrics/cursor/2613a-intent-e…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T12:00:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be58541ad771687522bfe8009ed785a3181d2bfc",
          "body": "Add IntentEdit to extraction parity stages, fix allow classification for intent-edit docs, and keep scaffold deps on repo-edit only so workspace packaging stays green.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2613-A): register IntentEdit stage and package-safe deps",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:48:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "64f3659e4b930ae19960084ab15eb005148642f2",
          "body": "Introduce intent-edit with parity/ledger registration, ADR-0002 forbidden-edge tests, and policy surfaces without wiring cargo-allow to intent-edit.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2613-A): scaffold intent-edit crate and boundary topology",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:30:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12c80d559f6caa9be89eb14fefeabf1e9f9bc646",
          "body": "propose --write uses CreateNewOnly or ReplaceWithBackup with fail-closed repository containment.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-J): migrate propose through repo-edit apply (#2737)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:24:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "579f0e0a540369cdded6cd00c873b5443f649258",
          "body": "* feat(#2602-I): migrate migrate through repo-edit apply\n\nmigrate --update and --out forward policy writes through SingleTargetApplyMode with repository-contained --out targets.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-I): hybrid apply for in-repo migrate --out\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-I): migrate migrate through repo-edit apply (#2736)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T11:04:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "13beac9eb3e4b34c0998bfd36cc0c42fa4999aba",
          "body": "* feat(#2602-H): migrate add through repo-edit apply\n\nadd --update/--write and add --from-plan forward policy writes through SingleTargetApplyMode with backup semantics preserved.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-H): canonicalize portable mutation targets on Windows\n\nCo-\n[…]\nsor <cursoragent@cursor.com>\n\n* fix(#2602-H): best-effort canonical paths for apply targets\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-H): migrate add through repo-edit apply (#2735)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T10:47:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d5b4701b4b42718108b4c12e8995f34c183c76e8",
          "body": "Replace force_create_new with AtomicReplace, CreateNewOnly, and ReplaceWithBackup modes preserving --force .toml.bak behavior.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-G): add SingleTargetApplyMode backup semantics (#2734)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T10:16:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "821c243e2de10933fa4e05b781ff8cde0d572fa1",
          "body": "Prune --write rewrites policy via apply_single_target with containment and mutation-lock unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-F): migrate prune through repo-edit apply (#2733)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:57:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cbc8c7d10c910b996202c77ff087c1e729f50f84",
          "body": "Refresh --write rewrites policy via apply_single_target with containment and mutation-lock unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-E): migrate refresh through repo-edit apply (#2732)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:41:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0f2c25cd6b4a23c344de5a5cc1fb9a26f6c38919",
          "body": "* feat(#2602-D): migrate init through repo-edit apply\n\nRoute cargo-allow init policy writes through repo-edit::single_target_apply with parity fixture, shim registry, and init test alignment.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-D): align init parent error test with apply path\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-D): migrate init through repo-edit apply (#2731)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:22:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "47739d1097c56def4ae7bd5d76522c1da1a98e65",
          "body": "* feat(#2602-C): add generic single-target apply receipts\n\nIntroduce repo-edit apply receipt envelope, digest helpers, and single_target_apply with containment-checked portable receipts and parity fixtures.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-C): receipt parity allow entry and clippy\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-C): generic single-target apply receipts in repo-edit (#2730)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T09:04:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a6fada9edf91f72c874140581f08d4329a7c4fc",
          "body": "* feat(#2602-B): extract single-target atomic write to repo-edit\n\nMove write_file and write_file_no_overwrite into repo-edit::atomic_write with cargo-allow ModuleFacade shims, parity fixtures, and focused regression tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-B): receipt par\n[…]\nv1.toml so diff/shallow-diff characterization passes, and apply rustfmt to repo-edit tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-B): extract single-target atomic write to repo-edit (#2729)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T08:39:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b24e7cddc958e1e8eed6a320c2ae081f979ec98",
          "body": "* feat(#2602-A): scaffold repo-edit lock and containment\n\nExtract mutation_lock and assert_path_within_root into repo-edit with cargo-allow ModuleFacade shims, parity fixtures, and stage receipt. Documents #2568 residual spec-system CI audit path.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* \n[…]\n<cursoragent@cursor.com>\n\n* fix(#2602-A): document repo-edit source-tree boundary in lib.rs\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2602-A): scaffold repo-edit lock and containment (#2728)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T07:59:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "78780b30a50c23ede3ac05e65175ca4e105a3627",
          "body": "* refactor(#2568): remove embedded precommit evaluator\n\nStaged precommit now delegates to cargo-intent or fails with provider_unavailable; embedded spec_system_workspace evaluation path removed from spec_precommit. Updates conformance tests, stage receipts, and parity claim boundaries.\n\nCo-authored-\n[…]\nrsor.com>\n\n* fix(#2568): use NotApplicable for empty delegated precommit; repair allow.toml\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "refactor(#2568): remove embedded precommit evaluator (#2727)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T06:58:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "129dc18d001cd35793b9ca81d70b06ab2f36d02e",
          "body": "…(#2726)\n\nWhen delegate_spec_system is enabled, legacy spec-system commands and the embedded precommit evaluator reject instead of falling back; staged precommit still delegates only via delegate_staged_precommit. Adds cutover fixtures, parity/shim claim updates, and reachability receipt evidence for #2568.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2601-C): fail closed embedded spec-system authority at cutover …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T06:22:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2632bca73d66efcc69cb195136a959330ba2395b",
          "body": "…recommit-delegate\n\nfeat(#2601-B): delegate staged precommit to cargo-intent",
          "is_bot": false,
          "headline": "Merge pull request #2722 from EffortlessMetrics/cursor/2601b-staged-p…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T06:04:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd321b9518f70f63276ab51eaf6f5cb6d1f47292",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "ci(#2601-B): build cargo-intent before delegation e2e tests",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T05:47:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f1b90f250f953f42332ee7da169dabee3cd44e8b",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "style: rustfmt intent_delegate and release_prep_tests",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T05:44:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0496822b31f32d31ea667e0bd7f36cd90fbf8719",
          "body": "When intent-delegation config enables delegate_staged_precommit, cargo-allow\ninvokes cargo-intent via subprocess and validates repo.analysis-receipt.v1\nthrough repo-protocol only, without an intent-protocol dependency.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2601-B): delegate staged precommit to cargo-intent",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T05:41:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6ab43a8043d1a4d78ebfa70a7eca0ae37de4ae7f",
          "body": "…#2724)\n\n* ci: add cargo-deny supply-chain audit and CODEOWNERS (#1897, #1899)\n\ncargo-allow is a governance tool but had no cargo-deny supply-chain audit\nand no CODEOWNERS file.\n\nAdd a cargo-deny CI job running cargo deny check advisories bans licenses\nsources on ubuntu-latest with a deny.toml confi\n[…]\npping each crate/directory to its owner for automatic\nreview requests.\n\nChild of #1786. CI-only; no production code changes.\n\n* fix(ci): correct cargo-deny-action SHA; receipt deny.toml and CODEOWNERS",
          "is_bot": false,
          "headline": "ci: add cargo-deny supply-chain audit and CODEOWNERS (#1897, #1899) (…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T04:42:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "457d9303ff3d4fd280d8e9f1fac8b029d2a17548",
          "body": "…725)\n\nParse errors from legacy migration said 'missing field owner' with no\nindication of which legacy ledger file produced the error. On a repo with\nmultiple ripr ledger files, the operator had to grep by hand.\n\nWrap load_legacy_or_canonical (single-file path) and load_lane_config\n(batch path) wit\n[…]\nallowlist`): missing field owner'\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2510 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): parse errors include source legacy filename (#1868) (#2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T04:10:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea457e25acd2cd1334c82b593715df982162b310",
          "body": "…(#1861) (#2723)\n\nimport_legacy_policy_dir concatenated lane outputs without checking global\nID uniqueness before validate_policy. When two lanes produced entries with\nthe same ID (e.g. both had id = allow-1), validate_policy caught the\nduplicate and aborted the entire migration — no partial result,\n[…]\nboth survive with namespaced IDs.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2510 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): namespace cross-lane ID collisions instead of aborting …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T03:24:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d83cacdc9a55fd94eaaad1cbbc1a2aa3cc601068",
          "body": "cmd_migrate only called validate_policy, skipping the source-tree evidence\nreference validation that add and refresh enforce. A migration could write\nentries with evidence pointing at non-existent or out-of-tree files to the\nlive ledger.\n\nAdd validate_evidence_references_for_source_tree to the --upd\n[…]\nlidator has the source-tree root.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(cli): migrate --update validates evidence references (#1871) (#2717)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T02:21:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebf60ede167ae2a9172d365ae21522d48482d7f4",
          "body": "…721)\n\nimport_legacy_policy_dir iterated only known lane descriptors and silently\nskipped any .toml files in the directory that didn't match. A user\nmigrating a ripr ledger with a custom section (e.g. [vendor] or [sbom])\nsaw 'migration complete' and silently lost that section.\n\nDetect unrecognized .\n[…]\noad_repo_policy_migration_config.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(migrate): warn on unrecognized legacy directory files (#1867) (#2…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T02:15:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd9006094f564edc7ca6f7f4567c1a0f66ebe833",
          "body": "…2696)\n\nlocation_drift fired on any 1-line delta, so every receipt drifted the\nmoment any code above an entry changed. This flooded the advisory channel\nand eroded reviewer trust — the exact opposite of what drift detection\nshould do.\n\nAdd DRIFT_LINE_TOLERANCE (default 3): line-only shifts within th\n[…]\nsage_fires_on_column_only_change.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(match): location_drift tolerance for small line shifts (#1808) (#…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T01:27:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be4ea6daed243f3462a5801beed91d7add169396",
          "body": "…handling (#1858) (#2695)\n\nevidence_repair_queues was conditionally omitted when empty in three\ndifferent ways across three artifacts:\n- report_json.rs: skipped the entire array when empty (early return)\n- receipt.rs: only inserted the key when queues was non-empty\n- doctor.rs: unrelated conditional\n[…]\npt_error, diff) with the new key.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2505 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(report): always emit evidence_repair_queues for consistent empty-…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T00:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9b877b47a7a5a22fd57f7d210a79b64620c0f26",
          "body": "…ds (#1877) (#2694)\n\nis_generated_path used file_name.contains(\".generated.\") and\nfile_name.ends_with(\".generated\") which matched compound words like\nreport-pre-generated.json where generated is part of a larger word, not a\nfile extension marker.\n\nReplace with has_generated_extension which splits on\n[…]\nes and three true-positive cases.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2506 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(scanner): .generated heuristic no longer misfires on compound wor…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-24T00:44:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a18189a0374755097fdc28267c861683c151288",
          "body": "…strings (#2659) (#2672)\n\nextract_lints tracked paren depth correctly but the final .split(',')\nwas a flat split that did not skip commas inside string literals. A\nreason like reason = \"see policy: a, b\" produced a spurious extra\nlint entry with a corrupt identity from the comma-separated fragment.\n\n[…]\nped quotes inside reason strings.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2500 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(scanner): extract_lints no longer splits on commas inside reason …",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T23:13:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1c96a3a8666f575fed17e2f734f37af7704b8a92",
          "body": "…capes (#1839) (#2671)\n\nvalidate_import_roots_config only checked duplicate id and duplicate path.\nThe entry.path was later joined via root.join(&entry.path) at discover.rs\nwith no source-tree-relative validation — the same bug class the federation\nlayer calls out in its #2011 comment. An absolute p\n[…]\nccepts_source_tree_relative_path.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2502 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(policy): validate import-root paths for traversal and absolute es…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T23:06:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df3abb8fdf2e0c9ddd57bfaed98ad75b1c8366d3",
          "body": "classification is a free-form string, but baseline_debt is the only value\nwith structural lifecycle semantics (requires expires + created, caps at\n120 days, blocks in Strict/Release). A typo like baseline-debt or\nBaselineDebt silently bypassed all three enforcements.\n\nAdd looks_like_baseline_debt_ty\n[…]\ng passes, unrelated values pass).\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2501 pass); cargo-allow check --mode\nno-new (status: passed).",
          "is_bot": false,
          "headline": "fix(policy): reject baseline_debt classification typos (#2661) (#2670)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T23:06:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c8b30b9ded33e5c1206bce90736515d34dfcdd8",
          "body": "…rovider-discovery\n\nfeat(#2601-A): cargo-intent provider discovery",
          "is_bot": false,
          "headline": "Merge pull request #2669 from EffortlessMetrics/cursor/2601a-intent-p…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T22:03:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c2e7e80606d2aa7facee01404322fa6eea9d18d",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2601-A): wire provider discovery into doctor for clippy",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:58:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3c670a0a0986bacc31e112a569495e7fd044d250",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: rustfmt intent_provider",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:51:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc4a9f106538ad2ec0d6958c8d55e78847e55c7a",
          "body": "Discover cargo-intent via explicit override, compatibility config, then PATH while rejecting workspace target and crates paths.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2601-A): cargo-intent provider discovery",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:46:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c5883f0625fa301c0ccba470d571b4897e795f3e",
          "body": "…nstall-smoke\n\nfeat(#2599-C): intent-candidate isolated install smoke",
          "is_bot": false,
          "headline": "Merge pull request #2657 from EffortlessMetrics/cursor/2599c-intent-i…",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:42:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fba19d8db50feff8853eba2bc4b086deacb8cdda",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): scope install isolation to cargo-intent closure",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:33:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "605dbb0965fad7184e4402e006536880ba5c8bab",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): avoid patch writer clobbering crate loop var",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:28:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "df54785d10e56e4993b00252de541bd5cf41b152",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): read packaged crates from isolated target dir",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:24:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "616d2b0b98a4235093e70be20d223380a4363f31",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): incremental patch without --locked",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:18:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ef7b3f238ab389899a25cad30d5f109fa39834de",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(#2599-C): package intent deps without patch lock drift",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:11:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "048e79fd53979cbce6551db42e04c76b493a618d",
          "body": "Prove the seven-crate intent stack packages and installs outside the workspace without proof/test invocation or workspace target/debug leakage.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2599-C): intent-candidate isolated install smoke",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T21:00:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d839ea6d62f1470612f924ca243e0496e20a5c98",
          "body": "* feat(#2599-B): change status staged precommit vertical\n\nWire cargo intent change status --staged --phase precommit through repo-snapshot, intent-engine phase obligations, and intent-protocol transport with render/exit mapping. No cargo-allow production dependency on intent crates.\n\nCo-authored-by:\n[…]\n\n\n* fix(#2599-B): restore parity registry field and exclude cargo-intent from package smoke\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(#2599-B): change status staged precommit vertical (#2656)",
          "author_name": "Steven Zimmerman, CPA",
          "author_login": "EffortlessSteven",
          "committed_at": "2026-07-23T20:53:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 5,
      "commits_last_year": 2295,
      "latest_release_at": "2026-07-18T00:52:46Z",
      "latest_release_tag": "v0.1.11",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 7,
      "mean_days_between_releases": 8.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "allow-core",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-core",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 6064,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2021,
          "first_published_at": "2026-05-27T03:18:05.875614Z",
          "latest_published_at": "2026-07-18T00:50:11.488335Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-diff",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-diff",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5656,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1885,
          "first_published_at": "2026-05-27T03:47:57.520975Z",
          "latest_published_at": "2026-07-18T00:51:02.330957Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-rust",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-rust",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5702,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1901,
          "first_published_at": "2026-05-27T03:18:39.115606Z",
          "latest_published_at": "2026-07-18T00:50:40.210362Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-files",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-files",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5698,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1899,
          "first_published_at": "2026-05-27T03:18:34.007252Z",
          "latest_published_at": "2026-07-18T00:50:30.152040Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "allow-match",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/allow-match",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5669,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1890,
          "first_published_at": "2026-05-27T03:27:40.457493Z",
          "latest_published_at": "2026-07-18T00:50:43.257274Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        },
        {
          "name": "cargo-allow",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "audit",
            "governance",
            "policy",
            "rust",
            "scanner",
            "command-line-utilities",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/cargo-allow",
          "is_deprecated": false,
          "latest_version": "0.1.11",
          "repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
          "versions_count": 12,
          "total_downloads": 5608,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 1869,
          "first_published_at": "2026-05-27T04:07:37.858491Z",
          "latest_published_at": "2026-07-18T00:51:22.688717Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-23",
            "count": 2
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 407
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/allow-core/Cargo.toml",
        "crates/allow-diff/Cargo.toml",
        "crates/allow-files/Cargo.toml",
        "crates/allow-inventory/Cargo.toml",
        "crates/allow-match/Cargo.toml",
        "crates/allow-policy-legacy/Cargo.toml",
        "crates/allow-policy/Cargo.toml",
        "crates/allow-report/Cargo.toml",
        "crates/allow-rust/Cargo.toml",
        "crates/cargo-allow/Cargo.toml",
        "crates/cargo-intent/Cargo.toml",
        "crates/cargo-proof/Cargo.toml",
        "crates/intent-edit/Cargo.toml",
        "crates/intent-engine/Cargo.toml",
        "crates/intent-model/Cargo.toml",
        "crates/intent-protocol/Cargo.toml",
        "crates/proof-adapter-cargo-allow/Cargo.toml",
        "crates/proof-adapter-command/Cargo.toml",
        "crates/proof-adapter-hawk/Cargo.toml",
        "crates/proof-adapter-ripr/Cargo.toml",
        "crates/proof-engine/Cargo.toml",
        "crates/proof-protocol/Cargo.toml",
        "crates/proof-provider-api/Cargo.toml",
        "crates/repo-edit/Cargo.toml",
        "crates/repo-protocol/Cargo.toml",
        "crates/repo-snapshot/Cargo.toml",
        "crates/rust-source-index/Cargo.toml"
      ],
      "largest_source_bytes": 229120,
      "source_files_sampled": 1010,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 5031
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "sha2",
          "manifest": "crates/allow-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-files",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy-legacy",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-rust",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/allow-diff/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-files/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-inventory/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-match/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-policy-legacy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy",
          "manifest": "crates/allow-policy-legacy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/allow-policy-legacy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-policy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/allow-policy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/allow-policy/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy-legacy",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/allow-report/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tree-sitter",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tree-sitter-rust",
          "manifest": "crates/allow-rust/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-inventory",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-files",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-rust",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-match",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-report",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-diff",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-policy-legacy",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-edit",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "intent-engine",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "intent-protocol",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-snapshot",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/cargo-intent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-engine",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/cargo-proof/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-edit",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-edit/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-engine/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/intent-engine/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-engine/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "allow-core",
          "manifest": "crates/intent-model/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-model/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-model/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/intent-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/intent-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/intent-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-adapter-command",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-command/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-hawk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-protocol",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "proof-provider-api",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "repo-protocol",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/proof-adapter-ripr/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 2077,
        "open_issues": 405,
        "closed_ratio": 0.41,
        "closed_issues": 281,
        "closed_unmerged_prs": 39
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "EffortlessSteven",
          "commits": 2308,
          "avatar_url": "https://avatars.githubusercontent.com/u/15812269?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml",
        "ub-review.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/12 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3366897b078191bee344d03af2d27bf635e322fd",
        "ran_at": "2026-07-25T12:18:32Z",
        "aggregate_score": 5.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T11:45:57Z",
      "oldest_open_prs": [
        {
          "number": 2623,
          "created_at": "2026-07-22T06:25:55Z",
          "last_comment_at": "2026-07-22T06:58:24Z",
          "last_comment_author": "chatgpt-codex-connector"
        },
        {
          "number": 2802,
          "created_at": "2026-07-25T09:40:48Z",
          "last_comment_at": "2026-07-25T09:40:56Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-25T11:39:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 1466,
          "created_at": "2026-06-06T19:34:20Z",
          "last_comment_at": "2026-07-23T23:55:08Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1471,
          "created_at": "2026-06-06T20:28:23Z",
          "last_comment_at": "2026-07-23T23:55:09Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1476,
          "created_at": "2026-06-06T20:34:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1477,
          "created_at": "2026-06-06T21:39:35Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1776,
          "created_at": "2026-06-21T16:09:45Z",
          "last_comment_at": "2026-07-23T23:19:14Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1777,
          "created_at": "2026-06-21T16:09:46Z",
          "last_comment_at": "2026-07-23T23:39:13Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1779,
          "created_at": "2026-06-21T16:10:40Z",
          "last_comment_at": "2026-07-23T23:39:39Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1780,
          "created_at": "2026-06-21T16:11:47Z",
          "last_comment_at": "2026-07-23T23:16:58Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1781,
          "created_at": "2026-06-21T16:12:23Z",
          "last_comment_at": "2026-07-23T23:17:25Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1782,
          "created_at": "2026-06-21T16:12:25Z",
          "last_comment_at": "2026-07-23T23:16:33Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1783,
          "created_at": "2026-06-21T16:13:02Z",
          "last_comment_at": "2026-07-23T23:19:42Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1784,
          "created_at": "2026-06-21T16:13:04Z",
          "last_comment_at": "2026-07-23T23:40:58Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1785,
          "created_at": "2026-06-21T16:13:39Z",
          "last_comment_at": "2026-07-21T03:23:39Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1786,
          "created_at": "2026-06-21T16:13:41Z",
          "last_comment_at": "2026-06-21T21:20:10Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1787,
          "created_at": "2026-06-21T16:13:42Z",
          "last_comment_at": "2026-06-21T21:20:26Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1797,
          "created_at": "2026-06-21T16:15:22Z",
          "last_comment_at": "2026-07-23T23:16:03Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1808,
          "created_at": "2026-06-21T16:17:18Z",
          "last_comment_at": "2026-07-23T23:54:37Z",
          "last_comment_author": "EffortlessSteven"
        },
        {
          "number": 1809,
          "created_at": "2026-06-21T16:17:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1823,
          "created_at": "2026-06-21T19:50:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1825,
          "created_at": "2026-06-21T19:51:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/EffortlessMetrics/cargo-allow",
    "host": "github.com",
    "name": "cargo-allow",
    "owner": "EffortlessMetrics"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 56,
        "vitality": 76,
        "community": 50,
        "governance": 53,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 2295,
              "human_commit_share": 0.87,
              "days_since_last_push": 0,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "2295 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 2295
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 5,
              "latest_release_tag": "v0.1.11",
              "releases_from_tags": false,
              "days_since_latest_release": 7,
              "mean_days_between_releases": 8.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "5 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 7 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 2,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "packages": [
                "allow-core",
                "allow-diff",
                "allow-rust",
                "allow-files",
                "allow-match",
                "cargo-allow"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 34397,
              "monthly_downloads": 11465
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "11,465 downloads/month across crates",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 11465,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "merged_prs": 2077,
              "open_issues": 405,
              "closed_issues": 281,
              "issue_closed_ratio": 0.41,
              "closed_unmerged_prs": 39
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "41% of issues closed",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 41
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2077/2116 decided PRs merged",
                "points": 37.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2077,
                      "decided": 2116
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/12 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 7,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "EffortlessMetrics",
              "public_repos": 75,
              "account_age_days": 852
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "7 followers of EffortlessMetrics",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 7,
                      "login": "EffortlessMetrics"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "75 public repos, account ~2 yr old",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 75
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "allow-core",
                "allow-diff",
                "allow-rust",
                "allow-files",
                "allow-match",
                "cargo-allow"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 7
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 7 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/12 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 80,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 5031
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 87,
                      "sampled": 87
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.48,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/allow-core/Cargo.toml",
                "crates/allow-diff/Cargo.toml",
                "crates/allow-files/Cargo.toml",
                "crates/allow-inventory/Cargo.toml",
                "crates/allow-match/Cargo.toml",
                "crates/allow-policy-legacy/Cargo.toml",
                "crates/allow-policy/Cargo.toml",
                "crates/allow-report/Cargo.toml",
                "crates/allow-rust/Cargo.toml",
                "crates/cargo-allow/Cargo.toml",
                "crates/cargo-intent/Cargo.toml",
                "crates/cargo-proof/Cargo.toml",
                "crates/intent-edit/Cargo.toml",
                "crates/intent-engine/Cargo.toml",
                "crates/intent-model/Cargo.toml",
                "crates/intent-protocol/Cargo.toml",
                "crates/proof-adapter-cargo-allow/Cargo.toml",
                "crates/proof-adapter-command/Cargo.toml",
                "crates/proof-adapter-hawk/Cargo.toml",
                "crates/proof-adapter-ripr/Cargo.toml",
                "crates/proof-engine/Cargo.toml",
                "crates/proof-protocol/Cargo.toml",
                "crates/proof-provider-api/Cargo.toml",
                "crates/repo-edit/Cargo.toml",
                "crates/repo-protocol/Cargo.toml",
                "crates/repo-snapshot/Cargo.toml",
                "crates/rust-source-index/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "48 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 48,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 229120,
              "source_files_sampled": 1010,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/1010 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1010,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch crates package 'cargo-proof' from its registry",
    "Could not fetch crates package 'intent-edit' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T12:18:48.202021Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/EffortlessMetrics/cargo-allow.svg",
  "full_name": "EffortlessMetrics/cargo-allow",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticscrates.io.