Public record
Software health reportschema 0.27.0 · metrics 1.14.0 · 2026-07-29 02:14 UTC

VenusProtocol / venus-protocol

BNB Smart Chain Venus Protocol

TypeScript · SolidityBSD-3-Clause★ 278 stars⑂ 202 forkssince Sep 2020View on GitHub ↗

VenusProtocol/venus-protocol holds a health index of 34 out of 100, placing it in the At risk band. It scores highest on Sustainability & Governance (78/100) and lowest on Security (24/100). It was last updated 7 days ago. 3 contributors account for most of its recent work.

34
overall / 100
At risk

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

34
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.

Ownership

Venus ProtocolOrganization
207 followers21 public repossince Jan 2021

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npm@venusprotocol/venus-protocol10.3.016,33125620 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

76Good · 22% of overall
How it's scored
36/36Push recency — last push 7 days ago
33.9/36Commit cadence — 49/52 weeks with commits
18/18Commit volume — 694 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year694
human_commit_share1
days_since_last_push7
active_weeks_last_year49
How it's scored
27/27Ships releases — 3 releases published
0/36Release recency — latest release 1,411 days ago
12.6/27Release cadence — a release every ~316.5 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count3
latest_release_tagvip-60
releases_from_tagsno
days_since_latest_release1,411
mean_days_between_releases316.5
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

76Good · 18% of overall
How it's scored
39.6/60Stars — 278 stars
19.2/25Forks — 202 forks
6.8/15Watchers — 18 watchers
Inputs used
forks202
stars278
watchers18
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (BSD-3-Clause)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
56.2/80Monthly downloads — 16,331 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@venusprotocol/venus-protocol
dependents
ecosystemsnpm
total_downloads
monthly_downloads16,331
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

78Good · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
17.8/22.5Commit distribution — top contributor authored 21% of commits
13.5/13.5Contributor breadth — 29 contributors
10/10OpenSSF Scorecard: Contributors — project has 8 contributing companies or organizations
Inputs used
bus_factor3
contributors_sampled29
top_contributor_share0.211
How it's scored
34.6/46.8Issue resolution — 74% of issues closed
32.1/38.3PR acceptance — 533/635 decided PRs merged
3/15OpenSSF Scorecard: Code-Review — Found 2/7 approved changesets -- score normalized to 2
Inputs used
merged_prs533
open_issues13
closed_issues37
issue_closed_ratio0.74
closed_unmerged_prs102
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
16.7/25Owner reach — 207 followers of VenusProtocol
20.8/25Track record — 21 public repos, account ~5 yr old
Inputs used
followers207
owner_typeOrganization
is_verified
owner_loginVenusProtocol
public_repos21
account_age_days2,020
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 20 days ago
20/20Version history — 256 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@venusprotocol/venus-protocol
ecosystemsnpm
any_deprecatedno
min_days_since_publish20

Engineering Quality

Are baseline engineering and documentation practices in place?

70Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
16/16Linter config — .eslintrc
0/9.6Pre-commit hooks
0/6.4.editorconfig
2/20OpenSSF Scorecard: CI-Tests — 1 out of 6 merged PRs checked by a CI test -- score normalized to 1
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

24Critical · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
0.2/2.5CI-Tests — 1 out of 6 merged PRs checked by a CI test -- score normalized to 1
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
1.5/7.5Code-Review — Found 2/7 approved changesets -- score normalized to 2
2.5/2.5Contributors — project has 8 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 135 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.6
high_risk_jurisdiction_cap49
high_risk_jurisdiction_multiplier50
security_posture_after_multiplier23
security_posture_before_jurisdiction46
Excluded from scoring (no data or not applicable): branch_protection, signed_releases. Remaining weights renormalized. High-Risk Jurisdiction Policy applies a 50% multiplier and gives Security posture an At risk ceiling of 49.
How it's scored
16.8/35Direct dependencies free of known advisories — 1 affected: @openzeppelin/contracts 4.9.3 (moderate 6.5)
1.4/25Indirect dependencies free of known advisories — 15 affected: @openzeppelin/contracts 3.4.2-solc-0.7 (critical 10.0), @openzeppelin/contracts-upgradeable 3.4.2-solc-0.7 (critical 10.0), @openzeppelin/contracts 3.4.2 (high 7.5), +12 more
11.7/40No advisories left outstanding — 13 advisory-carrying package(s) unaddressed past 90 days; oldest published 1,793 days ago
Inputs used
sourceosv
advisories66
affected_packages16
assessed_packages504
unassessed_packages0
affected_by_severitycritical 2, high 12, moderate 1, low 1
direct_affected_packages1
Matched the npm:@venusprotocol/venus-protocol@10.3.0 runtime dependency closure — what installing the published package pulls in — 504 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

60Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 97 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.97
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — .eslintrc
11/11Static type checking — tsconfig.json
10/10Reproducible environment — lockfile
6/10Demonstrated agent practice — 3 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesyarn.lock
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configstsconfig.json
agent_commit_share0.03
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
53.4/55Manageable file sizes — 8/270 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes2,168,472
source_files_sampled270
oversized_source_files8

Key facts

278GitHub stars
29contributors
694commits, last 12 months
7days since last push
3releases
3bus factor
13open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 0 ★ / 202 ⇿
0Stars
202Forks
3Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0408012016020019452020-102023-092026-07
Major 0Minor 0Patch 2

Each point covers 6 days.

OpenSSF Scorecard 4.6 / 10
4.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-29 02:13 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
1CI-Tests1 out of 6 merged PRs checked by a CI test -- score normalized to 1
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
2Code-ReviewFound 2/7 approved changesets -- score normalized to 2
10Contributorsproject has 8 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities135 existing vulnerabilities detected
Direct dependencies 11
RegistryPackageVersion constraintManifest
npm@nomicfoundation/hardhat-ethers^3.0.0package.json
npm@openzeppelin/contracts4.9.3package.json
npm@openzeppelin/contracts-upgradeable^4.8.0package.json
npm@venusprotocol/governance-contracts^2.13.0package.json
npm@venusprotocol/protocol-reserve^3.4.0package.json
npm@venusprotocol/solidity-utilities^2.1.0package.json
npm@venusprotocol/token-bridge^2.7.0package.json
npmbignumber.js^9.1.2package.json
npmdotenv^16.0.1package.json
npmmodule-alias^2.2.2package.json
npmpatch-package^8.0.0package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 16

Installing npm:@venusprotocol/venus-protocol@10.3.0 pulls in 504 packages, direct and transitive: 16 carry known advisories, of which 1 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
@openzeppelin/contracts3.4.2-solc-0.7indirectcritical54.8.3
@openzeppelin/contracts-upgradeable3.4.2-solc-0.7indirectcritical44.8.3
@openzeppelin/contracts3.4.2indirecthigh44.8.3
adm-zip0.4.16indirecthigh10.6.0
axios0.21.4indirecthigh231.18.0
brace-expansion2.1.2indirecthigh15.0.8
elliptic6.5.4indirecthigh76.6.1
elliptic6.6.1indirecthigh1
serialize-javascript6.0.2indirecthigh27.0.5
tmp0.0.33indirecthigh20.2.6
undici5.29.0indirecthigh98.5.0
uuid8.3.2indirecthigh113.0.1
ws7.4.6indirecthigh28.21.0
ws8.18.0indirecthigh28.21.0
@openzeppelin/contracts4.9.3directmoderate15.0.2
cookie0.4.2indirectlow10.7.0

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 96679,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 109,
        "Solidity": 1732233,
        "Handlebars": 1011,
        "JavaScript": 81231,
        "TypeScript": 2031209
      },
      "pushed_at": "2026-07-21T12:32:07Z",
      "created_at": "2020-09-28T14:08:34Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T09:25:57Z",
      "description": "BNB Smart Chain Venus Protocol",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "BSD-3-Clause",
      "default_branch": "develop",
      "license_spdx_raw": "BSD-3-Clause",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "Solidity"
      ]
    },
    "owner": {
      "blog": "https://venus.io",
      "name": "Venus Protocol",
      "type": "Organization",
      "login": "VenusProtocol",
      "company": null,
      "location": null,
      "followers": 207,
      "avatar_url": "https://avatars.githubusercontent.com/u/77491099?v=4",
      "created_at": "2021-01-15T11:50:26Z",
      "is_verified": null,
      "public_repos": 21,
      "account_age_days": 2020
    },
    "license": {
      "state": "standard",
      "spdx_id": "BSD-3-Clause",
      "raw_spdx": "BSD-3-Clause",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "vip-60",
          "kind": "other",
          "published_at": "2022-09-16T07:27:04Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2021-04-21T12:28:27Z"
        },
        {
          "tag": "v1.1.2",
          "kind": "patch",
          "published_at": "2020-12-22T09:21:05Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2ef5ebeff8062bbc8b6cfcda67c2c176299373c0",
          "body": "## 10.3.0-dev.4 (2026-07-21)\n\n* fix(bstock):: enforce Venus Liquidator gate checks in atomicLiquidate and safe-fallback scripts ([28ba594](https://github.com/VenusProtocol/venus-protocol/commit/28ba594))\n* Merge branch 'feat/VPD-1598' into feat/VPD-1589 ([2a26a80](https://github.com/VenusProtocol/ve\n[…]\nub.com/VenusProtocol/venus-protocol/commit/d17b5ba))\n* refactor(bstock): type LM API responses and validate the signing seed ([5c9cab2](https://github.com/VenusProtocol/venus-protocol/commit/5c9cab2))",
          "is_bot": false,
          "headline": "chore(release): 10.3.0-dev.4 [skip ci]",
          "author_name": "Venus Tools",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-21T05:23:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "083f75c63f243670ff42724e54d2ea30181249b2",
          "body": "[VPD-1430, 1431, 1432] feat(bstock): atomic backstop liquidator + off-chain scripts",
          "is_bot": false,
          "headline": "Merge pull request #683 from VenusProtocol/feat/VPD-1430",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-21T05:14:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6880065a52d8909eaf1bce2aea83cd775c8aa24",
          "body": null,
          "is_bot": false,
          "headline": "feat: updating deployment files",
          "author_name": "fred-venus",
          "author_login": "fred-venus",
          "committed_at": "2026-07-21T03:15:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e75d2b73edfde73efbc9281e008407f1597f7a25",
          "body": "[VPD-1636] BStockLiquidator deployment",
          "is_bot": false,
          "headline": "Merge pull request #702 from VenusProtocol/feat/VPD-1636",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-21T03:12:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "351501b2df31e464882f761e42817a947b0f2d4d",
          "body": "Feat/vpd 1598",
          "is_bot": false,
          "headline": "Merge pull request #703 from VenusProtocol/feat/VPD-1598",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-21T03:07:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "831c8b262d67bcad990ef0bc74a9b05b9d491975",
          "body": "test(bstock): fork-prove the full mode × hop-1 source × debt scenario matrix",
          "is_bot": false,
          "headline": "Merge pull request #701 from VenusProtocol/test/bstock-scenario-matrix",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-21T03:03:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ba70aa492bd58d2363c20b25f98f960fe7539f9",
          "body": null,
          "is_bot": false,
          "headline": "docs(audits): add HashDit BStockLiquidator audit report",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-20T13:54:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2536b362da9298dbcc493563366e85dc7b68a9df",
          "body": null,
          "is_bot": false,
          "headline": "chore(bstock): redeploy BStockLiquidator to bscmainnet",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-20T13:17:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00ca7109d99ad14f5816466693223ebd361064d8",
          "body": "[VPD-1598] BStockLiquidator: Liquid Mesh hop-1 source, VAI debt support, and HashDit audit mitigations",
          "is_bot": false,
          "headline": "Merge pull request #696 from VenusProtocol/feat/VPD-1598",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-20T12:56:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8441a7cd3dbe795d24e244ebcee18426a034793f",
          "body": null,
          "is_bot": false,
          "headline": "test(bstock): remove standalone fork workflow",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-20T11:33:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d94d4db8baefe6e551abbdbbc1bdde247d8d92a",
          "body": null,
          "is_bot": false,
          "headline": "test(bstock): harden scenario matrix",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-20T11:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ca908e36a6b3ba1ecbb30d490fcb2d4d991189e",
          "body": "ResilientOracle maps the native market to NATIVE_TOKEN_ADDR\n(0xbBbB…BBbB), not WBNB (0xbb4CdB…095c), so the matrix suite's price pin\nnever reached vBNB. Every vBNB read stayed on the live feed and reverted\n'invalid resilient oracle price' once a run drifted past its ~30min\nstaleness window, failing the BNB cells intermittently.",
          "is_bot": false,
          "headline": "fix(bstock): pin vBNB oracle under the native sentinel, not WBNB",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-20T07:11:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7b3adbfcfe20be9d24cf215383bf1b59bb21fec",
          "body": "… matrix\n\nCompletes BStockLiquidatorFork.ts coverage across\n{inventory, flash} × {native-style router-pulls, LM-style split-spender} ×\n{USDT, CAKE (real PCS), BNB (WBNB unwrap), VAI (real PSM)}:\n\n- adds the 8 previously untested positive cells — inv×LM×{CAKE,BNB,VAI},\n  flash×native×{CAKE,BNB}, flas\n[…]\nreverts any vBNB borrow/liquidity check\n  (the main suite's BNB cell hits this at its default block)\n\n10 passing at FORK_BSTOCK_BLOCK=110490000.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(bstock): fork-prove the full mode × hop-1 source × debt scenario…",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-20T04:19:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1507c56d0cad42338623cbc88fd75ceac146da3e",
          "body": null,
          "is_bot": false,
          "headline": "fix: [L07]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-17T13:27:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1925f0b67c5988c6374856cbd90b478dc000939",
          "body": "[VPD-1589] Add Liquid Mesh as a hop-1 liquidation source",
          "is_bot": false,
          "headline": "Merge pull request #694 from VenusProtocol/feat/VPD-1589",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-17T07:05:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1815d06f0e626c675298cf923c49f0259fc2b93",
          "body": "…and docs\n\n- Add lm-smoke.ts: a read-only Liquid Mesh /quote probe, the counterpart to\n  native-smoke.ts (never /swap; one best-effort symbol() label read, reusing\n  ARCHIVE_NODE_bscmainnet). Both smokes now print the same shape (amountIn/out,\n  px/token) with a mirrored firm-only / indicative block\n[…]\ncapped) rather than \"Native unavailable\".\n- Add the bStock secrets to .env.example (NATIVE_API_KEY, LM_API_KEY, LM_PRIVATE_KEY_SEED,\n  optional RPC_URL).\n\nUnit: tests/hardhat/BStock*.ts - 106 passing.",
          "is_bot": false,
          "headline": "feat(bstock): add lm-smoke probe, align smoke output, clarify naming …",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-17T06:12:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "316bbb480fdb00d9896ec51f26cb32a15ccde44f",
          "body": "The seize error strings hardcoded liquidateCalculateSeizeTokens even on the isVai\nbranch, which calls liquidateVAICalculateSeizeTokens — misleading when a VAI\nliquidation or Safe-batch build fails. Derive the function name from isVai and\ninterpolate it into both throws in atomic-liquidate.ts and safe-fallback.ts.",
          "is_bot": false,
          "headline": "fix(bstock): name the actual seize function in VAI error messages",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T20:59:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c18c57195fc80cbfe839d3ee641870706fbbaaaf",
          "body": "…label\n\nSplit the group header so \"2 · atomic-liquidate.ts\" stays left and \"DRY_RUN=1\" is\nright-aligned, leaving the vertical \"alive · auto\" edge a clear center gap.",
          "is_bot": false,
          "headline": "docs(bstock): stop the atomic arrow overlapping the DRY_RUN=1 header …",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T20:54:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b4a7544a7997b92272a9196e6997b79fe40bcb4",
          "body": "…fallback framing\n\nRework the operator flowchart to reflect the current multi-source, VAI-capable\nscripts: pre-flight gates (debt-type detect, shortfall/ALLOW_NO_SHORTFALL,\nVAI-forces-inventory), hop-2 routing by debt type (single-hop USDT, AMM for other\nERC20, WBNB unwrap for native BNB, PSM swapSt\n[…]\n README framing: the fallback triggers when the\nwhole quote path is down (every RFQ source, or the VAI PSM hop), and it is\nRFQ/PSM-independent because it ships bStock to the CEX with no on-chain swap.",
          "is_bot": false,
          "headline": "docs(bstock): expand liquidation flowchart and correct Native/LM/PSM …",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T20:51:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17bc7fd6a2123e199e9d2843ae6cdeae274acd6e",
          "body": "…e ERC20 borrower\n\nAdd a bscmainnet-fork test that stands up a real non-core e-mode pool listing vBStock\nat a divergent liquidation incentive (1.25x vs core 1.1x), puts a USDT borrower in it,\nand gaps the stock into shortfall. It proves (a) getEffectiveLiquidationIncentive and\ngetLiquidationIncentiv\n[…]\ns forced core-vs-effective\ndivergence is on-chain-impossible for VAI (core-pool-locked), so it guards the script's\ncut formula, not a reproducible mainnet state; the genuine case is the new fork test.",
          "is_bot": false,
          "headline": "test(bstock): fork-prove effective-incentive divergence for a non-cor…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T20:16:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "801f18040a5a00a1f90ec039238c4a71425fa988",
          "body": "…n scripts\n\nThe treasury-cut comments claimed getEffectiveLiquidationIncentive diverges from\nthe core getLiquidationIncentive \"whenever the borrower sits in a non-core pool\"\n— false for VAI. A VAI borrower is core-pool-locked (VAIController.mintVAI requires\nthe core pool and MarketFacet.hasValidPool\n[…]\nready call effective\nfor the cut (gate-parity with Liquidator._splitLiquidationIncentive + future-proofing);\nonly the rationale was wrong. Comments updated in atomic-liquidate.ts and safe-fallback.ts.",
          "is_bot": false,
          "headline": "docs(bstock): correct VAI incentive-divergence comments in liquidatio…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T20:16:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d5c7e9d0dc12f1871a9269cc7ebcd426bab79b3",
          "body": "…omments\n\n- README: add SETTLE_TTL_MARGIN and ALLOW_NO_SHORTFALL to the atomic env table,\n  SEIZE_BUFFER to the safe-fallback table, an advanced/override env subsection,\n  and correct \"4 txs\" to \"3-4\" (native BNB drops the approve). Note the\n  single-hop minOut is derived from the guaranteed floor a\n[…]\ne drift\n  alone can invalidate a safe-fallback batch.\n- amm.ts: correct the stale comments that described exact-match hop-2 sizing;\n  the caller passes the hop-1 floor and relies on floor <= midDelta.",
          "is_bot": false,
          "headline": "docs(bstock): document env knobs and correct the runbook and sizing c…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T15:14:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4214098bc967e3f1436d4828ed8af0056e2a7038",
          "body": "…ht guards\n\nCorrectness and safety fixes to the off-chain liquidation scripts, each with\ntests (mocked script suites + a bscmainnet-fork scenario):\n\n- Size the Venus Liquidator treasury cut off getEffectiveLiquidationIncentive\n  for every debt type, VAI included, mirroring Liquidator._splitLiquidati\n[…]\nt a millisecond-epoch value\n  that would silently disable the off-chain TTL guards.\n\nTest mocks gain a divergent effective-vs-core incentive and a getAccountLiquidity\nerror slot to exercise the above.",
          "is_bot": false,
          "headline": "fix(bstock): harden liquidation off-chain seize, minOut, and pre-flig…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T15:13:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "111af24985ba3d34fadddf9332b9baa9dd7d598f",
          "body": "Runs atomicLiquidate() itself end-to-end on the bscmainnet fork for a\nconstructed VAI-debt borrower (prime-only mint flag flipped through the\nreal ACM + timelock, bStock collateral gapped into shortfall): the\nscript detects the VAIController debt, sizes the seize with the VAI\noverload, builds the sw\n[…]\n exactly the previewed amount and the undershot hop-1\nsurplus stays as sweepable USDT. Also asserts the script refuses\nMODE=flash for VAI before quoting. VAI scaffolding extracted into\nshared helpers.",
          "is_bot": false,
          "headline": "test(bstock): script-driven VAI liquidation fork scenario",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T14:00:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1baf78f22f77016ade94a0ae143368b175c7a5b1",
          "body": "… module\n\nSettles a real underwater VAI position on a bscmainnet fork: bStock\ncollateral on the live diamond, VAI minted through the real\nVAIController (prime-only flag flipped via the real ACM + timelock),\nrepay through the real gate's VAI branch, and hop 2 executed with the\nexact swapStableForVAI \n[…]\nts exactly its previewSwapStableForVAI amount to the contract.\nA fresh proxy is used because the deployed one predates VAI support.\nAlso proves getPsmSwap refuses to build when the real PSM is paused.",
          "is_bot": false,
          "headline": "test(bstock): fork-test the VAI PSM hop against the real PegStability…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T13:23:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ab7e4f062f789e1f3aba98373ff901e80cae4f0",
          "body": "The contract and its tests already specified the Peg Stability Module\n(swapStableForVAI) as router2 for a VAI debt, but atomic-liquidate.ts\nhad no code to construct that calldata — a VAI run fell through to the\nAMM aggregator path. Add lib/psm.ts: encodes swapStableForVAI locally\n(receiver = the liq\n[…]\n-1 floor), derives\nexpectedOut from previewSwapStableForVAI, and pre-flights isPaused and\nmint-cap headroom. Reject MODE=flash for VAI before quoting, mirroring\nthe contract's FlashNotSupportedForVai.",
          "is_bot": false,
          "headline": "feat(bstock): build the VAI hop-2 PSM calldata in the script",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-16T12:57:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90fed52b1e0feab087c9b7f315e915106713c939",
          "body": "It detected vBNB by catching underlying(), which the VAIController also\nlacks, so a VAI debt built a {value: repay} batch the gate rejects. Detect\nVAI explicitly and use its own seize math (liquidateVAICalculateSeizeTokens,\nborrower-agnostic incentive). This path ships the seized bStock instead of\nswapping it, so it is the fallback when the atomic path's PSM hop is down.",
          "is_bot": false,
          "headline": "fix(bstock): stop safe-fallback misreading a VAI debt as native BNB",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-15T13:07:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a21bcac0f9c46dd82c167eea14a49b0e2a0dca1",
          "body": "A borrower whose only debt is VAI was unliquidatable: _liquidate called\nunderlying(), which the VAIController does not have. Resolve VAI via\ngetVAIAddress() and route it through the gate's _liquidateVAI branch,\ntwo-hop bStock->USDT->VAI with the PSM as hop 2. INVENTORY only — VAI is\nburned on repay, so there is no market to flash from.",
          "is_bot": false,
          "headline": "feat(bstock): support VAI debt in the backstop liquidator",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-15T13:06:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "591f6c73c02f548de8d8e384ad83131b4abdf20a",
          "body": "An LM /quote is indicative, but hop-2 calldata bakes in a fixed amountIn\nwhile the contract approves only the real hop-1 delta — an underfill left\nthe AMM pulling past the approval. Sizing off the guaranteed floor keeps\nthe pull covered; the surplus stays sweepable. Native unchanged (floor==out).",
          "is_bot": false,
          "headline": "fix(bstock): size the hop-2 leg off the LM floor, not the quote",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-15T11:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "929ec4121e652897b42ca14bcdf31d2ac7858c35",
          "body": null,
          "is_bot": false,
          "headline": "fix(bstock): restore router spender lookup in _swap",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-15T11:56:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a26a80eb024b05b65ed850db5bac6d218289342",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'feat/VPD-1598' into feat/VPD-1589",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-15T09:19:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2a4bc55cb77982dddfc8fdcd8a6d790038aa77c",
          "body": "## 10.3.0-dev.3 (2026-07-15)\n\n* Merge pull request #698 from VenusProtocol/fix/slim-publish-npm-engine ([0d21b55](https://github.com/VenusProtocol/venus-protocol/commit/0d21b55)), closes [#698](https://github.com/VenusProtocol/venus-protocol/issues/698)\n* Merge pull request #699 from VenusProtocol/f\n[…]\n46d51a](https://github.com/VenusProtocol/venus-protocol/commit/b46d51a))\n* ci: pin slim-publish npm to v11 to fix EBADENGINE ([2fe54b8](https://github.com/VenusProtocol/venus-protocol/commit/2fe54b8))",
          "is_bot": false,
          "headline": "chore(release): 10.3.0-dev.3 [skip ci]",
          "author_name": "Venus Tools",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-15T02:17:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9366bb4c52e765a3a9088b4795162b1333bfa28",
          "body": "feat: generate tokens.json in the slim package",
          "is_bot": false,
          "headline": "Merge pull request #699 from VenusProtocol/feat/slim-tokens",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-15T02:03:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b46d51afe6b8208d2ce7debaf85dcef74fa8a760",
          "body": null,
          "is_bot": false,
          "headline": "feat: generate tokens.json in the slim package",
          "author_name": "Gleiser Oliveira",
          "author_login": "gleiser-oliveira",
          "committed_at": "2026-07-14T17:59:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8d0e99ee64b0c0f66542c4053be205a58a4550b",
          "body": "Surface the swap router's own revert reason instead of an opaque\nSwapFailed(), so a failed hop reports the actual cause (e.g. insufficient\nallowance). SwapFailed() is kept only as the empty-returndata fallback.",
          "is_bot": false,
          "headline": "fix(bstock): bubble up router revert reason in _swap",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-14T13:56:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d21b558c8d2e9dc7b7f203f0bd14ae44fd091bb",
          "body": "ci: pin slim-publish npm to v11 to fix EBADENGINE",
          "is_bot": false,
          "headline": "Merge pull request #698 from VenusProtocol/fix/slim-publish-npm-engine",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-14T12:20:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2fe54b87658e082a00c69bf45d40c615f293e14e",
          "body": "npm@latest now resolves to npm@12.0.1, which requires node\n^22.22.2 || ^24.15.0 || >=26.0.0. CI runs node v22.14.0, so the\nglobal install failed with EBADENGINE and the slim publish step\nexited 1. Pin to npm@^11.5.1 (matching the step's stated intent)\nso it stays compatible with the CI node version.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: pin slim-publish npm to v11 to fix EBADENGINE",
          "author_name": "toolsvenus",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-14T12:08:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "07f38486a8888cc156f7f00c8d7a3786df425a80",
          "body": "## 10.3.0-dev.2 (2026-07-14)\n\n* Merge pull request #697 from VenusProtocol/bot/VDB-23-list-skhyb-on-platform ([004d3b3](https://github.com/VenusProtocol/venus-protocol/commit/004d3b3)), closes [#697](https://github.com/VenusProtocol/venus-protocol/issues/697)\n* feat: register SKHYB underlying + vSKH\n[…]\nctestnet) ([721ec17](https://github.com/VenusProtocol/venus-protocol/commit/721ec17))\n* chore: deploy artifacts (bsctestnet) ([e01e2bd](https://github.com/VenusProtocol/venus-protocol/commit/e01e2bd))",
          "is_bot": false,
          "headline": "chore(release): 10.3.0-dev.2 [skip ci]",
          "author_name": "Venus Tools",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-14T10:39:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "004d3b33f7ba8e677130e6aadb8553e49d8e5647",
          "body": "…latform\n\nVDB-23: Register SKHYB underlying + deploy vSKHYB market (bsctestnet + bscmainnet)",
          "is_bot": false,
          "headline": "Merge pull request #697 from VenusProtocol/bot/VDB-23-list-skhyb-on-p…",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-14T10:27:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "932d14d25dc6bb48a280fa3568cba844ff1b8163",
          "body": null,
          "is_bot": false,
          "headline": "feat: updating deployment files",
          "author_name": "trumpgpt-bot",
          "author_login": "trumpgpt-bot",
          "committed_at": "2026-07-14T08:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ca1961b7bba66307c346a8710029030f7b40324",
          "body": null,
          "is_bot": false,
          "headline": "chore: deploy artifacts (bscmainnet)",
          "author_name": "trumpgpt",
          "author_login": "trumpgpt-bot",
          "committed_at": "2026-07-14T08:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "721ec17a1ee6f4e474d9e11539f96837563a939e",
          "body": null,
          "is_bot": false,
          "headline": "chore: deploy artifacts (bsctestnet)",
          "author_name": "trumpgpt",
          "author_login": "trumpgpt-bot",
          "committed_at": "2026-07-14T08:03:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e01e2bd004f97664aeaa35fc338f6bb87219987c",
          "body": null,
          "is_bot": false,
          "headline": "chore: deploy artifacts (bsctestnet)",
          "author_name": "trumpgpt",
          "author_login": "trumpgpt-bot",
          "committed_at": "2026-07-14T07:59:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e248358f0cf79a3f23e062a1776d050cdd7bdbe8",
          "body": "…bscmainnet)\n\nAdd the SK Hynix (SKHYB) underlying and the Venus SK Hynix (vSKHYB) Core\nPool market to the token/market helpers for both networks, so the\nMockTokens (testnet) and Markets deploy scripts can deploy them.\n\n- Underlying SKHYB (18 dec); mainnet CA 0xCA750eF65f295BBECd685Abf54e82CAf297BDB61\n- vSKHYB: CF 50%, RF 10%, supply cap 140, borrow disabled\n- IRM: base 0%, multiplier 6.67%, kink 75%, jump 627%\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: register SKHYB underlying + vSKHYB market config (bsctestnet + …",
          "author_name": "trumpgpt",
          "author_login": "trumpgpt-bot",
          "committed_at": "2026-07-14T07:56:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ae6b50fd5cd33277a16db954ca18ea7b0d6415c9",
          "body": "Promise.allSettled waits for the slowest source, so a hung API blocked the\nlive one. Add fetchWithTimeout (SOURCE_TIMEOUT_MS, default 8s) to the Native\nand LM clients so a hung source aborts and drops out.",
          "is_bot": false,
          "headline": "fix(bstock): time out hung hop-1 source API calls",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-14T06:04:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b36c17e45b8d08e03085ce8d418a78585a27101e",
          "body": null,
          "is_bot": false,
          "headline": "fix(bstock): consistent LM slippage bps and tolerant SOURCE parsing",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T13:20:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aba7007ebd44c8a4bbc214bf4495a617ac1b11df",
          "body": null,
          "is_bot": false,
          "headline": "docs(bstock): clarify renounce and swap-underflow invariants",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T12:27:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15ac30de4784e4aa4625f33c049bdff22827b17b",
          "body": null,
          "is_bot": false,
          "headline": "docs(bstock): fix runbook env table and swap mermaid for SVG",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T10:55:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "510c9e867609c67df963cb882c16ce0f7ad51715",
          "body": "Zero-context operators had to infer the run order from scattered\nhints; give them a mermaid decision tree (smoke -> dry-run -> send,\nSafe fallback branches) plus rules of thumb up front.",
          "is_bot": false,
          "headline": "docs(bstock): add script decision flowchart to runbook",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T09:31:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18fce770efb7df3aecb0daf20f321829f280b579",
          "body": "Runbook lagged two behavior changes:\n- indicative LM winner is reconciled against the best firm quote after\n  build; operators see an expected `hop-1 reconcile:` source switch\n- setRouterSpender now requires an allowlisted router and a contract\n  spender; de-allowlisting clears the spender entry",
          "is_bot": false,
          "headline": "docs(bstock): document hop-1 reconcile and setRouterSpender ordering",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T09:11:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c9cab259171c411dac01a7fad270d31eb92ae04",
          "body": "Replace the two any-typed JSON parses with a typed LmResponse<T>\nenvelope, and reject an LM_PRIVATE_KEY_SEED that does not decode to\nexactly 32 bytes with a legible error instead of the cryptic\ncreatePrivateKey DER failure.",
          "is_bot": false,
          "headline": "refactor(bstock): type LM API responses and validate the signing seed",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T09:04:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b9c7a5c020ea3d0989a3df45f1f47b1358c0c31",
          "body": "LM RFQ orders are short-lived; an order already too tight to survive\nsigning + submission + inclusion would only fail on-chain with\nDeadlineExpired, mid-incident. Abort at build time instead when fewer\nthan LM_MIN_TTL seconds (default 15) remain on the order.",
          "is_bot": false,
          "headline": "fix(bstock): enforce a minimum TTL on built Liquid Mesh orders",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T09:02:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e53cd8a13353a3b314d62db912c5d73758de6e8e",
          "body": "… build\n\nLiquid Mesh's /quote number is indicative — the separately built /swap\norder only guarantees its own floor — while Native's firm quote executes\nat exactly its amountOut. Comparing the two raw outs let an optimistic\nLM quote win the hop-1 selection and then fill worse than Native\nguaranteed.\n\nTag each SourceQuote as firm/indicative and expose the built order's\nbuiltFloor from build(); when an indicative winner's floor undercuts the\nbest firm loser, execute the firm quote instead.",
          "is_bot": false,
          "headline": "fix(bstock): reconcile indicative LM quotes against firm quotes after…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T09:01:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d57fc0b15e3e49e5cbbdfb0f95239ccdec4a1b73",
          "body": "Couple the spender lifecycle to the router allowlist:\n- setRouterSpender reverts unless the router is currently allowlisted\n- a non-zero spender must be a deployed contract (it receives a live\n  exact-amount approval during _swap; an EOA is always a misconfig)\n- setRouter(router, false) clears any c\n[…]\nle\n  entry cannot silently reactivate on a later re-allowlist\n\nThe spender was previously unvalidated: a fat-fingered address would\nsilently receive the hop approval on every swap through that router.",
          "is_bot": false,
          "headline": "fix(bstock): harden setRouterSpender against misconfiguration",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T08:58:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4617af5461beb4b36409c657c6327b862f2218f4",
          "body": null,
          "is_bot": false,
          "headline": "fix: [I01]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T08:20:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d176db63038922337434104b9d67e4377b7942d",
          "body": null,
          "is_bot": false,
          "headline": "fix: [L06]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T08:17:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2d2043f4308253709b1992967e6d0b87acebbf2",
          "body": null,
          "is_bot": false,
          "headline": "fix: [L05]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T08:03:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "355b16b63ab1ab5e3718b49ad8dac8062ca9a6e4",
          "body": null,
          "is_bot": false,
          "headline": "fix: [L04]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T07:56:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce0b179ee17b190197e652b822673b89a289bf9f",
          "body": null,
          "is_bot": false,
          "headline": "fix: [L03]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T07:39:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03bd5da60569b607adc26de51c91b4b37ef06219",
          "body": null,
          "is_bot": false,
          "headline": "fix: [L02]",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-13T07:29:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5e3d091713de84d16833ff0e9fa2094eb1b90e3",
          "body": "Price Native and Liquid Mesh per liquidation and settle through the\nhigher-out source. The LM client uses disableSimulate to build swap\ncalldata for the not-yet-holding contract, keeping seize->sell atomic;\nsources sit behind a registry so future ones need no contract change",
          "is_bot": false,
          "headline": "feat(bstock): add Liquid Mesh as a hop-1 liquidation source",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-10T11:05:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f94350f524a5a07096a447a72c26cd39ea9f57a",
          "body": "…swaps\n\nSome aggregators (e.g. Liquid Mesh) pull the input token through a\nsettlement contract distinct from the call target. Add a routerSpender\nmapping so _swap approves the puller, defaulting to the router itself so\nNative is unchanged. Gap shrinks 50->49; storage-safe.",
          "is_bot": false,
          "headline": "feat(bstock): support a separate router spender for split-settlement …",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-10T11:04:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d97ae974fed088bcf3a9dab325fce0ec1d6a493",
          "body": "## 10.3.0-dev.1 (2026-07-08)\n\n* Merge branch 'fix/vpd-1241-certik-audit' into feat/vpd-1241-deployments ([062cbf7](https://github.com/VenusProtocol/venus-protocol/commit/062cbf7))\n* Merge branch 'main' into develop ([eadae38](https://github.com/VenusProtocol/venus-protocol/commit/eadae38))\n* Merge p\n[…]\n643](https://github.com/VenusProtocol/venus-protocol/commit/d574643))\n* fix: update tests to accommodate LI invariant checks ([432e985](https://github.com/VenusProtocol/venus-protocol/commit/432e985))",
          "is_bot": false,
          "headline": "chore(release): 10.3.0-dev.1 [skip ci]",
          "author_name": "Venus Tools",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-08T05:55:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8e266fe0b0653046e628a7d6774c7383b7a5588",
          "body": "Merge main back into develop (release 10.2.0 sync)",
          "is_bot": false,
          "headline": "Merge pull request #691 from VenusProtocol/chore/sync-main",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-08T05:43:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eadae38e665b646dea1d0e53eb151d7309dcea52",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into develop",
          "author_name": "fred-venus",
          "author_login": "fred-venus",
          "committed_at": "2026-07-08T05:03:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f0836a29b97e2a63beaa84161e6e6eee5444cd0",
          "body": "## 10.2.0-dev.11 (2026-07-06)\n\n* Merge branch 'fix/vpd-1241-certik-audit' into feat/vpd-1241-deployments ([062cbf7](https://github.com/VenusProtocol/venus-protocol/commit/062cbf7))\n* Merge pull request #673 from VenusProtocol/fix/vpd-1241-certik-audit ([0084639](https://github.com/VenusProtocol/venu\n[…]\n643](https://github.com/VenusProtocol/venus-protocol/commit/d574643))\n* fix: update tests to accommodate LI invariant checks ([432e985](https://github.com/VenusProtocol/venus-protocol/commit/432e985))",
          "is_bot": false,
          "headline": "chore(release): 10.2.0-dev.11 [skip ci]",
          "author_name": "Venus Tools",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-06T06:59:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "008463952e59feef8a625295b380cef912699756",
          "body": "[VPD 1241] Certik: Venus Labs - Core Feature Reaudit",
          "is_bot": false,
          "headline": "Merge pull request #673 from VenusProtocol/fix/vpd-1241-certik-audit",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-06T06:46:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2115a9bd750b2d2d181c75b8d22b275d752627d2",
          "body": "…ator",
          "is_bot": false,
          "headline": "test(bstock): run fork suite against deployed bscmainnet BStockLiquid…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T11:56:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2812b9d689754496441c843629f568aef383a4ff",
          "body": null,
          "is_bot": false,
          "headline": "feat: updating deployment files",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T11:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43409ff8f08fa3abe0ab368e2aad14dc3041e4bf",
          "body": "Add the 019 deploy script (owner Safe via initialize, timelock proxy\nadmin, BscScan verify) and record the bscmainnet deployment artifacts\nand migration entry.",
          "is_bot": false,
          "headline": "chore(bstock): deploy BStockLiquidator to bscmainnet",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T11:06:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "347bd6f742062a68a10204256fa2450f9c62831d",
          "body": "## 10.2.0 (2026-07-03)\n\n* Merge branch 'develop' into feat/VPD-233 ([d3c78a7](https://github.com/VenusProtocol/venus-protocol/commit/d3c78a7))\n* Merge branch 'develop' into feat/vpd-404 ([2e1f342](https://github.com/VenusProtocol/venus-protocol/commit/2e1f342))\n* Merge branch 'feat/VPD-1292' into fe\n[…]\nb.com/VenusProtocol/venus-protocol/commit/dd05f07))\n* refactor(VBep20): merge syncCash and sweepToken into sweepTokenAndSync ([2f578e9](https://github.com/VenusProtocol/venus-protocol/commit/2f578e9))",
          "is_bot": false,
          "headline": "chore(release): 10.2.0 [skip ci]",
          "author_name": "Venus Tools",
          "author_login": "toolsvenus",
          "committed_at": "2026-07-03T07:29:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66956de03e063b445bc139d36d6bea1df170c656",
          "body": "New release",
          "is_bot": false,
          "headline": "Merge pull request #688 from VenusProtocol/develop",
          "author_name": "Fred",
          "author_login": "fred-venus",
          "committed_at": "2026-07-03T07:17:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "812c60004ef2832b93a7eb54a1ab778ec2f874fe",
          "body": "- vBNB has no underlying(), so detect it by catching the revert and\n  account the debt as native BNB (18 decimals) instead of crashing\n- drop the ERC20 approve on the native path and send the repay as\n  msg.value, matching the Liquidator's msg.value == repayAmount check\n- read the Safe's native balance for the pre-execution fund check\n- extend the Safe-tx helper to carry an optional native value",
          "is_bot": false,
          "headline": "feat(bstock): support native BNB debt in safe fallback batch",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T06:35:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3cef17c4aa485b50f883b6133b3a8c2a34d642d9",
          "body": "…ved quote accuracy",
          "is_bot": false,
          "headline": "feat(bstock): add SEIZE_BUFFER parameter to atomicLiquidate for impro…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T06:28:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28ba5945ef78eac5b3b372279cf27122d39da752",
          "body": "… and safe-fallback scripts",
          "is_bot": false,
          "headline": "fix(bstock):: enforce Venus Liquidator gate checks in atomicLiquidate…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T06:08:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08f8c328e15be4686888203051d258987aec84e3",
          "body": "…quidate function",
          "is_bot": false,
          "headline": "docs: clarify comments regarding native BNB debt handling in atomicLi…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T05:55:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "327a36264eabc90778a1dc3892cf884434cd5cbe",
          "body": null,
          "is_bot": false,
          "headline": "chore: consolidate router validation into a single function",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-03T05:29:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "159c85e32c1dca8fd744efb67dc6e98df06b2c3d",
          "body": "…ate leak\n\nThe sweepNative test calls setBalance on default signer[3], draining it.\nWithout snapshot isolation this leaked into Fork/TokenRedeemer, whose\ntreasury reuses signer[3] and mints 3000 ETH vBNB in setup, failing under\ncoverage with 'Sender doesn't have enough funds'. Snapshot before the\nsuite and restore after for a clean signer handoff.",
          "is_bot": false,
          "headline": "test(bstock): restore chain snapshot after suite to prevent signer st…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T16:33:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f452db2083ad377231f3e4d8b07c04326ab122d",
          "body": null,
          "is_bot": false,
          "headline": "test(bstock): render dynamic sweep results as an aligned table",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T15:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1784444ecb86296eef3edd006b925d6bf7f8229f",
          "body": null,
          "is_bot": false,
          "headline": "chore: fix lint",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T14:53:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8c58d03464254760d784e6e24e22c5c63cd2c6e",
          "body": "…eed, summary",
          "is_bot": false,
          "headline": "test(bstock): richer fork sweep — market names, decoded skips, cash-s…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T14:48:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a3f35502c59dbcc4e9a4ba4527e607e36c1a0f6",
          "body": "…fork fuzz coverage\n\n- add MockReentrantRouter and assert nonReentrant blocks re-entry into\n  liquidate/flashLiquidate while the outer settle succeeds\n- add deadline-boundary and gate-approval-reset assertions\n- add fork helpers: underwater-borrower factory, swap-hop builders,\n  settle/rollback invariants\n- add curated fork scenarios (native BNB debt, two-hop PCS, forced\n  liquidation, minOut-breach rollback) + dynamic debt-market sweep\n- add seeded and fast-check property fuzz over repay/minOut",
          "is_bot": false,
          "headline": "test(bstock): harden liquidator suite with reentrancy, deadline, and …",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T14:48:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6319593e71338b6fe70ddeb5ce79ee083d49e4d8",
          "body": "Deploys a bStock ERC20 + real Venus vToken, lists it on the live Core diamond\nvia timelock/ACM, wires a ResilientOracle direct price, sets collateral factor,\nsupply cap, action-unpause, and the per-market liquidation incentive (diamond\ndefault 0 zeroes the seize). Plus seeded PRNG + balance-slot helpers.",
          "is_bot": false,
          "headline": "test(bstock): add fork helper to list a real bStock collateral market",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T14:48:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7df9596999cfedd52607c07f596fc42913cd667",
          "body": "Document the three manual-trigger scripts (atomic, safe-fallback,\nnative-smoke) with commands, env tables, and operator gotchas so the\nteam can drive liquidations without reading the source.",
          "is_bot": false,
          "headline": "docs(bstock): add operator runbook for liquidation scripts",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T13:40:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d843b27edc6614409774a648f173e9c3151cc19c",
          "body": "- vBNB has no underlying() and is repaid in native BNB, so the ERC20\n  repay path cannot handle it. Account the debt in WBNB for both the\n  inventory and flash modes, unwrap only the repay amount, and forward\n  it to the gate's payable vBNB branch; swap proceeds stay in WBNB.\n- Flash mode borrows vW\n[…]\n vBNB disburses a borrow\n  with a native transfer (a CALL into the borrower), and hardhat's\n  default accounts carry EIP-7702 delegation code that is an invalid\n  opcode under the fork's London rules.",
          "is_bot": false,
          "headline": "feat(bstock): support native BNB (vBNB) debt",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T12:52:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37bbaea1bbc0a9b3c60d6d66fb4da752ce212241",
          "body": null,
          "is_bot": false,
          "headline": "docs(bstock): clarify inventory floor and native-debt limits",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T12:05:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb3ee373e5bb28b17543b6eeaf265fb787a36ece",
          "body": "forceApprove(gate, 0) after liquidateBorrow so a partial pull (close-factor\ncap) leaves no standing allowance, matching the _swap invariant.",
          "is_bot": false,
          "headline": "fix(bstock): reset liquidation-gate approval to zero",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T12:05:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2968bf38fad862bf7c436067705033b5cc86193b",
          "body": "New deadline field on LiquidationParams; liquidate/flashLiquidate revert\nDeadlineExpired once block.timestamp passes it, so a stale mempool tx\ncannot settle against an expired quote.",
          "is_bot": false,
          "headline": "feat(bstock): add per-call swap deadline",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T12:04:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "087ab6c95fb125daea5503dbfc00a3a504c75e8a",
          "body": "- Rename `ours` to `treasuryCut`: it is the Venus Liquidator's treasury\n  share subtracted from the seize, not the amount we receive.\n- Document that hop-2 calldata encodes a fixed amountIn while the\n  contract approves only the actual hop-1 delta, so an under-fill\n  reverts SwapFailed (acute for the offline pcsv2 provider).",
          "is_bot": false,
          "headline": "refactor(bstock): clarify treasury-cut var and hop-2 amountIn constraint",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T09:34:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9afc4245537db042c039007a449d9b352def3af",
          "body": "- A zero floor passes the InsufficientOut check for any swap output,\n  so a misconfigured call could settle a liquidation at an arbitrary\n  loss, including zero if a router drains the input without returning\n  the debt asset.\n- Guard both entry points so the check fails before any flash borrow\n  or repay, not mid-pipeline after funds have moved.",
          "is_bot": false,
          "headline": "feat(bstock): reject zero minOut in liquidator",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T09:34:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17717bcc08b915afabc920d1c0bea13ecb5bc029",
          "body": "The event named the collateral market but not the repaid debt market,\nso consumers couldn't filter liquidations by debt. Add vDebt as a third\nindexed field, emitted in both inventory and flash paths.",
          "is_bot": false,
          "headline": "feat(bstock): index debt market in Liquidated event",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T08:56:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ae2c47d3cd998d8db7cd8d45546cdcf1d7105bd",
          "body": "- Native RFQ only quotes bStock->USDT on BSC, so only USDT-debt\n  markets could be liquidated atomically; non-USDT ERC20 debt\n  (BTCB, ETH, CAKE) was pushed to the manual Safe fallback.\n- Add an optional second hop (intermediate -> debt) through a\n  second allowlisted router. A single final minOut i\n[…]\n- LiquidationParams gains router2/swapCalldata2/intermediateToken,\n  changing the liquidate/flashLiquidate selectors. Pre-launch, and\n  the only consumer (the off-chain script) is updated in lockstep.",
          "is_bot": false,
          "headline": "feat(bstock): support non-USDT debt via two-hop swap",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T08:06:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "896dde9217cdac324bb20c83679a47ee41cf0afc",
          "body": "It is a read only diagnostic, not an operational script. Rename so it is\nvisibly distinct from the two runnable scripts (atomic-liquidate,\nsafe-fallback) and update its usage examples to the new path.",
          "is_bot": false,
          "headline": "refactor(bstock): rename native-quote smoke test to native-smoke",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T06:56:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d17b5ba98f1ab8fcc783c494ad3cc7dcf7cdb430",
          "body": "… map\n\nThe smoke test hardcoded a two-entry TSLAB/NVDAB address map, but Native\nlists many more bStock tokens (SPCXB, CRCLB, MSTRB, ...) and keeps adding\nthem. Resolve the token address from the live orderbook instead, so the\nscript stays correct with no edits as the listing grows.",
          "is_bot": false,
          "headline": "refactor(bstock): resolve bStock token from orderbook, drop hardcoded…",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T06:51:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08eff13e4a0c4630988189f2f820814afef07305",
          "body": "atomic-liquidate hardcoded the firm-quote output to USDT while the\ncontract measures proceeds and enforces minOut in vDebt.underlying().\nA non-USDT debt market would then fail with a cryptic on-chain\nInsufficientOut(0, minOut) revert.\n\nRequest the quote in the debt underlying and fail fast off-chain when\nit isn't the Native output token (USDT on BSC, the only bStock quote\nasset), pointing operators at the Safe fallback for non-USDT debt.",
          "is_bot": false,
          "headline": "fix(bstock): quote the debt asset, assert it matches Native output",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-02T06:29:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14729b771c9f047829c6457ae8d399235c13c5ab",
          "body": null,
          "is_bot": false,
          "headline": "docs(bstock): generalize debt-asset wording, drop stale comments",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-01T13:51:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81fa8df81bd995224081c40dadc660aa427a3482",
          "body": "A direct vDebt.liquidateBorrow reverts UNAUTHORIZED while the pool gate\nis set, so the emitted batch was unexecutable on mainnet. Route the\nrepay through the Venus Liquidator when set, redeem only the credited\namount (net of its bonus cut), and apply the redeem treasuryPercent so\nthe transfer never exceeds what the Safe holds. Add a driver test",
          "is_bot": false,
          "headline": "fix(bstock): route safe-fallback batch through the Liquidator gate",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-01T12:14:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d9d1e04a68bdecb4045c55cc6c75a2d5bbf5231",
          "body": "The repay always routes through the pool-wide Venus Liquidator, which\nkeeps a treasury cut of the liquidation bonus, so the contract receives\nfewer vTokens than seizeTokens. Deduct it before sizing the RFQ quote,\nelse the overstated amountIn makes the fixed-amount router pull revert.\nAdd mock getters so the fork test resolves the reads.",
          "is_bot": false,
          "headline": "fix(bstock): deduct Venus Liquidator cut in seize precompute",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-01T11:49:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8db39462188f6d03fffc3b9b6f41165cfa8c6238",
          "body": "The swap output is the generic debt asset (vDebt.underlying()), not\nliterally USDT, so rename usdtOut/usdtBefore to debtOut/debtBefore.\nNaming only; the output-must-equal-debt invariant is unchanged.",
          "is_bot": false,
          "headline": "refactor(bstock): rename usdt* vars to debt* for clarity",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-01T11:32:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7df4df2dbf8b695e23118e2e16f4befb80f639e3",
          "body": "Remove _flashActive: the FlashLoanFacet passes the executeFlashLoan\ncaller as initiator, and only flashLiquidate calls it, so initiator ==\nthis already proves the callback is ours. Saves two SSTOREs plus an\nSLOAD and drops the NoFlashInFlight error. Add zero-address guards to\nsweep for a clear revert.",
          "is_bot": false,
          "headline": "refactor(bstock): drop redundant flash guard, harden sweep",
          "author_name": "Debugger022",
          "author_login": "Debugger022",
          "committed_at": "2026-07-01T10:56:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 3,
      "commits_last_year": 694,
      "latest_release_at": "2022-09-16T07:27:04Z",
      "latest_release_tag": "vip-60",
      "releases_from_tags": false,
      "days_since_last_push": 7,
      "active_weeks_last_year": 49,
      "days_since_latest_release": 1411,
      "mean_days_between_releases": 316.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@venusprotocol/venus-protocol",
          "exists": true,
          "license": "BSD-3-Clause",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@venusprotocol/venus-protocol",
          "is_deprecated": false,
          "latest_version": "10.3.0",
          "repository_url": "https://github.com/VenusProtocol/venus-protocol",
          "versions_count": 256,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 5,
          "monthly_downloads": 16331,
          "first_published_at": "2022-09-27T18:21:29.492000Z",
          "latest_published_at": "2026-07-08T07:51:30.655000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 20
        }
      ]
    },
    "popularity": {
      "forks": 202,
      "stars": 278,
      "watchers": 18,
      "fork_history": {
        "days": [
          {
            "date": "2020-10-27",
            "count": 1
          },
          {
            "date": "2020-12-20",
            "count": 1
          },
          {
            "date": "2021-01-19",
            "count": 1
          },
          {
            "date": "2021-02-06",
            "count": 1
          },
          {
            "date": "2021-02-08",
            "count": 1
          },
          {
            "date": "2021-02-11",
            "count": 1
          },
          {
            "date": "2021-02-16",
            "count": 1
          },
          {
            "date": "2021-02-19",
            "count": 1
          },
          {
            "date": "2021-02-22",
            "count": 1
          },
          {
            "date": "2021-02-24",
            "count": 1
          },
          {
            "date": "2021-03-03",
            "count": 1
          },
          {
            "date": "2021-03-08",
            "count": 1
          },
          {
            "date": "2021-03-10",
            "count": 1
          },
          {
            "date": "2021-03-31",
            "count": 1
          },
          {
            "date": "2021-04-09",
            "count": 1
          },
          {
            "date": "2021-04-10",
            "count": 1
          },
          {
            "date": "2021-04-12",
            "count": 1
          },
          {
            "date": "2021-04-13",
            "count": 1
          },
          {
            "date": "2021-04-15",
            "count": 1
          },
          {
            "date": "2021-04-17",
            "count": 1
          },
          {
            "date": "2021-04-20",
            "count": 1
          },
          {
            "date": "2021-04-24",
            "count": 1
          },
          {
            "date": "2021-04-26",
            "count": 1
          },
          {
            "date": "2021-05-02",
            "count": 1
          },
          {
            "date": "2021-05-04",
            "count": 2
          },
          {
            "date": "2021-05-11",
            "count": 1
          },
          {
            "date": "2021-05-15",
            "count": 1
          },
          {
            "date": "2021-05-16",
            "count": 1
          },
          {
            "date": "2021-05-17",
            "count": 1
          },
          {
            "date": "2021-05-21",
            "count": 1
          },
          {
            "date": "2021-05-22",
            "count": 2
          },
          {
            "date": "2021-05-29",
            "count": 1
          },
          {
            "date": "2021-06-01",
            "count": 1
          },
          {
            "date": "2021-06-03",
            "count": 1
          },
          {
            "date": "2021-06-06",
            "count": 1
          },
          {
            "date": "2021-06-16",
            "count": 1
          },
          {
            "date": "2021-06-17",
            "count": 1
          },
          {
            "date": "2021-07-02",
            "count": 1
          },
          {
            "date": "2021-07-05",
            "count": 1
          },
          {
            "date": "2021-07-20",
            "count": 1
          },
          {
            "date": "2021-07-21",
            "count": 1
          },
          {
            "date": "2021-08-03",
            "count": 1
          },
          {
            "date": "2021-08-17",
            "count": 1
          },
          {
            "date": "2021-08-18",
            "count": 1
          },
          {
            "date": "2021-08-23",
            "count": 1
          },
          {
            "date": "2021-08-25",
            "count": 1
          },
          {
            "date": "2021-08-26",
            "count": 1
          },
          {
            "date": "2021-08-30",
            "count": 1
          },
          {
            "date": "2021-08-31",
            "count": 1
          },
          {
            "date": "2021-09-14",
            "count": 1
          },
          {
            "date": "2021-10-12",
            "count": 1
          },
          {
            "date": "2021-10-18",
            "count": 1
          },
          {
            "date": "2021-10-27",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 1
          },
          {
            "date": "2021-11-23",
            "count": 1
          },
          {
            "date": "2021-11-25",
            "count": 1
          },
          {
            "date": "2021-11-30",
            "count": 1
          },
          {
            "date": "2021-12-17",
            "count": 1
          },
          {
            "date": "2021-12-24",
            "count": 1
          },
          {
            "date": "2021-12-29",
            "count": 1
          },
          {
            "date": "2022-01-05",
            "count": 1
          },
          {
            "date": "2022-01-09",
            "count": 1
          },
          {
            "date": "2022-01-10",
            "count": 1
          },
          {
            "date": "2022-01-14",
            "count": 1
          },
          {
            "date": "2022-01-24",
            "count": 1
          },
          {
            "date": "2022-01-25",
            "count": 1
          },
          {
            "date": "2022-03-06",
            "count": 1
          },
          {
            "date": "2022-04-18",
            "count": 1
          },
          {
            "date": "2022-05-15",
            "count": 1
          },
          {
            "date": "2022-05-23",
            "count": 1
          },
          {
            "date": "2022-05-25",
            "count": 1
          },
          {
            "date": "2022-06-19",
            "count": 1
          },
          {
            "date": "2022-06-24",
            "count": 1
          },
          {
            "date": "2022-07-01",
            "count": 1
          },
          {
            "date": "2022-07-04",
            "count": 1
          },
          {
            "date": "2022-07-05",
            "count": 1
          },
          {
            "date": "2022-07-06",
            "count": 1
          },
          {
            "date": "2022-07-08",
            "count": 1
          },
          {
            "date": "2022-07-20",
            "count": 1
          },
          {
            "date": "2022-07-25",
            "count": 1
          },
          {
            "date": "2022-08-05",
            "count": 1
          },
          {
            "date": "2022-08-28",
            "count": 1
          },
          {
            "date": "2022-09-12",
            "count": 2
          },
          {
            "date": "2022-09-29",
            "count": 1
          },
          {
            "date": "2022-10-13",
            "count": 1
          },
          {
            "date": "2022-10-14",
            "count": 1
          },
          {
            "date": "2022-10-21",
            "count": 1
          },
          {
            "date": "2022-12-05",
            "count": 1
          },
          {
            "date": "2022-12-09",
            "count": 1
          },
          {
            "date": "2022-12-31",
            "count": 1
          },
          {
            "date": "2023-01-07",
            "count": 1
          },
          {
            "date": "2023-01-20",
            "count": 1
          },
          {
            "date": "2023-02-01",
            "count": 2
          },
          {
            "date": "2023-02-12",
            "count": 1
          },
          {
            "date": "2023-04-03",
            "count": 1
          },
          {
            "date": "2023-04-12",
            "count": 2
          },
          {
            "date": "2023-04-20",
            "count": 1
          },
          {
            "date": "2023-05-11",
            "count": 1
          },
          {
            "date": "2023-06-19",
            "count": 1
          },
          {
            "date": "2023-06-24",
            "count": 1
          },
          {
            "date": "2023-06-27",
            "count": 1
          },
          {
            "date": "2023-06-28",
            "count": 1
          },
          {
            "date": "2023-06-29",
            "count": 1
          },
          {
            "date": "2023-07-05",
            "count": 1
          },
          {
            "date": "2023-07-30",
            "count": 1
          },
          {
            "date": "2023-08-14",
            "count": 1
          },
          {
            "date": "2023-08-26",
            "count": 1
          },
          {
            "date": "2023-09-02",
            "count": 1
          },
          {
            "date": "2023-09-23",
            "count": 1
          },
          {
            "date": "2023-11-05",
            "count": 1
          },
          {
            "date": "2023-11-14",
            "count": 1
          },
          {
            "date": "2023-11-27",
            "count": 1
          },
          {
            "date": "2023-11-30",
            "count": 1
          },
          {
            "date": "2023-12-05",
            "count": 1
          },
          {
            "date": "2023-12-07",
            "count": 1
          },
          {
            "date": "2023-12-21",
            "count": 1
          },
          {
            "date": "2024-01-03",
            "count": 1
          },
          {
            "date": "2024-01-08",
            "count": 1
          },
          {
            "date": "2024-01-14",
            "count": 4
          },
          {
            "date": "2024-01-15",
            "count": 1
          },
          {
            "date": "2024-02-01",
            "count": 1
          },
          {
            "date": "2024-02-02",
            "count": 1
          },
          {
            "date": "2024-02-03",
            "count": 1
          },
          {
            "date": "2024-02-13",
            "count": 1
          },
          {
            "date": "2024-03-05",
            "count": 1
          },
          {
            "date": "2024-03-07",
            "count": 1
          },
          {
            "date": "2024-03-16",
            "count": 1
          },
          {
            "date": "2024-03-27",
            "count": 2
          },
          {
            "date": "2024-04-03",
            "count": 1
          },
          {
            "date": "2024-04-09",
            "count": 1
          },
          {
            "date": "2024-04-30",
            "count": 1
          },
          {
            "date": "2024-05-14",
            "count": 1
          },
          {
            "date": "2024-05-17",
            "count": 1
          },
          {
            "date": "2024-07-07",
            "count": 1
          },
          {
            "date": "2024-07-20",
            "count": 1
          },
          {
            "date": "2024-07-21",
            "count": 1
          },
          {
            "date": "2024-08-14",
            "count": 1
          },
          {
            "date": "2024-08-20",
            "count": 1
          },
          {
            "date": "2024-09-19",
            "count": 1
          },
          {
            "date": "2024-09-29",
            "count": 1
          },
          {
            "date": "2024-10-08",
            "count": 1
          },
          {
            "date": "2024-10-09",
            "count": 1
          },
          {
            "date": "2024-11-09",
            "count": 1
          },
          {
            "date": "2024-11-17",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-13",
            "count": 1
          },
          {
            "date": "2025-01-22",
            "count": 1
          },
          {
            "date": "2025-01-27",
            "count": 1
          },
          {
            "date": "2025-02-18",
            "count": 1
          },
          {
            "date": "2025-03-04",
            "count": 1
          },
          {
            "date": "2025-03-13",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-03-30",
            "count": 1
          },
          {
            "date": "2025-04-17",
            "count": 1
          },
          {
            "date": "2025-04-21",
            "count": 1
          },
          {
            "date": "2025-04-23",
            "count": 1
          },
          {
            "date": "2025-05-06",
            "count": 1
          },
          {
            "date": "2025-06-09",
            "count": 1
          },
          {
            "date": "2025-06-26",
            "count": 1
          },
          {
            "date": "2025-06-29",
            "count": 1
          },
          {
            "date": "2025-06-30",
            "count": 1
          },
          {
            "date": "2025-07-17",
            "count": 1
          },
          {
            "date": "2025-07-28",
            "count": 1
          },
          {
            "date": "2025-08-19",
            "count": 1
          },
          {
            "date": "2025-09-12",
            "count": 1
          },
          {
            "date": "2025-09-16",
            "count": 1
          },
          {
            "date": "2025-10-09",
            "count": 1
          },
          {
            "date": "2025-10-19",
            "count": 1
          },
          {
            "date": "2025-10-23",
            "count": 1
          },
          {
            "date": "2025-11-05",
            "count": 1
          },
          {
            "date": "2025-11-27",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 2
          },
          {
            "date": "2025-12-31",
            "count": 1
          },
          {
            "date": "2026-01-12",
            "count": 1
          },
          {
            "date": "2026-02-02",
            "count": 1
          },
          {
            "date": "2026-02-05",
            "count": 1
          },
          {
            "date": "2026-02-27",
            "count": 1
          },
          {
            "date": "2026-03-25",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-07-04",
            "count": 1
          },
          {
            "date": "2026-07-08",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 194,
        "total_forks": 202
      },
      "star_history": null,
      "open_issues_and_prs": 19
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 2168472,
      "source_files_sampled": 270,
      "oversized_source_files": 8,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@openzeppelin/contracts",
            "direct": false,
            "version": "3.4.2-solc-0.7",
            "severity": "critical",
            "ecosystem": "npm",
            "cvss_score": 10,
            "advisory_ids": [
              "GHSA-7grf-83vw-6f5x",
              "GHSA-88g8-f5mf-f5rj",
              "GHSA-9c22-pwxw-p6hx",
              "GHSA-fg47-3c2x-m2wr",
              "GHSA-mx2q-35m2-x2rh"
            ],
            "fixed_version": "4.8.3",
            "advisory_count": 5,
            "oldest_advisory_days": 1793
          },
          {
            "name": "@openzeppelin/contracts-upgradeable",
            "direct": false,
            "version": "3.4.2-solc-0.7",
            "severity": "critical",
            "ecosystem": "npm",
            "cvss_score": 10,
            "advisory_ids": [
              "GHSA-7grf-83vw-6f5x",
              "GHSA-9c22-pwxw-p6hx",
              "GHSA-mx2q-35m2-x2rh",
              "GHSA-vrw4-w73r-6mm8"
            ],
            "fixed_version": "4.8.3",
            "advisory_count": 4,
            "oldest_advisory_days": 1793
          },
          {
            "name": "@openzeppelin/contracts",
            "direct": false,
            "version": "3.4.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-7grf-83vw-6f5x",
              "GHSA-88g8-f5mf-f5rj",
              "GHSA-9c22-pwxw-p6hx",
              "GHSA-mx2q-35m2-x2rh"
            ],
            "fixed_version": "4.8.3",
            "advisory_count": 4,
            "oldest_advisory_days": 1687
          },
          {
            "name": "adm-zip",
            "direct": false,
            "version": "0.4.16",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-xcpc-8h2w-3j85"
            ],
            "fixed_version": "0.6.0",
            "advisory_count": 1,
            "oldest_advisory_days": 18
          },
          {
            "name": "axios",
            "direct": false,
            "version": "0.21.4",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 8.6,
            "advisory_ids": [
              "GHSA-3g43-6gmg-66jw",
              "GHSA-3p68-rc4w-qgx5",
              "GHSA-43fc-jf86-j433",
              "GHSA-5c9x-8gcm-mpgx",
              "GHSA-62hf-57xw-28j9",
              "GHSA-6chq-wfr3-2hj9",
              "GHSA-7q8q-rj6j-mhjq",
              "GHSA-898c-q2cr-xwhg",
              "GHSA-fvcv-3m26-pcqx",
              "GHSA-hfxv-24rg-xrqf"
            ],
            "fixed_version": "1.18.0",
            "advisory_count": 23,
            "oldest_advisory_days": 993
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 1,
            "oldest_advisory_days": 4
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "6.5.4",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-434g-2637-qmqr",
              "GHSA-49q7-c7j4-3p7m",
              "GHSA-848j-6mx2-7j84",
              "GHSA-977x-g7h5-7qgw",
              "GHSA-f7q4-pwc6-w24p",
              "GHSA-fc9h-whq2-v747",
              "GHSA-vjh7-7g9h-fjfh"
            ],
            "fixed_version": "6.6.1",
            "advisory_count": 7,
            "oldest_advisory_days": 725
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "6.6.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.3,
            "advisory_ids": [
              "GHSA-848j-6mx2-7j84"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 201
          },
          {
            "name": "serialize-javascript",
            "direct": false,
            "version": "6.0.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 8.1,
            "advisory_ids": [
              "GHSA-5c6j-r48x-rmvq",
              "GHSA-qj8w-gfj5-8c6v"
            ],
            "fixed_version": "7.0.5",
            "advisory_count": 2,
            "oldest_advisory_days": 150
          },
          {
            "name": "tmp",
            "direct": false,
            "version": "0.0.33",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52f5-9888-hmc6",
              "GHSA-ph9p-34f9-6g65"
            ],
            "fixed_version": "0.2.6",
            "advisory_count": 2,
            "oldest_advisory_days": 356
          },
          {
            "name": "undici",
            "direct": false,
            "version": "5.29.0",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-2mjp-6q6p-2qxm",
              "GHSA-35p6-xmwp-9g52",
              "GHSA-4992-7rv2-5pvq",
              "GHSA-g8m3-5g58-fq7m",
              "GHSA-g9mf-h72j-4rw9",
              "GHSA-p88m-4jfj-68fv",
              "GHSA-v9p9-hfj2-hcw8",
              "GHSA-vrm6-8vpv-qv8q",
              "GHSA-vxpw-j846-p89q"
            ],
            "fixed_version": "8.5.0",
            "advisory_count": 9,
            "oldest_advisory_days": 195
          },
          {
            "name": "uuid",
            "direct": false,
            "version": "8.3.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-w5hq-g745-h8pq"
            ],
            "fixed_version": "13.0.1",
            "advisory_count": 1,
            "oldest_advisory_days": 97
          },
          {
            "name": "ws",
            "direct": false,
            "version": "7.4.6",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3h5v-q93c-6h6q",
              "GHSA-96hv-2xvq-fx4p"
            ],
            "fixed_version": "8.21.0",
            "advisory_count": 2,
            "oldest_advisory_days": 771
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.18.0",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-58qx-3vcg-4xpx",
              "GHSA-96hv-2xvq-fx4p"
            ],
            "fixed_version": "8.21.0",
            "advisory_count": 2,
            "oldest_advisory_days": 71
          },
          {
            "name": "@openzeppelin/contracts",
            "direct": true,
            "version": "4.9.3",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 6.5,
            "advisory_ids": [
              "GHSA-9vx6-7xxf-x967"
            ],
            "fixed_version": "5.0.2",
            "advisory_count": 1,
            "oldest_advisory_days": 880
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.4.2",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-pxg6-pf52-xh8x"
            ],
            "fixed_version": "0.7.0",
            "advisory_count": 1,
            "oldest_advisory_days": 662
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 1,
          "high": 12,
          "critical": 2,
          "moderate": 1
        },
        "advisory_count": 66,
        "affected_count": 16,
        "assessed_count": 504,
        "malicious_count": 0,
        "assessed_package": "npm:@venusprotocol/venus-protocol@10.3.0",
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@nomicfoundation/hardhat-ethers",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "@openzeppelin/contracts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "4.9.3"
        },
        {
          "name": "@openzeppelin/contracts-upgradeable",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.8.0"
        },
        {
          "name": "@venusprotocol/governance-contracts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.13.0"
        },
        {
          "name": "@venusprotocol/protocol-reserve",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.4.0"
        },
        {
          "name": "@venusprotocol/solidity-utilities",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.0"
        },
        {
          "name": "@venusprotocol/token-bridge",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.7.0"
        },
        {
          "name": "bignumber.js",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.1.2"
        },
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.0.1"
        },
        {
          "name": "module-alias",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.2"
        },
        {
          "name": "patch-package",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 533,
        "open_issues": 13,
        "closed_ratio": 0.74,
        "closed_issues": 37,
        "closed_unmerged_prs": 102
      },
      "bus_factor": 3,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "web3rover",
          "commits": 790,
          "avatar_url": "https://avatars.githubusercontent.com/u/7037606?v=4"
        },
        {
          "type": "User",
          "login": "Debugger022",
          "commits": 663,
          "avatar_url": "https://avatars.githubusercontent.com/u/104391977?v=4"
        },
        {
          "type": "User",
          "login": "GitGuru7",
          "commits": 503,
          "avatar_url": "https://avatars.githubusercontent.com/u/128375421?v=4"
        },
        {
          "type": "User",
          "login": "kkirka",
          "commits": 345,
          "avatar_url": "https://avatars.githubusercontent.com/u/10987782?v=4"
        },
        {
          "type": "User",
          "login": "chechu",
          "commits": 275,
          "avatar_url": "https://avatars.githubusercontent.com/u/366222?v=4"
        },
        {
          "type": "User",
          "login": "coreyar",
          "commits": 269,
          "avatar_url": "https://avatars.githubusercontent.com/u/7258308?v=4"
        },
        {
          "type": "User",
          "login": "0xlucian",
          "commits": 264,
          "avatar_url": "https://avatars.githubusercontent.com/u/96285542?v=4"
        },
        {
          "type": "User",
          "login": "toolsvenus",
          "commits": 219,
          "avatar_url": "https://avatars.githubusercontent.com/u/127902000?v=4"
        },
        {
          "type": "User",
          "login": "defistar",
          "commits": 107,
          "avatar_url": "https://avatars.githubusercontent.com/u/70688600?v=4"
        },
        {
          "type": "User",
          "login": "brightdev33",
          "commits": 75,
          "avatar_url": "https://avatars.githubusercontent.com/u/60588151?v=4"
        }
      ],
      "contributors_sampled": 29,
      "top_contributor_share": 0.211
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "cd.yml",
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".eslintrc"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "yarn.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 1,
            "reason": "1 out of 6 merged PRs checked by a CI test -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 2,
            "reason": "Found 2/7 approved changesets -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 8 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "135 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2ef5ebeff8062bbc8b6cfcda67c2c176299373c0",
        "ran_at": "2026-07-29T02:13:30Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T05:24:01Z",
      "oldest_open_prs": [
        {
          "number": 604,
          "created_at": "2025-07-09T13:02:22Z",
          "last_comment_at": "2025-12-16T10:39:09Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 650,
          "created_at": "2025-11-13T14:48:58Z",
          "last_comment_at": "2025-11-19T07:51:58Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 692,
          "created_at": "2026-07-09T05:51:51Z",
          "last_comment_at": "2026-07-10T06:19:05Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 704,
          "created_at": "2026-07-21T12:35:55Z",
          "last_comment_at": "2026-07-21T13:13:36Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 705,
          "created_at": "2026-07-21T18:03:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 706,
          "created_at": "2026-07-21T18:03:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-21T05:14:18Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 48,
          "created_at": "2021-05-25T02:41:31Z",
          "last_comment_at": "2021-05-25T15:55:15Z",
          "last_comment_author": "Sam202120201"
        },
        {
          "number": 53,
          "created_at": "2021-06-11T09:14:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 54,
          "created_at": "2021-06-11T09:28:27Z",
          "last_comment_at": "2024-11-09T06:31:50Z",
          "last_comment_author": "Chicken12834"
        },
        {
          "number": 86,
          "created_at": "2021-12-05T12:01:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 89,
          "created_at": "2021-12-15T05:30:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 103,
          "created_at": "2022-02-16T05:36:58Z",
          "last_comment_at": "2026-07-21T17:52:59Z",
          "last_comment_author": "piyushbag"
        },
        {
          "number": 145,
          "created_at": "2022-08-19T02:36:25Z",
          "last_comment_at": "2022-12-30T13:41:22Z",
          "last_comment_author": "coreyar"
        },
        {
          "number": 409,
          "created_at": "2023-12-13T23:18:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 444,
          "created_at": "2024-02-07T12:32:50Z",
          "last_comment_at": "2026-07-21T17:53:00Z",
          "last_comment_author": "piyushbag"
        },
        {
          "number": 546,
          "created_at": "2025-01-07T18:36:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 569,
          "created_at": "2025-02-15T08:40:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 663,
          "created_at": "2026-03-01T12:19:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 665,
          "created_at": "2026-03-19T00:28:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/VenusProtocol/venus-protocol",
    "host": "github.com",
    "name": "venus-protocol",
    "owner": "VenusProtocol"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": "High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
      "notes": [
        {
          "code": "jurisdiction_overall_adjustment",
          "params": {
            "cap": 49,
            "pct": 50
          }
        }
      ],
      "value": 34,
      "inputs": {
        "security": 24,
        "vitality": 76,
        "community": 76,
        "governance": 78,
        "engineering": 70,
        "high_risk_jurisdiction_cap": 49,
        "high_risk_jurisdiction_multiplier": 50,
        "weighted_overall_before_jurisdiction": 67,
        "overall_after_jurisdiction_multiplier": 34
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "commits_last_year": 694,
              "human_commit_share": 1,
              "days_since_last_push": 7,
              "active_weeks_last_year": 49
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 7 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "49/52 weeks with commits",
                "points": 33.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 49
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "694 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 694
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "releases_count": 3,
              "latest_release_tag": "vip-60",
              "releases_from_tags": false,
              "days_since_latest_release": 1411,
              "mean_days_between_releases": 316.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "3 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1411 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1411
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~316.5 days",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 316.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 12,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 12 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 12
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 76,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "forks": 202,
              "stars": 278,
              "watchers": 18,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "278 stars",
                "points": 39.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 278
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "202 forks",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 202
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "18 watchers",
                "points": 6.8,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (BSD-3-Clause)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "BSD-3-Clause"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 70,
            "inputs": {
              "packages": [
                "@venusprotocol/venus-protocol"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 16331
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "16,331 downloads/month across npm",
                "points": 56.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 16331,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 78,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 29,
              "top_contributor_share": 0.211
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 21% of commits",
                "points": 17.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 21
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "29 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 8 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "merged_prs": 533,
              "open_issues": 13,
              "closed_issues": 37,
              "issue_closed_ratio": 0.74,
              "closed_unmerged_prs": 102
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "74% of issues closed",
                "points": 34.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 74
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "533/635 decided PRs merged",
                "points": 32.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 533,
                      "decided": 635
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/7 approved changesets -- score normalized to 2",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "followers": 207,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "VenusProtocol",
              "public_repos": 21,
              "account_age_days": 2020
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "207 followers of VenusProtocol",
                "points": 16.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 207,
                      "login": "VenusProtocol"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "21 public repos, account ~5 yr old",
                "points": 20.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 21
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@venusprotocol/venus-protocol"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 20
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 20 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "256 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 256
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".eslintrc",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 6 merged PRs checked by a CI test -- score normalized to 1",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 24,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized. High-Risk Jurisdiction Policy applies a 50% multiplier to Security posture and gives it an At risk ceiling of 49.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "jurisdiction_posture_adjustment",
                "params": {
                  "cap": 49,
                  "pct": 50
                }
              }
            ],
            "value": 23,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.6,
              "high_risk_jurisdiction_cap": 49,
              "high_risk_jurisdiction_multiplier": 50,
              "security_posture_after_multiplier": 23,
              "security_posture_before_jurisdiction": 46
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 6 merged PRs checked by a CI test -- score normalized to 1",
                "points": 0.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/7 approved changesets -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 8 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "135 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "at_risk",
            "name": "Dependency advisories",
            "note": "Matched the npm:@venusprotocol/venus-protocol@10.3.0 runtime dependency closure — what installing the published package pulls in — 504 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@venusprotocol/venus-protocol@10.3.0",
                  "assessed": 504
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "source": "osv",
              "advisories": 66,
              "affected_packages": 16,
              "assessed_packages": 504,
              "unassessed_packages": 0,
              "affected_by_severity": "critical 2, high 12, moderate 1, low 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: @openzeppelin/contracts 4.9.3 (moderate 6.5)",
                "points": 16.8,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@openzeppelin/contracts 4.9.3 (moderate 6.5)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "15 affected: @openzeppelin/contracts 3.4.2-solc-0.7 (critical 10.0), @openzeppelin/contracts-upgradeable 3.4.2-solc-0.7 (critical 10.0), @openzeppelin/contracts 3.4.2 (high 7.5), +12 more",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 15,
                      "packages": "@openzeppelin/contracts 3.4.2-solc-0.7 (critical 10.0), @openzeppelin/contracts-upgradeable 3.4.2-solc-0.7 (critical 10.0), @openzeppelin/contracts 3.4.2 (high 7.5)"
                    }
                  },
                  {
                    "code": "advisories_affected_more",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "13 advisory-carrying package(s) unaddressed past 90 days; oldest published 1793 days ago",
                "points": 11.7,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 13,
                      "oldest": 1793
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 504,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "moderate",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": true,
              "exposures": [
                {
                  "role": "top_contributor",
                  "count": 1,
                  "country": "Russia"
                }
              ],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "Russia: top_contributor (1)",
                "points": 50,
                "status": "partial",
                "details": [
                  {
                    "code": "jurisdiction_exposure",
                    "params": {
                      "role": "top_contributor",
                      "count": 1,
                      "country": "Russia"
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.97,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "yarn.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.03,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".eslintrc",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "3 of the last 100 commits agent-authored or agent-credited",
                "points": 6,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 2168472,
              "source_files_sampled": 270,
              "oversized_source_files": 8
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "8/270 source files over 60KB",
                "points": 53.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 270,
                      "oversized": 8
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.14.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T02:14:07.528699Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/v/VenusProtocol/venus-protocol.svg",
  "full_name": "VenusProtocol/venus-protocol",
  "license_state": "standard",
  "license_spdx": "BSD-3-Clause"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.14.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.