Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-26 00:26 UTC

TryGhost / Deploy

Shipit plugin that deploys internal Ghost projects to servers over SSH

JavaScript · TypeScriptMIT★ 7 stars⑂ 3 forkssince Jun 2017View on GitHub ↗

TryGhost/Deploy holds a health index of 60 out of 100, placing it in the Moderate band. It scores highest on Security (70/100) and lowest on Community & Adoption (40/100). It was last updated today. 3 contributors account for most of its recent work.

60
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

60
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

GhostOrganization
1,734 followers153 public repossince Aug 2012

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npm@tryghost/deploy0.6.23,0202312 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

60Moderate · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
7.6/36Commit cadence — 11/52 weeks with commits
16.8/18Commit volume — 74 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year74
human_commit_share0.64
days_since_last_push0
active_weeks_last_year11
How it's scored
27/27Ships releases — 1 releases published
0/36Release recency — latest release 3,054 days ago
12.6/27Release cadence — cadence unknown (single release)
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count1
latest_release_tag0.0.1
releases_from_tagsno
days_since_latest_release3,054
mean_days_between_releases
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

40At risk · 18% of overall
How it's scored
12.6/60Stars — 7 stars
2.5/25Forks — 3 forks
5.3/15Watchers — 10 watchers
Inputs used
forks3
stars7
watchers10
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
46.4/80Monthly downloads — 3,020 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@tryghost/deploy
dependents
ecosystemsnpm
total_downloads
monthly_downloads3,020
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

69Moderate · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
16.9/22.5Commit distribution — top contributor authored 25% of commits
12.2/13.5Contributor breadth — 9 contributors
10/10OpenSSF Scorecard: Contributors — project has 4 contributing companies or organizations
Inputs used
bus_factor3
contributors_sampled9
top_contributor_share0.25
How it's scored
0/46.8Issue resolution — 0% of issues closed
29.4/38.3PR acceptance — 60/78 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 1/29 approved changesets -- score normalized to 0
Inputs used
merged_prs60
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs18
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
23.3/25Owner reach — 1,734 followers of TryGhost
25/25Track record — 153 public repos, account ~13 yr old
Inputs used
followers1,734
owner_typeOrganization
is_verified
owner_loginTryGhost
public_repos153
account_age_days5,088
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 12 days ago
20/20Version history — 23 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@tryghost/deploy
ecosystemsnpm
any_deprecatedno
min_days_since_publish12

Engineering Quality

Are baseline engineering and documentation practices in place?

60Moderate · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 23 out of 23 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configno
has_precommit_configno

Documentation

40At risk
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

70Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 23 out of 23 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/29 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 4 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
2.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate7.1
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
6.6/25Indirect dependencies free of known advisories — 4 affected: brace-expansion 1.1.16 (high 7.5), braces 2.3.2 (high 7.5), tmp 0.1.0 (high 7.5), +1 more
26.5/40No advisories left outstanding — 3 advisory-carrying package(s) unaddressed past 90 days; oldest published 802 days ago
Inputs used
sourceosv
advisories5
affected_packages4
assessed_packages149
unassessed_packages0
affected_by_severityhigh 3, moderate 1
direct_affected_packages0
Matched the npm:@tryghost/deploy@0.6.2 runtime dependency closure — what installing the published package pulls in — 149 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

63Moderate · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md, CLAUDE.md
0/15Machine-readable docs (llms.txt)
19.2/40Legible commit history — 23 of 64 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.359
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes4,661
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — tsconfig.json
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 36 of the last 100 commits are automated dependency updates
5/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 5
Inputs used
has_nixno
has_testsyes
lockfilespnpm-lock.yaml
has_dockerfileyes
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.36
How it's scored
27/45Type-checkable code — JavaScript with type-check config (tsconfig.json)
55/55Manageable file sizes — 0/10 source files over 60KB
Inputs used
primary_languageJavaScript
largest_source_bytes8,795
source_files_sampled10
oversized_source_files0

Key facts

7GitHub stars
9contributors
74commits, last 12 months
0days since last push
1releases
3bus factor
1open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 3 ⇿
0Stars
3Forks

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

12233312018-032019-022020-01

Each point covers 2 days.

OpenSSF Scorecard 7.1 / 10
7.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-26 00:26 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests23 out of 23 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/29 approved changesets -- score normalized to 0
10Contributorsproject has 4 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
5Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 5
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
3Vulnerabilities7 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
npmshipit-cli5.3.0package.json
All dependencies 313

Full resolved dependency set from the GitHub dependency graph: 1 direct and 312 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npmshipit-cli5.3.0direct
npm@babel/helper-string-parser7.29.7indirect
npm@babel/helper-validator-identifier7.29.7indirect
npm@babel/parser7.29.7indirect
npm@babel/types7.29.7indirect
npm@bcoe/v8-coverage1.0.2indirect
npm@emnapi/core1.10.0indirect
npm@emnapi/runtime1.10.0indirect
npm@emnapi/wasi-threads1.2.1indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@napi-rs/wasm-runtime1.1.5indirect
npm@oxc-project/types0.133.0indirect
npm@oxfmt/binding-android-arm-eabi0.60.0indirect
npm@oxfmt/binding-android-arm640.60.0indirect
npm@oxfmt/binding-darwin-arm640.60.0indirect
npm@oxfmt/binding-darwin-x640.60.0indirect
npm@oxfmt/binding-freebsd-x640.60.0indirect
npm@oxfmt/binding-linux-arm-gnueabihf0.60.0indirect
npm@oxfmt/binding-linux-arm-musleabihf0.60.0indirect
npm@oxfmt/binding-linux-arm64-gnu0.60.0indirect
npm@oxfmt/binding-linux-arm64-musl0.60.0indirect
npm@oxfmt/binding-linux-ppc64-gnu0.60.0indirect
npm@oxfmt/binding-linux-riscv64-gnu0.60.0indirect
npm@oxfmt/binding-linux-riscv64-musl0.60.0indirect
npm@oxfmt/binding-linux-s390x-gnu0.60.0indirect
npm@oxfmt/binding-linux-x64-gnu0.60.0indirect
npm@oxfmt/binding-linux-x64-musl0.60.0indirect
npm@oxfmt/binding-openharmony-arm640.60.0indirect
npm@oxfmt/binding-win32-arm64-msvc0.60.0indirect
npm@oxfmt/binding-win32-ia32-msvc0.60.0indirect
npm@oxfmt/binding-win32-x64-msvc0.60.0indirect
npm@oxlint/binding-android-arm-eabi1.75.0indirect
npm@oxlint/binding-android-arm641.75.0indirect
npm@oxlint/binding-darwin-arm641.75.0indirect
npm@oxlint/binding-darwin-x641.75.0indirect
npm@oxlint/binding-freebsd-x641.75.0indirect
npm@oxlint/binding-linux-arm-gnueabihf1.75.0indirect
npm@oxlint/binding-linux-arm-musleabihf1.75.0indirect
npm@oxlint/binding-linux-arm64-gnu1.75.0indirect
npm@oxlint/binding-linux-arm64-musl1.75.0indirect
npm@oxlint/binding-linux-ppc64-gnu1.75.0indirect
npm@oxlint/binding-linux-riscv64-gnu1.75.0indirect
npm@oxlint/binding-linux-riscv64-musl1.75.0indirect
npm@oxlint/binding-linux-s390x-gnu1.75.0indirect
npm@oxlint/binding-linux-x64-gnu1.75.0indirect
npm@oxlint/binding-linux-x64-musl1.75.0indirect
npm@oxlint/binding-openharmony-arm641.75.0indirect
npm@oxlint/binding-win32-arm64-msvc1.75.0indirect
npm@oxlint/binding-win32-ia32-msvc1.75.0indirect
npm@oxlint/binding-win32-x64-msvc1.75.0indirect
npm@rolldown/binding-android-arm641.0.3indirect
npm@rolldown/binding-darwin-arm641.0.3indirect
npm@rolldown/binding-darwin-x641.0.3indirect
npm@rolldown/binding-freebsd-x641.0.3indirect
npm@rolldown/binding-linux-arm-gnueabihf1.0.3indirect
npm@rolldown/binding-linux-arm64-gnu1.0.3indirect
npm@rolldown/binding-linux-arm64-musl1.0.3indirect
npm@rolldown/binding-linux-ppc64-gnu1.0.3indirect
npm@rolldown/binding-linux-s390x-gnu1.0.3indirect
npm@rolldown/binding-linux-x64-gnu1.0.3indirect
npm@rolldown/binding-linux-x64-musl1.0.3indirect
npm@rolldown/binding-openharmony-arm641.0.3indirect
npm@rolldown/binding-wasm32-wasi1.0.3indirect
npm@rolldown/binding-win32-arm64-msvc1.0.3indirect
npm@rolldown/binding-win32-x64-msvc1.0.3indirect
npm@rolldown/pluginutils1.0.1indirect
npm@standard-schema/spec1.1.0indirect
npm@tryghost/pro-ship1.1.7indirect
npm@tryghost/root-utils2.3.2indirect
npm@tybys/wasm-util0.10.2indirect
npm@types/chai5.2.3indirect
npm@types/deep-eql4.0.2indirect
npm@types/estree1.0.9indirect
npm@types/node24.13.3indirect
npm@typescript/typescript-aix-ppc647.0.2indirect
npm@typescript/typescript-darwin-arm647.0.2indirect
npm@typescript/typescript-darwin-x647.0.2indirect
npm@typescript/typescript-freebsd-arm647.0.2indirect
npm@typescript/typescript-freebsd-x647.0.2indirect
npm@typescript/typescript-linux-arm7.0.2indirect
npm@typescript/typescript-linux-arm647.0.2indirect
npm@typescript/typescript-linux-loong647.0.2indirect
npm@typescript/typescript-linux-mips64el7.0.2indirect
npm@typescript/typescript-linux-ppc647.0.2indirect
npm@typescript/typescript-linux-riscv647.0.2indirect
npm@typescript/typescript-linux-s390x7.0.2indirect
npm@typescript/typescript-linux-x647.0.2indirect
npm@typescript/typescript-netbsd-arm647.0.2indirect
npm@typescript/typescript-netbsd-x647.0.2indirect
npm@typescript/typescript-openbsd-arm647.0.2indirect
npm@typescript/typescript-openbsd-x647.0.2indirect
npm@typescript/typescript-sunos-x647.0.2indirect
npm@typescript/typescript-win32-arm647.0.2indirect
npm@typescript/typescript-win32-x647.0.2indirect
npm@vitest/coverage-v84.1.10indirect
npm@vitest/expect4.1.10indirect
npm@vitest/mocker4.1.10indirect
npm@vitest/pretty-format4.1.10indirect
npm@vitest/runner4.1.10indirect
npm@vitest/snapshot4.1.10indirect
npm@vitest/spy4.1.10indirect
npm@vitest/utils4.1.10indirect
npmansi-styles3.2.1indirect
npmarr-diff4.0.0indirect
npmarr-flatten1.1.0indirect
npmarr-union3.1.0indirect
npmarray-each1.0.1indirect
npmarray-slice1.1.0indirect
npmarray-unique0.3.2indirect
npmassertion-error2.0.1indirect
npmassign-symbols1.0.0indirect
npmast-v8-to-istanbul1.0.4indirect
npmasync0.2.10indirect
npmatob2.1.2indirect
npmbalanced-match1.0.2indirect
npmbase0.11.2indirect
npmbrace-expansion1.1.15indirect
npmbraces2.3.2indirect
npmcache-base1.0.1indirect
npmcaller1.1.0indirect
npmchai6.2.2indirect
npmchalk2.4.2indirect
npmclass-utils0.3.6indirect
npmcollection-visit1.0.0indirect
npmcolor-convert1.9.3indirect
npmcolor-name1.1.3indirect
npmcommander3.0.2indirect
npmcomponent-emitter1.3.1indirect
npmconcat-map0.0.1indirect
npmconvert-source-map2.0.0indirect
npmcopy-descriptor0.1.1indirect
npmdebug2.6.9indirect
npmdecode-uri-component0.2.2indirect
npmdefine-property0.2.5indirect
npmdefine-property1.0.0indirect
npmdefine-property2.0.2indirect
npmdetect-file1.0.0indirect
npmdetect-libc2.1.2indirect
npmend-of-stream0.1.5indirect
npmes-errors1.3.0indirect
npmes-module-lexer2.1.0indirect
npmescape-string-regexp1.0.5indirect
npmestree-walker3.0.3indirect
npmexpand-brackets2.1.4indirect
npmexpand-tilde2.0.2indirect
npmexpect-type1.3.0indirect
npmextend3.0.2indirect
npmextend-shallow2.0.1indirect
npmextend-shallow3.0.2indirect
npmextglob2.0.4indirect
npmfdir6.5.0indirect
npmfill-range4.0.0indirect
npmfind-root1.1.0indirect
npmfindup-sync3.0.0indirect
npmfined1.2.0indirect
npmflagged-respawn1.0.1indirect
npmfor-in1.0.2indirect
npmfor-own1.0.0indirect
npmfragment-cache0.2.1indirect
npmfs.realpath1.0.0indirect
npmfsevents2.3.3indirect
npmfunction-bind1.1.2indirect
npmget-value2.0.6indirect
npmglob7.2.3indirect
npmglobal-modules1.0.0indirect
npmglobal-prefix1.0.2indirect
npmhas-flag3.0.0indirect
npmhas-flag4.0.0indirect
npmhas-value0.3.1indirect
npmhas-value1.0.0indirect
npmhas-values0.1.4indirect
npmhas-values1.0.0indirect
npmhasown2.0.4indirect
npmhomedir-polyfill1.0.3indirect
npmhtml-escaper2.0.2indirect
npminflight1.0.6indirect
npminherits2.0.4indirect
npmini1.3.8indirect
npminterpret1.4.0indirect
npmis-absolute1.0.0indirect
npmis-accessor-descriptor1.0.2indirect
npmis-buffer1.1.6indirect
npmis-core-module2.16.2indirect
npmis-data-descriptor1.0.1indirect
npmis-descriptor0.1.8indirect
npmis-descriptor1.0.4indirect
npmis-extendable0.1.1indirect
npmis-extendable1.0.1indirect
npmis-extglob2.1.1indirect
npmis-glob4.0.3indirect
npmis-number3.0.0indirect
npmis-plain-object2.0.4indirect
npmis-relative1.0.0indirect
npmis-unc-path1.0.0indirect
npmis-windows1.0.2indirect
npmisarray1.0.0indirect
npmisexe2.0.0indirect
npmisobject2.1.0indirect
npmisobject3.0.1indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-reports3.2.0indirect
npmjs-tokens10.0.0indirect
npmkind-of3.2.2indirect
npmkind-of4.0.0indirect
npmkind-of6.0.3indirect
npmliftoff3.1.0indirect
npmlightningcss1.32.0indirect
npmlightningcss-android-arm641.32.0indirect
npmlightningcss-darwin-arm641.32.0indirect
npmlightningcss-darwin-x641.32.0indirect
npmlightningcss-freebsd-x641.32.0indirect
npmlightningcss-linux-arm-gnueabihf1.32.0indirect
npmlightningcss-linux-arm64-gnu1.32.0indirect
npmlightningcss-linux-arm64-musl1.32.0indirect
npmlightningcss-linux-x64-gnu1.32.0indirect
npmlightningcss-linux-x64-musl1.32.0indirect
npmlightningcss-win32-arm64-msvc1.32.0indirect
npmlightningcss-win32-x64-msvc1.32.0indirect
npmlodash4.17.21indirect
npmmagic-string0.30.21indirect
npmmagicast0.5.3indirect
npmmake-dir4.0.0indirect
npmmake-iterator1.0.1indirect
npmmap-cache0.2.2indirect
npmmap-visit1.0.0indirect
npmmicromatch3.1.10indirect
npmminimatch3.1.5indirect
npmmixin-deep1.3.2indirect
npmms2.0.0indirect
npmnanoid3.3.15indirect
npmnanomatch1.2.13indirect
npmobject-copy0.1.0indirect
npmobject-visit1.0.1indirect
npmobject.defaults1.1.0indirect
npmobject.map1.0.1indirect
npmobject.pick1.3.0indirect
npmobug2.1.3indirect
npmonce1.3.3indirect
npmonce1.4.0indirect
npmorchestrator0.3.8indirect
npmoxfmt0.60.0indirect
npmoxlint1.75.0indirect
npmparse-filepath1.0.2indirect
npmparse-passwd1.0.0indirect
npmpascalcase0.1.1indirect
npmpath-is-absolute1.0.1indirect
npmpath-parse1.0.7indirect
npmpath-root0.1.1indirect
npmpath-root-regex0.1.2indirect
npmpathe2.0.3indirect
npmpicocolors1.1.1indirect
npmpicomatch4.0.4indirect
npmposix-character-classes0.1.1indirect
npmpostcss8.5.15indirect
npmpretty-hrtime1.0.3indirect
npmrechoir0.6.2indirect
npmregex-not1.0.2indirect
npmrepeat-element1.1.4indirect
npmrepeat-string1.6.1indirect
npmresolve1.22.12indirect
npmresolve-dir1.0.1indirect
npmresolve-url0.2.1indirect
npmret0.1.15indirect
npmrimraf2.7.1indirect
npmrolldown1.0.3indirect
npmsafe-regex1.1.0indirect
npmsemver7.8.5indirect
npmsequencify0.0.7indirect
npmset-value2.0.1indirect
npmsiginfo2.0.0indirect
npmsnapdragon0.8.2indirect
npmsnapdragon-node2.1.1indirect
npmsnapdragon-util3.0.1indirect
npmsource-map0.5.7indirect
npmsource-map-js1.2.1indirect
npmsource-map-resolve0.5.3indirect
npmsource-map-url0.4.1indirect
npmsplit-string3.1.0indirect
npmssh-pool5.3.0indirect
npmstackback0.0.2indirect
npmstatic-extend0.1.2indirect
npmstd-env4.1.0indirect
npmstream-consume0.1.1indirect
npmstream-line-wrapper0.1.1indirect
npmsupports-color5.5.0indirect
npmsupports-color7.2.0indirect
npmsupports-preserve-symlinks-flag1.0.0indirect
npmtinybench2.9.0indirect
npmtinyexec1.2.4indirect
npmtinyglobby0.2.17indirect
npmtinypool2.1.0indirect
npmtinyrainbow3.1.0indirect
npmtmp0.1.0indirect
npmto-object-path0.3.0indirect
npmto-regex3.0.2indirect
npmto-regex-range2.1.1indirect
npmtslib2.8.1indirect
npmtypescript7.0.2indirect
npmunc-path-regex0.1.2indirect
npmundici-types7.18.2indirect
npmunion-value1.0.1indirect
npmunset-value1.0.0indirect
npmurix0.1.0indirect
npmuse3.1.1indirect
npmv8flags3.2.0indirect
npmvite8.0.16indirect
npmvitest4.1.10indirect
npmwhich1.3.1indirect
npmwhy-is-node-running2.3.0indirect
npmwrappy1.0.2indirect
Dependency advisories 4

Installing npm:@tryghost/deploy@0.6.2 pulls in 149 packages, direct and transitive: 4 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
brace-expansion1.1.16indirecthigh15.0.8
braces2.3.2indirecthigh13.0.3
tmp0.1.0indirecthigh20.2.6
micromatch3.1.10indirectmoderate14.0.8

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 403,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Shell": 1732,
        "Dockerfile": 921,
        "JavaScript": 18946,
        "TypeScript": 7391
      },
      "pushed_at": "2026-07-25T06:56:32Z",
      "created_at": "2017-06-08T15:16:04Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-25T06:56:39Z",
      "description": "Shipit plugin that deploys internal Ghost projects to servers over SSH",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://ghost.org",
      "name": "Ghost",
      "type": "Organization",
      "login": "TryGhost",
      "company": null,
      "location": null,
      "followers": 1734,
      "avatar_url": "https://avatars.githubusercontent.com/u/2178663?v=4",
      "created_at": "2012-08-19T13:28:58Z",
      "is_verified": null,
      "public_repos": 153,
      "account_age_days": 5088
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "0.0.1",
          "kind": "patch",
          "published_at": "2018-03-15T11:50:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "743e692aae503b2f9571aa1359823daf63cc8cd4",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxfmt to v0.60.0 (#78)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-25T06:56:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bcbf50398f4175ffe8fb0ad1993e0ffc09b027e",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxlint to v1.75.0 (#79)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-25T03:16:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "090e8b024086bab13fa7c3e489fc28da39b0e96d",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/checkout action to v7.0.1 (#77)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T23:55:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b0f47a16602ddebf8a9ae360404b02954776e9f",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxlint to v1.74.0 (#76)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-17T19:35:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b112395175f7886436b005d963f8441df3c57c02",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxfmt to v0.59.0 (#75)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-17T12:36:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25c4ce5f92c0d9555766663824af1e8677a34cd7",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency @tryghost/pro-ship to v1.1.7 (#74)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-16T11:59:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76163213f1c5d63e0e85e65a295177f7162d16bc",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/setup-node action to v7 (#73)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-14T07:42:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd4fda7367a32c973df3fb2dbc16f6a09f604ce1",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/setup-node action to v6.5.0 (#72)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-14T03:45:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7df8e0f9216d7926f3594937f6d561a0867bf63d",
          "body": null,
          "is_bot": false,
          "headline": "v0.6.2",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-07-13T12:53:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3f0b355fa2f0d4147b02e44abee844b1a82ca0c",
          "body": null,
          "is_bot": true,
          "headline": "Update Node.js",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-13T12:51:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b34ba1523c6d9b155bc940f38cf0f2b8697dc98a",
          "body": "The rule pinning the CI runtime to Node 20.20.0 used\nmatchPackageNames: ['node'], but the github-actions manager extracts\nnode-version entries with depName \"node\" and packageName\n\"actions/node-versions\". Renovate v41 removed the fallback where\nmatchPackageNames also compared depName, so the rule has\n[…]\nthis rule.\n\nSwitching to matchDepNames targets the field Renovate actually\ncompares for this dependency, so allowedVersions can filter the\nupdates as intended. Verified with renovate-config-validator.",
          "is_bot": false,
          "headline": "Fixed the Node pin rule so Renovate actually applies it",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-07-13T12:50:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad445afccc9577eb50d228fc638c655cadd69c32",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pnpm to v10.34.5 (#71)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-13T12:46:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d5555487c7b45cef433ca67e17af58abb932af7",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency typescript to v7 (#69)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-11T19:59:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df7c8cc825b6977fcadca0290e5838fe9c578715",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency @types/node to v24.13.3 (#68)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-11T12:09:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "514219376468bb2af741291363ccdd6bb4cdd5ba",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxlint to v1.73.0 (#67)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-10T07:42:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3029ca6b51ca56449cc6312cda82f82d004b2bc",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxfmt to v0.58.0 (#66)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-10T00:31:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab9a8fb6758badece9ba96e3d706d8a35b55ec84",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update vitest monorepo to v4.1.10 (#65)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T07:36:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6382aa5c1539d6c745f0f5e564d3e601b40a16a0",
          "body": "The CI gate was renamed to \"Required checks pass\" in 5bb0b54, but\nAGENTS.md still referenced the old \"All tests pass\" name.",
          "is_bot": false,
          "headline": "Updated AGENTS.md to match the renamed CI gate",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-07-08T08:27:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f6b54e15bd49449a5191fef34edc4e9959d613e",
          "body": "Publishing now runs in CI via OIDC (no stored npm token). The local\nrelease command moves to @tryghost/pro-ship, which bumps/commits/tags/\npushes; the new Publish workflow fires on the package.json change on main\nand publishes dist/ to npm with provenance, skipping already-published\nversions. Mirrors the knex-migrator setup.",
          "is_bot": false,
          "headline": "Added OIDC trusted publishing to npm",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-07-07T15:31:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bb0b549e0255447a2a2a06c2a36ec0de0ca2d5e",
          "body": "Branch protection currently requires the check named \"All tests pass\",\nwhich couples the ruleset to this repo's particular CI naming. The org\nis standardizing every repository on a single stable aggregator check\nnamed \"Required checks pass\", so rulesets stay valid no matter how the\nunderlying job ma\n[…]\nhen any needed job reports failure or cancelled. The branch ruleset is\nbeing switched to require the new check in the same pass, so this PR\nmust go green on \"Required checks pass\" before it can merge.",
          "is_bot": false,
          "headline": "Renamed the CI gate to the org-standard \"Required checks pass\"",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-07-06T10:36:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4732d44bb0c714ea8d0acf1b57f0b0d56bdf228b",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxlint to v1.72.0 (#60)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-03T07:39:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1ae70f5341e1507a76923219c0e1926935b7ff1",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxfmt to v0.57.0 (#59)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-03T03:51:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ea80c75c64723febdc6568a92472ed335534caa",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxlint to v1.71.0 (#58)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-25T19:33:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de9fbcb5b985261b97a2f69052acfa47f6906b97",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency oxfmt to v0.56.0 (#57)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-25T12:56:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45f85e7d4e350d7760dacf5e021079eaab067820",
          "body": null,
          "is_bot": false,
          "headline": "0.6.1",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-06-24T11:03:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c385ce811c8955e74817bdfdde669122086fd76",
          "body": null,
          "is_bot": false,
          "headline": "Added TS version of shipit command",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-06-24T11:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99002d8269587248d816f8a9490a5aefd749827a",
          "body": null,
          "is_bot": false,
          "headline": "Ensure shipit bin is exposed after typescript build",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-06-24T11:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6ffc3adc7536bf01b1f39f338b9e62524ce31e5",
          "body": null,
          "is_bot": false,
          "headline": "0.6.0",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-06-24T10:55:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5720cf930b3a68d054527179d004496c13966bc",
          "body": null,
          "is_bot": false,
          "headline": "Alphabetise the package.json",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-06-24T10:53:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "622eedb26af51aef5ae7ac1406451ed8fe6f3d5a",
          "body": null,
          "is_bot": false,
          "headline": "Added shipit command to hoist it for pnpm",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-06-24T10:51:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df08db47e997bfd4da2c90c0c86d474a2a0f7dba",
          "body": null,
          "is_bot": false,
          "headline": "0.5.1",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-23T13:21:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8093d1495e43910c8b4ab9185d21a5c35da753cc",
          "body": "Added a Renovate package rule for the GitHub Actions `node` dependency when the raw value is `20.20.0`, keeping those CI runtime jobs pinned to the repo consumer runtime floor. This prevents Renovate from reopening patch updates such as `20.20.0` to `20.20.2` while leaving the separate Node 22 and 24 compatibility jobs untouched.",
          "is_bot": false,
          "headline": "Updated Renovate to pin Node runtime updates",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-23T11:50:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f05cf5a78f84139c7d1e0e16be11d9364e0cf88a",
          "body": "This reverts commit e885e5ef6056007d60b0fa56e0f659905db01205.",
          "is_bot": false,
          "headline": "Revert \"Update dependency node to v20.20.2 (#54)\"",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-23T11:45:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e885e5ef6056007d60b0fa56e0f659905db01205",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency node to v20.20.2 (#54)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-23T11:39:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d21327859e3c8f1fc6c397c7328fe22c044e40b",
          "body": "Changed `.nvmrc` to use Node 22 for local development while leaving the package runtime floor at Node 20.20.0. This lets contributors develop against the newer LTS line without changing the repo `engines.node` contract or the CI matrix coverage for Node 20.20.0.",
          "is_bot": false,
          "headline": "Updated `.nvmrc` to Node 22",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-23T11:37:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "500a76dc26f0712c5c820bef91ba666173bb52ff",
          "body": "Added a Renovate package rule for `pnpm` so dependency automation does not propose pnpm 11 while `@tryghost/deploy` still supports Node 20.20.0. This keeps automated package manager updates aligned with the repo Node floor, since pnpm 11 requires Node 22.13 or newer.",
          "is_bot": false,
          "headline": "Updated Renovate to keep `pnpm` on 10.x",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-23T11:33:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01c5edbbe61580a330564bffceb9eb9cceae3222",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#51)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-22T03:56:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19badebaa144c61dac60bc915baf4d22ada391b0",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pnpm to v10.34.4 (#50)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-21T22:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd49f8ab5c111795dff5b72407c8e2b7479ee1c5",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/checkout action to v7 (#49)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-19T02:08:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d3a373fe16b2908d5a4ef447f4549153ac76dee",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update vitest monorepo to v4.1.9 (#48)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-18T17:05:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dab67356edea346b728e580b3e3f0632644b7fbe",
          "body": "Per the updated Clean Repos oxlint baseline, the lint script runs oxlint with\n--quiet so only errors are reported. The suspicious category is configured as\nwarn, so without --quiet those warnings add noise to every lint run while never\nfailing it; --quiet keeps lint output focused on what actually gates CI.",
          "is_bot": false,
          "headline": "Run oxlint with --quiet in the lint script",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T13:09:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d03ceb3b1e4240fbe0a07accafff6ac38db7565",
          "body": "pnpm publish doesn't choose the version, so releases go: pnpm version <bump>\nthen pnpm ship. Add a preversion hook that runs the test suite before the bump\nso a failing build aborts the version (no stranded commit/tag) — pnpm version\naborts when preversion exits non-zero. The same flow covers patch, minor, and\nmajor; only the bump argument changes. Document the release flow in the README\nand AGENTS.md.",
          "is_bot": false,
          "headline": "Run tests before a version bump via the preversion hook",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T12:45:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fc96bcf4cc708d1bf4e690ae14bb2dc8baf1eda",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update Types packages to v24 (#45)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T12:25:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "969eef35e7ea599d8ed32e9308facf10725c62c8",
          "body": "This is a tiny but high-blast-radius library — its deploy behaviour is a\ncontract that daisy.js, zuul, stats-service and other Jenkins-deployed\nservices depend on. Typing it gives real confidence in those API contracts\n(the shipit surface and the deploy config) when consumers integrate it and\nwhen d\n[…]\ne .ts source (dist excluded); unit\n  coverage stays at 100%.\n- README now leads with the pnpm install command (org standard).\n\nConsumers keep `require('@tryghost/deploy')` unchanged and now get types.",
          "is_bot": false,
          "headline": "Rewrite the plugin in TypeScript",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T12:18:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4588c40aa07facae0103e03d2b9f02c7b5f2ac3",
          "body": "The README still referenced the old `ghost-deploy` package name in two code\nsamples, documented only the yarn invocation, and carried a stale copyright\nyear. After the pnpm migration and the runtime package-manager support, the\ninvocation docs were also actively misleading for pnpm users.\n\n- Fix the\n[…]\n/22/24 support window and why pnpm is pinned to 10.x,\nthe SHA-pinned-actions policy, the Docker-based two-container e2e, the\n`All tests pass` required check, and the pnpm publish/version release flow.",
          "is_bot": false,
          "headline": "Refresh README and add AGENTS.md",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T09:17:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "057c7700360837b3ac31fb7023eeab75275ff532",
          "body": "Standardises this repo on the Clean Repos lint/format baseline: oxlint for\nlinting and oxfmt for formatting, replacing ESLint 4 + eslint-plugin-ghost.\noxlint is far faster and is the direction the TryGhost estate is moving;\neslint-plugin-ghost 1.0.0 also pinned the repo to the long-deprecated\nESLint\n[…]\ny plus\nthe existing unit/e2e suites cover behaviour, and oxfmt owns style. Verified\nwith pnpm lint, pnpm test:unit (13 tests, 100% coverage), and the docker e2e\nsuite (21 tests) on the Node 20 runner.",
          "is_bot": false,
          "headline": "Replace ESLint with oxlint and oxfmt",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T09:04:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5b2ac977a787c0dc6864f97b306187326f70ce3",
          "body": "- resolvePackageManager now rejects an explicitly set but invalid value\n  including an empty string (was a truthy check that silently fell back to\n  the legacy yarn/npm selector). undefined/null still fall back.\n- Correct the claim that yarn \"ships with Node\": only npm is bundled with\n  Node; yarn is commonly preinstalled (e.g. in the Node Docker images) but\n  not guaranteed, and pnpm usually is not. Fixed in the lib comment and the\n  README so server-provisioning expectations are accurate.",
          "is_bot": false,
          "headline": "Address review: empty packageManager and bundling wording",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T08:35:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec031c093c5bc97aa4c11b6aa0d1484ccc7a109c",
          "body": "Consumers migrating to pnpm (GVA-795 — e.g. Stats-Service via GVA-794) need\nthe deploy to be able to install their dependencies with pnpm on the server,\nnot just yarn or npm. The runtime already shells the install command, so the\npackage-manager choice is the only thing in the way.\n\nReplace the bina\n[…]\ners must omit node_modules\n  from sharedLinks.\n\nCovered by unit tests for the resolver (100% coverage) and an e2e leg that\ndeploys with pnpm to a real target, alongside the existing yarn and npm legs.",
          "is_bot": false,
          "headline": "Add pnpm as a deploy-time package manager option",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T08:35:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb0d865bac7a8d50e8423dd05a8a008f4bb271db",
          "body": "CI is the gate that lets Renovate auto-merge dependency updates safely, so\nevery runtime branch a bump could break needs real end-to-end coverage. The\ndeploy runtime chooses npm vs yarn from shipit.config.npm (lib/deploy.js),\nbut only the yarn branch was exercised against a real target — the npm\nbra\n[…]\n the release, so the shared-dir optimisation only applies to the\nyarn path.\n\nThe shipit fixture now accepts per-deploy config overrides so both package\nmanagers can be exercised from the same harness.",
          "is_bot": false,
          "headline": "Add e2e coverage for the npm install path",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T08:33:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8b737ddebc878aea640f66920f6f4a22c6e7f88a",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#29)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T08:25:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7dcb5206fe9b5720c8a41ebf69905ffe147bef9e",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update eslint monorepo to v4.19.1 (#36)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T08:20:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3516cea1b2517b5260ab8aa14074b13ff5c8441",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update vitest monorepo to v4 (#34)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T07:54:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea332a34b8d58693ca7f121ce6b1600a7d50c307",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/setup-node action to v6 (#23)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T07:47:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50e8a06347412e1d2d868518ac639550a48331be",
          "body": "Standardises this repo's own package management on pnpm, matching the\ndirection the rest of the TryGhost estate is moving and unblocking\nconsumers that require a pnpm-based toolchain. Only the repo's build/test\ntooling changes here; the deploy runtime is deliberately untouched.\n\n- Pin pnpm via packa\n[…]\nripts stay blocked by pnpm's default.\n\nVerified with pnpm install --frozen-lockfile, pnpm lint, pnpm test:unit\n(8 tests, 100% coverage), and the full docker e2e suite (17 tests) on the\nNode 20 runner.",
          "is_bot": false,
          "headline": "Migrate repo tooling from Yarn to pnpm (#38)",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T07:45:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ca3e062b3e1b97fe26484004f2dfdf2d292121e",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update vitest monorepo to v3.2.6 (#33)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T07:26:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28c2295fcd103bbd0b4604675bc772a2db96ab70",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/checkout action to v6 (#22)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T07:17:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bef67d8942d610c7e86f5a5103ea14fc2de611d",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency vitest to v3.2.6 [SECURITY] (#31)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-17T07:13:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69131d93ec549a80997f61054d10d3f455378a71",
          "body": "The Renovate config extended the legacy npm-style @tryghost:base shareable\npreset, which is no longer the standardised reference across TryGhost repos\nand reads as a wrong-preset on the clean-repos dashboard.\n\nSwitch to the shared local>TryGhost/renovate-config default preset so this\nrepo tracks the same Renovate policy as the rest of the org, and migrate the\nfile to renovate.json5 with the schema reference to match the shared-config\nconvention. No local overrides existed to preserve.",
          "is_bot": false,
          "headline": "Standardise Renovate config to shared TryGhost default preset",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T07:08:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad788305d2023fedabaf6efa6efa1054b6f2c9eb",
          "body": "TryGhost org policy rejects floating action tags; pin checkout (v4.3.1) and\nsetup-node (v4.4.0) to full-length commit SHAs so CI can run.",
          "is_bot": false,
          "headline": "Pin GitHub Actions to commit SHAs",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T06:45:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f81d086b5eda6f7c3328eefa026af955078c8d4e",
          "body": "Deploy is a high-blast-radius shipit plugin consumed by many Jenkins-deployed\nservices, but its CI only ran ESLint on Node 18 — there was no coverage and the\n`test` script just linted. A dependency update that broke the deploy contract,\nor dropped support for the Node runtimes consumers pin, could m\n[…]\n is ported faithfully (17/17 still pass). The consumer-facing\nruntime contract in lib/deploy.js (shelling yarn/npm install on remote servers\nbased on shipit.config.npm) is deliberately left untouched.",
          "is_bot": false,
          "headline": "Made CI trustworthy for automated dependency updates",
          "author_name": "Aileen Booker",
          "author_login": "aileen",
          "committed_at": "2026-06-17T06:45:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "628ae89b3bf65edf0bba6b8c13673b475b3c19f5",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#28)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-12T14:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3b1520800c0d4cf0c5e02f1f618b663528c3525",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#27)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-28T12:56:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfa2e12681e4e98bba677b8c638be1e0b4849958",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#26)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-21T18:16:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "288ad02a1f63f2b4211cd4082aca2a5b1a0b28f3",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#11)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-16T14:04:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbbf1289e80c71ebf72ab7fd64b3d2999f2f61f2",
          "body": null,
          "is_bot": false,
          "headline": "v0.4.1",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T13:14:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ab97830a1eb5290dfbb089c36dbb70565bed47d",
          "body": "We've got a problem that the downstream apps (which actually use\n`shipit` in the CLI) don't have `shipit-cli` as a dependency. That\nactually makes sense, given this package includes the plugin.",
          "is_bot": false,
          "headline": "Made shipit-cli a full depedency",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T13:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e56ed473f791c8e557dbfa152c61cddcd65eb57",
          "body": null,
          "is_bot": false,
          "headline": "v0.4.0",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T12:26:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e8f0007a2a01836913b7c785a2f04917032beb9",
          "body": null,
          "is_bot": false,
          "headline": "Added tests for release cleanup",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:35:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad98e03336109aeb328d42be7299964f3625b49c",
          "body": null,
          "is_bot": false,
          "headline": "Added clean-up feature, removes old releases leaving at most 10",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:35:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86119b26ed1dd72a7518055a1b588c3bb29f2d41",
          "body": null,
          "is_bot": false,
          "headline": "Swapped var for let/const",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d27aa18b653ce284fea86061dbf8ad4597f5249",
          "body": null,
          "is_bot": false,
          "headline": "Removed unnecessary dependencies",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bab45717bf3a0d43b0f66cf75fb9059e5cd1820",
          "body": null,
          "is_bot": false,
          "headline": "Improved E2E tests",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5856fe03c6328268fd91516ca3c077861d00866",
          "body": null,
          "is_bot": false,
          "headline": "Added CI for lint & testing",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80e8d937f101159aa9c22cc0d120920ef5c8795f",
          "body": null,
          "is_bot": false,
          "headline": "Added E2E tests",
          "author_name": "Sam Lord",
          "author_login": "sam-lord",
          "committed_at": "2026-03-24T10:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4963662ac0cbd9f74dba63fa3e4e525e675c8e22",
          "body": null,
          "is_bot": false,
          "headline": "2023",
          "author_name": "John O'Nolan",
          "author_login": "JohnONolan",
          "committed_at": "2023-08-03T20:00:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dd7bd3eb525d894455d605e78d776b897a323b0",
          "body": null,
          "is_bot": false,
          "headline": "v0.3.3",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2022-07-04T15:43:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5339b9874f4f64cedc935ee7257da1526e8915db",
          "body": "- replaceAll is not a function until Node 15 :(",
          "is_bot": false,
          "headline": "Fixed Node 14 compatibility",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2022-07-04T15:42:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f630876853fe1d9f4ab841d2ec393d6cffbf3d33",
          "body": null,
          "is_bot": false,
          "headline": "v0.3.2",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2022-07-04T15:32:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "324438ed6bdbc994f9927821dedef0847c60b68a",
          "body": "refs https://github.com/getsentry/sentry-javascript/issues/5151\n\n- this works around the above issue by replacing colons and periods with\n  an underscore",
          "is_bot": false,
          "headline": "Fixed colons and periods in filenames",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2022-07-04T15:30:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "943a3ba8788632c93607bf797c85ae7b7867b7ea",
          "body": null,
          "is_bot": false,
          "headline": "2022",
          "author_name": "John O'Nolan",
          "author_login": "JohnONolan",
          "committed_at": "2022-01-06T13:39:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12d30604273349e6041f2b664ec9240968a1f2e8",
          "body": null,
          "is_bot": false,
          "headline": "2021",
          "author_name": "John O'Nolan",
          "author_login": "JohnONolan",
          "committed_at": "2021-01-25T16:39:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad6803c3fb43ba14c70c9a4b979f64e682252951",
          "body": null,
          "is_bot": false,
          "headline": "v0.3.1",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-09-18T12:42:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "557cdb18063dea3180262c3dbe22eeecd7db7d5c",
          "body": "- goddamn types",
          "is_bot": false,
          "headline": "Fixed false check",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-09-18T12:41:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adaf232da48d3e9e0315599e94ad3c886ac8ce80",
          "body": null,
          "is_bot": false,
          "headline": "v0.3.0",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-09-18T10:43:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ffba3b525a40a6f7c0d63ccf04dfad108b94992",
          "body": null,
          "is_bot": false,
          "headline": "Removed unneeded comments",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-09-18T10:43:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c5c6c83bbc46d22f426a8b4e9e031d44f670b6f",
          "body": null,
          "is_bot": false,
          "headline": "Added NO_RESTART functionality",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-09-18T10:43:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f5cdb2d6db6daf7c090725cb42b12dbf3797d46",
          "body": null,
          "is_bot": false,
          "headline": "Update dependency lodash to v4.17.20",
          "author_name": "Renovate Bot",
          "author_login": "renovate-bot",
          "committed_at": "2020-09-18T10:40:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d767c5d8f60aecc26a51523ec7f72622ba79359",
          "body": null,
          "is_bot": false,
          "headline": "Update dependency bluebird to v3.7.2",
          "author_name": "Renovate Bot",
          "author_login": "renovate-bot",
          "committed_at": "2020-09-03T09:25:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "000c76a1283de1728c5928e9646a8e362f721c32",
          "body": null,
          "is_bot": false,
          "headline": "v0.2.3",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-19T11:49:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0717c8edbc8b4d8d51efee32173ab101a39e8ea0",
          "body": null,
          "is_bot": false,
          "headline": "Added optional target name for a link",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-19T11:49:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bfa0621bec0710df2732cf7538de7612cae78c5",
          "body": null,
          "is_bot": false,
          "headline": "v0.2.2",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T19:35:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f22ddc871c4cb28cc49d5ed2adfe7d8833d1f23c",
          "body": null,
          "is_bot": false,
          "headline": "Switched from using cwd",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T19:34:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fccca03c9f038fbceeb90a2f03172f5e502f343",
          "body": null,
          "is_bot": false,
          "headline": "v0.2.1",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:39:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50435ffd766462243227c79e2bcab418ee00e6dd",
          "body": null,
          "is_bot": false,
          "headline": "Fixed exporting of helper function",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:38:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "589493d251db8d4a738301f13d6ed7edd634c3e5",
          "body": null,
          "is_bot": false,
          "headline": "v0.2.0",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:32:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1cdf36d340bb08d71f71d2e4ea9e1b4b7b60cb2",
          "body": null,
          "is_bot": false,
          "headline": "Added getServerList helper function",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:32:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4136b70dac31af52fbff0b433201ccd5036f53f",
          "body": "- the logging messages were a bit unnecessary as shipit is already quite\n  verbose in its actions\n- as a result, chalk was not needed",
          "is_bot": false,
          "headline": "Removed chalk from project",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:12:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f359d7b91911b320a9e761e82f15fd1e68b555c",
          "body": null,
          "is_bot": false,
          "headline": "v0.1.5",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:05:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20cd4d3b93239bfa702079ce29913d523b3ac9fa",
          "body": null,
          "is_bot": false,
          "headline": "Pinned dependencies",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:04:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4b108972e3eabcd585d61d91e3f81ce38cd4ddf",
          "body": "- we don't want to enable automerge yet, but want dependency PRs available",
          "is_bot": false,
          "headline": "Updated Renovate config",
          "author_name": "Daniel Lockyer",
          "author_login": "daniellockyer",
          "committed_at": "2020-08-18T18:03:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 74,
      "latest_release_at": "2018-03-15T11:50:20Z",
      "latest_release_tag": "0.0.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 3054,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@tryghost/deploy",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@tryghost/deploy",
          "is_deprecated": false,
          "latest_version": "0.6.2",
          "repository_url": "https://github.com/TryGhost/Deploy",
          "versions_count": 23,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 34,
          "monthly_downloads": 3020,
          "first_published_at": "2018-03-15T11:48:56.817000Z",
          "latest_published_at": "2026-07-13T12:53:57.097000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 12
        }
      ]
    },
    "popularity": {
      "forks": 3,
      "stars": 7,
      "watchers": 10,
      "fork_history": {
        "days": [
          {
            "date": "2018-03-23",
            "count": 1
          },
          {
            "date": "2019-07-12",
            "count": 1
          },
          {
            "date": "2020-01-24",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 3,
        "total_forks": 3
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 8795,
      "source_files_sampled": 10,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 4661
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.16",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "braces",
            "direct": false,
            "version": "2.3.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-grv7-fg5c-xmjg"
            ],
            "fixed_version": "3.0.3",
            "advisory_count": 1,
            "oldest_advisory_days": 802
          },
          {
            "name": "tmp",
            "direct": false,
            "version": "0.1.0",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52f5-9888-hmc6",
              "GHSA-ph9p-34f9-6g65"
            ],
            "fixed_version": "0.2.6",
            "advisory_count": 2,
            "oldest_advisory_days": 353
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "3.1.10",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-952p-6rrq-rcjv"
            ],
            "fixed_version": "4.0.8",
            "advisory_count": 1,
            "oldest_advisory_days": 802
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 3,
          "moderate": 1
        },
        "advisory_count": 5,
        "affected_count": 4,
        "assessed_count": 149,
        "malicious_count": 0,
        "assessed_package": "npm:@tryghost/deploy@0.6.2",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "shipit-cli",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "5.3.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "shipit-cli",
            "direct": true,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/core",
            "direct": false,
            "version": "1.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/wasi-threads",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/wasm-runtime",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@oxc-project/types",
            "direct": false,
            "version": "0.133.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-android-arm-eabi",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-android-arm64",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-darwin-arm64",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-darwin-x64",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-freebsd-x64",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-arm-musleabihf",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-arm64-gnu",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-arm64-musl",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-ppc64-gnu",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-riscv64-gnu",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-riscv64-musl",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-s390x-gnu",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-x64-gnu",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-linux-x64-musl",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-openharmony-arm64",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-win32-arm64-msvc",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-win32-ia32-msvc",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxfmt/binding-win32-x64-msvc",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-android-arm-eabi",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-android-arm64",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-darwin-arm64",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-darwin-x64",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-freebsd-x64",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-arm-musleabihf",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-arm64-musl",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-riscv64-gnu",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-riscv64-musl",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-x64-gnu",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-linux-x64-musl",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-openharmony-arm64",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-win32-ia32-msvc",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxlint/binding-win32-x64-msvc",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-android-arm64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-arm64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-x64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-freebsd-x64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-musl",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-musl",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-openharmony-arm64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-wasm32-wasi",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-x64-msvc",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/pluginutils",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@standard-schema/spec",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tryghost/pro-ship",
            "direct": false,
            "version": "1.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@tryghost/root-utils",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tybys/wasm-util",
            "direct": false,
            "version": "0.10.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "24.13.3",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-aix-ppc64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-darwin-arm64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-darwin-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-freebsd-arm64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-freebsd-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-arm",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-arm64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-loong64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-mips64el",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-ppc64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-riscv64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-s390x",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-linux-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-netbsd-arm64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-netbsd-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-openbsd-arm64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-openbsd-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-sunos-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-win32-arm64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript/typescript-win32-x64",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "arr-diff",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "arr-flatten",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "arr-union",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "array-each",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-slice",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "array-unique",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "assign-symbols",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "async",
            "direct": false,
            "version": "0.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "atob",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "base",
            "direct": false,
            "version": "0.11.2",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.15",
            "ecosystem": "npm"
          },
          {
            "name": "braces",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "cache-base",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "caller",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "class-utils",
            "direct": false,
            "version": "0.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "collection-visit",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "1.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "component-emitter",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "copy-descriptor",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "2.6.9",
            "ecosystem": "npm"
          },
          {
            "name": "decode-uri-component",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "define-property",
            "direct": false,
            "version": "0.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "define-property",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "define-property",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "detect-file",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "end-of-stream",
            "direct": false,
            "version": "0.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expand-brackets",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "expand-tilde",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "extend",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "extend-shallow",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "extend-shallow",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "extglob",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fill-range",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-root",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "findup-sync",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fined",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "flagged-respawn",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "for-in",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "for-own",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fragment-cache",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "fs.realpath",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-value",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "7.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "global-modules",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "global-prefix",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-value",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "has-value",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-values",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "has-values",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "homedir-polyfill",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "inflight",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "interpret",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-absolute",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-accessor-descriptor",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-buffer",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "is-core-module",
            "direct": false,
            "version": "2.16.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-data-descriptor",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-descriptor",
            "direct": false,
            "version": "0.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "is-descriptor",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-extendable",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extendable",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-number",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-plain-object",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-relative",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-unc-path",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-windows",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "isarray",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isobject",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "isobject",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "kind-of",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "kind-of",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "kind-of",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "liftoff",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-android-arm64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-arm64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-x64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-freebsd-x64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-gnu",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-musl",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-gnu",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-musl",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-arm64-msvc",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-x64-msvc",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash",
            "direct": false,
            "version": "4.17.21",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "make-iterator",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "map-cache",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "map-visit",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "3.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "mixin-deep",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.15",
            "ecosystem": "npm"
          },
          {
            "name": "nanomatch",
            "direct": false,
            "version": "1.2.13",
            "ecosystem": "npm"
          },
          {
            "name": "object-copy",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "object-visit",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "object.defaults",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "object.map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "object.pick",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "obug",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "orchestrator",
            "direct": false,
            "version": "0.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "oxfmt",
            "direct": false,
            "version": "0.60.0",
            "ecosystem": "npm"
          },
          {
            "name": "oxlint",
            "direct": false,
            "version": "1.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse-filepath",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "parse-passwd",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "pascalcase",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-is-absolute",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-parse",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "path-root",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-root-regex",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "posix-character-classes",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.15",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-hrtime",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "rechoir",
            "direct": false,
            "version": "0.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "regex-not",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "repeat-element",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "repeat-string",
            "direct": false,
            "version": "1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "1.22.12",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-dir",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-url",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "ret",
            "direct": false,
            "version": "0.1.15",
            "ecosystem": "npm"
          },
          {
            "name": "rimraf",
            "direct": false,
            "version": "2.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "rolldown",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "safe-regex",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "sequencify",
            "direct": false,
            "version": "0.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "set-value",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "snapdragon",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "snapdragon-node",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "snapdragon-util",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.5.7",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-resolve",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-url",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "split-string",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ssh-pool",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "static-extend",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "stream-consume",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "stream-line-wrapper",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "5.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-preserve-symlinks-flag",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinypool",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "tmp",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "to-object-path",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex-range",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "unc-path-regex",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "union-value",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "unset-value",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "urix",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "use",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8flags",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "8.0.16",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 313,
        "direct_count": 1,
        "indirect_count": 312
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 60,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 18
      },
      "bus_factor": 3,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "daniellockyer",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/964245?v=4"
        },
        {
          "type": "User",
          "login": "aileen",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/8037602?v=4"
        },
        {
          "type": "User",
          "login": "sam-lord",
          "commits": 18,
          "avatar_url": "https://avatars.githubusercontent.com/u/34093537?v=4"
        },
        {
          "type": "User",
          "login": "ErisDS",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/101513?v=4"
        },
        {
          "type": "User",
          "login": "JohnONolan",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/120485?v=4"
        },
        {
          "type": "User",
          "login": "sebgie",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/539213?v=4"
        },
        {
          "type": "User",
          "login": "renovate-bot",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/25180681?v=4"
        },
        {
          "type": "User",
          "login": "cobbspur",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/4405395?v=4"
        },
        {
          "type": "User",
          "login": "kirrg001",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/1160712?v=4"
        }
      ],
      "contributors_sampled": 9,
      "top_contributor_share": 0.25
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 4 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 5,
            "reason": "dependency not pinned by hash detected -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "743e692aae503b2f9571aa1359823daf63cc8cd4",
        "ran_at": "2026-07-26T00:26:29Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T06:56:52Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-25T06:56:31Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 15,
          "created_at": "2021-10-18T21:28:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/TryGhost/Deploy",
    "host": "github.com",
    "name": "Deploy",
    "owner": "TryGhost"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 60,
      "inputs": {
        "security": 70,
        "vitality": 60,
        "community": 40,
        "governance": 69,
        "engineering": 60
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 60,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "commits_last_year": 74,
              "human_commit_share": 0.64,
              "days_since_last_push": 0,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "74 commits in the last year",
                "points": 16.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 74
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "0.0.1",
              "releases_from_tags": false,
              "days_since_latest_release": 3054,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3054 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3054
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 12,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 12 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 12
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 40,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "forks": 3,
              "stars": 7,
              "watchers": 10,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "7 stars",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "3 forks",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "10 watchers",
                "points": 5.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "@tryghost/deploy"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3020
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,020 downloads/month across npm",
                "points": 46.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3020,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 69,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 9,
              "top_contributor_share": 0.25
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 25% of commits",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 25
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "9 contributors",
                "points": 12.2,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 29,
            "inputs": {
              "merged_prs": 60,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 18
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "60/78 decided PRs merged",
                "points": 29.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 60,
                      "decided": 78
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "followers": 1734,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "TryGhost",
              "public_repos": 153,
              "account_age_days": 5088
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,734 followers of TryGhost",
                "points": 23.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1734,
                      "login": "TryGhost"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "153 public repos, account ~13 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 153
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@tryghost/deploy"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 12
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 12 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 12
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "23 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 60,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "at_risk",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 70,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "23 out of 23 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 2.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Matched the npm:@tryghost/deploy@0.6.2 runtime dependency closure — what installing the published package pulls in — 149 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@tryghost/deploy@0.6.2",
                  "assessed": 149
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "source": "osv",
              "advisories": 5,
              "affected_packages": 4,
              "assessed_packages": 149,
              "unassessed_packages": 0,
              "affected_by_severity": "high 3, moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "4 affected: brace-expansion 1.1.16 (high 7.5), braces 2.3.2 (high 7.5), tmp 0.1.0 (high 7.5), +1 more",
                "points": 6.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 4,
                      "packages": "brace-expansion 1.1.16 (high 7.5), braces 2.3.2 (high 7.5), tmp 0.1.0 (high 7.5)"
                    }
                  },
                  {
                    "code": "advisories_affected_more",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "3 advisory-carrying package(s) unaddressed past 90 days; oldest published 802 days ago",
                "points": 26.5,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 3,
                      "oldest": 802
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 149,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 63,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "moderate",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.359,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 4661
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "23 of 64 human commits state their intent (structured subject or explanatory body)",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 23,
                      "sampled": 64
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.36
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "36 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 36,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 5",
                "points": 5,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 8795,
              "source_files_sampled": 10,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript with type-check config (tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "tsconfig.json",
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/10 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 10,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T00:26:47.336767Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/TryGhost/Deploy.svg",
  "full_name": "TryGhost/Deploy",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.