Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 02:07 UTC

Gitlawb / zero

The coding agent that answers to you, your model, your machine, your rules.

GoMIT★ 1,104 stars⑂ 110 forkssince May 2026View on GitHub ↗

Gitlawb/zero holds a health index of 73 out of 100, placing it in the Good band. It scores highest on AI Readiness (86/100) and lowest on Security (62/100). It was last updated today. 2 contributors account for most of its recent work.

73
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

73
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

GitlawbOrganization
932 followers17 public repossince Mar 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/Gitlawb/zerov0.5.0-50 days ago
npm@gitlawb/zero0.5.03,240160 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

72Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
5.5/36Commit cadence — 8/52 weeks with commits
18/18Commit volume — 587 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year587
human_commit_share0.97
days_since_last_push0
active_weeks_last_year8
How it's scored
27/27Ships releases — 5 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~4.9 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count5
latest_release_tagv0.5.0
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases4.9

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

74Good · 18% of overall
How it's scored
49.4/60Stars — 1,104 stars
17/25Forks — 110 forks
1.7/15Watchers — 3 watchers
Inputs used
forks110
stars1,104
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonwindow_too_short

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
46.8/80Monthly downloads — 3,240 downloads/month across go, npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesgithub.com/Gitlawb/zero, @gitlawb/zero
dependents
ecosystemsgo, npm
total_downloads
monthly_downloads3,240
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

73Good · 24% of overall
How it's scored
25.2/54Bus factor — 2 contributor(s) cover half of all commits
14.5/22.5Commit distribution — top contributor authored 35% of commits
13.5/13.5Contributor breadth — 28 contributors
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Inputs used
bus_factor2
contributors_sampled28
top_contributor_share0.354
How it's scored
31.7/46.8Issue resolution — 68% of issues closed
34.1/38.3PR acceptance — 531/595 decided PRs merged
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs531
open_issues46
closed_issues97
issue_closed_ratio0.678
closed_unmerged_prs64
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
21.4/25Owner reach — 932 followers of Gitlawb
9.8/25Track record — 17 public repos, account ~0 yr old
Inputs used
followers932
owner_typeOrganization
is_verified
owner_loginGitlawb
public_repos17
account_age_days127
How it's scored
25/25Published & resolvable — 2 package(s) on go, npm
35/35Publish recency — latest publish 0 days ago
20/20Version history — 16 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/Gitlawb/zero, @gitlawb/zero
ecosystemsgo, npm
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

81Good · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://zero.gitlawb.com
10/10Repository description
10/10Topics — 13 topics
10/10Wiki
Inputs used
topicsai-agent, ai, anthropic, cli, code-assistant, coding-agent, developer-tools, gemini, llm, mcp, ollama, openai, terminal
has_wikiyes
homepagehttps://zero.gitlawb.com
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — no data
5/5Pinned-Dependencies — all dependencies are pinned
3.5/5SAST — SAST tool is not run on all commits -- score normalized to 7
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.2
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages104
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 104 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

86Excellent · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 97 of 97 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes3,827
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 7 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum, package-lock.json
has_dockerfileno
typed_languageyes
bootstrap_filesMakefile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.07
toolchain_manifestsgo.mod, internal/agenteval/testdata/fixtures/zero-mini/go.mod, internal/perfbench/testdata/edit/go.mod, internal/perfbench/testdata/fix/go.mod, internal/perfbench/testdata/nav/go.mod, internal/perfbench/testdata/refactor/go.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
54.3/55Manageable file sizes — 16/1,231 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes217,150
source_files_sampled1,231
oversized_source_files16

Key facts

1,104GitHub stars
28contributors
587commits, last 12 months
0days since last push
5releases
2bus factor
46open issues
Go, npmpackage ecosystems

Data collection warnings

  • deps.dev does not index npm:@gitlawb/zero@0.5.0; advisories assessed against the repository dependency graph instead

More detail

Star and fork history 1,104 ★ / 110 ⇿
1,104Stars
110Forks
4Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

Only the most recent history is shown — this repository exceeds the collection window, so the earliest history is not captured.

02004006008001,0001,2001,1041104872026-072026-072026-07
Major 0Minor 4Patch 0
OpenSSF Scorecard 5.2 / 10
5.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 02:06 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/aPackagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
7SASTSAST tool is not run on all commits -- score normalized to 7
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 15
RegistryPackageVersion constraintManifest
Gocharm.land/bubbles/v2v2.1.1go.mod
Gocharm.land/bubbletea/v2v2.0.8go.mod
Gocharm.land/lipgloss/v2v2.0.5go.mod
Gogithub.com/alecthomas/chroma/v2v2.27.0go.mod
Gogithub.com/atotto/clipboardv0.1.4go.mod
Gogithub.com/aymanbagabas/go-udiffv0.4.1go.mod
Gogithub.com/charmbracelet/colorprofilev0.4.3go.mod
Gogithub.com/charmbracelet/x/ansiv0.11.7go.mod
Gogithub.com/charmbracelet/x/termv0.2.2go.mod
Gogithub.com/coder/websocketv1.8.15go.mod
Gogithub.com/ledongthuc/pdfv0.0.0-20250511090121-5959a4027728go.mod
Gogolang.org/x/sysv0.47.0go.mod
Gomvdan.cc/sh/v3v3.13.1go.mod
npmagent-browser^0.30.1package.json
npmtuistory^0.10.0package.json
All dependencies 104

Full resolved dependency set from the GitHub dependency graph: 15 direct and 89 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gocharm.land/bubbles/v2v2.1.1direct
Gocharm.land/bubbletea/v2v2.0.8direct
Gocharm.land/lipgloss/v2v2.0.5direct
Gogithub.com/alecthomas/chroma/v2v2.27.0direct
Gogithub.com/atotto/clipboardv0.1.4direct
Gogithub.com/aymanbagabas/go-udiffv0.4.1direct
Gogithub.com/charmbracelet/colorprofilev0.4.3direct
Gogithub.com/charmbracelet/x/ansiv0.11.7direct
Gogithub.com/charmbracelet/x/termv0.2.2direct
Gogithub.com/coder/websocketv1.8.15direct
Gogithub.com/ledongthuc/pdfv0.0.0-20250511090121-5959a4027728direct
Gogolang.org/x/sysv0.47.0direct
Gomvdan.cc/sh/v3v3.13.1direct
npmagent-browser0.30.1direct
npmtuistory0.10.0direct
Gogithub.com/charmbracelet/ultravioletv0.0.0-20260703014108-f5a850f9c2b7indirect
Gogithub.com/charmbracelet/x/exp/goldenv0.0.0-20260615092313-b57e5e6d29bbindirect
Gogithub.com/charmbracelet/x/termiosv0.1.1indirect
Gogithub.com/charmbracelet/x/windowsv0.2.2indirect
Gogithub.com/clipperhouse/displaywidthv0.11.0indirect
Gogithub.com/clipperhouse/uax29/v2v2.7.0indirect
Gogithub.com/dlclark/regexp2/v2v2.5.0indirect
Gogithub.com/go-quicktest/qtv1.102.0indirect
Gogithub.com/lucasb-eyer/go-colorfulv1.4.0indirect
Gogithub.com/mattn/go-runewidthv0.0.24indirect
Gogithub.com/muesli/cancelreaderv0.2.2indirect
Gogithub.com/rivo/unisegv0.4.7indirect
Gogithub.com/rogpeppe/go-internalv1.15.0indirect
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41eindirect
Gogolang.org/x/expv0.0.0-20260611194520-c48552f49976indirect
Gogolang.org/x/syncv0.22.0indirect
npm@clack/core1.4.2indirect
npm@clack/prompts1.6.0indirect
npm@hono/node-server1.19.14indirect
npm@hono/node-ws1.3.1indirect
npm@opentui/core0.2.16indirect
npm@opentui/core-darwin-arm640.2.16indirect
npm@opentui/core-darwin-x640.2.16indirect
npm@opentui/core-linux-arm640.2.16indirect
npm@opentui/core-linux-x640.2.16indirect
npm@opentui/core-win32-arm640.2.16indirect
npm@opentui/core-win32-x640.2.16indirect
npm@opentui/react0.2.16indirect
npm@resvg/resvg-wasm2.6.2indirect
npm@sec-ant/readable-stream0.4.1indirect
npm@sindresorhus/merge-streams4.0.0indirect
npmansi-regex6.2.2indirect
npmbun-ffi-structs0.2.2indirect
npmclone1.0.4indirect
npmcross-spawn7.0.6indirect
npmdefaults1.0.4indirect
npmdiff9.0.0indirect
npmemoji-regex10.6.0indirect
npmerrore0.11.0indirect
npmexeca9.6.1indirect
npmfast-string-truncated-width3.0.3indirect
npmfast-string-width3.0.2indirect
npmfast-wrap-ansi0.2.2indirect
npmfigures6.1.0indirect
npmget-east-asian-width1.6.0indirect
npmget-stream9.0.1indirect
npmget-them-args1.3.2indirect
npmghostty-opentui1.5.0indirect
npmgoke6.12.3indirect
npmhono4.12.27indirect
npmhuman-signals8.0.1indirect
npmis-plain-obj4.1.0indirect
npmis-stream4.0.1indirect
npmis-unicode-supported2.1.0indirect
npmisexe2.0.0indirect
npmkill-port-process4.0.2indirect
npmmarked17.0.1indirect
npmnpm-run-path6.0.0indirect
npmparse-ms4.0.0indirect
npmpath-key3.1.1indirect
npmpath-key4.0.0indirect
npmpicocolors1.1.1indirect
npmpid-port2.0.1indirect
npmpretty-ms9.3.0indirect
npmreact19.2.7indirect
npmreact-devtools-core7.0.1indirect
npmreact-reconciler0.33.0indirect
npmscheduler0.27.0indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmshell-quote1.9.0indirect
npmsignal-exit4.1.0indirect
npmsisteransi1.0.5indirect
npmstd-env4.1.0indirect
npmstring-dedent3.0.2indirect
npmstring-width7.2.0indirect
npmstrip-ansi7.1.2indirect
npmstrip-final-newline4.0.0indirect
npmtypescript5.9.3indirect
npmunicorn-magic0.3.0indirect
npmwcwidth1.0.1indirect
npmweb-tree-sitter0.25.10indirect
npmwhich2.0.2indirect
npmws7.5.11indirect
npmws8.21.0indirect
npmyoctocolors2.1.2indirect
npmyoga-layout3.2.1indirect
npmzigpty0.2.1indirect
npmzod4.3.6indirect
Dependency advisories 1

This repository publishes no package the index resolves, so its own dependency graph was assessed — 104 packages, which also include development and test pins that never ship: 1 carry known advisories, of which 0 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
@hono/node-server1.19.14indirectmoderate12.0.5

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-agent",
        "ai",
        "anthropic",
        "cli",
        "code-assistant",
        "coding-agent",
        "developer-tools",
        "gemini",
        "llm",
        "mcp",
        "ollama",
        "openai",
        "terminal"
      ],
      "is_fork": false,
      "size_kb": 7987,
      "has_wiki": true,
      "homepage": "https://zero.gitlawb.com",
      "languages": {
        "Go": 11160305,
        "Shell": 9514,
        "Makefile": 1846,
        "JavaScript": 43861,
        "PowerShell": 5821
      },
      "pushed_at": "2026-07-22T01:37:48Z",
      "created_at": "2026-05-28T14:11:35Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T01:37:42Z",
      "description": "The coding agent that answers to you, your model, your machine, your rules.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://gitlawb.com",
      "name": "Gitlawb",
      "type": "Organization",
      "login": "Gitlawb",
      "company": null,
      "location": null,
      "followers": 932,
      "avatar_url": "https://avatars.githubusercontent.com/u/268502891?v=4",
      "created_at": "2026-03-16T03:54:24Z",
      "is_verified": null,
      "public_repos": 17,
      "account_age_days": 127
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-22T01:37:48Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-17T05:25:43Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-09T15:19:22Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-06T03:51:15Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-02T07:20:55Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a50574f673c3cb681937f02ce5f9be86e81beba8",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.5.0 (#714)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-22T01:37:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c00a4734b5a830f861ba638388d5e0a3b361a10a",
          "body": "Co-authored-by: binyangzhu000-sudo <224954946+binyangzhu000-sudo@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Atlas Cloud provider preset (#784)",
          "author_name": "nb213",
          "author_login": "binyangzhu000-sudo",
          "committed_at": "2026-07-22T00:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2479884dea49580c853a53536c3bbab22ce8a2bf",
          "body": "* feat(plugins): add zero plugins info command\n\nAdd plugins info to inspect manifest state, extension counts, and\nlockfile source/hash with optional hash drift detection.\n\n* fix(plugins): derive lock dir from plugin install path for info\n\nRemove LockDir from InfoOptions and read the lockfile from\nfilepath.Dir(plugin.PluginDir) so lock metadata matches the resolved\nplugin location. Consolidate duplicate lock hash output lines.",
          "is_bot": false,
          "headline": "feat(plugins): add zero plugins info command (#773)",
          "author_name": "Felix-Ayush",
          "author_login": "Ayush7614",
          "committed_at": "2026-07-22T00:14:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab2f9fbd3e43c1665f45f73f185579cd93a65618",
          "body": "* Add shell completion generation\n\nAdd zero completions for bash, zsh, fish, PowerShell, and Elvish using one shared command tree that covers aliases, nested commands, root flags, and common exec flags.\n\nValidate missing and unsupported shell arguments as usage errors and document safe installation \n[…]\nvation.\n\nRefs #499\n\n* Fix Elvish completion syntax\n\nClose generated Elvish conditional branches, use value equality, and validate generated script structure plus native Bash and Zsh syntax.\n\nRefs #499",
          "is_bot": false,
          "headline": "Add shell completion generation (#764)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-22T00:13:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "baa4be13ac5321da4e9f53e864dd1cd395481200",
          "body": "Co-authored-by: Amp <amp@ampcode.com>",
          "is_bot": false,
          "headline": "fix: make extension installs transactional (#762)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-22T00:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddfdf2878e7e5ffd0a7682df51831d8ece6ee65b",
          "body": "* fix: expose authenticated ChatGPT models to ACP\n\nCo-authored-by: Pierre Bruno <pierrebruno@hotmail.ch>\n\n* fix(acp): persist discovered model selections\n\n* fix(acp): normalize model selections\n\n---------\n\nCo-authored-by: Amp <amp@ampcode.com>",
          "is_bot": false,
          "headline": "Fix ChatGPT OAuth model discovery and ACP model selection (#724)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-22T00:11:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96859c9bd16f6dad4e332efc7e68178b9116118a",
          "body": "* feat(sandbox): unify command execution and enforcement\n\n* test(sandbox): make platform contracts portable\n\n* fix(sandbox): close execution lifecycle races\n\nBound retained interactive output, preserve interruption state, and start workspace observation before process launch.\n\nProtect active runtime\n[…]\neatbelt host-local network allowances after native validation showed localhost filters can reach host interfaces.\n\nTrack process reap completion so retained sessions cannot signal a stale numeric PID.",
          "is_bot": false,
          "headline": "feat(sandbox): unify command execution and enforcement (#781)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-21T13:25:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3524f795e5fdbb827166a84f03351cedfc9eba30",
          "body": "… (#767)\n\nCloses #721.\n\n`zero providers use <name>` wrote activeProvider to config.json and reported\n\"Active provider set to <name>\" even when ZERO_PROVIDER was set, which applyEnv\nmakes win over config.json unconditionally. So the switch was reported as a\nsuccess while `providers current` still sho\n[…]\n) so tests stay hermetic against an\nambient ZERO_PROVIDER. The related env-derived-profile \"not found\" case the issue\nalso mentions is already handled by the unpersisted-provider path (#707) and #716.",
          "is_bot": false,
          "headline": "fix(cli): warn when ZERO_PROVIDER overrides a providers-use selection…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:30:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1f41735a7f6b7928a1875e986a4dca39d106cb9",
          "body": "…il the suite (#684) (#766)\n\n* fix(lsp): make the real-gopls check opt-in so a broken gopls can't fail the suite\n\nCloses #684.\n\nTestManagerCheckRealGopls skipped only when gopls was absent from PATH, so an\ninstalled-but-unhealthy gopls (e.g. an unusable persistent-index cache that makes\nthe server e\n[…]\nver and never touches the developer's global gopls; the\nreal check still runs on demand with ZERO_GOPLS_INTEGRATION=1.\n\n* test(lsp): require ZERO_GOPLS_INTEGRATION=1 exactly, so =0 keeps the check off",
          "is_bot": false,
          "headline": "fix(lsp): make the real-gopls check opt-in so a broken gopls can't fa…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:30:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4945684fa26aa5994eda59dcabedc817423c535d",
          "body": "… (#765)\n\nCloses #728.\n\nThe Windows ACL setup resolved each target's pathname independently across\nos.Stat, GetNamedSecurityInfo, and SetNamedSecurityInfo (and again on rollback),\nso during elevated setup a lower-privileged local user could swap a target for a\nsymlink/junction between operations and\n[…]\n it runs in CI), and the not-exist\nmapping. The full privilege-boundary race can't be reproduced in CI, so the guard\nis verified structurally (one handle for read and write) and by junction rejection.",
          "is_bot": false,
          "headline": "fix(sandbox): bind Windows elevated ACL setup to one no-follow handle…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:30:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5140d4bf7b115dff72ec33d104e062aaca96cf40",
          "body": "Documents expectations for keeping contribution flow sustainable during the\nstabilization phase: one issue per bug (no bundled multi-finding audits), keep\nonly a few items open at a time, and hold AI-assisted contributions to the same\nper-item verification bar. Complements the existing issue-approved gate, which\nalready covers PR-to-issue linkage and scope; the gap was submission volume.",
          "is_bot": false,
          "headline": "docs(contributing): add contribution volume and batching guidance (#783)",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-21T07:16:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3967d49d64998341af8ef6d7523fc63aeb2a5a7a",
          "body": "* feat(tui): let the permission prompt take free-text feedback inline\n\n\"No, and tell Zero what to do differently\" now opens an inline input on the\npermission card instead of silently cancelling: type an instruction, Enter sends\nit, Esc returns to the option list. The text is delivered as a Deny deci\n[…]\nceKeepsStagedAttachment (mutation-verified\nagainst the missing guard) and TestPermissionFeedbackRendersNoClickableOptionsWhileTyping.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(tui): permission prompt takes free-text feedback inline (#780)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T17:59:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89bdc6719a1e1b3a3ef0e36b91a7839b3efdfba9",
          "body": "…ring (#779)\n\n* fix(tools): read_file recovers a backwards line range instead of erroring\n\nrenderReadFileRange hard-failed when end_line < start_line, costing the caller a\nwhole retry for an arithmetic slip. It was also inconsistent: start_line past EOF\nreturns a friendly note and end_line past EOF \n[…]\nheader/separator or a stray out-of-range line would still pass. Compare the\nwhole result.Output against the exact expected rendering.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(tools): read_file recovers a backwards line range instead of erro…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T17:27:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "722bb3121682d9cd9cd4bc6c127e9014d719262a",
          "body": "The focused permission prompt was the only prompt card in the TUI that used\nbrand/warning colours for its interior, and both read badly on cool themes such\nas dracula:\n\n1. The selected option (\"Yes, proceed\") was filled with zeroTheme.badge — the\n   brand chip meant for short labels (\" 0 \", \" ASK \",\n[…]\ng and not the brand accent, the body carries no permBg wash, and\nthe PERMISSION badge keeps its amber fill so the card still reads as a warning.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(tui): stop the permission card clashing on cool themes (#778)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T17:09:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a21a052a4a32ce9cb3c93c94350cd24e138532cd",
          "body": "* feat(sandbox): disable the sandbox via config (#687)\n\nAdd a sandbox.enabled field (`\"sandbox\": {\"enabled\": false}`). ModeDisabled\nalready short-circuits the engine but had no config surface.\n\n- SandboxConfig.Enabled *bool (pointer distinguishes an explicit false from an\n  omitted key).\n- mergeConf\n[…]\nannot enable) and asserting the provider itself is\nstill applied, so the guard cannot be satisfied by dropping the command wholesale.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(sandbox): disable the sandbox via config (#687) (#746)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T15:37:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f079b90f82dac7b7ae0864b279dc9094e31a6627",
          "body": "…73) (#745)\n\n* fix(sandbox): AST second opinion for interactive-command bypasses (#473)\n\nThe interactive-command guard split shell commands with a hand-written parser\n(splitShellSegments), which mis-handles unusual quoting, command substitution,\nsubshells, and newline separators — an interactive pro\n[…]\nof hard-blocking.\n\nGenuine detection is unchanged: `git rebase -i HEAD~1` and the #473 bypass\ncases still classify exactly as before.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(sandbox): AST second opinion for interactive-command bypasses (#4…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T15:31:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b30c3971b40b06ba52ad649ba9dc0ad560d4be4c",
          "body": "…ep the sidebar under the / palette (#775)\n\n* fix(tui): label model rows by id when the description is prose\n\nThe model picker (provider wizard AND onboarding, which share displayLabel)\nlabelled each row with the provider's Description, falling back to the ID only\nwhen the description was \"generic\".\n[…]\n rows beneath it.\n\nThe genuinely full-width overlays keep suppressing the sidebar, pinned by the\nnew test alongside the palette case.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(tui): model rows labelled by id when the description is prose; ke…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T15:28:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da9fb50f549f6701eb136fc99f6178d0772d9334",
          "body": "…ry guidance (#749 follow-up) (#768)\n\n* fix(tools): give write_stdin's invalid-session errors the same recovery guidance\n\nFollow-up to #749 (write_stdin session-id probing) / #702.\n\nwrite_stdin had three \"no valid live session\" error paths with three different\nmessages and signatures: a missing sess\n[…]\nSessionID to cover missing/zero/negative/\nnon-integer and assert the recovery message. Guardrail signature/halt tests\nunchanged.\n\n* test(tools): cover the explicit session_id: nil case for write_stdin",
          "is_bot": false,
          "headline": "fix(tools): give write_stdin's invalid-session errors the same recove…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-20T08:29:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "684901165d1b7f50a8bb4af31b1c1951e6926a79",
          "body": "…(#727) (#744)\n\nThe ambient ZERO_SANDBOXED=1 + ZERO_SANDBOX_BACKEND markers are user-controlled\nat an unsandboxed process boundary. Policy could auto-allow an ordinary shell\ncommand (backend reports a native wrapping sandbox) while the runner, seeing the\nsame markers, returned an unwrapped pass-thro\n[…]\ns the normal approval\npath instead of auto-allowing. Immediate mitigation per the issue; authenticated\nlaunch provenance is the longer-term fix.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(sandbox): don't auto-allow shell when re-entrancy skips wrapping …",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T06:26:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1975c1b396b3236ed648870230b4f85863b1d03",
          "body": "…s (#763)\n\n* fix(perfbench): grant write tools so mutating tasks measure real edits\n\nThe turn benchmark invoked `zero exec` in its default read-only posture,\nwhich exposes no write or shell tools (no edit_file/apply_patch/\nwrite_file/exec_command/bash). So the mutating classes (edit/fix/\nrefactor) c\n[…]\nTest on its own.\n- Drop the now-dead \"if WorkspaceFixture != empty\" branch: the fixtureless guard\n  added earlier already guarantees it is set.\n\nNo behavior change; the 4-task glm-5.2 smoke stays 4/4.",
          "is_bot": false,
          "headline": "fix(perfbench): grant write tools so mutating tasks measure real edit…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-20T06:04:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c6d3022bd7801eaad6a0440bb21a27221887297",
          "body": "* feat(tui): add /undo as an alias for /rewind (#698)\n\n/undo was unregistered and fell through to commandUnknown. Add it to the\n/rewind command's aliases (the same mechanism /quit, /find, /mcp-status use), so\nit dispatches to the existing rewind handler with args intact.\n\n* test(tui): cover the /und\n[…]\nmmand(\"/undo 123\") assertion so both the latest and numeric\n<sequence> forms of the /rewind contract are exercised through the alias.\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(tui): add /undo as an alias for /rewind (#698) (#747)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T06:02:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "974fc036c2f9a194722f2e8fddbb4fdbf797effe",
          "body": "Token exchange/refresh and the device authorization/poll POSTs validated only\nthe initial endpoint, then let the http.Client follow a 307/308 that replays the\nform body (code, PKCE verifier, refresh_token, client_secret) to an unvalidated\norigin.\n\nAdd withoutRedirects(): a shallow client copy whose \n[…]\n to it), RequestDeviceCode, and pollDeviceOnce. The caller's\nclient is never mutated; legitimate token endpoints that return 200 are unaffected.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(oauth): refuse redirects on credential POSTs (#729) (#741)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-20T02:49:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cbd144d11e5cb67bc5fea46f5b294562dac7a1a",
          "body": "…716)\n\n* fix(providers): stop \"provider not found\" for env-derived profiles\n\n* fix(providers): address env profile review feedback\n\n* fix(providers): keep env JSON response schemas stable",
          "is_bot": false,
          "headline": "fix(providers): stop \"provider not found\" for env-derived profiles (#…",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-20T02:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0b6b9e5c96fcedb7905999cdcb501cce2af7247",
          "body": "…711)\n\n* docs(readme): note govulncheck/golangci-lint install to GOPATH/bin\n\nThe installed binaries land in $GOPATH/bin (default ~/go/bin), which must\nbe on PATH to run govulncheck directly. Document the export snippet so the\nlint/security tooling from the contributor setup actually resolves.\n\n* doc\n[…]\nlback, and\nrerunning the old snippet appended the same directory repeatedly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): note govulncheck/golangci-lint install to GOPATH/bin (#…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-20T02:21:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d74ceb11271ed68a21c19248210e098f411805fb",
          "body": "* fix(tui): cache settled alt-screen transcript\n\n* fix(tui): invalidate settled alt-screen cache on in-place status row updates\n\nsetDoctorStatusRow, setSandboxSetupStatusRow, and setCompactStatusRow all\nmutate an already-flushed transcript row in place (m.transcript[i] = row)\nwithout invalidating th\n[…]\now, so the next settle rebuilds the cache.\n\nAddresses PR #647 review feedback from Vasanthdev2004.\n\n* fix(tui): invalidate settled transcript cache\n\n* fix(tui): invalidate settled file selection cards",
          "is_bot": false,
          "headline": "fix(tui): cache settled alt-screen transcript (#647)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-20T02:20:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fbf85984f679058125951fe2d5e4f200e09a3e2f",
          "body": "A model that calls write_stdin with no live session probed sequential\nsession_ids (1, 2, 3, …), each failing, and the run ground on for a long\ntime before halting. The repeated-failure guard keys on a normalized,\n80-char-truncated signature of the tool error, and the old message\n\"Unknown exec sessio\n[…]\nold, plus the schema floor and the\nrecovery text. The TUI \"Sent input\" label on a failed write_stdin\n(issue criterion 4) is a separate cosmetic concern in a shared hot path\nand is left as a follow-up.",
          "is_bot": false,
          "headline": "fix(agent): stop write_stdin session_id probing thrash (#702) (#749)",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-19T16:43:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9242b9e037eb9b38f90e7fa076b5228a759697ae",
          "body": "* Add transcript-grounded structured task state\n\nProject existing plan, tool-result, changed-file, verification, and completion events into a deterministic per-run snapshot.\n\nEmit content-free aggregate snapshots to traces. Carry bounded objective context through compaction and ground completion che\n[…]\nested: go run ./cmd/zero-release smoke\n\nTested: govulncheck ./... (no vulnerabilities found)\n\nAdvisory: pinned golangci-lint reports only unrelated pre-existing findings\n\nTested: git diff HEAD --check",
          "is_bot": false,
          "headline": "Add transcript-grounded structured task state (#761)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-19T16:08:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e267bdbee4a77813e93a7ab51f0c575b66cee8c",
          "body": "* feat(tui): add isolated btw conversations\n\nAdd /btw with inline-question support, isolated non-resumable session forks, background main-run routing, and safe return behavior.\n\nRefs #637\n\n* test(tui): cover btw return controls\n\nPreserve drafts when Ctrl+C is pressed during an active BTW run and cover returning to the parent through the documented /btw toggle.\n\n* Address BTW isolation review feedback\n\n* Reject explicit resumes of side sessions\n\n* Harden BTW isolation lifecycle",
          "is_bot": false,
          "headline": "feat(tui): add isolated /btw conversations (#748)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-19T15:07:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "739a47e3eac92c3decc8734f52a4d99c7480c3ca",
          "body": "* perf(agent): preserve prompt cache prefixes\n\nBuild the system prompt once per run, fingerprint the exact emitted prompt and ordered tool definitions, and expose the full system-prompt hash in traces.\n\nAdd normalized and serialized two-turn regressions covering append-only messages, stable tools, a\n[…]\norder\n\nReturn registered tools in name order so provider-visible tool lists and prompt-prefix fingerprints cannot drift with Go map iteration. Add a regression covering the registry ordering contract.",
          "is_bot": false,
          "headline": "perf(agent): preserve prompt cache prefixes (#760)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-19T14:59:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce4a996ffac4482e704f0fd61b3e442398fb2401",
          "body": "Discovery metadata was merged without the https/loopback endpoint rule that\nconfigured endpoints already pass, letting a malicious issuer downgrade the\nauthorization/token/device/registration endpoint after config validation.\n\n- Add exported ValidateEndpointURL as the single endpoint-safety rule;\n  \n[…]\niscovered endpoint before merge in the provider resolveEndpoints\n  and validate resolved MCP metadata in both branches; fail closed on insecure.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(oauth): validate discovered endpoints before merge/use (#511) (#739)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-19T04:26:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "378d538e240c289e57821e9f9628f76034419d01",
          "body": "…0b+PR10c) (#740)\n\n* perf(agent): execution profiles, --exec-profile, bench passthrough, TUI /profile (PR10b+10c)\n\n* fix(execprofile): harden profiles against review findings\n\n- fast escalates on critical-risk mutations, not high: the sandbox marks\n  every shell command high before command analysis,\n[…]\ning may\nlegitimately be empty); an unknown ring preserves an explicit preference,\nmatching the cross-provider picker's behavior, while the profile's own\nfill still applies only where support is known.",
          "is_bot": false,
          "headline": "perf(agent): execution profiles with one-shot posture escalation (PR1…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T19:23:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "015452c1c98a39eabb021324182094e188a8bd47",
          "body": "…reps (#737)\n\n* fix(perfbench): keep the stamped answer file out of negative oracle greps\n\n* fix(perfbench): exclude stamped answer from positive oracle greps too",
          "is_bot": false,
          "headline": "fix(perfbench): keep the stamped answer file out of negative oracle g…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T17:24:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af875df58775484304fc65586bd6c74552ad01a2",
          "body": "* trace(perf): add posture escalation counter\n\n* feat(agent): typed posture-escalation policy and tool-result risk field\n\n* feat(agent): posture controller wiring and executed-risk stamping\n\n* test(agent): cover posture controller, escalation act path, and risk stamping\n\n* test(agent): pin zero risk on not-executed results\n\n* fix(agent): wire uncertain-path escalation and validate risk thresholds",
          "is_bot": false,
          "headline": "perf(agent): posture-escalation signals and controller (PR10a) (#736)",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T17:02:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbd94430143df6754d68551d1028ad8f15b82f1b",
          "body": "…rst-class (#730)\n\n* fix(perfbench): absolutize the bench binary and make errored tasks first-class\n\n* fix(perfbench): state that errored tasks count as pass-rate failures\n\n* fix(perfbench): align errored-task wording with the actual tier accounting\n\n* chore(perfbench): never commit generated baseline reports",
          "is_bot": false,
          "headline": "fix(perfbench): absolutize the bench binary and make errored tasks fi…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T16:09:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fae754460832bbb557c0880cbe2abea8a9d1011",
          "body": "* docs: refresh repository agent guidelines\n\n* docs: make validation guidance non-mutating",
          "is_bot": false,
          "headline": "docs: refresh repository agent guidelines (#734)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-18T16:07:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cc6f43bf7f6f7c6d9f654113dc2141ec3acfc5b",
          "body": "… ideas (#732)\n\n* docs(community): wire Discussions as the front door for questions and ideas\n\n* docs(community): restore LF endings and make feature routing coherent",
          "is_bot": false,
          "headline": "docs(community): wire Discussions as the front door for questions and…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T16:04:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77960229b839dca856616f846839aa773f2923f7",
          "body": "* fix(doctor): report missing npm native binary in wrapper\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(doctor): preserve JSON output for missing native binary\n\n* fix(doctor): preserve doctor CLI behavior in wrapper fallback\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* style: gofmt\n[…]\nme copy. Add regression tests with ZERO_WRAPPER_SIMULATE_BUN to guard against future drift.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(doctor): detect missing native binary during runtime checks (#450)",
          "author_name": "uma-prasad",
          "author_login": "michaelkillgta",
          "committed_at": "2026-07-18T14:49:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "60dc84e7a38c5544ebc047f3cfaf4625dd1e83b5",
          "body": "…telemetry (PR8) (#723)\n\n* trace(perf): add provider prewarm span and prefix-stability counters\n\n* feat(openai): optimized turn session with prewarm and prefix telemetry\n\n* feat(providers): gate optimized OpenAI turn sessions behind env flag\n\n* feat(cli): wire optimized turn sessions into headless e\n[…]\nnsports, fingerprint wire order and cache key\n\n* test(openai): pin keep-alive transports in probe-expecting tests\n\n* feat(providers): preserve resolved capabilities on switched-model fallback sessions",
          "is_bot": false,
          "headline": "perf(openai): optimized turn session — background prewarm and prefix …",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T08:54:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30e2c3f7ffa1d5e487bd10b59d4e823cda191d48",
          "body": "…er (PR7) (#720)\n\n* perf(providers): add provider capabilities and default turn-session adapter (PR7)\n\n* fix(providers): project effective reasoning efforts into capabilities\n\n* feat(agent): carry optimized turn sessions across mid-run model switches\n\n* test(agent): cover swap-time session open failure",
          "is_bot": false,
          "headline": "perf(providers): provider capabilities and default turn-session adapt…",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-18T04:03:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18cce358a29409ab937e92ff9af77bf98749f6aa",
          "body": "Extract completion decisions from the agent loop into a feature-gated typed policy with complete, incomplete, and uncertain outcomes. Preserve bounded plan-stall nudges and allow at most one semantic acceptance check for self-correcting runs.\n\nTested: make build\n\nTested: make test\n\nTested: go fmt ./...\n\nTested: go vet ./...\n\nTested: make lint\n\nTested: govulncheck ./...\n\nNote: repository-wide pinned golangci-lint reports 36 pre-existing unrelated findings; internal/agent/... reports 0 issues.",
          "is_bot": false,
          "headline": "Add deterministic completion policy (#719)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-17T18:59:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5670c427ff39c628fb0822fd5c9317ee2174583",
          "body": "* perf(output): add token-aware budget contract\n\n* perf(output): add semantic retention policies\n\n* perf(output): budget results after redaction\n\n* perf(output): propagate tool truncation metadata\n\n* perf(output): trace semantic budget decisions\n\n* perf(output): classify core tool output\n\n* docs(out\n[…]\n hook budgets and search paths\n\n* fix(output): preserve alias and truncation metadata\n\n* test(trace): validate output budget metadata\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "perf(output): add token-aware semantic output budgeting (PR11) (#717)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-17T18:32:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31d45d5f14e915acb9946e8b8eb81632c48f126a",
          "body": "…715)\n\nUpgrade the parallel tool planner from SideEffectRead probes to the PR5\nCapabilitiesOf contract: EffectReadOnly + ThreadSafe + auto-allowed, with\nresource-key conflict boundaries so same-path reads stay sequential.\n\nMark audited pure reads ThreadSafe (read_file, read_minified_file,\nlist_direc\n[…]\ne-conflict).\n\nTests cover the capability gate, key conflicts, extendParallelRun windows,\nand catalog ThreadSafe audit for concurrent-safe reads.\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "perf(agent): concurrent read-only tool batches via capability gate (#…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-17T12:22:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "727ad4d321fab45d0cf40f8535522e3d94e55c4a",
          "body": "…misread as correctness (#712)\n\n* perf(turn-bench): Phase 0 — strengthen oracles so pass rate can't be misread as correctness\n\nThe baseline manifest's pass/fail contract had three holes that let a weak\nor no-op agent read as a pass:\n\n  - edit grep oracles were substring checks: a reworded line (e.g.\n[…]\nfactor-05 removed from the\n'no oracleTest' inventory (it now has TestGreetWrapped); the nav-01 named-\nfact prose corrected to the three files the oracle actually anchors on;\ntest comment #701 -> #712.",
          "is_bot": false,
          "headline": "perf(turn-bench): Phase 0 — strengthen oracles so pass rate can't be …",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-17T12:02:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e666395d47a059a54c9cf00ab251d127ecc4f21f",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.4.0 (#625)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T05:25:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9043baedcff7776c7373645b57563cac06b31847",
          "body": "* fix(sandbox): scrub dynamic credential env vars\n\n* fix(sandbox): tolerate env assignments in configured sensitive keys\n\nA config value mistakenly given as a full assignment (e.g.\n\"COMPANY_LLM_SECRET=...\") would never match the real env key during\nscrubbing, silently re-exposing the credential to s\n[…]\negraded-fallback\npath with both a configured and a dynamically named secret.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sandbox): scrub dynamic credential env vars (#682)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-17T05:04:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4d8c31cf16a3080344e3be7039408fcae71c075d",
          "body": "…ride user disable (#609)\n\nA user-level MCP server disable is now sticky. The project config\n(a cloned repo's ./.zero/config.json) cannot re-enable a server the\nuser disabled, and cannot disable a server the user explicitly enabled.\n\nThe previous merge just assigned base.Disabled = next.Disabled, so\n[…]\n ignored.\n\nPorts the fix onto main's refactored MCP merge (internal/config/mcp_merge.go\nand mergeProjectMCPConfig), which splits project-scope merging from the\ngeneral mergeMCPConfig path.\n\nFixes #512",
          "is_bot": false,
          "headline": "fix(config): enforce MCP trust boundary so project config cannot over…",
          "author_name": "Ashwinhegde19",
          "author_login": "Ashwinhegde19",
          "committed_at": "2026-07-17T05:03:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "824ecdbcf9c467c35ef4e2666770fdadcb5bf402",
          "body": "* fix(hooks): run sessionEnd hooks after Esc/Ctrl+C interrupts\n\nOn interrupt, Run returns with ctx already canceled. The deferred\ndispatchSessionEnd call passed that same ctx into Hooks.Dispatch, whose\ncontext.WithTimeout derives an already-canceled child context, so the\nhook process never actually \n[…]\nude Sonnet 5 <noreply@anthropic.com>\n\n* test(agent): fall back to GOROOT for hook regression\n\n* test(agent): justify GOROOT fallback\n\n---------\n\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hooks): run sessionEnd hooks after Esc/Ctrl+C interrupts (#606)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-17T05:03:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b9c2f0c083e02bcd3aad68fb7af0501a9e7cd61",
          "body": "…y issuance) (#655)\n\n* feat(aimlapi): AI/ML API guided onboarding (top-up + key issuance)\n\nAdd the AI/ML API provider integration to the zero CLI: a guided TUI\nonboarding sub-flow that takes an existing key or an email top-up and\nwrites the issued key into the provider profile, attributed to the\nGit\n[…]\nheckout responses\n\n* fix(providers): reconcile aimlapi catalog after rebase\n\n---------\n\nCo-authored-by: Lookoff123 <bataryshkinairina@gmail.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(aimlapi): AI/ML API provider with guided onboarding (top-up + ke…",
          "author_name": "StanAIML",
          "author_login": "Lookoff-AIMLAPI",
          "committed_at": "2026-07-17T04:49:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ef8576df7d0775a5b815bc0776a794cadb75c34",
          "body": "* perf(tools): add explicit tool effect metadata\n\nIntroduce fail-closed EffectClass and ToolCapabilities on every built-in\ntool so a later concurrent read-only batch PR can decide safety from\nexplicit metadata rather than tool names. Plugin and MCP tools stay\nEffectUnknown. No concurrent execution i\n[…]\n for conflict keys\n- Validate constructor-declared capabilities before normalization\n- Unify session/process ID key extraction helper\n\n---------\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "perf(tools): add explicit effect metadata for safe concurrency (#705)",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-17T04:48:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1c5c6e78a8a0e228bdf53d7be90934fbce9d98c3",
          "body": "Compute a seven-field SHA-256 fingerprint of the cacheable prompt\nprefix (base instructions, confirmation policy, project context, skills,\ntools, tool schemas, complete) and emit one prefix_hash event per turn\nthrough the trace recorder. The complete hash is the SHA-256 of the\ncanonical join of the \n[…]\ns unchanged; the fingerprint is purely\nadditive observability. The Anthropic cache_control breakpoint work\nalready in main is not touched.\n\nCo-authored-by: anandh8x <anandh8x@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(perf): emit prompt-prefix hash fingerprint per turn (#704)",
          "author_name": "Anandan",
          "author_login": "anandh8x",
          "committed_at": "2026-07-17T04:47:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f669f455021be51319ee3b8298cd48a17f745c7",
          "body": "* feat(tui): Ctrl+X leader chords and emacs menu navigation\n\nAdd Ctrl+X leader shortcuts for common slash commands (with Ctrl+X ?\nchord map), and Ctrl+P/N previous/next selection in modals and pickers.\n\n* fix(tui): drop Ctrl+X e /edit leader chord\n\n/edit replaces the composer and would discard an in\n[…]\nN as a no-op\n\nReserve Ctrl+N for emacs menu navigation so it never falls through to\nremapped global bindings when no selection surface is open.\n\n* docs: drop manual CHANGELOG entries for TUI shortcuts",
          "is_bot": false,
          "headline": "feat(tui): Ctrl+X leader chords and emacs menu navigation (#699)",
          "author_name": "Leonardo Faoro",
          "author_login": "lfaoro",
          "committed_at": "2026-07-17T04:44:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b42cd567b96d6f7e0818594e53ff31cce1e42e9",
          "body": "… (#672)\n\n* fix(tui): stop the composer cursor blinking while typing or unfocused\n\nThe composer's cursor blinked on a fixed timer unconditionally, including\nmid-keystroke, which made typing feel janky since the cursor's job is to mark\nthe current position. Gate the existing blink tick on two states \n[…]\n.PasteMsg and right-click clipboardReadMsg paths, so a paste right after\nthe blink phase hid the caret renders solid immediately instead of waiting\nfor a tick that would toggle off a stale idle state.",
          "is_bot": false,
          "headline": "fix(tui): stop the composer cursor blinking while typing or unfocused…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-17T04:43:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "665bd4b3d0c6c54c6622bfa44b6e024d2acc06d9",
          "body": "* draft(tui): add theme interface and Claude/Codex presets proposal\n\nIntroduces the Theme interface alongside the initial specifications and styling models for the Claude (card-based, warm) and Codex (high-density, split-screen cyberpunk) layout presets. Detailed design plans are documented in docs/\n[…]\ngs.\n- docs/THEMES.md no longer claims the extended invariants run against the\n  whole registry: it now says new palettes must be added to the\n  per-palette contrast tests or given equivalent coverage.",
          "is_bot": false,
          "headline": "WIP: feat(tui): TUI theme presets (Dune and Neon) (#634)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-17T04:38:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9acb4113cc3337b3f361a16278e9cf11ca105e34",
          "body": "* feat(cli): show ZERO wordmark on --version\n\nThe TUI's empty-state ZERO ascii art gets exposed via a new tui.Wordmark\nhelper and printed above the version line for `zero -v`/`--version`.\nColoring only applies when stdout is a real TTY and NO_COLOR isn't set,\nso redirected or piped output (scripts p\n[…]\nerminals. The terminal's default foreground works on any background.\n- smokeVersion goes back to requiring the exact \"zero <version>\" output\n  instead of the suffix match that papered over the banner.",
          "is_bot": false,
          "headline": "feat(cli): show ZERO wordmark on --version (#673)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-16T15:02:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d66a9dda69c32aa59f4bea903cfefe00d4b7adef",
          "body": "* feat(providers): add AI/ML API preset\n\n* fix(providers): relocate aimlapi preset and drop referral header\n\nAddresses the two review asks on #402:\n\n- Move the AI/ML API descriptor out of catalog slot #2 (it sat above the\n  first-party OpenAI/Anthropic/Google entries) down next to openrouter in\n  th\n[…]\ny: Dmitry Tumanov <d1m7asis@gmail.com>\nCo-authored-by: Vasanthdev2004 <vasanth.dev2004@gmail.com>\nCo-authored-by: Cursor <cursoragent@cursor.com>\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "feat(providers): add AI/ML API preset (rebased onto main) (#621)",
          "author_name": "404ҜĦΔƗ",
          "author_login": "404khai",
          "committed_at": "2026-07-16T14:57:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7d579996b43741a2e57e3e38fcdd8484fcfc34e9",
          "body": "…loading (#696)\n\n* feat(skills): discover shared ~/.agents/skills with multi-root skill loading\n\nAdd ~/.agents/skills as a read-only global discovery root after the\nprimary\nZero skills dir and before plugin roots. Unify runtime and CLI discovery\non\none multi-root path (DiscoveryRoots / LoadFromRoots\n[…]\nrror on Windows\n\nWindows maps ENOTDIR to ErrNotExist, so ReadDir on a regular file looked\nlike a missing skills dir. Reclassify existing non-directories and assert\nthe portable load behavior in tests.",
          "is_bot": false,
          "headline": "feat(skills): discover shared ~/.agents/skills with multi-root skill …",
          "author_name": "Leonardo Faoro",
          "author_login": "lfaoro",
          "committed_at": "2026-07-16T13:59:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abe24bcb10244c57e6b7d30acf3aa2a58d6081d0",
          "body": "…(#700)\n\n* Add per-turn tracing and a turn-benchmark harness (Phase 0 baseline)\n\nIntroduce an opt-in `internal/trace` package that attributes a run's wall\ntime to named spans — prompt build, provider connect/queue, generation,\ntool queue/execution, permission wait, verification, compaction,\npersiste\n[…]\nildOnlyClasses field (taskbench.go), and the PR body already says\n'48-task manifest'. The Share->exclusiveShare rename is tracked in #701.\n\ngo build/vet/gofmt clean; go test -race green for perfbench.",
          "is_bot": false,
          "headline": "Add per-turn tracing and a turn-benchmark harness (Phase 0 baseline) …",
          "author_name": "Vasanth T",
          "author_login": "Vasanthdev2004",
          "committed_at": "2026-07-16T13:58:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "75a78e715bf23154f69c8c79cb58eb4b535b2a2a",
          "body": "* feat(cli): wire MCP serve WorkspaceRoot and --add-dir scope\n\nPass the resolved workspace into mcp.ServeOptions and honor --add-dir so\nresources/list and scoped tools can expose extra roots beyond cwd.\n\n* fix(cli): keep lexical serve --add-dir roots for path matching\n\nUse symlink-resolved paths only for deduplication so Scope roots stay\naligned with the un-evaluated WorkspaceRoot MCP serve already passes.",
          "is_bot": false,
          "headline": "feat(cli): wire MCP serve WorkspaceRoot and --add-dir scope (#694)",
          "author_name": "Felix-Ayush",
          "author_login": "Ayush7614",
          "committed_at": "2026-07-15T13:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "850244943031a3cbe0f20714d00e896f355a81cc",
          "body": null,
          "is_bot": false,
          "headline": "test(tui): isolate provider wizard credentials (#688)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-15T13:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0bcfdda41e08dfd18bfbde4cd89a3fe1c1c416c",
          "body": "Updates charm.land bubbles/bubbletea/lipgloss v2, golang.org/x/sys,\ngolang.org/x/sync, and dlclark/regexp2/v2 to their latest patch releases.",
          "is_bot": false,
          "headline": "chore(deps): bump go module dependencies (#669)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-15T13:06:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bb6b5745af90321d1e657a12a1976cded5dd1bd",
          "body": "The launcher recording a spawn and the job's Runs counter incrementing\nare sequential but distinct steps in the scheduler goroutine\n(fireIfIdle's Spawn call, then run's job.incRuns()). The test polled\nonly the launcher's recorded count, then asserted Runs immediately\nwith no wait, so a scheduler goroutine preempted between those two\nsteps could be observed with a stale Runs value under CI load. Wait\nfor Runs itself instead of assuming the launcher signal implies it.",
          "is_bot": false,
          "headline": "fix(swarm): wait for job.Runs directly in scheduler skip test (#667)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-15T13:05:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fc1220f6ac66fb3ae67b637cbbed7068d2213c0",
          "body": "…660)\n\n* fix(windows): retry atomic file renames on Access is denied / Sharing violation\n\n* test(swarm): add unit tests for rename retry and non-retryable errors\n\n* test(swarm): skip TestMailboxRenameRetry on non-Windows platforms\n\n* fix(sandbox): scrub sensitive provider credentials from sandbox en\n[…]\nensitiveEnv's sensitiveKeys list: both are real bearer secrets read\nfrom the environment but were missing from the scrub list, leaving them\nreadable by sandboxed commands when set in the parent shell.",
          "is_bot": false,
          "headline": "fix(sandbox): scrub sensitive credentials from sandbox environment (#…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T13:46:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80c39aa599b6a1caf1ce229c40efbc8157983ae9",
          "body": null,
          "is_bot": false,
          "headline": "docs: add codebase minimization guideline to AGENTS.md (#661)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T07:15:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bd9742fa95c41b93ea4e718628aed0ff3ae9dd0",
          "body": "…ox denials (#659)\n\n* fix(tools): classify silent wrapped Windows command failures as sandbox denials\n\nA Windows restricted-token sandbox failure is often completely silent:\nwhen the token cannot open the target executable or its DLLs (or an\nMSYS runtime dies during init), the command exits nonzero \n[…]\nnd in the silent-denial test\n\nThe heuristic treats windows-elevated identically to\nwindows-restricted-token, but only the latter was exercised.\nParameterize the silent-failure test over both backends.",
          "is_bot": false,
          "headline": "fix(tools): classify silent wrapped Windows command failures as sandb…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T07:13:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91ea6ded7503538834a84d090f78670a363c62d3",
          "body": "* fix(keyring): pass generic password via stdin on macOS\n\nPass the generic password secret to security add-generic-password via stdin instead of passing it as a command-line argument. This prevents the secret from leaking to the local process list (visible via ps) and aligns the macOS keyring implem\n[…]\nslash and\ndouble quote escaped inside double quotes). The parser is line-based with a\n4096-byte buffer, so Set rejects newlines and oversized payloads up front\nrather than corrupting the stored value.",
          "is_bot": false,
          "headline": "fix(keyring): pass generic password via stdin on macOS (#574)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-14T06:46:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa3052a1422a4ad30a3a6295829564f42dee31a8",
          "body": "Co-authored-by: octo-patch <266937838+octo-patch@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(providers): refresh MiniMax model coverage (#665)",
          "author_name": "Octopus",
          "author_login": "octo-patch",
          "committed_at": "2026-07-13T14:33:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c986d327b5ed26338d295c23bea5839681db8d0",
          "body": "* feat(tui): press up to edit queued messages\n\nPressing up with a message queued pops it back into the composer for\nediting, taking priority over history recall. While a message is queued\nthe empty composer shows a hint placeholder. A second prompt queued\nduring the same run now stacks under the first instead of replacing it.\n\n* refactor(tui): remove openclaude references from queued_message comments",
          "is_bot": false,
          "headline": "feat(tui): press up to edit queued messages (#656)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T14:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5d2e327c8681671aa8a9e5378801215b747edcf",
          "body": "…onfigured (#658)\n\nRemoving the WRITE_RESTRICTED flag in #612 made the restricted-SID check\napply to reads as well as writes. Default Windows DACLs grant\nBUILTIN\\Users rather than any SID in the token's restricted list\n(random capability SIDs, logon SID, Everyone), so the sandboxed process\ncould no \n[…]\ned token and trade spawn\ncapability for read-deny enforcement. DenyRead is empty by default, so\nthe common case regains a working sandbox while #612's guarantee holds\nfor the profiles that rely on it.",
          "is_bot": false,
          "headline": "fix(sandbox): use WRITE_RESTRICTED token when no DenyRead paths are c…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T14:17:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c4815a66ed07d9cf90b825adfd936d3ac07639d",
          "body": "… sandbox (#654)\n\n* fix(sandbox): stop blocking git fetch/commit/add by unblocking .git writes\n\nThe sandbox denied every write under .git for shell-executed commands,\nso any git operation that touches its own metadata (fetch, commit, add,\npull, merge, stash) failed under the default sandbox. Narrow \n[…]\nonly converted a bare backslash, so\nthe Windows smoke run diverged from the forward-slash golden. Replace all\nbackslashes with slashes during normalization so the shared golden passes on\nevery runner.",
          "is_bot": false,
          "headline": "fix(sandbox): unblock git fetch/commit/add under the write-restricted…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T13:56:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "635c93af51ebc20f3e0917917e55a79edfe27c35",
          "body": "* fix(agent): raise default and deep-mode turn budgets\n\nThe default per-run tool-turn budget of 50 was still too low for larger\nmulti-step tasks that span several files: agents hit the ceiling and\nstopped with a \"remaining work\" summary instead of finishing. Raise the\ndefault from 50 to 80.\n\nThe \"de\n[…]\n runs get a genuinely larger budget again.\n\nUsers can still override per-session with /turns or --max-turns (bounded\nby MaxTurnsCeiling).\n\n* test(cli): expect deep-mode MaxTurns=160 after budget raise",
          "is_bot": false,
          "headline": "fix(agent): raise default and deep-mode turn budgets (#650)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T13:54:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "893b7b424cc203a2fcf92327a4e25c84286a90e0",
          "body": "… dropping them (#645)\n\n* fix(config): surface unknown/typo'd config fields instead of silently dropping them\n\njson.Unmarshal ignores unknown JSON keys by default, so typos such as\n\"maxTurn\" or \"sandbox.network\" were silently discarded: the user\nbelieved a setting (e.g. a sandbox hardening option) w\n[…]\n the unknown-field test assertions order-independent (search by\n  FieldPath instead of assuming issues[0]).\n\nAdd regression coverage for legacy provider keys and valid case\nvariants not being flagged.",
          "is_bot": false,
          "headline": "fix(config): surface unknown/typo'd config fields instead of silently…",
          "author_name": "Ashwinhegde19",
          "author_login": "Ashwinhegde19",
          "committed_at": "2026-07-13T13:52:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da41c3a75b782d6e0836fe13346321e40a90fbb4",
          "body": "… (#628)\n\n* fix(lock): prevent POSIX lock file overwrite and leak on Windows/Unix\n\nDuring lock reclamation, reclaiming a suspected stale lock renames the file aside and renames it back if not stale. On POSIX systems, the rename back silently overwrites any new lock file created in the gap. On Window\n[…]\nrite a competing\nlock rather than detect it. A fully race-free reclaim would need an\nOS-level advisory lock checked non-destructively instead of by moving\nthe file, which is a larger change than this.",
          "is_bot": false,
          "headline": "fix(lock): prevent POSIX lock file overwrite and leak on Windows/Unix…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-13T13:45:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a5b7fd5b8af636ecb8ff8d796e7cf6ebcf20f78",
          "body": "…26+ (#635)\n\n* docs: add Go code quality & security checks and bump Go version to 1.26+\n\n* docs: address CodeRabbit review comments and use pinned versions and Go 1.26.5+\n\n* docs: remove trailing blank lines at end of AGENTS.md\n\n* docs: add missing /v2/ segment to golangci-lint install path\n\nThe go \n[…]\n the same section already\nhad the correct v2 path.\n\n* docs: trim AGENTS.md below 8 KiB guideline and clean up README cross-compile header\n\n* docs: address CodeRabbit review feedback on extending guide",
          "is_bot": false,
          "headline": "docs: add Go code quality & security checks and bump Go version to 1.…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-12T14:37:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "212734adf3b5f982e22385161205aa1afe4634fe",
          "body": "…name (#631)\n\nWhen writing credentials or generating user secrets, files are written using a write-to-temp-then-rename pattern. However, neither package called Sync (fsync) on the temporary file before closing and renaming. If a crash or power failure occurred shortly after write, this could result in truncated or 0-byte key/credential files on disk.\n\nAdd tmp.Sync() calls to writeNewSecretFile and Store.write to guarantee durability.",
          "is_bot": false,
          "headline": "fix(securefile,credstore): call Sync on temp file before close and re…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-12T14:35:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2efe6d539e29374b3ef39c2290bdea81f33a228b",
          "body": "…#627)\n\n* fix(plugins): resolve relative executable paths against plugin root\n\nWhen a plugin registers a tool or a hook command as a relative path (e.g. ./tools/helper.sh), running it in the caller's workspace CWD allows local execution hijacking by placing a malicious script at that path in the unt\n[…]\n permission was always overwritten by one of\nthe switch arms below it, including a case that just reassigned the\nsame PermissionPrompt value the initializer already held. Flagged by\nineffassign in CI.",
          "is_bot": false,
          "headline": "fix(plugins): resolve relative executable paths against plugin root (…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-12T14:34:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e1405d0b7abff5b3ccb3cfdb66d64d6d3322922",
          "body": "…626)\n\n* feat(npm): ship the native binary as platform optionalDependencies\n\nReplace the postinstall downloader with Codex-style platform packages:\nsuffixed versions of @gitlawb/zero (X.Y.Z-<platform>-<arch>) carrying the\nbinary, sandbox helpers, and the vendored agent-browser/tuistory tree,\nreferen\n[…]\n platforms and say so honestly in the notice and docs.\n- Correct Windows support wording everywhere: x64 only, ARM runs under\n  emulation (README, README_ZH, INSTALL.md incl. the release-target list).",
          "is_bot": false,
          "headline": "feat(npm): ship the native binary as platform optionalDependencies (#…",
          "author_name": "Kevin Codex",
          "author_login": "kevincodex1",
          "committed_at": "2026-07-11T15:25:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1af58828eb3c22567599c000736c913a290959d2",
          "body": "…636)\n\nInteractive TUI always has a session ID, so every completion request\nforwarded OpenAI's prompt_cache_key. Strict openai-compatible gateways\n(e.g. NVIDIA NIM) reject unknown fields with a 400, while plain zero\nexec usually has no session and omits the field.\n\nDisable prompt_cache_key for ProviderKindOpenAICompatible; keep it for\nofficial OpenAI. ZERO_DISABLE_PROMPT_CACHE_KEY remains a global kill\nswitch.\n\nFixes #624\n\nCo-authored-by: KRATOS <kratos@KRATOSs-Mac-mini.local>",
          "is_bot": false,
          "headline": "fix(openai): omit prompt_cache_key for openai-compatible providers (#…",
          "author_name": "KRATOS",
          "author_login": "gnanam1990",
          "committed_at": "2026-07-10T13:43:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc06fe72caf45f72d2cba1e8a835c0f5b405c1e8",
          "body": "When executing a security-critical beforeTool hook, if the hook command fails to launch (e.g. binary not found, missing execute permission), it previously failed open and let tool execution proceed.\n\nUpdate classifyResult to return AuditBlocked, true when a launch error occurs on a beforeTool hook, enforcing a fail-closed policy. Observational afterTool hooks still fail open.",
          "is_bot": false,
          "headline": "fix(hooks): fail closed on launch failures for beforeTool hooks (#629)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T08:42:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4bd703cfb28dab2dfa3c2ddba46237e1bb2e164",
          "body": "… (#630)\n\nInside fireJob, the Mutate transaction callback previously returned the stale in-memory job copy (read at tick start). This clobbered any concurrent updates made to the job (such asExpr, Prompt, or Cwd edits) while the job was running.\n\nUpdate the callback to apply schedule and status changes directly onto the fresh current job loaded from disk, and return current.",
          "is_bot": false,
          "headline": "fix(cron): prevent cron job Mutate from clobbering concurrent updates…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T08:41:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa73a76f1bd1b6fe97bac2fbff2d61b7474139f2",
          "body": "…#620)\n\nWhen a run is completed or canceled (agentResponseMsg) while an askUser prompt is pending, or when a stale/superseded askUserRequestMsg is received, the answer callback is now invoked with nil. This unblocks the waiting agent loop goroutine, preventing goroutine leaks and runner hangs.",
          "is_bot": false,
          "headline": "fix(tui): resolve pending askUser callbacks to prevent runner hangs (…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:12:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b4f48d2dcb66402c13bde0c3cfe9c9371da19fb",
          "body": "When parsing CLI flags, positional prompt text placed immediately after flags requiring values (e.g. --auto, --notify, --max-turns) would be greedily consumed as their value by nextFlagValue. Refine nextFlagValue to validate choices/types (autonomy levels, notify modes, integers) to detect invalid values early and fail validation rather than eating positional arguments.",
          "is_bot": false,
          "headline": "fix(cli): prevent consuming positional arguments as flag values (#619)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f78b36c770daa4577a9f99265b18a354454e36eb",
          "body": "When falling back from a failed PTY start to a pipe execution, the command attributes are reset. Previously, resetExecCommandForPipeFallback set command.SysProcAttr = nil, which stripped custom settings like Windows CmdLine quoting. Update the fallback logic to restore the original SysProcAttr instance, and add TestStartExecProcessPTYFallbackPreservesSysProcAttr to cover.",
          "is_bot": false,
          "headline": "fix(tools): preserve SysProcAttr during PTY fallback (#618)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2db00ee3d57db97e0fbe23cb8628e8bcb47f6f09",
          "body": "… (#617)\n\nUsing unqualified taskkill / taskkill.exe commands on Windows can allow binary hijacking under certain conditions. Update all process termination callers on Windows to resolve the absolute path to taskkill.exe under System32 (referencing SystemRoot/windir environment variables, falling back to C:\\Windows).",
          "is_bot": false,
          "headline": "fix(windows): resolve absolute path for taskkill to prevent hijacking…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:08:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ea53841a5d54c37a153779ae86bea010659433c",
          "body": "…creation (#616)\n\nOn Windows, a concurrent holder's os.Remove leaves the lock file in a 'delete pending' state, causing a racing O_EXCL create to fail with ERROR_ACCESS_DENIED (mapped to os.ErrPermission). Treat os.ErrPermission as lock contention / already-existing lock, matching the collision checks in cron, hooks, oauth, and securefile.",
          "is_bot": false,
          "headline": "fix(daemon): handle os.ErrPermission as collision during O_EXCL lock …",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:07:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8536cc87f7a885f9e436d6ef28f5f325201623dc",
          "body": "…615)\n\n* fix(securefile): reclaim stale lock files to prevent permanent DOS\n\nWhen createSecretFile fails to acquire the O_EXCL lock because it already exists, check if the file is stale (older than 10 seconds). If so, atomically reclaim it via a rename-aside check, preventing a permanent DOS after a\n[…]\nshes. Update the lock file to write and verify process-specific tokens, and add TestCreateSecretFileReclaimsStaleLock to cover the stale reclaim flow.\n\n* style(securefile): gofmt const block alignment",
          "is_bot": false,
          "headline": "fix(securefile): reclaim stale lock files to prevent permanent DOS (#…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:07:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddc4927aac5544bf4dd2c46615aeda5a81c96576",
          "body": "truncateHint slices string hints using a raw byte offset (s[:max]), which can split multi-byte UTF-8 characters (like CJK characters, emojis, or accents) in half and produce invalid UTF-8 sequences. Update it to count and slice by runes to guarantee valid UTF-8, and add a unit test TestToolTitleTruncateHintRuneSafe to verify.",
          "is_bot": false,
          "headline": "fix(acp): make truncateHint rune-safe (#614)",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:05:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0184581ec234ea414e0a47bc33e8b0f4ddfb497b",
          "body": "…bdirectories (#613)\n\nCurrently, both gitBranchForPrompt (agent) and gitBranch (tui) check for a .git entry directly inside the current working directory. When starting Zero in nested folders/subdirectories of a repository, the check fails and the branch segment is omitted.\n\nExport findProjectGitRoo\n[…]\npackage, and use it in both functions to resolve the correct repository root before checking HEAD and resolving the branch name. Also resolve relative worktree gitdirs relative to the repository root.",
          "is_bot": false,
          "headline": "fix(agent,tui): resolve git branch detection when starting Zero in su…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:05:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d96ac7e55c760a97f28c0e6ceaf1ec3b4ab717a",
          "body": "…ss (#612)\n\nOn Windows, creating restricted tokens with windowsWriteRestricted (0x08) instructs the kernel to skip checking the restricted SIDs list for read operations. This bypasses DenyRead path policies on NTFS. Remove the flag to enforce restricted SID constraints on both read and write operations, and add integration test assertions to verify that DenyRead paths are correctly blocked.",
          "is_bot": false,
          "headline": "fix(sandbox): remove windowsWriteRestricted flag to fix DenyRead bypa…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T02:05:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdddb05ba84b1600ae6c3a20028bf83afe474c44",
          "body": "Co-authored-by: Gautam Manchandani <gautammanch@Gautams-MacBook-Air.local>",
          "is_bot": false,
          "headline": "fix: harden MCP credential boundaries (#597)",
          "author_name": "Gautam Manchandani",
          "author_login": "GautamBytes",
          "committed_at": "2026-07-10T01:00:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6117af86d6bc87a4ee66910e99d76cb16b03fed",
          "body": "…essages (#608)\n\n* fix(agent): scope self-reported incompletion to sentences about the current objective\n\nThe detector matched inability stems anywhere in the final message, so a\nconversational recap of a past exchange (\"You asked if I could work\nautonomously ... so I couldn't actually do it at the \n[…]\nmpletion-gate combined with --use-spec is now rejected at parse\ntime, mirroring the --self-correct check: the spec-draft path never\nconsults the completion gate, so the flag would be silently ignored.",
          "is_bot": false,
          "headline": "fix(exec): stop false INCOMPLETE downgrades on conversational final m…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-10T00:59:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "584ef75a46b58e5b87e42c68467ece523cec5ea6",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(main): release 0.3.0 (#537)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-09T15:19:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a880ce80a6ec72da511fb9bdf6dd69291c72a64b",
          "body": "…space trust (#529)\n\n* feat(workspacetrust): add exact-match trust store for project config gating\n\n* feat(hooks): add ExcludeProject option to LoadConfig\n\n* feat(plugins): add ExcludeProject option to Load\n\n* feat(cli): gate project hooks and plugins behind workspace trust\n\nTrust check lives inside\n[…]\not and the extensions listing) are enumeration-only and stay\nungated.\n\n* test(cli): adapt MCP startup-skip tests to two-arg resolveMCPConfig\n\n---------\n\nCo-authored-by: Kevin Codex <kevin@gitlawb.com>",
          "is_bot": false,
          "headline": "feat: gate project-scoped hooks, plugins, and MCP servers behind work…",
          "author_name": "beardthelion",
          "author_login": "beardthelion",
          "committed_at": "2026-07-09T02:51:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7cfb99fed7b88ebc09a2f251cb82864d3c2cade",
          "body": null,
          "is_bot": false,
          "headline": "fix: bump Go to 1.26.5 for crypto/tls fix (GO-2026-5856) (#607)",
          "author_name": "Kevin Codex",
          "author_login": "kevincodex1",
          "committed_at": "2026-07-09T02:02:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fc9b2d25c79e089f34cb7b5b6a7f7c7b8233123",
          "body": "…ermux) (#603)\n\n* fix(update): clearer error on unsupported release platform (android/termux)\n\nzero update/upgrade fails on Android/Termux because GOOS \"android\" has\nno published release archive. Replace the generic \"unsupported release\nplatform: android\" error with a clear, actionable message expla\n[…]\nfrom source. Termux runs zero fine via the npm wrapper; it just has no self-updating release archive. Point users at 'npm update -g @gitlawb/zero', the documented Termux install/upgrade path, instead.",
          "is_bot": false,
          "headline": "fix(update): clearer error on unsupported release platform (android/t…",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-09T01:34:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66a63964149fb2f07e646e5f1987627c5cd9ac28",
          "body": "* fix(modelregistry): reject oversized models.dev cache responses\n\nRead modelsDevFetchLimit+1 bytes instead of modelsDevFetchLimit. If the\nresponse exceeds the 32 MiB guard, return an error and leave any\nexisting cache untouched.\n\nFixes #510\n\n* address review: include byte count in error, make overs\n[…]\nad vs the limit\n- test payload is limit+1 bytes (matches the reported repro)\n- test explicitly clears ZERO_DISABLE_MODELS_FETCH so it exercises\n  the oversized path regardless of the outer environment",
          "is_bot": false,
          "headline": "fix(modelregistry): reject oversized models.dev cache responses (#602)",
          "author_name": "Ashwinhegde19",
          "author_login": "Ashwinhegde19",
          "committed_at": "2026-07-09T01:33:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a05e6486f7a63281b869064db03dfc5531e6a04",
          "body": "Co-authored-by: Gautam Manchandani <gautammanch@Gautams-MacBook-Air.local>",
          "is_bot": false,
          "headline": "perf(grep): stop content scan after head limit (#601)",
          "author_name": "Gautam Manchandani",
          "author_login": "GautamBytes",
          "committed_at": "2026-07-09T01:33:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92a92ceb29dc63f5216ab140ef9a6dd9afe17df8",
          "body": "…refixed model ids (#599)",
          "is_bot": false,
          "headline": "feat(modelregistry): infer reasoning efforts for Hunyuan and vendor-p…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-09T01:33:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "062328b632a2d27353a6d47c522bbd22d7282539",
          "body": "* fix: warn about untracked scratch files left behind after a run\n\nFixes #551. Headless exec runs could leave behind debug/scratch files\n(e.g. _fix_test.py, _debug.py) created by write_file during iteration,\nwhich would then be silently swept up by a later git add -A.\n\n- FileTracker now records bran\n[…]\ntch-created scratch files\n\n* fix: address scratch warning review feedback\n\n* fix: tighten scratch warning lifecycle\n\n---------\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: warn about untracked scratch files left behind after a run (#571)",
          "author_name": "PierrunoYT",
          "author_login": "PierrunoYT",
          "committed_at": "2026-07-09T01:25:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f10ed0c893ce6de08923f143d681ba96f0fcfe3a",
          "body": "…ix (#468)\n\n* merge: rebase onto main, combine Windows shell guidance with #476's MSYS text\n\n#476 merged into main and rewrote the same \"Shell syntax: Windows cmd.exe...\"\nguidance string in system_prompt.go and shellGuidanceForGOOS in\nshell_runtime.go that this branch also edits (this PR's fix for t\n[…]\nell syntax description test for exec_command\n\n* chore: retrigger CI after infra flake\n\n* style(tools): gofmt exec_command_test.go\n\n---------\n\nCo-authored-by: Vasanthdev2004 <vasanth.dev2004@gmail.com>",
          "is_bot": false,
          "headline": "fix(tools): Windows cmd.exe quoting guidance and clipboard escaping f…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-09T01:23:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a52d98cad7cd0086dee9aede4ce477e432bd385",
          "body": "…red (#586)\n\n* fix(mcp): skip RFC 8414 discovery when OAuth endpoints are preconfigured\n\nresolveAuthorizationServer performed a real network metadata discovery call even when the MCP server config already supplied both the authorization and token endpoints. When discovery blocks (offline, unreachabl\n[…]\nendpoints. Use a transport that\nfails the test on any outbound request so the fast path is actually\nwhat is being verified.\n\n---------\n\nCo-authored-by: gnanam1990 <gnanam1990@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(mcp): skip RFC 8414 discovery when OAuth endpoints are preconfigu…",
          "author_name": "euxaristia",
          "author_login": "euxaristia",
          "committed_at": "2026-07-09T01:21:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 5,
      "commits_last_year": 587,
      "latest_release_at": "2026-07-22T01:37:48Z",
      "latest_release_tag": "v0.5.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 8,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 4.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/Gitlawb/zero",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/Gitlawb/zero",
          "is_deprecated": false,
          "latest_version": "v0.5.0",
          "repository_url": "https://github.com/Gitlawb/zero",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-22T01:37:36Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "@gitlawb/zero",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@gitlawb/zero",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/Gitlawb/zero",
          "versions_count": 16,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3240,
          "first_published_at": "2026-07-02T07:09:39.913000Z",
          "latest_published_at": "2026-07-22T01:46:36.923000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 110,
      "stars": 1104,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-02",
            "count": 31
          },
          {
            "date": "2026-07-03",
            "count": 35
          },
          {
            "date": "2026-07-04",
            "count": 3
          },
          {
            "date": "2026-07-05",
            "count": 6
          },
          {
            "date": "2026-07-06",
            "count": 11
          },
          {
            "date": "2026-07-07",
            "count": 3
          },
          {
            "date": "2026-07-08",
            "count": 4
          },
          {
            "date": "2026-07-09",
            "count": 3
          },
          {
            "date": "2026-07-10",
            "count": 2
          },
          {
            "date": "2026-07-11",
            "count": 1
          },
          {
            "date": "2026-07-14",
            "count": 2
          },
          {
            "date": "2026-07-15",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 3
          },
          {
            "date": "2026-07-19",
            "count": 2
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 110,
        "total_forks": 110
      },
      "star_history": {
        "days": [
          {
            "date": "2026-07-02",
            "count": 145
          },
          {
            "date": "2026-07-03",
            "count": 487
          },
          {
            "date": "2026-07-04",
            "count": 94
          },
          {
            "date": "2026-07-05",
            "count": 43
          },
          {
            "date": "2026-07-06",
            "count": 65
          },
          {
            "date": "2026-07-07",
            "count": 41
          },
          {
            "date": "2026-07-08",
            "count": 31
          },
          {
            "date": "2026-07-09",
            "count": 11
          },
          {
            "date": "2026-07-10",
            "count": 16
          },
          {
            "date": "2026-07-11",
            "count": 9
          },
          {
            "date": "2026-07-12",
            "count": 9
          },
          {
            "date": "2026-07-13",
            "count": 8
          },
          {
            "date": "2026-07-14",
            "count": 10
          },
          {
            "date": "2026-07-15",
            "count": 5
          },
          {
            "date": "2026-07-16",
            "count": 5
          },
          {
            "date": "2026-07-17",
            "count": 3
          },
          {
            "date": "2026-07-18",
            "count": 7
          },
          {
            "date": "2026-07-19",
            "count": 4
          },
          {
            "date": "2026-07-20",
            "count": 4
          },
          {
            "date": "2026-07-21",
            "count": 2
          },
          {
            "date": "2026-07-22",
            "count": 1
          }
        ],
        "complete": false,
        "collected": 1000,
        "total_stars": 1104
      },
      "open_issues_and_prs": 89
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "internal/agenteval/testdata/fixtures/zero-mini/go.mod",
        "internal/perfbench/testdata/edit/go.mod",
        "internal/perfbench/testdata/fix/go.mod",
        "internal/perfbench/testdata/nav/go.mod",
        "internal/perfbench/testdata/refactor/go.mod"
      ],
      "largest_source_bytes": 217150,
      "source_files_sampled": 1231,
      "oversized_source_files": 16,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 3827
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 104,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "charm.land/bubbles/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.1"
        },
        {
          "name": "charm.land/bubbletea/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.8"
        },
        {
          "name": "charm.land/lipgloss/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.5"
        },
        {
          "name": "github.com/alecthomas/chroma/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.27.0"
        },
        {
          "name": "github.com/atotto/clipboard",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.4"
        },
        {
          "name": "github.com/aymanbagabas/go-udiff",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.1"
        },
        {
          "name": "github.com/charmbracelet/colorprofile",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.3"
        },
        {
          "name": "github.com/charmbracelet/x/ansi",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.11.7"
        },
        {
          "name": "github.com/charmbracelet/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.2"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.15"
        },
        {
          "name": "github.com/ledongthuc/pdf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250511090121-5959a4027728"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.47.0"
        },
        {
          "name": "mvdan.cc/sh/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.13.1"
        },
        {
          "name": "agent-browser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.30.1"
        },
        {
          "name": "tuistory",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.10.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "charm.land/bubbles/v2",
            "direct": true,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "charm.land/bubbletea/v2",
            "direct": true,
            "version": "v2.0.8",
            "ecosystem": "go"
          },
          {
            "name": "charm.land/lipgloss/v2",
            "direct": true,
            "version": "v2.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecthomas/chroma/v2",
            "direct": true,
            "version": "v2.27.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/atotto/clipboard",
            "direct": true,
            "version": "v0.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-udiff",
            "direct": true,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": true,
            "version": "v0.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": true,
            "version": "v0.11.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": true,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coder/websocket",
            "direct": true,
            "version": "v1.8.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ledongthuc/pdf",
            "direct": true,
            "version": "v0.0.0-20250511090121-5959a4027728",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "mvdan.cc/sh/v3",
            "direct": true,
            "version": "v3.13.1",
            "ecosystem": "go"
          },
          {
            "name": "agent-browser",
            "direct": true,
            "version": "0.30.1",
            "ecosystem": "npm"
          },
          {
            "name": "tuistory",
            "direct": true,
            "version": "0.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "github.com/charmbracelet/ultraviolet",
            "direct": false,
            "version": "v0.0.0-20260703014108-f5a850f9c2b7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/exp/golden",
            "direct": false,
            "version": "v0.0.0-20260615092313-b57e5e6d29bb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/termios",
            "direct": false,
            "version": "v0.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/windows",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/displaywidth",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/uax29/v2",
            "direct": false,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dlclark/regexp2/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-quicktest/qt",
            "direct": false,
            "version": "v1.102.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.24",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/cancelreader",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rogpeppe/go-internal",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260611194520-c48552f49976",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "@clack/core",
            "direct": false,
            "version": "1.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@clack/prompts",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-ws",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-darwin-arm64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-darwin-x64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-linux-arm64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-linux-x64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-win32-arm64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/core-win32-x64",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@opentui/react",
            "direct": false,
            "version": "0.2.16",
            "ecosystem": "npm"
          },
          {
            "name": "@resvg/resvg-wasm",
            "direct": false,
            "version": "2.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "@sec-ant/readable-stream",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sindresorhus/merge-streams",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "bun-ffi-structs",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "clone",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "defaults",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "errore",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-truncated-width",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-width",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-wrap-ansi",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "figures",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-them-args",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ghostty-opentui",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "goke",
            "direct": false,
            "version": "6.12.3",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.27",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-obj",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "kill-port-process",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "marked",
            "direct": false,
            "version": "17.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse-ms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "pid-port",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-ms",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-devtools-core",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-reconciler",
            "direct": false,
            "version": "0.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shell-quote",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "sisteransi",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-dedent",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "unicorn-magic",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "wcwidth",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "web-tree-sitter",
            "direct": false,
            "version": "0.25.10",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "7.5.11",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "yoctocolors",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "yoga-layout",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "zigpty",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "4.3.6",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 104,
        "direct_count": 15,
        "indirect_count": 89
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 43,
        "merged_prs": 531,
        "open_issues": 46,
        "closed_ratio": 0.678,
        "closed_issues": 97,
        "closed_unmerged_prs": 64
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "gnanam1990",
          "commits": 208,
          "avatar_url": "https://avatars.githubusercontent.com/u/84986124?v=4"
        },
        {
          "type": "User",
          "login": "Vasanthdev2004",
          "commits": 152,
          "avatar_url": "https://avatars.githubusercontent.com/u/148849890?v=4"
        },
        {
          "type": "User",
          "login": "anandh8x",
          "commits": 91,
          "avatar_url": "https://avatars.githubusercontent.com/u/223495731?v=4"
        },
        {
          "type": "User",
          "login": "euxaristia",
          "commits": 54,
          "avatar_url": "https://avatars.githubusercontent.com/u/25621994?v=4"
        },
        {
          "type": "User",
          "login": "PierrunoYT",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/95778421?v=4"
        },
        {
          "type": "User",
          "login": "kevincodex1",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/268502447?v=4"
        },
        {
          "type": "User",
          "login": "GautamBytes",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/161146829?v=4"
        },
        {
          "type": "User",
          "login": "Ashwinhegde19",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/107956700?v=4"
        },
        {
          "type": "User",
          "login": "KunjShah95",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/154980682?v=4"
        },
        {
          "type": "User",
          "login": "pengdst",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/40013467?v=4"
        }
      ],
      "contributors_sampled": 28,
      "top_contributor_share": 0.354
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "pr-auto-review.yml",
        "release-artifacts.yml",
        "release-please.yml",
        "zero-action-smoke.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 7,
            "reason": "SAST tool is not run on all commits -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a50574f673c3cb681937f02ce5f9be86e81beba8",
        "ran_at": "2026-07-22T02:06:55Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T01:46:47Z",
      "oldest_open_prs": [
        {
          "number": 489,
          "created_at": "2026-07-04T13:16:48Z",
          "last_comment_at": "2026-07-04T13:19:37Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 504,
          "created_at": "2026-07-05T01:50:44Z",
          "last_comment_at": "2026-07-06T06:05:09Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 532,
          "created_at": "2026-07-06T01:09:01Z",
          "last_comment_at": "2026-07-08T06:21:16Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 550,
          "created_at": "2026-07-06T08:58:17Z",
          "last_comment_at": "2026-07-11T08:37:14Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 570,
          "created_at": "2026-07-06T17:34:36Z",
          "last_comment_at": "2026-07-14T13:02:21Z",
          "last_comment_author": "pengdst"
        },
        {
          "number": 572,
          "created_at": "2026-07-06T23:40:21Z",
          "last_comment_at": "2026-07-11T15:33:05Z",
          "last_comment_author": "aitorse"
        },
        {
          "number": 590,
          "created_at": "2026-07-08T07:20:58Z",
          "last_comment_at": "2026-07-21T05:28:03Z",
          "last_comment_author": "glatinone"
        },
        {
          "number": 591,
          "created_at": "2026-07-08T08:43:15Z",
          "last_comment_at": "2026-07-14T03:28:28Z",
          "last_comment_author": "CengSin"
        },
        {
          "number": 594,
          "created_at": "2026-07-08T10:34:02Z",
          "last_comment_at": "2026-07-11T08:37:15Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 632,
          "created_at": "2026-07-10T03:44:44Z",
          "last_comment_at": "2026-07-22T00:08:29Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 640,
          "created_at": "2026-07-10T14:43:01Z",
          "last_comment_at": "2026-07-21T00:39:51Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 642,
          "created_at": "2026-07-10T14:52:42Z",
          "last_comment_at": "2026-07-20T11:08:06Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 643,
          "created_at": "2026-07-10T14:54:30Z",
          "last_comment_at": "2026-07-20T11:11:17Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 649,
          "created_at": "2026-07-10T17:03:57Z",
          "last_comment_at": "2026-07-10T17:31:44Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 668,
          "created_at": "2026-07-14T08:40:02Z",
          "last_comment_at": "2026-07-20T11:06:16Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 671,
          "created_at": "2026-07-14T10:27:53Z",
          "last_comment_at": "2026-07-20T11:07:56Z",
          "last_comment_author": "euxaristia"
        },
        {
          "number": 681,
          "created_at": "2026-07-14T19:13:47Z",
          "last_comment_at": "2026-07-20T16:05:44Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 685,
          "created_at": "2026-07-14T19:43:23Z",
          "last_comment_at": "2026-07-18T09:34:06Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 686,
          "created_at": "2026-07-14T19:55:29Z",
          "last_comment_at": "2026-07-14T19:57:50Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 689,
          "created_at": "2026-07-14T20:39:03Z",
          "last_comment_at": "2026-07-18T21:19:31Z",
          "last_comment_author": "PierrunoYT"
        }
      ],
      "last_merged_pr_at": "2026-07-22T01:37:36Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 390,
          "created_at": "2026-07-02T14:11:06Z",
          "last_comment_at": "2026-07-15T19:53:20Z",
          "last_comment_author": "lfaoro"
        },
        {
          "number": 404,
          "created_at": "2026-07-02T18:58:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 446,
          "created_at": "2026-07-03T11:17:53Z",
          "last_comment_at": "2026-07-05T20:20:31Z",
          "last_comment_author": "vshuraeff"
        },
        {
          "number": 447,
          "created_at": "2026-07-03T11:55:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 454,
          "created_at": "2026-07-03T13:22:35Z",
          "last_comment_at": "2026-07-03T13:36:09Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 488,
          "created_at": "2026-07-04T13:16:40Z",
          "last_comment_at": "2026-07-04T14:09:13Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 507,
          "created_at": "2026-07-05T07:59:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 508,
          "created_at": "2026-07-05T08:33:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 514,
          "created_at": "2026-07-05T11:00:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 530,
          "created_at": "2026-07-05T23:16:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 531,
          "created_at": "2026-07-05T23:19:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 534,
          "created_at": "2026-07-06T02:52:50Z",
          "last_comment_at": "2026-07-09T16:57:58Z",
          "last_comment_author": "pengdst"
        },
        {
          "number": 554,
          "created_at": "2026-07-06T10:45:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 556,
          "created_at": "2026-07-06T11:15:22Z",
          "last_comment_at": "2026-07-06T11:29:00Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 559,
          "created_at": "2026-07-06T12:26:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 566,
          "created_at": "2026-07-06T15:45:54Z",
          "last_comment_at": "2026-07-07T11:53:39Z",
          "last_comment_author": "PierrunoYT"
        },
        {
          "number": 569,
          "created_at": "2026-07-06T16:48:29Z",
          "last_comment_at": "2026-07-08T10:34:10Z",
          "last_comment_author": "baoyu0"
        },
        {
          "number": 579,
          "created_at": "2026-07-07T10:46:52Z",
          "last_comment_at": "2026-07-07T10:48:45Z",
          "last_comment_author": "gauravbhatia4601"
        },
        {
          "number": 584,
          "created_at": "2026-07-07T19:18:32Z",
          "last_comment_at": "2026-07-08T09:41:39Z",
          "last_comment_author": "Vasanthdev2004"
        },
        {
          "number": 592,
          "created_at": "2026-07-08T09:11:40Z",
          "last_comment_at": "2026-07-08T09:41:38Z",
          "last_comment_author": "Vasanthdev2004"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Gitlawb/zero",
    "host": "github.com",
    "name": "zero",
    "owner": "Gitlawb"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 73,
      "inputs": {
        "security": 62,
        "vitality": 72,
        "community": 74,
        "governance": 73,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 72,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 587,
              "human_commit_share": 0.97,
              "days_since_last_push": 0,
              "active_weeks_last_year": 8
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "8/52 weeks with commits",
                "points": 5.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "587 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 587
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 5,
              "latest_release_tag": "v0.5.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 4.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "5 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 74,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "forks": 110,
              "stars": 1104,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "window_too_short"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,104 stars",
                "points": 49.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1104
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "110 forks",
                "points": 17,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 110
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "github.com/Gitlawb/zero",
                "@gitlawb/zero"
              ],
              "dependents": null,
              "ecosystems": "go, npm",
              "total_downloads": null,
              "monthly_downloads": 3240
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,240 downloads/month across go, npm",
                "points": 46.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3240,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 73,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 28,
              "top_contributor_share": 0.354
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 35% of commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 35
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "28 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 28
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 531,
              "open_issues": 46,
              "closed_issues": 97,
              "issue_closed_ratio": 0.678,
              "closed_unmerged_prs": 64
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "68% of issues closed",
                "points": 31.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 68
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "531/595 decided PRs merged",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 531,
                      "decided": 595
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "followers": 932,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "Gitlawb",
              "public_repos": 17,
              "account_age_days": 127
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "932 followers of Gitlawb",
                "points": 21.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 932,
                      "login": "Gitlawb"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "17 public repos, account ~0 yr old",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 17
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/Gitlawb/zero",
                "@gitlawb/zero"
              ],
              "ecosystems": "go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "16 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "ai-agent",
                "ai",
                "anthropic",
                "cli",
                "code-assistant",
                "coding-agent",
                "developer-tools",
                "gemini",
                "llm",
                "mcp",
                "ollama",
                "openai",
                "terminal"
              ],
              "has_wiki": true,
              "homepage": "https://zero.gitlawb.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://zero.gitlawb.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "13 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 104 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 104
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 104,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 104,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 86,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 3827
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 97 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 97
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.07,
              "toolchain_manifests": [
                "go.mod",
                "internal/agenteval/testdata/fixtures/zero-mini/go.mod",
                "internal/perfbench/testdata/edit/go.mod",
                "internal/perfbench/testdata/fix/go.mod",
                "internal/perfbench/testdata/nav/go.mod",
                "internal/perfbench/testdata/refactor/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "7 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 7,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 217150,
              "source_files_sampled": 1231,
              "oversized_source_files": 16
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "16/1231 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1231,
                      "oversized": 16
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "deps.dev does not index npm:@gitlawb/zero@0.5.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T02:07:24.060811Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/Gitlawb/zero.svg",
  "full_name": "Gitlawb/zero",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo, npm.