Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 18:21 UTC

LabOverWire / mqtt-lib

MQTT v5.0 full in Rust

RustApache-2.0★ 54 stars⑂ 4 forkssince Nov 2025View on GitHub ↗

LabOverWire/mqtt-lib holds a health index of 64 out of 100, placing it in the Moderate band. It scores highest on Vitality (89/100) and lowest on Sustainability & Governance (54/100). It was last updated 1 day ago. A single contributor accounts for most of its recent work.

64
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

64
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

LabOverWireOrganization
3 followers5 public repossince Nov 2025

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

89Excellent · 22% of overall
How it's scored
36/36Push recency — last push 1 days ago
24.9/36Commit cadence — 36/52 weeks with commits
18/18Commit volume — 242 commits in the last year
10/10OpenSSF Scorecard: Maintained — 24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year242
human_commit_share1
days_since_last_push1
active_weeks_last_year36
How it's scored
27/27Ships releases — 56 releases published
36/36Release recency — latest release 1 days ago
27/27Release cadence — a release every ~7.2 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count56
latest_release_tagv0.38.0
releases_from_tagsno
days_since_latest_release1
mean_days_between_releases7.2

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

60Moderate · 18% of overall
How it's scored
28/60Stars — 54 stars
4/25Forks — 4 forks
0/15Watchers — 1 watchers
Inputs used
forks4
stars54
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
48.5/80Monthly downloads — 4,354 downloads/month across crates
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesmqtt5, mqtt5-wasm, mqttv5-cli, mqtt5-protocol
dependents
ecosystemscrates
total_downloads23,277
monthly_downloads4,354
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

54Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0.4/22.5Commit distribution — top contributor authored 98% of commits
2.7/13.5Contributor breadth — 2 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.983
How it's scored
44.5/46.8Issue resolution — 95% of issues closed
36.5/38.3PR acceptance — 85/89 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 2/30 approved changesets -- score normalized to 0
Inputs used
merged_prs85
open_issues1
closed_issues20
issue_closed_ratio0.952
closed_unmerged_prs4
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
4.3/25Owner reach — 3 followers of LabOverWire
7/25Track record — 5 public repos, account ~0 yr old
Inputs used
followers3
owner_typeOrganization
is_verified
owner_loginLabOverWire
public_repos5
account_age_days249
How it's scored
25/25Published & resolvable — 4 package(s) on crates
35/35Publish recency — latest publish 1 days ago
20/20Version history — 63 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesmqtt5, mqtt5-wasm, mqttv5-cli, mqtt5-protocol
ecosystemscrates
any_deprecatedno
min_days_since_publish1

Engineering Quality

Are baseline engineering and documentation practices in place?

61Moderate · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 27 out of 27 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

50Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

56Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 27 out of 27 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 2/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
4.5/5SAST — SAST tool is not run on all commits -- score normalized to 9
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate5.5

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

58Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
37.3/40Legible commit history — 70 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.7
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — Cargo.toml, crates/mqtt5-conformance-cli/Cargo.toml, crates/mqtt5-conformance-macros/Cargo.toml (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Rust (statically typed)
10/10Reproducible environment — Dockerfile
4/10Demonstrated agent practice — 2 of the last 100 commits agent-authored or agent-credited
5/8Automated maintenance — dependency automation configured, none observed in the sampled commits
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.02
toolchain_manifestsCargo.toml, crates/mqtt5-conformance-cli/Cargo.toml, crates/mqtt5-conformance-macros/Cargo.toml, crates/mqtt5-conformance/Cargo.toml, crates/mqtt5-protocol/Cargo.toml, crates/mqtt5-wasm/Cargo.toml, crates/mqtt5/Cargo.toml, crates/mqttv5-cli/Cargo.toml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Rust (statically typed)
54.3/55Manageable file sizes — 5/380 source files over 60KB
Inputs used
primary_languageRust
largest_source_bytes82,896
source_files_sampled380
oversized_source_files5
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

54GitHub stars
2contributors
242commits, last 12 months
1days since last push
56releases
1bus factor
1open issues
crates.iopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'mqtt5-conformance' from its registry
  • Could not fetch crates package 'mqtt5-conformance-cli' from its registry
  • Could not fetch crates package 'mqtt5-conformance-macros' from its registry
  • No resolved dependencies carried a version and a supported ecosystem

More detail

Star and fork history 0 ★ / 4 ⇿
0Stars
4Forks
19Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

1223344412026-032026-052026-07
Major 0Minor 10Patch 9
OpenSSF Scorecard 5.5 / 10
5.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 18:20 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests27 out of 27 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 2/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
9SASTSAST tool is not run on all commits -- score normalized to 9
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 87
RegistryPackageVersion constraintManifest
crates.iofutures-util0.3.32crates/mqtt5-conformance-cli/Cargo.toml
crates.iolibtest-mimic0.8.2crates/mqtt5-conformance-cli/Cargo.toml
crates.iomqtt5-conformance0.1.0crates/mqtt5-conformance-cli/Cargo.toml
crates.ioserde_json1.0.149crates/mqtt5-conformance-cli/Cargo.toml
crates.iotokio1.51.1crates/mqtt5-conformance-cli/Cargo.toml
crates.ioproc-macro21.0.106crates/mqtt5-conformance-macros/Cargo.toml
crates.ioquote1.0.46crates/mqtt5-conformance-macros/Cargo.toml
crates.iosyn2.0.118crates/mqtt5-conformance-macros/Cargo.toml
crates.iomqtt5crates/mqtt5-conformance/Cargo.toml
crates.iomqtt5-protocolcrates/mqtt5-conformance/Cargo.toml
crates.iotokio1.47crates/mqtt5-conformance/Cargo.toml
crates.iotracing0.1crates/mqtt5-conformance/Cargo.toml
crates.iotracing-subscriber0.3crates/mqtt5-conformance/Cargo.toml
crates.ioserde1.0crates/mqtt5-conformance/Cargo.toml
crates.ioserde_json1.0crates/mqtt5-conformance/Cargo.toml
crates.iotoml1crates/mqtt5-conformance/Cargo.toml
crates.iobytes1.12.0crates/mqtt5-conformance/Cargo.toml
crates.ioulid1.2.1crates/mqtt5-conformance/Cargo.toml
crates.iolinkme0.3.35crates/mqtt5-conformance/Cargo.toml
crates.iomqtt5-conformance-macros0.1.0crates/mqtt5-conformance/Cargo.toml
crates.iotokio-tungstenite0.29crates/mqtt5-conformance/Cargo.toml
crates.iofutures-util0.3crates/mqtt5-conformance/Cargo.toml
crates.iohttp1.4.0crates/mqtt5-conformance/Cargo.toml
crates.iobebytes3.0.2crates/mqtt5-protocol/Cargo.toml
crates.iobytes1.12crates/mqtt5-protocol/Cargo.toml
crates.iothiserror2.0crates/mqtt5-protocol/Cargo.toml
crates.ioserde1.0crates/mqtt5-protocol/Cargo.toml
crates.iotracing0.1.41crates/mqtt5-protocol/Cargo.toml
crates.iohashbrown0.17crates/mqtt5-protocol/Cargo.toml
crates.ioportable-atomic1.12crates/mqtt5-protocol/Cargo.toml
crates.ioportable-atomic-util0.2.4crates/mqtt5-protocol/Cargo.toml
crates.iomqtt5-protocol0.14.0crates/mqtt5-wasm/Cargo.toml
crates.iomqtt50.38crates/mqtt5-wasm/Cargo.toml
crates.iowasm-bindgen0.2.126crates/mqtt5-wasm/Cargo.toml
crates.iowasm-bindgen-futures0.4.76crates/mqtt5-wasm/Cargo.toml
crates.iojs-sys0.3.103crates/mqtt5-wasm/Cargo.toml
crates.ioconsole_error_panic_hook0.1crates/mqtt5-wasm/Cargo.toml
crates.iogetrandom0.4.3crates/mqtt5-wasm/Cargo.toml
crates.iobytes1.12.0crates/mqtt5-wasm/Cargo.toml
crates.iofutures0.3crates/mqtt5-wasm/Cargo.toml
crates.iofutures-util0.3crates/mqtt5-wasm/Cargo.toml
crates.iotracing0.1.41crates/mqtt5-wasm/Cargo.toml
crates.iogloo-timers0.4crates/mqtt5-wasm/Cargo.toml
crates.ioflume0.12.0crates/mqtt5-wasm/Cargo.toml
crates.iominiz_oxide0.9crates/mqtt5-wasm/Cargo.toml
crates.iosha20.11crates/mqtt5-wasm/Cargo.toml
crates.ioweb-sys0.3.103crates/mqtt5-wasm/Cargo.toml
crates.iobase640.22crates/mqtt5/Cargo.toml
crates.iobytes1.12.0crates/mqtt5/Cargo.toml
crates.iofutures0.3crates/mqtt5/Cargo.toml
crates.iofutures-util0.3crates/mqtt5/Cargo.toml
crates.iohex0.4crates/mqtt5/Cargo.toml
crates.iorand0.10.2crates/mqtt5/Cargo.toml
crates.ioserde1.0crates/mqtt5/Cargo.toml
crates.ioserde_json1.0crates/mqtt5/Cargo.toml
crates.iosha20.11crates/mqtt5/Cargo.toml
crates.iothiserror2.0crates/mqtt5/Cargo.toml
crates.iotoml1crates/mqtt5/Cargo.toml
crates.iotracing0.1crates/mqtt5/Cargo.toml
crates.iourl2.5crates/mqtt5/Cargo.toml
crates.iotracing-subscriber0.3crates/mqtt5/Cargo.toml
crates.ioturmoil0.7crates/mqtt5/Cargo.toml
crates.ioopentelemetry_sdk0.32crates/mqtt5/Cargo.toml
crates.ioopentelemetry-otlp0.32crates/mqtt5/Cargo.toml
crates.iotracing-opentelemetry0.33crates/mqtt5/Cargo.toml
crates.ioopentelemetry0.32crates/mqtt5/Cargo.toml
crates.iomqtt5-protocol0.14.0crates/mqtt5/Cargo.toml
crates.ioargon20.5crates/mqtt5/Cargo.toml
crates.iogetrandom0.4.3crates/mqtt5/Cargo.toml
crates.iobebytes3.0crates/mqtt5/Cargo.toml
crates.ioregex1.12.2crates/mqtt5/Cargo.toml
crates.ioflume0.12.0crates/mqtt5/Cargo.toml
crates.ioparking_lot0.12.5crates/mqtt5/Cargo.toml
crates.ioflate21.1.8crates/mqtt5/Cargo.toml
crates.iozeroize1.8.2crates/mqtt5/Cargo.toml
crates.iomqtt50.38crates/mqttv5-cli/Cargo.toml
crates.ioanyhow1.0.103crates/mqttv5-cli/Cargo.toml
crates.iotracing0.1crates/mqttv5-cli/Cargo.toml
crates.ioserde1.0crates/mqttv5-cli/Cargo.toml
crates.ioserde_json1.0.145crates/mqttv5-cli/Cargo.toml
crates.iohex0.4.3crates/mqttv5-cli/Cargo.toml
crates.iogetrandom0.4.3crates/mqttv5-cli/Cargo.toml
crates.iohumantime2.4.0crates/mqttv5-cli/Cargo.toml
crates.iotime0.3.53crates/mqttv5-cli/Cargo.toml
crates.iobebytes3.0.2crates/mqttv5-cli/Cargo.toml
crates.ioflate21.1.9crates/mqttv5-cli/Cargo.toml
crates.ioquinn0.11.11crates/mqttv5-cli/Cargo.toml
All dependencies 73

Full resolved dependency set from the GitHub dependency graph: 54 direct and 19 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
crates.ioanyhowdirect
crates.ioargon2direct
crates.iobase64direct
crates.iobebytesdirect
crates.iobytesdirect
crates.ioconsole_error_panic_hookdirect
crates.ioflate2direct
crates.ioflumedirect
crates.iofuturesdirect
crates.iofutures-utildirect
crates.iogetrandomdirect
crates.iogloo-timersdirect
crates.iohashbrowndirect
crates.iohexdirect
crates.iohttpdirect
crates.iohumantimedirect
crates.iojs-sysdirect
crates.iolibtest-mimicdirect
crates.iolinkmedirect
crates.iominiz_oxidedirect
crates.iomqtt5direct
crates.iomqtt5-conformancedirect
crates.iomqtt5-conformance-macrosdirect
crates.iomqtt5-protocoldirect
crates.ioopentelemetrydirect
crates.ioopentelemetry-otlpdirect
crates.ioopentelemetry_sdkdirect
crates.ioparking_lotdirect
crates.ioportable-atomicdirect
crates.ioportable-atomic-utildirect
crates.ioproc-macro2direct
crates.ioquinndirect
crates.ioquotedirect
crates.ioranddirect
crates.ioregexdirect
crates.ioserdedirect
crates.ioserde_jsondirect
crates.iosha2direct
crates.iosyndirect
crates.iothiserrordirect
crates.iotimedirect
crates.iotokiodirect
crates.iotokio-tungstenitedirect
crates.iotomldirect
crates.iotracingdirect
crates.iotracing-opentelemetrydirect
crates.iotracing-subscriberdirect
crates.ioturmoildirect
crates.iouliddirect
crates.iourldirect
crates.iowasm-bindgendirect
crates.iowasm-bindgen-futuresdirect
crates.ioweb-sysdirect
crates.iozeroizedirect
crates.ioclapindirect
crates.iodialoguerindirect
crates.iohttp-body-utilindirect
crates.iohumantime-serdeindirect
crates.iohyperindirect
crates.iohyper-rustlsindirect
crates.iohyper-utilindirect
crates.ioproptestindirect
crates.iorcgenindirect
crates.ioringindirect
crates.iorpasswordindirect
crates.iorustlsindirect
crates.iorustls-pki-typesindirect
crates.iotempfileindirect
crates.iotokio-rustlsindirect
crates.iotokio-testindirect
crates.iowasm-bindgen-testindirect
crates.ioweb-timeindirect
crates.iowebpki-rootsindirect
Dependency advisories not assessed

Advisory matching could not run for this report: No resolved dependencies carried a version and a supported ecosystem

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 6713,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "CSS": 3981,
        "HCL": 2522,
        "TLA": 72814,
        "TeX": 132692,
        "HTML": 464153,
        "Rust": 3818161,
        "Shell": 173946,
        "Python": 188634,
        "Dockerfile": 498,
        "JavaScript": 14286,
        "BibTeX Style": 31802
      },
      "pushed_at": "2026-07-24T14:56:22Z",
      "created_at": "2025-11-18T01:13:21Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T16:09:53Z",
      "description": "MQTT v5.0 full in Rust",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "laboverwire.com",
      "name": "LabOverWire",
      "type": "Organization",
      "login": "LabOverWire",
      "company": null,
      "location": "Canada",
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/244627368?v=4",
      "created_at": "2025-11-18T01:06:55Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 249
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2026-07-24T15:02:07Z"
        },
        {
          "tag": "v0.37.2",
          "kind": "patch",
          "published_at": "2026-07-15T19:56:24Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2026-07-12T02:16:56Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2026-07-11T23:46:18Z"
        },
        {
          "tag": "v0.36.1",
          "kind": "patch",
          "published_at": "2026-07-10T20:52:11Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2026-07-09T21:00:05Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2026-07-06T15:13:26Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2026-07-01T14:44:38Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2026-06-14T13:50:39Z"
        },
        {
          "tag": "v0.32.2",
          "kind": "patch",
          "published_at": "2026-05-20T18:23:17Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-05-17T23:07:43Z"
        },
        {
          "tag": "v0.31.4",
          "kind": "patch",
          "published_at": "2026-04-13T03:29:14Z"
        },
        {
          "tag": "v0.31.3",
          "kind": "patch",
          "published_at": "2026-04-11T16:17:39Z"
        },
        {
          "tag": "v0.31.2",
          "kind": "patch",
          "published_at": "2026-04-09T18:17:06Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2026-03-30T18:39:16Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-03-25T20:56:10Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-03-25T02:17:43Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-03-22T02:32:18Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-03-16T14:17:44Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-03-16T02:02:57Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-03-14T03:35:58Z"
        },
        {
          "tag": "v0.22.10",
          "kind": "patch",
          "published_at": "2026-03-02T14:58:01Z"
        },
        {
          "tag": "v0.22.9",
          "kind": "patch",
          "published_at": "2026-02-22T17:16:39Z"
        },
        {
          "tag": "v0.22.8",
          "kind": "patch",
          "published_at": "2026-02-17T00:17:23Z"
        },
        {
          "tag": "v0.22.7",
          "kind": "patch",
          "published_at": "2026-02-14T22:02:57Z"
        },
        {
          "tag": "v0.22.6",
          "kind": "patch",
          "published_at": "2026-02-13T18:50:38Z"
        },
        {
          "tag": "v0.22.4",
          "kind": "patch",
          "published_at": "2026-02-11T15:25:29Z"
        },
        {
          "tag": "v0.22.3",
          "kind": "patch",
          "published_at": "2026-02-11T01:08:12Z"
        },
        {
          "tag": "v0.22.1",
          "kind": "patch",
          "published_at": "2026-02-02T23:52:15Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-01-30T00:13:33Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-01-27T01:52:16Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-01-23T02:17:29Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-01-20T19:38:38Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-01-20T18:15:16Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-01-18T00:05:10Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2026-01-13T23:31:22Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-01-08T17:27:30Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-01-07T02:33:23Z"
        },
        {
          "tag": "v0.17.2",
          "kind": "patch",
          "published_at": "2026-01-05T22:23:01Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2025-12-31T00:50:37Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2025-12-30T12:49:42Z"
        },
        {
          "tag": "v0.16.3",
          "kind": "patch",
          "published_at": "2025-12-28T00:43:57Z"
        },
        {
          "tag": "v0.16.2",
          "kind": "patch",
          "published_at": "2025-12-27T12:35:34Z"
        },
        {
          "tag": "v0.16.1",
          "kind": "patch",
          "published_at": "2025-12-27T06:11:14Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2025-12-24T23:17:01Z"
        },
        {
          "tag": "v0.15.2",
          "kind": "patch",
          "published_at": "2025-12-21T05:29:23Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2025-12-20T18:01:44Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2025-12-20T02:16:53Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2025-12-18T23:37:06Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2025-12-12T12:47:39Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2025-12-11T04:28:38Z"
        },
        {
          "tag": "v0.11.4",
          "kind": "patch",
          "published_at": "2025-12-07T02:04:26Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2025-12-03T21:50:15Z"
        },
        {
          "tag": "v0.11.2",
          "kind": "patch",
          "published_at": "2025-11-29T13:48:08Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2025-11-28T15:37:25Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2025-11-26T00:58:40Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ca61532ee1ceb8ca1ed1af5b321523ed42dd4ceb",
          "body": "…vior",
          "is_bot": false,
          "headline": "correct 0.38.0 changelog session_present=0 note to match shipped beha…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-24T14:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "538caa56d55c1b57bac75ec8cd9c283d067511cf",
          "body": null,
          "is_bot": false,
          "headline": "validate deferred-ack end-to-end against real brokers",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-24T14:02:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "955953d94ff1676f1824950f25a45aa88d9fb0da",
          "body": null,
          "is_bot": false,
          "headline": "harden deferred-ack reconnect and qos2 packet-id edges",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-23T18:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b776e93b06071701166e5050a467a48157e94b90",
          "body": null,
          "is_bot": false,
          "headline": "add deferred acknowledgement with AckToken and subscribe_with_ack",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-21T02:04:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec109537378d78ca1a6c475778d61b78aa2dc1d4",
          "body": "Closes #112",
          "is_bot": false,
          "headline": "fix qos2 duplicate delivery and qos>0 delivery over quic (0.38.0)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-17T22:03:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8195528d86285228dacba2476e847f7e511da146",
          "body": "Closes #113.\n\n## Problem\n\nWhen a client subscribed with a Subscription Identifier to a topic that\nalready had a retained message, the retained message was delivered\n**without** the identifier. Live delivery (publish-after-subscribe)\nalready attached it correctly, so the two paths diverged. This viol\n[…]\nfirmed it fails (`left: []`)\nwithout the fix and passes with it.\n\n## Other changes\n\n- `mqtt5` 0.37.1 → 0.37.2 (patch; cli/wasm `0.37` pins remain satisfied)\n- CHANGELOG entry\n- Conformance diary entry",
          "is_bot": false,
          "headline": "include subscription identifier on retained messages at subscribe (#114)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-14T02:42:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc7f579e729b21d1ac3d431b0013014658315e68",
          "body": "…111)\n\n## Problem\n\nThe `Conformance (external mqtt5 broker)` CI job intermittently fails\nwith `Timeout(\"puback\")` (seen on #107's post-merge run), even though\nthe identical code passes on re-run. The flake is timeout-tightness\nagainst an out-of-process broker on an oversubscribed runner, not a\nbroke\n[…]\nrsion bump:** changes are entirely within `mqtt5-conformance`\n(`publish = false`); the published `mqtt5` crate is untouched.\n\nFull investigation log in\n`crates/mqtt5-conformance/CONFORMANCE_DIARY.md`.",
          "is_bot": false,
          "headline": "remove redundant post-suback sleeps and raise conformance timeouts (#…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-12T23:26:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f00604776490d187ddbf51b3b269fc6ee40cf625",
          "body": "Closes #106. Resolves the question raised in discussion #102.\n\n## Problem\n\nAn invalid bridge (e.g. one with no topic mappings) was logged at\n`ERROR` level but the broker started anyway — the misconfigured bridge\nwas silently dropped, leaving a broker that looked healthy but was not\nbridging.\n\n```\nER\n[…]\n 0.37.1 (additive patch); cli/wasm `0.37` reqs still\nresolve the local path — no lockstep change\n- CHANGELOG and ARCHITECTURE.md updated\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "fail broker startup on invalid bridge config (#107)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-12T02:10:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "86ec8b9e648794763736d6cbde14acaad3544e7d",
          "body": null,
          "is_bot": false,
          "headline": "support tls-only broker without plaintext listener",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-11T23:31:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70b7e2d273cf7b0589c5110ab9de6ea6c4126499",
          "body": null,
          "is_bot": false,
          "headline": "make $SYS topic publishing configurable",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-11T22:20:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba5bd556f66f42dd3ed87a5a3425dd7abba3494c",
          "body": "Closes #97.\n\n## Problem\n\nThe client never recorded the broker's **Maximum Packet Size**\nadvertised in CONNACK. It only stored its own inbound limit\n(`get_maximum_qos` was wired up; `get_maximum_packet_size` was not). As\na result, an oversized PUBLISH was serialized and sent, the broker\nclosed the co\n[…]\nm) and\n`mqtt5-protocol = \"0.14.0\"` (mqtt5) both cover the bumps.\n\nVerified: `cargo make ci-verify` (fmt + workspace clippy pedantic +\ntests) passes; client-only `--no-default-features` build compiles.",
          "is_bot": false,
          "headline": "enforce broker max packet size on client publish",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-10T15:04:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d03e8ce31abaea1982ef6248e306e1b6d29ce16e",
          "body": "Closes #100",
          "is_bot": false,
          "headline": "gate broker behind cargo feature for client-only builds",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-09T19:26:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "563cc1ce26383b5f89cc289df476aa79aad8da99",
          "body": "Refreshes all outdated workspace dependencies to their latest compatible\nversions and bumps the affected published crates.\n\n## Dependency bumps\n\nDone via `cargo add` (features / `optional` / `default-features` all\npreserved), plus a full `cargo update` for transitive deps.\n\n- **mqtt5**: `bytes` 1.12\n[…]\nd** the wasm32 target\n- 447 lib tests + TLS/QUIC/transport/client/complete-flow integration\nall pass (QUIC especially, since rustls/quinn/rustls-platform-verifier\n0.6→0.7 moved)\n- pre-commit CI passed",
          "is_bot": false,
          "headline": "update outdated dependencies",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-06T14:54:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f5108a8d564bf46631b8fcef2780f322a4ee9749",
          "body": "Fixes the broker never actually shutting down when driven by an external\nCtrl+C, reported in #91. Fixes #92.\n\n## Problem\n\n`broker.run()` spawns detached background tasks (the `$SYS` publisher,\nTCP/TLS/WS/QUIC accept loops, resource monitor, storage, hot-reload) and\nparks itself on an internal shutdo\n[…]\n\nturmoil) — 0 failures.\n- Manually confirmed `simple_broker` now exits cleanly on SIGINT with\n`$SYS` publishing stopped.\n- clippy pedantic clean, fmt clean; pre-commit CI (incl. wasm32 target)\npassed.",
          "is_bot": false,
          "headline": "wire up broker graceful shutdown via shutdown_handle (#93)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-06T13:05:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50d9cfdc72fbd8cf03354b773d3d6f006e9488af",
          "body": "…er, SCRAM lock (#89)\n\n## Summary\n\nBroker-hardening cleanups to the `mqtt5` crate (surfaced while reviewing\nthe public AWS broker deployment), now also wired through the wasm\nbroker:\n\n1. **Configurable inbound limits.** `BrokerConfig` gains\n`max_message_rate_per_client` (msg/s) and `max_bandwidth_pe\n[…]\n`scram` 16/16, `client::direct` 17/17.\n- `cargo tree` confirms `mqttv5-cli` and `mqtt5-wasm --features broker`\nboth resolve to local `mqtt5 v0.34.0`; `cargo metadata` reports no\nunused-patch warnings.",
          "is_bot": false,
          "headline": "broker hardening: configurable inbound limits, drop dead memory limit…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-07-01T02:40:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f7a9d3967a3390d61826e320cc1ee72a2e65dc8",
          "body": "Resolves the secret-scanning alert for\n`crates/mqtt5/src/transport/tls.rs` (RSA Private Key, commit\n`dea578ac`).\n\nThe TLS PEM-loading unit test embedded a hardcoded RSA private key blob,\nwhich secret scanning flags. It was a throwaway test fixture guarding\nnothing, but its presence in source keeps t\n[…]\n will not be rewritten — those alerts should be\ndismissed as \"used in tests\". After this merges, the `tls.rs` alert can\nlikewise be dismissed (the key still exists in history, only removed\nfrom HEAD).",
          "is_bot": false,
          "headline": "generate test tls key at runtime instead of embedding (#88)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-06-15T22:34:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49bfc60f3b22d3108ccbc4d255d952aae0a564e5",
          "body": null,
          "is_bot": false,
          "headline": "remove npm publish from release pipeline",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-06-14T13:36:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db32571001e8134978a47d63387e1671284160dd",
          "body": "The release workflow extracted notes with `sed -n \"/##\n\\[${VERSION}\\]/...\"`, looking for `## [0.33.0]`. Our CHANGELOG headers\nare per-crate (`## [mqtt5 0.33.0]`), so the pattern never matched and\nthe GitHub Release body fell back to the bare `Release <version>` text.\n\nReplaced it with an awk extract\n[…]\n for the\ncycle and stops at the prior release.\n\nVerified locally against the current CHANGELOG for `0.33.0` — extracts\nthe full mqtt5 + protocol + wasm + cli sections and stops at `## [mqtt5\n0.32.2]`.",
          "is_bot": false,
          "headline": "fix release notes changelog extraction (#87)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-06-14T02:08:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37d5d7edd29df7ebab87b247d19462316018b9e1",
          "body": "Closes #85\n\n## Config defaults (fixes #85)\n`load_config_from_file` deserializes the JSON config straight into\n`BrokerConfig`, but the struct had no container-level\n`#[serde(default)]`, so any omitted non-`Option`/non-defaulted field\n(e.g. `max_clients`) made parsing fail — contradicting the per-fiel\n[…]\nch ... ` produces a valid credential\nline through the wrapped error path\n- wasm32 target builds; `cargo metadata`/`cargo tree` confirm `mqtt5\n0.33.0` and `mqtt5-protocol 0.14.0` resolve to local paths",
          "is_bot": false,
          "headline": "default missing broker config fields and update all dependencies (#86)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-06-14T01:54:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23d177d9f0f140a9d4592f7c93877ec41288bce5",
          "body": "## Summary\n- Closes #82. `rustls-pemfile` is flagged by\n[RUSTSEC-2025-0134](https://rustsec.org/advisories/RUSTSEC-2025-0134.html)\nas unmaintained; its functionality is now provided by\n`rustls-pki-types::pem::PemObject`, which `CertificateDer` and\n`PrivateKeyDer` already implement.\n- Removed the `ru\n[…]\n [x] `cargo test -p mqtt5 --tests` (incl. `tls_integration`,\n`tls_direct_config`, `wss_alpn_integration`)\n- [x] `cargo tree` and `Cargo.lock` confirm `rustls-pemfile` is gone\nfrom the dependency graph",
          "is_bot": false,
          "headline": "drop rustls-pemfile for rustls-pki-types pem api (#83)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-05-20T18:11:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f164f9f2b596226fafc6621a6b059c4fa5b7bf92",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5 to 0.32.1, update changelog",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-05-17T22:43:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a35485c73f204b47b023521c38c0f2f46bf5cbb",
          "body": "Closes #80.\n\n## Summary\n\nWhen the broker overrides the client's requested keep-alive via\n`BrokerConfig.server_keep_alive` (writing `ServerKeepAlive` into CONNACK\nper `[MQTT-3.2.2-22]`), it was continuing to compute its own\nread-timeout from the **client's original** requested value rather than\nthe v\n[…]\nplan\n- [x] `cargo test -p mqtt5 --test keepalive_negotiation` (all 7 tests\npass)\n- [x] Counter-example: temporarily reverted the fix and confirmed the\nnew test fails\n- [x] `cargo make ci-verify` clean",
          "is_bot": false,
          "headline": "broker: honor self-imposed ServerKeepAlive in read timeout (#81)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-05-17T22:42:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "681c7ac25b697e7204592f724ca9593a78010422",
          "body": "## Summary\n\n- The client previously ignored the `ServerKeepAlive` property in\nCONNACK — even when the broker imposed a smaller interval the client\nkept pinging on its originally requested cadence, violating\n`[MQTT-3.2.2-22]`.\n- Reads `ServerKeepAlive` from CONNACK and uses the negotiated value to\nsp\n[…]\nnce, but the broker should\nideally drive its own timeout off the same negotiated value. Happy to\nfollow up in a separate PR if desired.\n\n---------\n\nCo-authored-by: Fabrício Bracht <fabracht@gmail.com>",
          "is_bot": false,
          "headline": "feat(client): honor MQTT v5 ServerKeepAlive negotiation (#78)",
          "author_name": "Michael Zhu",
          "author_login": "butterflyfish",
          "committed_at": "2026-05-16T23:46:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52d5677216564f7c9e8c7ebffe684b4f99a613be",
          "body": "Fixes #77.\n\n## Summary\n- `broker::storage::RetainedMessage` only stored\npayload/qos/retain/expiry — `response_topic`, `correlation_data`,\n`content_type`, `user_properties`, and `payload_format_indicator` were\ndropped on the way into storage and never restored on subscribe.\n- Added those five fields \n[…]\nration_complete_flow --test\nintegration_retain_as_published --test message_queuing --test\npersistence` — all pass\n- [x] `cargo make ci-verify` (pre-commit hook) — fmt + clippy clean on\nnative and wasm",
          "is_bot": false,
          "headline": "preserve v5 properties on retained messages (#79)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-05-15T23:40:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b483b0dbe5bd59e9c822e84369b083254704f0b1",
          "body": "## Summary\n\n- OpenTelemetry env vars (`MQTT5_OTEL_ENDPOINT`,\n`MQTT5_OTEL_SERVICE_NAME`, `MQTT5_OTEL_SAMPLING`) were silently ignored\nwhen the broker was started with `--config <file>`. The OTel\ninitialization lived inside `create_interactive_config()`, which is only\ncalled in the CLI-args path. The \n[…]\nbled:\" log line appears\n- [ ] Run broker without `--config` with same env var — verify behavior\nunchanged\n- [ ] Run broker without OTel env var — verify no regression (basic\ntracing init, no OTel log)",
          "is_bot": false,
          "headline": "fix OTel env vars ignored when using --config file (#76)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-14T00:27:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5502d27ac961d5b9d6f5ea479a67a783fcfe6171",
          "body": "## Summary\n- Adds `opentelemetry` boolean input to the Docker workflow_dispatch\ntrigger\n- Passes `--features opentelemetry` as a build-arg to the Dockerfile\nwhen enabled\n- Tag-push releases are unaffected (no features flag)\n\n## Test plan\n- [ ] Trigger workflow manually with `opentelemetry: true`, `tag:\ndev-otel` — verify `--features opentelemetry` in cargo build logs\n- [ ] Trigger without opentelemetry — verify no features flag appears\n- [ ] Tag push path unchanged",
          "is_bot": false,
          "headline": "add OpenTelemetry toggle to Docker workflow (#75)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-13T18:41:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f31e9bff215c8354f2baa21a280a76af6493ed26",
          "body": "## Summary\n- WSS listener was enforcing `mqtt` ALPN, causing browsers to fail TLS\nhandshake with alert 120 (no application protocol) since they offer\n`h2,http/1.1`\n- Changed WSS `TlsAcceptorConfig` to advertise `http/1.1` ALPN instead\nof `mqtt`\n- MQTTS listener (port 8883) retains `mqtt` ALPN unchan\n[…]\nass (5/5)\n- [x] Existing WebSocket integration tests pass (4/4)\n- [x] `cargo clippy --all-targets --workspace -- -D warnings -W\nclippy::pedantic` clean\n- [ ] Manual: connect to WSS port from a browser",
          "is_bot": false,
          "headline": "use http/1.1 ALPN for WSS listener (#74)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-13T03:12:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "816caa29caca2dab946b9cbbb74cd2829db0e6e4",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5 to 0.31.3",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-11T16:09:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6cd026f389675d09a4337e4741deefa6370d067",
          "body": "## Summary\n- Fix all 9 conformance test failures verified against Mosquitto — none\nwere broker bugs (1 test parsing bug, rest are spec ambiguities or test\nexpectations beyond what the spec mandates)\n- Harden QUIC integration tests: replace ad-hoc sleeps with\n`ready_receiver()`, fix port conflicts, a\n[…]\n tests pass with inprocess fixture\n- [x] QUIC integration tests pass on Linux (CI pipeline)\n- [x] `cargo clippy --all-targets --workspace -- -D warnings` clean\n- [x] `cargo fmt --all -- --check` clean",
          "is_bot": false,
          "headline": "fix 9 conformance test failures and harden QUIC integration tests (#73)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-11T05:48:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "012a71159c99795b61bece8995e84e0e651d5360",
          "body": "## Summary\n- New `mqtt5-conformance-macros` proc-macro crate with\n`#[conformance_test]` attribute that registers tests into a distributed\nslice with capability requirements and RFC identifiers\n- New `mqtt5-conformance-cli` binary runner built on `libtest_mimic` —\nsupports in-process and external SUT\n[…]\nx] `cargo clippy --all-targets --workspace -- -D warnings -W\nclippy::pedantic` passes\n- [x] `cargo build --workspace` succeeds\n- [x] Run against external Mosquitto/EMQX to validate SUT descriptor\nflow",
          "is_bot": false,
          "headline": "vendor-neutral conformance platform with proc-macro and CLI runner (#72)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-11T02:08:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4bc8d10886c7dab55bcdf23c3b0ad786678f72c",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5 to 0.31.2, update changelog",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-04-09T17:46:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "492686c51c989bec62152fdf33c6079ad34f2d2d",
          "body": "## Summary\n- stop restored subscriptions from being persisted and replayed again on\nreconnect\n- isolate connection-scoped reader, keepalive, and QUIC acceptor tasks\nso stale tasks cannot mutate a newer connection\n- add reconnect regressions for repeated restore and post-reconnect QUIC\npublish handli\n[…]\nintegration_reconnection`\n- `cargo test -p mqtt5 --test broker_quic_integration`\n- `cargo clippy -p mqtt5 --all-targets -- -D warnings`\n\n---------\n\nCo-authored-by: Fabrício Bracht <fabracht@gmail.com>",
          "is_bot": false,
          "headline": "fix(client): harden reconnect lifecycle and subscription restore (#70)",
          "author_name": "Michael Zhu",
          "author_login": "butterflyfish",
          "committed_at": "2026-04-09T17:29:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc49e4091d64ddcf4bb589eadc54dc5f5ebaec52",
          "body": "## Summary\n\nThis changes the client lifecycle so a caller-initiated `disconnect()`\nis terminal for\nthe current client instance until the caller explicitly connects again.\n\nBefore this change, the background connection monitor could continue\ndriving automatic\nreconnection after `disconnect()`. That m\n[…]\nt -p mqtt5 --test integration_reconnection\ntest_automatic_reconnection --\n  --exact --nocapture`\n\n  I also reran `cargo make ci-verify`\n\n---------\n\nCo-authored-by: Fabrício Bracht <fabracht@gmail.com>",
          "is_bot": false,
          "headline": "Stop auto-reconnect after client disconnect (#69)",
          "author_name": "Michael Zhu",
          "author_login": "butterflyfish",
          "committed_at": "2026-04-03T20:49:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43a103b93b579f16080a6beff538cb132bee3b0f",
          "body": "## Summary\n\n- Every flag on `broker`, `pub`, and `sub` subcommands can now be set\nvia `MQTT5_` prefixed environment variables (e.g., `MQTT5_HOST`,\n`MQTT5_TLS_CERT`, `MQTT5_NON_INTERACTIVE`)\n- CLI flags take precedence over env vars, which take precedence over\ndefaults\n- Repeatable flags (`--host`, `\n[…]\nT5_HOST=0.0.0.0:11883 MQTT5_NON_INTERACTIVE=true\nMQTT5_ALLOW_ANONYMOUS=true cargo run -p mqttv5-cli -- broker` starts\ncorrectly\n- [x] `--help` output shows `[env: MQTT5_...]` annotations for all flags",
          "is_bot": false,
          "headline": "add environment variable support for all CLI flags (#68)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-30T17:59:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d47b39be6c95392aa4aa1ea7e3455db814e3160a",
          "body": "## Summary\n- Remove `CapturedLogs` / `set_default()` log-capture machinery from\n`test_quic_migration_detected_by_server`\n- `set_default()` sets a thread-local subscriber, but async tasks run on\narbitrary tokio threads where the global subscriber wins — reliably\nfails under `--all-features` when OpenTelemetry's `try_init()` installs\na global subscriber first\n- Functional assertions (message received after migration) already prove\nmigration works",
          "is_bot": false,
          "headline": "remove flaky log-capture assertions from QUIC migration test (#66)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-30T01:16:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08b6be2009559bf186747bbb16bffaba38c245fb",
          "body": null,
          "is_bot": false,
          "headline": "expose QUIC UDP port 14567 in Dockerfile",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-29T22:39:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60ca32f60ac0d012de5ec75bae1800106b48257b",
          "body": "## Summary\n- Span instrumentation on broker hot paths (connect, disconnect,\npublish, subscribe, unsubscribe, QoS handshake, will, route, deliver,\nbridge forward) gated behind `opentelemetry` feature\n- `MetricsBridge` registers 10 observable instruments from `BrokerStats`\natomics via OTLP export\n- `OnceLock`-stored tracer and meter providers with proper flush +\nshutdown on broker stop\n- `TelemetryConfig::with_metrics_enabled()` and `init_meter_provider()`\n- Zero overhead when feature is disabled",
          "is_bot": false,
          "headline": "add comprehensive OpenTelemetry coverage (#65)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-28T22:42:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b34ce4d4739db5eea19a9f13b0064db0bc647de2",
          "body": null,
          "is_bot": false,
          "headline": "fix RoutableMessage field access in turmoil_multi_client test",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-26T16:35:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbcac48b6814810d8517404dfbbd3689ec0aae23",
          "body": "## Summary\n- Rewrites bullet-heavy sections into flowing prose across all 10\nmarkdown files that feed the docs site\n- Merges duplicate security sections in AUTHENTICATION.md\n- Adds intro paragraphs and transitions to ARCHITECTURE.md,\nCLI_USAGE.md, and crate READMEs\n- Removes GitHub-only sections (AI\n[…]\nclippy, tests)\n- [x] All 5 mermaid diagrams preserved in ARCHITECTURE.md\n- [x] No skipped heading levels across all files\n- [x] Sync script rewrites links correctly\n- [x] Frontend renders all 10 pages",
          "is_bot": false,
          "headline": "polish documentation for web display (#64)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-25T19:03:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59a8b23a5268367ac4f033308f577586c631bd56",
          "body": "…ery (#62)\n\n## Summary\n- Broker-side flow-bound subscriptions: `RoutableMessage` wrapper,\nflow-aware subscribe/unsubscribe, per-topic server data stream delivery\nvia `ServerStreamManager.write_publish_to_flow()`\n- Client-side SUBSCRIBE/UNSUBSCRIBE routing through `QuicStreamManager`\ndata flows when \n[…]\nace tests pass (0 failures)\n- [x] Clippy clean with pedantic\n- [x] Local smoke test: per-topic-flow shows 4 distinct stream_ids\n(2,4,6,8); control shows all stream_id=0\n- [x] Run experiment on GCP VMs",
          "is_bot": false,
          "headline": "add subscribe-on-data-flows with client routing and broker flow deliv…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-25T16:47:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0136b71324c613ec0f02c7cff78e270925e9cc95",
          "body": "… (#63)\n\n## Summary\n\n  - Add Cargo feature gates for optional transports in `mqtt5`\n- Keep `TCP/TLS` as baseline transports and make `WebSocket` / `QUIC`\noptional via `transport-websocket` and `transport-quic`\n- Split shared client transport config out of `quic.rs` into\n`transport/client_config.rs`\n\n[…]\nl\n- Transport-specific examples/tests are now aligned with the feature\nmatrix to support reduced builds such as `--no-default-features`\n\n---------\n\nCo-authored-by: Fabrício Bracht <fabracht@gmail.com>",
          "is_bot": false,
          "headline": "feat(mqtt5): gate QUIC and WebSocket transports behind Cargo features…",
          "author_name": "Michael Zhu",
          "author_login": "butterflyfish",
          "committed_at": "2026-03-25T02:09:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "00c53cad8c557f832a6154f2b4734aefc3af195c",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5-protocol to 0.12.0 and mqtt5 to 0.29.0",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-22T00:52:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4d2d4302da54abdbb9ba1a77ef33f23d9d666ce",
          "body": "…(#60)\n\n## Summary\n\n- Define `QuicConnectionCode` (5 variants) and `QuicStreamCode` (16\nvariants) enums in `mqtt5-protocol` for QUIC CONNECTION_CLOSE and\nRESET_STREAM frames per spec §12\n- Add 7 missing `ReasonCode` variants and rename `MqoqProtocolError` →\n`MqoqNotFlowOwner` to match spec naming\n- \n[…]\nicConnectionCode` and `QuicStreamCode`\nround-trips, display, error levels, discard state\n- [x] Unit tests for `QuicCloseReason`, `StreamResetReason`,\n`StreamStopReason` display and Quinn error parsing",
          "is_bot": false,
          "headline": "add MQTT-next QUIC error codes and error tolerance levels (§11, §12) …",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-22T00:44:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7abbe5606d26acf4e6fce8d0768d4633bc8ac39",
          "body": "## Summary\n\n- Implement QUIC 0-RTT early data for reconnecting clients, eliminating\none RTT from the handshake on subsequent connections\n- Broker enables `max_early_data_size` and `send_half_rtt_data` via\n`enable_early_data` config; client caches `quinn::ClientConfig` (session\nticket store) across r\n[…]\nect is 1-RTT, reconnect uses 0-RTT,\nserver-without-early-data fallback, pub/sub after 0-RTT reconnect (4/4\npass)\n- [x] Manual test with `--quic-early-data` on broker + client over\nnetwork with latency",
          "is_bot": false,
          "headline": "add QUIC 0-RTT connection resumption (MQTT-next §8.1) (#59)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-20T15:36:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c06d878467bec7135f75bbfbe8530f827860ff5c",
          "body": "## Summary\n- Implement Gap 4 from the MQTT-next spec gap analysis: client can force\nthe broker to discard flow state via bidirectional QUIC stream with\n`clean_start=1` and all persistent flags cleared\n- Client API: `MqttClient::discard_flow(flow_id)` opens bi stream,\nwrites discard header, sends FIN\n[…]\nn test: discard_flow returns error when flow headers are\nnot enabled\n- [x] `cargo clippy --all-targets --workspace -- -D warnings -W\nclippy::pedantic`\n- [x] `cargo test --lib --bins` (396+ tests pass)",
          "is_bot": false,
          "headline": "add discard flow state at peer (MQTT-next §9.16) (#58)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-19T04:30:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57a6448870bfb69d94f3a334539322ced6c8fbef",
          "body": null,
          "is_bot": false,
          "headline": "add ALPN MQTT-next negotiation for advanced multistreams",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-18T22:45:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8be02fb027bc034ac2c4c14dd4bd5b491a009135",
          "body": "## Summary\n- Reorganize `experiments/` and `comnet/` under `publications/comnet/`,\n`joss/` under `publications/joss/`\n- Add flat single-file LaTeX submission for Computer Networks (Elsevier\nCAS template)\n- Add comprehensive README with experiment guide, figure mapping, and\nreproduction instructions\n\n[…]\nTest plan\n- [x] PDF builds cleanly (10 pages, no warnings)\n- [x] Pre-commit hooks pass (fmt, clippy, wasm clippy)\n- [x] No large files committed (terraform provider excluded)\n- [x] Zenodo DOI resolves",
          "is_bot": false,
          "headline": "add ComNet paper, experiments, and Zenodo dataset (#57)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-18T21:09:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52ffb234598668b48d50c626934bb46f01b25394",
          "body": "## Summary\n- Server-side migration detection:\n`ClientHandler::check_quic_migration()` polls\n`Connection::remote_address()` after each packet, updates `client_addr`\nand atomically transitions per-IP tracking in `ResourceMonitor`\n- Client-side active migration: `MqttClient::migrate()` calls\n`Endpoint:\n[…]\nonnected client\ngets `NotConnected`\n- [x] `cargo clippy --all-targets --workspace -- -D warnings -W\nclippy::pedantic` passes\n- [x] WASM target unaffected (`#[cfg(not(target_arch = \"wasm32\"))]`\nguards)",
          "is_bot": false,
          "headline": "add QUIC connection migration support (#56)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-16T14:09:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59a296a1d8a65dfb9397ab784d7eda0dbe5cca5a",
          "body": "## Summary\n- Add `LoadBalancerConfig` to `BrokerConfig` — broker acts as pure\nconnection redirector using CONNACK `UseAnotherServer` (0x9C) with\n`ServerReference` property\n- Client-side redirect loop in `connect_internal()` follows up to 3\nhops, parsing URL scheme (`mqtt://`, `mqtts://`, `quic://`) \n[…]\nnual: run WASM `load-balancer-redirect` example with 2 native\nbrokers, verify clients redirect to correct backends\n- [x] Manual: AWS `tests/aws-lb/run_tests.sh` for cross-transport\nredirect validation",
          "is_bot": false,
          "headline": "add server redirect load balancer for horizontal scaling (#55)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-16T01:45:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1acc1aceaabcd6dac08bc55ea99d047c6f293cf2",
          "body": "## Summary\n- Merges all changes from `payload-format-experiments` branch into main\n- Removes the temporary Quinn fork dependency (`[patch.crates-io]` for\nquinn/quinn-proto) and all frame packing policy references throughout\nthe codebase\n- Updates all 17 analysis/figure scripts to point to `results-v\n[…]\ntargets --workspace -- -D warnings -W\nclippy::pedantic` passes\n- [x] Pre-commit hooks (fmt + clippy native + clippy wasm) pass\n- [x] No remaining `frame_packing`/`FramePacking` references in Rust\ncode",
          "is_bot": false,
          "headline": "merge experiment branch changes (without Quinn fork) (#54)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-14T03:28:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dccfc2ac3e18f19d6d1a138622c9ff064d48b566",
          "body": null,
          "is_bot": false,
          "headline": "add sideEffects and wasm.d.ts to npm package manifest",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-02T16:37:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e38385729e5b041236e7246b846de323a981626",
          "body": null,
          "is_bot": false,
          "headline": "update changelog and docs for mqtt5-wasm 1.0.0 camelCase API",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-02T14:48:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81806ddac7ba1e970667ff99bc6c57cec96d972f",
          "body": "## Summary\n- Add `#[wasm_bindgen(js_name = \"...\")]` to all exported structs and\nmethods in `mqtt5-wasm`, mapping Rust snake_case to JS camelCase\n- Drop `Wasm` prefix from all exported types (e.g., `WasmMqttClient` →\n`MqttClient`, `WasmBroker` → `Broker`)\n- Update all 22 example HTML files, app.js, a\n[…]\n:pedantic` passes\n- [x] Verified no remaining `Wasm`-prefixed type names or snake_case\nmethod calls in examples\n- [x] Rust-side names unchanged — only JS-facing names affected via\n`js_name` attributes",
          "is_bot": false,
          "headline": "map WASM exports to camelCase JS names (#50)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-02T14:36:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d179b16ff7deabfbdb44a130d74feb17174b2a03",
          "body": "## Summary\n- Bench tool with throughput, latency, HOL-blocking, and connection\nmodes supporting TCP/TLS/QUIC with configurable stream strategies\n- `--payload-format` flag (raw/json/bebytes/compressed-json) for\nserialization overhead comparison\n- Server-side per-topic QUIC stream delivery for independent topic\nmultiplexing\n- GCP Terraform provisioning, netem scripts, resource monitoring, and\nexperiment scripts (01-06)\n- GKE Autopilot infrastructure for Phase 2 pod-based experiments (07-11)",
          "is_bot": false,
          "headline": "MQTT-over-QUIC benchmarking infrastructure (#49)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-03-01T05:27:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e206e48192c634ef55dc4e79dd6a2bea5d99328e",
          "body": "## Summary\n- Adds an AI Assistance Disclosure section to the README covering\ntools/models used, scope of assistance, and human review confirmation",
          "is_bot": false,
          "headline": "add AI assistance disclosure to README (#47)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-23T16:40:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f8cdfeadcf4e5d8ee80bbfeab97ced88c4eaa7c",
          "body": "… suppressions (#46)\n\n## Summary\n- Add `mqtt5-conformance` crate (v0.1.0) — 197 tests across 22 test\nfiles covering all 247 MQTT v5.0 normative statements\n- Implement raw TCP test harness (`RawMqttClient`, `RawPacketBuilder`)\nfor byte-level protocol validation\n- Add `conformance.toml` manifest track\n[…]\n and file storage backends (persistence across restart)\n- Throughput (~380K msg/s), latency (p50: 122us), connection benchmarks\n  - Error handling (invalid QoS, connection refused, invalid URL scheme)",
          "is_bot": false,
          "headline": "add MQTT v5.0 conformance test suite and remove clippy too_many_lines…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-22T17:02:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a4dd4563f06e4fc0dba1a6dbedcbf6810e4a447b",
          "body": "## Summary\n- Custom `Debug` impls on `ConnectPacket`, `ConnectOptions`, and\n`EnhancedAuthResult` to redact passwords and auth exchange data\n- QUIC data stream reader logs only packet type name instead of full\npacket contents at `debug!` level\n- Password/certificate file parse errors no longer includ\n[…]\n] Verify `Debug` output of `ConnectPacket` shows `[REDACTED]` for\npassword field\n- [ ] Verify QUIC debug logs show packet type name only\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "redact sensitive data from Debug output and logs",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-17T00:10:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ef2ca70fc9d62acea142cf4fad881d23dd86f8f",
          "body": "…management (#44)\n\n## Summary\n\n- Enforce max packet size before buffer allocation in all packet read\npaths (native + WASM), preventing OOM from malicious remaining-length\nfields\n- Add `AuthorizationMode` enum (`PrimaryOnly`/`Or`/`And`) to\n`CompositeAuthProvider` with safe `PrimaryOnly` default — fal\n[…]\nsts)\n- [x] New `CompositeAuthProvider` tests cover `PrimaryOnly`, `Or`, and\n`And` modes\n- [x] Updated ALPN tests verify filter behavior instead of panics\n- [x] All 405+ existing tests continue to pass",
          "is_bot": false,
          "headline": "security hardening across packet parsing, auth, codecs, and resource …",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-16T22:38:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ecba5b0dc0db641d830c079ba9cd92a6f12051e8",
          "body": null,
          "is_bot": false,
          "headline": "skip npm publish when mqtt5-wasm version is unchanged",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-14T21:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab77ba1122e66dbfa7320e24a9fbf0ed93aa060a",
          "body": "## Summary\n- `write_file_atomic` could fail with ENOENT when a concurrent\n`remove_queued_messages` (via `remove_dir_all`) deleted the client\ndirectory between the temp file write and the rename\n- Fix: retry the entire write-and-rename once if the rename fails with\nNotFound, recreating the directory on the second attempt\n\n## Test plan\n- [ ] Verify `cargo clippy` and tests pass\n- [ ] Confirm the error no longer appears under concurrent offline\nmessage queuing + clean session starts",
          "is_bot": false,
          "headline": "fix atomic write race with concurrent directory removal (#43)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-14T20:18:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1869c4ae00f7c5c0eafde1ff184fca418be363f9",
          "body": null,
          "is_bot": false,
          "headline": "add DeepWiki badge to readme",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-13T19:37:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49b9f2890616679446e94df70233f190f67c5b05",
          "body": null,
          "is_bot": false,
          "headline": "add npm publish step to release workflow",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-13T19:05:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b85edc56e0c9e7bd0803a79ea15b67d22463e60c",
          "body": "## Summary\n\n- WASM MQTT client detects browser online/offline state during\nreconnection via `navigator.onLine` and `online`/`offline` events\n- `on_connectivity_change(callback)` fires when network state changes;\n`is_browser_online()` returns current state synchronously\n- Reconnection pauses while of\n[…]\npass 5/5 consecutive runs (no flakiness)\n- [x] Playwright verification: connect → offline (badge updates,\ncallback fires, `is_browser_online()` returns false) → online (badge\nrestores, callback fires)",
          "is_bot": false,
          "headline": "add browser connectivity detection to WASM client (#42)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-13T18:38:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1da496381206c8b91017995bfc7c26ca52c703db",
          "body": "## Summary\n- **sleep_ms**: replace `window().expect()` with global `setTimeout`\nbinding so it works in Service Workers\n- **connect guard**: reject `connect()` if already connected or\nreconnecting\n- **connection generation**: background tasks (reader, keepalive, qos2\ncleanup) exit when generation cha\n[…]\n] `cargo clippy --all-targets --workspace -- -D warnings -W\nclippy::pedantic`\n- [x] `cargo test --all-features` (all pass)\n- [x] Pre-commit hooks pass (fmt, clippy native, clippy wasm pedantic,\ntests)",
          "is_bot": false,
          "headline": "fix wasm mqtt client wiring bugs (#41)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-13T00:02:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e3f20298d0fdc160e710406b037f36bebe11435",
          "body": "## Summary\n- Inject `x-mqtt-client-id` user property on every PUBLISH with the\npublisher's MQTT client_id (alongside existing `x-mqtt-sender` for\nuser_id)\n- Add `EchoSuppressionConfig` to skip delivery when a configurable user\nproperty (default `x-origin-client-id`) matches the subscriber's\nclient_i\n[…]\ngration test: published message has correct `x-mqtt-client-id`\n- [x] Integration test: spoofed `x-mqtt-client-id` gets replaced\n- [x] Integration test: echo suppression end-to-end with two subscribers",
          "is_bot": false,
          "headline": "add x-mqtt-client-id injection and echo suppression (#40)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-12T21:34:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "036a3798f97f230ed9f3a2c5755e23034b0d9b8b",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5 to 0.22.4",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-11T15:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb58577d6667d172a92dbfb3eb1d28ba6289e39f",
          "body": "## Summary\n- Wire existing `HotReloadManager` into `MqttBroker` so config file\nchanges propagate to new connections at runtime\n- Add `watch` channels for config and auth provider snapshots consumed\nby accept loops\n- Add SIGHUP handler in CLI for manual reload triggers on Unix\n- Make `ResourceMonitor\n[…]\no test --all-features` passes (all unit + integration tests)\n- [x] Manual test: start broker with `--config`, edit file, verify\nreload logs\n- [x] Manual test: `kill -HUP <pid>` triggers reload on Unix",
          "is_bot": false,
          "headline": "wire hot-reload config into broker with SIGHUP support (#39)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-11T14:26:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0125786f2780238e26559050de5a11c7ea8aa694",
          "body": "## Summary\n- Persist in-flight QoS 2 messages across client reconnections for both\nnative and WASM brokers\n- `InflightMessage` stores decomposed publish data with direction\n(Inbound/Outbound) and phase\n(AwaitingPubrec/AwaitingPubrel/AwaitingPubcomp)\n- `StorageBackend` trait extended with inflight CR\n[…]\nn -p mqtt5-wasm\n--features broker -- -D warnings -W clippy::pedantic`\n- [x] `cargo test --all-features`\n- [x] Manual: `wasm-pack build` + serve `qos2-recovery` example, verify\nmid-flight recovery flow",
          "is_bot": false,
          "headline": "add QoS 2 inflight persistence for native and WASM brokers (#38)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-11T00:55:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0e4a23c170256990fcce4d5d8ba17c44ccfe533",
          "body": "## Summary\n- Enhanced (JWT) auth success paths never captured `result.user_id` into\n`self.user_id`, so JWT-authenticated clients had no identity propagated\ndownstream\n- Password auth path correctly did `self.user_id = auth_result.user_id`\nbut all three enhanced auth success arms omitted it\n- Fixes: \n[…]\n# Test plan\n- [ ] Existing tests pass (verified locally)\n- [ ] Verify JWT-authenticated client publishes include `x-mqtt-sender`\nuser property\n- [ ] Verify re-authentication updates identity correctly",
          "is_bot": false,
          "headline": "fix missing user_id in enhanced auth success paths (#37)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-10T13:33:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "556c1dc254e0687169c9949643cdaa8175740bf3",
          "body": "…fixes (#36)\n\n## Summary\n- ACL topic patterns support `%u` placeholder that expands to the\nauthenticated username, scoping users to their own topic namespace\n- Broker injects `x-mqtt-sender` user property on PUBLISH packets with\nthe authenticated identity (strips client-provided values to prevent\nsp\n[…]\nal, cleanup of\nempty entries, and no-op when absent\n- [x] WASM builds without panics on closure drop or websocket connect\n- [x] Pre-commit CI verification passes (fmt, clippy, clippy-wasm, unit\ntests)",
          "is_bot": false,
          "headline": "add %u ACL substitution, x-mqtt-sender injection, and WASM transport …",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-02-02T17:58:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "56bcb86a7c82aa9489375a14d6433f27286b1e81",
          "body": "## Summary\n- Add `CompositeAuthProvider` that chains primary auth with fallback\n- Falls through to fallback only on `BadAuthenticationMethod`\n- Add `MqttBroker::auth_provider()` getter to extract built provider for\nwrapping\n\n## Versions\n- mqtt5: 0.21.1 → 0.22.0\n- mqtt5-wasm: 0.10.1 → 0.10.2\n- mqttv5-cli: 0.20.1 → 0.20.2\n\n## Test plan\n- [x] `cargo test -- composite` passes (7 tests)\n- [x] `cargo clippy` clean",
          "is_bot": false,
          "headline": "add composite auth provider with primary/fallback chain (#35)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-29T22:18:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "880c696ebd7ccc6d875b70b679fb1b70e4a122e0",
          "body": "## Summary\n\n- Fix `PublishPacket::new` setting packet_id to 0 for QoS > 0 (0 is not\na valid MQTT packet identifier)\n- Add debug tracing for outgoing PUBLISH packets and retained message\ndelivery\n- Bump versions: mqtt5 0.21.1, mqtt5-wasm 0.10.1, mqttv5-cli 0.20.1",
          "is_bot": false,
          "headline": "fix invalid packet_id 0 and add publish/retained tracing (#34)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-27T01:46:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "deb4dadffdfd06e1afd0b7ed9fa92c98729619e6",
          "body": "## Summary\n- Add change-only delivery: broker-configured duplicate payload\nsuppression for subscribers\n- Disable WASM bridge loop prevention by default (TTL 60s → 0)\n- Fix WASM bridge loop prevention time source\n- Add WASM example demonstrating change-only delivery\n- Add integration tests (10 tests)\n[…]\n- mqtt5-wasm: 0.9.2 → 0.10.0\n- mqttv5-cli: 0.19.0 → 0.20.0\n\n## Test plan\n- [x] `cargo test --test change_only_delivery` passes (10 tests)\n- [x] `cargo clippy` clean\n- [x] WASM example works in browser",
          "is_bot": false,
          "headline": "add change-only delivery feature (#33)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-23T02:03:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddc2c43ea4e252608e82d1368ac728717b76e36f",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5-wasm to 0.9.2",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-20T21:47:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b296ab0254628150aad5a4c3baabcc842172f0f8",
          "body": null,
          "is_bot": false,
          "headline": "replace wasm-pack with wasm-bindgen in build process",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-20T21:36:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6f426697f3b60ee776000791d58c7ccd94dea04",
          "body": null,
          "is_bot": false,
          "headline": "bump mqtt5 to 0.20.1",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-20T19:17:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6145978de7321e3c83d80f703707517d304dcd7",
          "body": "…ocol to 0.9.3 and mqtt5-wasm to 0.9.1",
          "is_bot": false,
          "headline": "add wasm-clippy to pre-commit, fix pedantic warnings, bump mqtt5-prot…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-20T18:29:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f241c7755c78dd34af8dd8270abec7b95bd6b930",
          "body": "…ments (#32)\n\n## Summary\n- Add codec compression system (gzip/deflate) for native mqtt5 and\nmqtt5-wasm crates\n- Add configurable bridge loop prevention with TTL and cache size\nsetters\n- Add CLI flags for compression: `--codec`, `--codec-level`,\n`--codec-min-size`\n- Add WASM examples for codec-compression and loop-prevention features\n- Fix WASM stack overflow with miniz_oxide by using boxed allocation",
          "is_bot": false,
          "headline": "mqtt5 0.20.0: codec compression, loop prevention config, WASM improve…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-20T18:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f04334b51b909725fcd95902a93e17a2fe6ce14d",
          "body": null,
          "is_bot": false,
          "headline": "update mqtt5 version to 0.19 in README",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-17T23:56:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddbef0cbd6ebaa224926bc1e685b740fa099bfc9",
          "body": "…nfig (#31)\n\n## Summary\n\n### Connection Stability\n- Async callback dispatch to prevent reader task blocking under load\n- Priority keepalive with try_lock retry mechanism for reliable pings\n- Configurable `KeepaliveConfig` for timeout tolerance on high-latency\nconnections\n\n### WASM Broker\n- 6 lifecyc\n[…]\nasm: 0.8.2 → 0.8.3\n\n## Test plan\n\n- [x] All unit tests pass\n- [x] Clippy clean\n- [x] WASM builds successfully\n- [x] Embedded target builds successfully\n- [x] New WASM examples verified with Playwright",
          "is_bot": false,
          "headline": "mqtt5 0.19.0: connection stability, WASM lifecycle events, cluster co…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-17T23:52:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "903ddedc4d38bddbdaf8fc161536d496f476c06b",
          "body": "…sues (#30)\n\n* remove embedded-single-core feature, use cfg instead\n\n* clarify --url vs --host/--port in CLI help\n\n* fix turmoil test type conversion errors\n\n* bump versions\n\n* fix channel overflow and respect require_client_cert setting\n\n* add broker generate-config subcommand and fix doc URL formatting\n\n* add multi-arch Docker build with optimized 2MB image\n\n* fix docker workflow latest tag condition\n\n* refactor deliver_to_subscriber into smaller helper functions",
          "is_bot": false,
          "headline": "remove embedded-single-core feature, add Docker builds, fix broker is…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-13T23:03:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f33d0994fd072295ac4cca583651cad1ed506c4c",
          "body": "* add unified humantime duration parsing to CLI and --delay flag\n\n* add --repeat and --interval flags for repeated publishing\n\n* add --at flag for scheduled publishing\n\n* bump mqttv5-cli to 0.18.0\n\n* use compile-time format descriptions instead of runtime unwraps\n\n* extract shared duration parsers with saturating u64-to-u32 conversion\n\n* fix parse_duration_millis to treat raw numbers as milliseconds and add unit tests\n\n* clarify --interval uses milliseconds for raw numbers in changelog",
          "is_bot": false,
          "headline": "add timing and scheduling features to CLI (#29)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-09T22:44:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c94d4d62a03b1dc77ea71d745db99d91ad724b43",
          "body": "* add runtime ACL default permission modification\n\n* fix WASM client to await PUBACK, PUBCOMP, and SUBACK properly\n\n* fix QoS 2 PUBREC rejection to clean up session state\n\n* add --wait-response to pub command for request-response pattern\n\n* add human-readable CONNACK rejection messages\n\n* fix response_topic consumed before wait_response used it\n\n* bump mqtt5 to 0.18.1, mqtt5-wasm to 0.8.1, mqttv5-cli to 0.17.1\n\n* address PR #28 review - simplify WASM client and add QoS warning",
          "is_bot": false,
          "headline": "add --wait-response, runtime ACL, and WASM client fixes (#28)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-08T17:16:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19c20a543b7c445beecfb6a692cf690857190583",
          "body": null,
          "is_bot": false,
          "headline": "update version numbers in READMEs (#27)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-07T02:59:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b64ef5e90c914ca9510d6d1a9ecd2a2aa9274b03",
          "body": "…d (#26)\n\n* share bridge types between mqtt5 and mqtt5-wasm via mqtt5-protocol\n\n* use shared bridge forwarding logic from mqtt5-protocol\n\n* add reconnection, failover, and hot reload to wasm client and broker\n\n* bump mqtt5-wasm to 0.8.0\n\n* bump mqtt5 to 0.18.0, mqtt5-protocol to 0.9.0, mqttv5-cli to 0.17.0\n\n* fix wasm config locking, add reconnection jitter and logging\n\n* use fmt-check in pre-commit to catch formatting issues",
          "is_bot": false,
          "headline": "share bridge types and add WASM reconnection, failover, and hot reloa…",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-07T02:06:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7087aacd8ed6bcac11b09a51043a47f9e868f89f",
          "body": "* reduce binary size by using only ring crypto backend\n\n* add fallback_tcp convenience field to BridgeConfig\n\n* bump versions and update documentation for protocol unification\n\n* add connection_retries to retry before protocol fallback\n\n* make bridge startup non-blocking to prevent deadlock\n\n* make \n[…]\nbridge forwarding\n\n* queue bridge messages when not connected instead of dropping\n\n* restore connection_retries functionality lost in refactor\n\n* remove unused connect_timeout field from bridge config",
          "is_bot": false,
          "headline": "reduce binary size and add fallback_tcp convenience field (#25)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2026-01-05T21:43:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a70622e507fc8800cf1854ec77ef80d0a9cefcd",
          "body": "* add QUIC transport options to bridge config and fix CLI mTLS for quics://\n\n* format bridge connection code\n\n* bump versions to mqtt5 0.17.1 and mqttv5-cli 0.16.1\n\n* add --response-topic and --correlation-data to CLI pub command\n\n* fix error propagation in configure_quic_tls and remove unnecessary clone",
          "is_bot": false,
          "headline": "add QUIC bridge options and CLI request/response support (#24)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-31T00:34:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cec780af620ec484cb5786869033dcdeb5ae5aed",
          "body": null,
          "is_bot": false,
          "headline": "clarify quic vs quics in changelog",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-30T13:07:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b85749662958e29a830d00c1efac06ea0d3111ec",
          "body": null,
          "is_bot": false,
          "headline": "update changelog for v0.17.0",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-30T13:03:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66fc26cf6b9d5fab63c51c2678f4a3f3712907f4",
          "body": "* add connection state types to protocol crate\n\n* use PacketIdGenerator from protocol crate in mqtt5-wasm\n\n* add shared keepalive logic and timeout detection to mqtt5 client\n\n* add shared error classification to protocol crate\n\n* unify ReconnectConfig to use protocol crate\n\n* format reconnection cod\n[…]\n versions and update documentation for protocol unification\n\n* add QUIC transport support to bridge connections\n\n* format bridge connection code\n\n* fix no_std build by replacing powi with integer math",
          "is_bot": false,
          "headline": "unify protocol connection state and add QUIC bridge support (#23)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-30T12:37:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1d769fc8d6a9cf540ecd7fd74483888a95b9e67",
          "body": null,
          "is_bot": false,
          "headline": "downgrade loop detection logging from warn to debug (#22)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-28T00:34:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52ff48cdb6021a98dffc5e0325f9029e88cb164c",
          "body": null,
          "is_bot": false,
          "headline": "rate-limit loop detection warnings to one per fingerprint (#21)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-27T12:23:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ddbd25b5d86bf4e0ae36dfbdec6370913247f7b",
          "body": null,
          "is_bot": false,
          "headline": "add strict pedantic clippy for wasm crate to CI (#20)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-27T06:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "304bcd657dcd6c9f8ddc2cfc3c17116e5fba251c",
          "body": "* add no_std support to mqtt5-protocol for embedded targets\n\n* fix embedded time provider and code quality issues\n\n* update READMEs with no_std and embedded documentation\n\n* add embedded CI builds and bump crate versions for no_std release\n\n* add runtime-agnostic client protocol layer with sans-io p\n[…]\n formatting\n\n* update documentation for version 0.16 and add event hooks docs\n\n* fix CI failures for embedded-single-core feature and WASM payload types\n\n* fix WASM RustMessage payload type conversion",
          "is_bot": false,
          "headline": "add no_std support and broker event hooks (#19)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-24T22:55:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e7330aabed1aef448a470f034e2dce9521499434",
          "body": null,
          "is_bot": false,
          "headline": "fix XSS in example app and add workflow permissions",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-21T16:38:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab330db0d82a7e458c96230d0538b7a1b43b1e22",
          "body": "* update bebytes to 3.0 and bump crate versions\n\n* update CHANGELOG for 0.15.2",
          "is_bot": false,
          "headline": "update bebytes to 3.0 and bump crate versions (#18)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-21T05:11:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64f012d25bbd40e3d55ea2c1cc39625665701247",
          "body": "* fix WASM dead code warnings and add  topic support\n\n* bump mqtt5-wasm to 0.6.1\n\n* add stop mechanism for WASM sys topics provider",
          "is_bot": false,
          "headline": "fix WASM dead code warnings and add $SYS topic support (#17)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-20T17:51:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31549f66f6b5086631efd00508337cec167d5ec2",
          "body": "* broker performance optimizations: 180k to 500k msg/s\n\n- add benchmark command with multi-publisher/subscriber support\n- remove yield_now from publish loop\n- remove flush after TCP/TLS writes (TCP_NODELAY handles it)\n- increase flume channel capacity from 100 to 10000\n- reduce message cloning in ro\n[…]\nin CLI readme\n\n* bump versions to 0.15.0, mqtt5-protocol 0.6.0, mqtt5-wasm 0.6.0\n\n* add pull request template\n\n* fix broker QUIC datagram receiving\n\n* document bench command and storage-backend option",
          "is_bot": false,
          "headline": "performance optimizations and 0.15.0 release (#16)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-20T02:02:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ded55b1203ca5c343d83a556dab3edf4b18e8922",
          "body": "* add RBAC support and fix SUBACK reason code handling\n\n* add client-side enhanced authentication support\n\n* format\n\n* add enhanced auth mechanisms (SCRAM, JWT, PLAIN) for broker and client\n\n* add federated JWT auth with JWKS support and claims-to-roles mapping\n\n* add server and CLI integration for \n[…]\nace manual HTTP parsing with hyper in JWKS client\n- add WASM size optimization (opt-level=z, strip=debuginfo)\n- update documentation and examples\n\n* fix SCRAM async safety and add fallback key warning",
          "is_bot": false,
          "headline": "add RBAC, enhanced authentication, and federated JWT support (#15)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-18T23:12:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0fd3265501ff656b104432ef7018ad814f4b691",
          "body": "* add max QoS validation and retain_handling to session restore\n\n* fix retained message delivery to always set retain flag true\n\n* change with_credentials password param to AsRef<[u8]>\n\n* use humantime_serde for duration fields in broker config\n\n* bump versions to 0.13.0 and update changelog\n\n* add \n[…]\nor password and ACL file generation\n\n* make humantime_serde conditional for WASM compatibility\n\n* update changelog with WASM broker auth changes\n\n* add serde default and validation for retain_handling",
          "is_bot": false,
          "headline": "fix MQTT v5 implementation gaps and add WASM broker auth (#14)",
          "author_name": "Fabrício Bracht",
          "author_login": "fabracht",
          "committed_at": "2025-12-12T12:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 56,
      "commits_last_year": 242,
      "latest_release_at": "2026-07-24T15:02:07Z",
      "latest_release_tag": "v0.38.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 36,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 7.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "mqtt5",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "async",
            "broker",
            "client",
            "messaging",
            "mqtt",
            "asynchronous",
            "network-programming"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/mqtt5",
          "is_deprecated": false,
          "latest_version": "0.38.0",
          "repository_url": "https://github.com/LabOverWire/mqtt-lib",
          "versions_count": 63,
          "total_downloads": 10397,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2104,
          "first_published_at": "2025-08-04T17:12:30.636890Z",
          "latest_published_at": "2026-07-24T14:58:12.645362Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 1
        },
        {
          "name": "mqtt5-wasm",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "iot",
            "mqtt",
            "pubsub",
            "wasm",
            "webassembly",
            "network-programming",
            "wasm"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/mqtt5-wasm",
          "is_deprecated": false,
          "latest_version": "1.4.4",
          "repository_url": "https://github.com/LabOverWire/mqtt-lib",
          "versions_count": 36,
          "total_downloads": 817,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 82,
          "first_published_at": "2025-11-26T00:57:30.628283Z",
          "latest_published_at": "2026-07-24T14:59:00.792024Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 1
        },
        {
          "name": "mqttv5-cli",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "broker",
            "cli",
            "client",
            "iot",
            "mqtt",
            "command-line-utilities",
            "network-programming"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/mqttv5-cli",
          "is_deprecated": false,
          "latest_version": "0.28.4",
          "repository_url": "https://github.com/LabOverWire/mqtt-lib",
          "versions_count": 47,
          "total_downloads": 3273,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 89,
          "first_published_at": "2025-08-04T17:15:14.465466Z",
          "latest_published_at": "2026-07-24T15:00:17.882873Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 1
        },
        {
          "name": "mqtt5-protocol",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "codec",
            "iot",
            "mqtt",
            "packet",
            "protocol",
            "network-programming",
            "parsing",
            "encoding"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/mqtt5-protocol",
          "is_deprecated": false,
          "latest_version": "0.14.2",
          "repository_url": "https://github.com/LabOverWire/mqtt-lib",
          "versions_count": 27,
          "total_downloads": 8790,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2079,
          "first_published_at": "2025-11-26T00:55:25.187266Z",
          "latest_published_at": "2026-07-10T20:46:15.699536Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 14
        }
      ]
    },
    "popularity": {
      "forks": 4,
      "stars": 54,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-11",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 1
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-07-14",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 4,
        "total_forks": 4
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/mqtt5-conformance-cli/Cargo.toml",
        "crates/mqtt5-conformance-macros/Cargo.toml",
        "crates/mqtt5-conformance/Cargo.toml",
        "crates/mqtt5-protocol/Cargo.toml",
        "crates/mqtt5-wasm/Cargo.toml",
        "crates/mqtt5/Cargo.toml",
        "crates/mqttv5-cli/Cargo.toml"
      ],
      "largest_source_bytes": 82896,
      "source_files_sampled": 380,
      "oversized_source_files": 5,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 73,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "futures-util",
          "manifest": "crates/mqtt5-conformance-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.32"
        },
        {
          "name": "libtest-mimic",
          "manifest": "crates/mqtt5-conformance-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8.2"
        },
        {
          "name": "mqtt5-conformance",
          "manifest": "crates/mqtt5-conformance-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.0"
        },
        {
          "name": "serde_json",
          "manifest": "crates/mqtt5-conformance-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.149"
        },
        {
          "name": "tokio",
          "manifest": "crates/mqtt5-conformance-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.51.1"
        },
        {
          "name": "proc-macro2",
          "manifest": "crates/mqtt5-conformance-macros/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.106"
        },
        {
          "name": "quote",
          "manifest": "crates/mqtt5-conformance-macros/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.46"
        },
        {
          "name": "syn",
          "manifest": "crates/mqtt5-conformance-macros/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.0.118"
        },
        {
          "name": "mqtt5",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "mqtt5-protocol",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.47"
        },
        {
          "name": "tracing",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "tracing-subscriber",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "serde",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "serde_json",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "toml",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "bytes",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.12.0"
        },
        {
          "name": "ulid",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.2.1"
        },
        {
          "name": "linkme",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.35"
        },
        {
          "name": "mqtt5-conformance-macros",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.0"
        },
        {
          "name": "tokio-tungstenite",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.29"
        },
        {
          "name": "futures-util",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "http",
          "manifest": "crates/mqtt5-conformance/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.4.0"
        },
        {
          "name": "bebytes",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3.0.2"
        },
        {
          "name": "bytes",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.12"
        },
        {
          "name": "thiserror",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.0"
        },
        {
          "name": "serde",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "tracing",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.41"
        },
        {
          "name": "hashbrown",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "portable-atomic",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.12"
        },
        {
          "name": "portable-atomic-util",
          "manifest": "crates/mqtt5-protocol/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2.4"
        },
        {
          "name": "mqtt5-protocol",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14.0"
        },
        {
          "name": "mqtt5",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.38"
        },
        {
          "name": "wasm-bindgen",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2.126"
        },
        {
          "name": "wasm-bindgen-futures",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.76"
        },
        {
          "name": "js-sys",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.103"
        },
        {
          "name": "console_error_panic_hook",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "getrandom",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.3"
        },
        {
          "name": "bytes",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.12.0"
        },
        {
          "name": "futures",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "futures-util",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "tracing",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.41"
        },
        {
          "name": "gloo-timers",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "flume",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12.0"
        },
        {
          "name": "miniz_oxide",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "sha2",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "web-sys",
          "manifest": "crates/mqtt5-wasm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.103"
        },
        {
          "name": "base64",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "bytes",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.12.0"
        },
        {
          "name": "futures",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "futures-util",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "hex",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "rand",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10.2"
        },
        {
          "name": "serde",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "serde_json",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "sha2",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "thiserror",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.0"
        },
        {
          "name": "toml",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tracing",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "url",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.5"
        },
        {
          "name": "tracing-subscriber",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "turmoil",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "opentelemetry_sdk",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.32"
        },
        {
          "name": "opentelemetry-otlp",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.32"
        },
        {
          "name": "tracing-opentelemetry",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.33"
        },
        {
          "name": "opentelemetry",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.32"
        },
        {
          "name": "mqtt5-protocol",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14.0"
        },
        {
          "name": "argon2",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.5"
        },
        {
          "name": "getrandom",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.3"
        },
        {
          "name": "bebytes",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3.0"
        },
        {
          "name": "regex",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.12.2"
        },
        {
          "name": "flume",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12.0"
        },
        {
          "name": "parking_lot",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12.5"
        },
        {
          "name": "flate2",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1.8"
        },
        {
          "name": "zeroize",
          "manifest": "crates/mqtt5/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.8.2"
        },
        {
          "name": "mqtt5",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.38"
        },
        {
          "name": "anyhow",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.103"
        },
        {
          "name": "tracing",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "serde",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "serde_json",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.145"
        },
        {
          "name": "hex",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.3"
        },
        {
          "name": "getrandom",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.3"
        },
        {
          "name": "humantime",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.4.0"
        },
        {
          "name": "time",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.53"
        },
        {
          "name": "bebytes",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3.0.2"
        },
        {
          "name": "flate2",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1.9"
        },
        {
          "name": "quinn",
          "manifest": "crates/mqttv5-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11.11"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "anyhow",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "argon2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "base64",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "bebytes",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "bytes",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "console_error_panic_hook",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "flate2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "flume",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "futures",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "futures-util",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "gloo-timers",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hashbrown",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "http",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "humantime",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "js-sys",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "libtest-mimic",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "linkme",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "miniz_oxide",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "mqtt5",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "mqtt5-conformance",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "mqtt5-conformance-macros",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "mqtt5-protocol",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "opentelemetry",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "opentelemetry-otlp",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "opentelemetry_sdk",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "parking_lot",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "portable-atomic",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "portable-atomic-util",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "quinn",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "quote",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rand",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "regex",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "sha2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "syn",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "time",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio-tungstenite",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "toml",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing-opentelemetry",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing-subscriber",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "turmoil",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ulid",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "url",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen-futures",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "web-sys",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "zeroize",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "clap",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "dialoguer",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "http-body-util",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "humantime-serde",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hyper",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hyper-rustls",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hyper-util",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "proptest",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rcgen",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ring",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rpassword",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rustls",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rustls-pki-types",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tempfile",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio-rustls",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio-test",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen-test",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "web-time",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "webpki-roots",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 73,
        "direct_count": 54,
        "indirect_count": 19
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 85,
        "open_issues": 1,
        "closed_ratio": 0.952,
        "closed_issues": 20,
        "closed_unmerged_prs": 4
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "fabracht",
          "commits": 237,
          "avatar_url": "https://avatars.githubusercontent.com/u/22660453?v=4"
        },
        {
          "type": "User",
          "login": "butterflyfish",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/14833825?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.983
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "conformance.yml",
        "dependencies.yml",
        "docker.yml",
        "release.yml",
        "rust.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "27 out of 27 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 2/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool is not run on all commits -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ca61532ee1ceb8ca1ed1af5b321523ed42dd4ceb",
        "ran_at": "2026-07-25T18:20:59Z",
        "aggregate_score": 5.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T15:55:32Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-24T14:55:15Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 115,
          "created_at": "2026-07-14T03:18:37Z",
          "last_comment_at": "2026-07-16T15:13:58Z",
          "last_comment_author": "fabracht"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/LabOverWire/mqtt-lib",
    "host": "github.com",
    "name": "mqtt-lib",
    "owner": "LabOverWire"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 56,
        "vitality": 89,
        "community": 60,
        "governance": 54,
        "engineering": 61
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 89,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 89,
            "inputs": {
              "commits_last_year": 242,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 36
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "36/52 weeks with commits",
                "points": 24.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 36
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "242 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 242
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 56,
              "latest_release_tag": "v0.38.0",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 7.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "56 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 56
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~7.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 7.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 60,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "forks": 4,
              "stars": 54,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "54 stars",
                "points": 28,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 54
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "4 forks",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "mqtt5",
                "mqtt5-wasm",
                "mqttv5-cli",
                "mqtt5-protocol"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 23277,
              "monthly_downloads": 4354
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,354 downloads/month across crates",
                "points": 48.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4354,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.983
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 85,
              "open_issues": 1,
              "closed_issues": 20,
              "issue_closed_ratio": 0.952,
              "closed_unmerged_prs": 4
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "95% of issues closed",
                "points": 44.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 95
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "85/89 decided PRs merged",
                "points": 36.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 85,
                      "decided": 89
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "followers": 3,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "LabOverWire",
              "public_repos": 5,
              "account_age_days": 249
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of LabOverWire",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "LabOverWire"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "mqtt5",
                "mqtt5-wasm",
                "mqttv5-cli",
                "mqtt5-protocol"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 1
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "4 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 4,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "63 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 63
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 61,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "27 out of 27 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 5.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "27 out of 27 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 58,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 37,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.7,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "70 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 37.3,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 70,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/mqtt5-conformance-cli/Cargo.toml",
                "crates/mqtt5-conformance-macros/Cargo.toml",
                "crates/mqtt5-conformance/Cargo.toml",
                "crates/mqtt5-protocol/Cargo.toml",
                "crates/mqtt5-wasm/Cargo.toml",
                "crates/mqtt5/Cargo.toml",
                "crates/mqttv5-cli/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml, crates/mqtt5-conformance-cli/Cargo.toml, crates/mqtt5-conformance-macros/Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml, crates/mqtt5-conformance-cli/Cargo.toml, crates/mqtt5-conformance-macros/Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 82896,
              "source_files_sampled": 380,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/380 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 380,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'mqtt5-conformance' from its registry",
    "Could not fetch crates package 'mqtt5-conformance-cli' from its registry",
    "Could not fetch crates package 'mqtt5-conformance-macros' from its registry",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T18:21:16.960150Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/LabOverWire/mqtt-lib.svg",
  "full_name": "LabOverWire/mqtt-lib",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticscrates.io.