Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 18:01 UTC

VitalyOstanin / youtrack-mcp

MCP server for YouTrack: issues, attachments, work items, time reports, knowledge base

TypeScriptMIT★ 5 stars⑂ 6 forkssince Oct 2025View on GitHub ↗

VitalyOstanin/youtrack-mcp holds a health index of 60 out of 100, placing it in the Moderate band. It scores highest on Vitality (82/100) and lowest on Sustainability & Governance (43/100). It was last updated 3 days ago. A single contributor accounts for most of its recent work.

60
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

60
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Vitaly OstaninPersonal account
5 followers45 public repossince Aug 2010

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npm@vitalyostanin/youtrack-mcp0.15.12,546265 days agomcpmodel-context-protocolyoutrackjetbrainsissue-trackingwork-itemstime-trackingclaude

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

82Good · 22% of overall
How it's scored
36/36Push recency — last push 3 days ago
6.2/36Commit cadence — 9/52 weeks with commits
18/18Commit volume — 148 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year148
human_commit_share0.95
days_since_last_push3
active_weeks_last_year9

Release discipline

100Excellent
How it's scored
27/27Ships releases — 26 releases published
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~8.2 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count26
latest_release_tagv0.15.1
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases8.2
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

45At risk · 18% of overall
How it's scored
9.8/60Stars — 5 stars
5.8/25Forks — 6 forks
0/15Watchers — 1 watchers
Inputs used
forks6
stars5
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
45.4/80Monthly downloads — 2,546 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@vitalyostanin/youtrack-mcp
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,546
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

43At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0.5/22.5Commit distribution — top contributor authored 98% of commits
5.4/13.5Contributor breadth — 4 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled4
top_contributor_share0.979
How it's scored
0/46.8Issue resolution — no issues or no data
10.6/38.3PR acceptance — 8/29 decided PRs merged
1.5/15OpenSSF Scorecard: Code-Review — Found 3/25 approved changesets -- score normalized to 1
Inputs used
merged_prs8
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs21
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
5.6/25Owner reach — 5 followers of VitalyOstanin
24.1/25Track record — 45 public repos, account ~15 yr old
Inputs used
followers5
owner_typeUser
is_verified
owner_loginVitalyOstanin
public_repos45
account_age_days5,833
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 26 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@vitalyostanin/youtrack-mcp
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

69Moderate · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.mjs
0/9.6Pre-commit hooks
6.4/6.4.editorconfig
12/20OpenSSF Scorecard: CI-Tests — 5 out of 8 merged PRs checked by a CI test -- score normalized to 6
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configyes
has_precommit_configno

Documentation

50Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

60Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
1.5/2.5CI-Tests — 5 out of 8 merged PRs checked by a CI test -- score normalized to 6
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 3/25 approved changesets -- score normalized to 1
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

71Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md, CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 88 of 95 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.926
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes19,476
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.mjs
11/11Static type checking — tsconfig.json
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 5 of the last 100 commits are automated dependency updates
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.05
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
55/55Manageable file sizes — 0/79 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes24,392
source_files_sampled79
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_files

Key facts

5GitHub stars
4contributors
148commits, last 12 months
3days since last push
26releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@vitalyostanin/youtrack-mcp@0.15.1; advisories assessed against the repository dependency graph instead

More detail

Star and fork history 0 ★ / 6 ⇿
0Stars
6Forks
8Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

123456612026-032026-052026-07
Major 0Minor 4Patch 4
OpenSSF Scorecard 6.0 / 10
6.0aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 18:01 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
6CI-Tests5 out of 8 merged PRs checked by a CI test -- score normalized to 6
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 3/25 approved changesets -- score normalized to 1
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
8Vulnerabilities2 existing vulnerabilities detected
Direct dependencies 7
RegistryPackageVersion constraintManifest
npm@modelcontextprotocol/sdk^1.29.0package.json
npm@vitalyostanin/mutex-pool^0.0.3package.json
npmaxios^1.18.1package.json
npmform-data^4.0.6package.json
npmluxon^3.7.2package.json
npmstream-json^3.5.0package.json
npmzod^4.4.3package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 573,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 5255,
        "TypeScript": 403789
      },
      "pushed_at": "2026-07-20T03:17:59Z",
      "created_at": "2025-10-13T14:26:13Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T10:44:56Z",
      "description": "MCP server for YouTrack: issues, attachments, work items, time reports, knowledge base",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Vitaly Ostanin",
      "type": "User",
      "login": "VitalyOstanin",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/352594?v=4",
      "created_at": "2010-08-03T09:07:38Z",
      "is_verified": null,
      "public_repos": 45,
      "account_age_days": 5833
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-07-18T10:46:22Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-08T19:33:48Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2026-07-03T19:38:13Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-03T18:47:27Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2026-07-03T18:11:03Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-05-07T09:35:35Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-05-06T20:24:55Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-05-06T20:09:54Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-06T09:04:29Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-05-05T17:54:39Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2025-11-18T22:28:33Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2025-11-16T21:51:31Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2025-11-04T16:48:42Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2025-10-31T20:16:32Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2025-10-31T18:29:56Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2025-10-24T15:05:21Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2025-10-23T16:24:42Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2025-10-23T13:55:41Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2025-10-21T22:27:29Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2025-10-21T17:34:40Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2025-10-21T10:16:08Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2025-10-18T16:37:05Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2025-10-17T12:21:29Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2025-10-16T16:43:19Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2025-10-16T14:09:47Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2025-10-14T20:58:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "09a1716815ba7a1c98c12a0afc3213fc700cf622",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.15.1",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-18T10:43:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad54fd027aada44497568c33e68e089726b1474d",
          "body": "…tes (#26)\n\nBumps the eslint group with 2 updates in the / directory: [eslint](https://github.com/eslint/eslint) and [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint).\n\n\nUpdates `eslint` from 10.6.0 to 10.7.0\n- [Release notes](https://gi\n[…]\nype: version-update:semver-minor\n  dependency-group: eslint\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the eslint group across 1 directory with 2 upda…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-18T09:34:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d08ac2cf29511134a4cc086c5c656c7218942604",
          "body": "…tes (#27)\n\nBumps the vitest group with 1 update in the / directory: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8).\n\n\nUpdates `@vitest/coverage-v8` from 4.1.9 to 4.1.10\n- [Release notes](https://github.com/vitest-dev/vitest/releases)\n- [Changelog](https:/\n[…]\nype: version-update:semver-patch\n  dependency-group: vitest\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the vitest group across 1 directory with 2 upda…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-18T09:31:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78eee767d3129526364efc6f6ff7b11f9709d950",
          "body": "Bumps [stream-json](https://github.com/uhop/stream-json) from 3.4.0 to 3.5.0.\n- [Commits](https://github.com/uhop/stream-json/compare/3.4.0...3.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: stream-json\n  dependency-version: 3.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump stream-json from 3.4.0 to 3.5.0 (#29)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-18T09:30:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef07bfeaf7b8b83dae004fbdf238819ddb3d19bf",
          "body": "Bumps the types group with 1 update: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).\n\n\nUpdates `@types/node` from 26.1.0 to 26.1.1\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/Def\n[…]\ntype: version-update:semver-patch\n  dependency-group: types\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @types/node in the types group (#25)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-18T09:28:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9800459fcf26a52c9b23e8b178c95cc8542f98a5",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.15.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-08T19:32:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c25992888020fb522172ff7b7f9094ae67fdf2c",
          "body": "Extends issue_create with customFields[], parent custom-field inheritance, and directed Subtask links. Includes review fixes: explicit non-enum field-type handling, normalized subtask-link dedup, domain YoutrackClientError for validation, field $type constants.",
          "is_bot": false,
          "headline": "feat: support custom fields and subtask links in issue_create (#24)",
          "author_name": "Shant Mnatsakanyan",
          "author_login": "themnts",
          "committed_at": "2026-07-08T19:28:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da5307bbaf791b5857db48d279ba729cb7762c40",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.14.1",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-03T19:36:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d368d97846c46a70b23498326e6fd569434105f",
          "body": null,
          "is_bot": false,
          "headline": "ci(deps): bump codecov/codecov-action to v7.0.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-03T18:58:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cad3eb1f88ae9597346edbb50840f095835406d",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/checkout from 6 to 7 (#19)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T18:57:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b7dc5c1949b0a68e069de686c0ccfee1ac443bd",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): bump dependencies to latest (dependabot backlog)",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-03T18:55:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "443d30d4d6d6614d410f66ebb678ec91cc471766",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.14.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-03T18:46:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d74869015d42e9da61eda153041c3e79363004a",
          "body": "Add YOUTRACK_SILENT_COMMANDS (default false) so command-based link\ncreate/delete no longer fail with HTTP 403 on accounts lacking the\n\"Apply Commands Silently\" permission. This notably affects on-prem\ninstances where POST /api/issues/{id}/links returns 405 and the\n/api/commands fallback is the only \n[…]\nch of changeIssueState.\n\nIncludes unit tests, README, and CHANGELOG updates.\n\nCo-authored-by: Alexandre Vautier <alexandre.vautier@akceler.io>\nCo-authored-by: Vitaly Ostanin <vitaly.ostanin@gmail.com>",
          "is_bot": false,
          "headline": "feat: configurable silent commands + issue_change_type tool (#23)",
          "author_name": "alexvaut",
          "author_login": "alexvaut",
          "committed_at": "2026-07-03T18:43:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6f00f61d5d7e833e4020ba52f706e00ba793f54f",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): patch form-data/hono/qs advisories (npm audit)",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-03T18:09:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f7080193a53f010962d6a6b83b306fe44410a11",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.13.3",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-07-03T18:03:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2c2ee96c22af0cbe474c2ab74feab12b7e64e9f",
          "body": null,
          "is_bot": false,
          "headline": "fix(validators): allow { } in issues_search query (#5)",
          "author_name": "Paul Semionov",
          "author_login": "duffpod",
          "committed_at": "2026-07-03T17:57:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1719c9d77d2abf7a2812bc23335de6dd0a4c66e9",
          "body": "Match the postgres-mcp pattern: replace\n`token: ${{ secrets.CODECOV_TOKEN }}` with `use_oidc: true` so\nshort-lived GitHub-issued JWTs are exchanged for upload credentials\non the fly, and add job-level `permissions: id-token: write`. Once\nthis run uploads successfully the CODECOV_TOKEN secret can be\nremoved from repository settings.\n\nPin codecov/codecov-action to v6.0.0 SHA (was @v6).\n\nAdd a codecov badge to README.md and README-ru.md alongside the\nexisting CI badge.",
          "is_bot": false,
          "headline": "ci: switch codecov upload to OIDC (drop CODECOV_TOKEN)",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-07T20:51:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e2b3352c1b8e9aab1d7da3f5b8e9f8c0761fbfd",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.13.2",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-07T09:34:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50399c5a17ce130db49b62aee383a4da763383fb",
          "body": "….build, audit, smoke pack-and-install)\n\n- Add MIT LICENSE at repo root and ship it in the `files` allow-list.\n- Add a dedicated `tsconfig.build.json` so production builds emit only\n  `src/` + `index.ts` to `dist/` and exclude tests; keep `tsconfig.json`\n  as the IDE/typecheck profile (`noEmit: true\n[…]\n.ts` from `tsconfig.eslint.json` so it is\n  resolved exclusively via `allowDefaultProject` in\n  `eslint.config.mjs` (typescript-eslint refuses to parse a file that\n  is registered under both buckets).",
          "is_bot": false,
          "headline": "chore: align with shared MCP toolchain (LICENSE, dependabot, tsconfig…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-07T09:07:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "affbab1ead40f664d946c95721f9767cb07fd05a",
          "body": null,
          "is_bot": false,
          "headline": "0.13.1",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T20:23:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ad4138752acb1dfac15cd4429c8f0629e49906a",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): add 0.13.1 entry for tools/list zod 4 fix",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T20:23:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbaa69fb352f9d0aacd4e52b9c654e55d3f250e3",
          "body": "…er zod 4\n\nZod 4 throws \"Date cannot be represented in JSON Schema\" when MCP SDK\nconverts inputSchema for tools/list, causing every client to receive an\nempty tool list after the zod 3->4 bump (f7de96d). Date objects can never\narrive over JSON-RPC anyway, so the union member was unreachable.",
          "is_bot": false,
          "headline": "fix(tools): drop z.date() from input unions to unblock tools/list und…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T20:20:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f91024b70d08c54812105dd3d69b8c69b22c413b",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.13.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T20:07:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f04fc10652c0976ae29d88982e550cb51430cbb8",
          "body": "Replace every deprecated server.tool(name, description, schema, cb)\ncall with the modern server.registerTool(name, { description,\ninputSchema, annotations }, cb). Removes the SDK 1.10+ deprecation\nhint that TypeScript was emitting for every registration site.\n\nEach tool now also declares the full To\n[…]\nSTRUCTIVE: irreversible deletes (issue_attachment_delete,\n  issue_link_delete, workitem_delete).\n\nBrings yt in line with chrome and mongo, both of which already use\nregisterTool with full annotations.",
          "is_bot": false,
          "headline": "refactor(tools): migrate to registerTool with ToolAnnotations",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T19:55:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9d3e15e3d1880a167e9d1e3dc8b938235b3fbc7",
          "body": "Aligns with mongodb-mcp / mcp-chrome-debugger-protocol DX layout.\n\n- .nvmrc: pin Node 24 for nvm/asdf users (matches CI publish job and the\n  current LTS line we declare in engines.node).\n- tsconfig.base.json: shared compilerOptions (target/module/lib/types,\n  strict + the three strict flags from th\n[…]\nnd only keeps the\n  ESLint-specific overrides (moduleResolution: node, importHelpers: false,\n  vitest.config.ts in include).\n\nBehaviour unchanged: lint clean, typecheck clean, build ok, tests 117/117.",
          "is_bot": false,
          "headline": "chore(dx): add .nvmrc and tsconfig.base.json with extends",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T18:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43f6a6ad8d9b0bc5130aaeeb51b6bcab00d1dea2",
          "body": "…s, noImplicitOverride\n\nPromotes the project from plain --strict to the three-flag set (mirrors\nmongodb-mcp baafed7).\n\nCore changes\n- tsconfig.json / tsconfig.eslint.json: enable noUncheckedIndexedAccess,\n  exactOptionalPropertyTypes, noImplicitOverride.\n\nType adjustments to satisfy exactOptionalPro\n[…]\nctly that with the new flag\n  set) flows through.\n\nVerification\n- npm run lint: clean\n- npm run typecheck: clean\n- npm run build: ok\n- npm test: 22 files, 117/117 passed\n- npm audit: 0 vulnerabilities",
          "is_bot": false,
          "headline": "chore(ts): enable noUncheckedIndexedAccess, exactOptionalPropertyType…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T18:06:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7de96dace5749feb610b6fe1bfc281c676391b4",
          "body": "Aligns the stack with mongodb-mcp / postgres-mcp / mcp-chrome-debugger-protocol.\n\nDependency upgrades:\n- zod ^3.25.76 -> ^4.4.3\n- typescript ^5.6.2 -> ^6.0.3 (default `types` is now empty -> add `types: [\"node\"]`\n  to tsconfig.json and tsconfig.eslint.json so @types/node ambient declarations\n  resol\n[…]\n\n  `prefer-optional-chain` finding surfaced by stricter typescript-eslint.\n\nVerification: lint clean, typecheck clean, build ok, npm test 22/117 suites\n117/117 tests pass, npm audit 0 vulnerabilities.",
          "is_bot": false,
          "headline": "chore(deps): bump zod 3->4, TypeScript 5.6->6, ESLint 9->10",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T17:52:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25b99034965a525192586093b121ed10209b330b",
          "body": "The previous cleanupAndReject fired off fsp.unlink as a fire-and-\nforget (`void unlink().catch(...)`) and then called rejectP\nsynchronously. Callers that observed the filesystem immediately\nafter the awaited rejection could see the partial file still in\nplace — this manifested as the streaming-clien\n[…]\n to async, await the unlink (swallowing\nENOENT-like errors) before calling rejectP, and wrap the one\ndirect (non-promise-chained) call site in `void` so eslint's\nno-floating-promises rule stays happy.",
          "is_bot": false,
          "headline": "fix(streaming): await unlink before settling rejection",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T09:03:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "303eb2ae756d13cbc37daa300209eca53ba44e3f",
          "body": "Bump version, sync package-lock, finalize CHANGELOG with the\n0.12.0 entry covering the Node 22 bump, security/perf fixes,\nthe YoutrackClient split into base + domain mixins, and the\nbuild/lint/CI tooling work accumulated since v0.11.0.",
          "is_bot": false,
          "headline": "release: v0.12.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:59:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d036fdfb478f3975f9d3458a4310d1c14df85393",
          "body": "Review reports under docs/reviews/ are local working notes, not\nsomething that should be tracked in the repo.",
          "is_bot": false,
          "headline": "chore: ignore local docs/reviews/ artifacts",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:54:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d533dc14c7ffc7c590f878f8ec9ea916c94ecb26",
          "body": "Move all 13 work-item methods (listWorkItems, createWorkItem,\nupdateWorkItem, generateWorkItemReport, etc.) and 2 helpers\n(getWorkItemById, resolveReportBoundary) from\nsrc/youtrack-client/index.ts into a new withWorkItems mixin in\nsrc/youtrack-client/workitems.ts.\n\nAfter this change index.ts only assembles the mixin chain; the\nlong-running split of the original 3397-line youtrack-client.ts\ninto domain mixins is complete.",
          "is_bot": false,
          "headline": "refactor(client): extract workitems domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:52:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21c1e79d960f5db7757f49e1cde74e0e9fefa396",
          "body": "Stage 5 of the YoutrackClient refactor. Splits two domains together because\nissue-search depends on activities through this.getIssueActivities.\n\nsrc/youtrack-client/activities.ts adds withActivities<TBase> with the\nActivitiesMixin interface (2 public methods: getIssueActivities,\nlistActivities). Con\n[…]\n search/list/count methods, eight private helpers\n(~660 lines) and 13 type/constant imports leave src/youtrack-client/\nindex.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract activities + issue-search domains to mixins",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:44:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "890b06dd127d7168abcbb202ae87d3dba0305e24",
          "body": "Stage 4e of the YoutrackClient refactor. Adds src/youtrack-client/batch.ts\nwith the withIssueBatch<TBase> mixin and the IssueBatchMixin interface\n(5 public methods: getIssues, getIssuesDetails, getIssuesDetailsLight,\ngetMultipleIssuesComments, getMultipleIssuesCommentsLight).\n\nThese five methods sha\n[…]\n\nsrc/youtrack-client/index.ts are issue search, work items, activity feeds\nand listIssues/countIssues, scheduled for Stages 5-7.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract issue batch domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:36:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88d3dbf808754ca84edd0fdcf444faebf29e79da",
          "body": "Stage 4d of the YoutrackClient refactor. Adds src/youtrack-client/core.ts\nwith the withIssueCore<TBase> mixin and the IssueCoreMixin interface.\n\nPublic surface (5 methods): getIssue, getIssueDetails, createIssue,\nupdateIssue, assignIssue. The previously private getIssueRaw helper moves\ninto the mixi\n[…]\nplus the YOUTRACK_ENTITY_TYPE / withIssueCustomFieldEvents-related imports\nthat core absorbs leave src/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract issue core domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:34:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c65ca0237611f8b18d6f622268887d4403954fb",
          "body": "Stage 4c of the YoutrackClient refactor. Adds src/youtrack-client/links.ts\nwith the withIssueLinks<TBase> mixin and the IssueLinksMixin interface.\n\nPublic surface (4 methods): getIssueLinks, listLinkTypes, addIssueLink,\ndeleteIssueLink. Internal helpers buildPartialError and\nbuildPartialErrorMessage\n[…]\n(~380 lines, 4 public + 5\nprivate + 2 partial-error helpers) and 9 link-related type imports leave\nsrc/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract issue links domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:30:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "823352930ebfe4f5aff817019fbbec43617cdc1a",
          "body": "Stage 4b of the YoutrackClient refactor. Adds src/youtrack-client/state.ts\nwith the withIssueState<TBase> mixin and the IssueStateMixin interface\n(4 public methods: getIssueState, getIssuesState, getIssueCustomFields,\nchangeIssueState).\n\nState only depends on YoutrackClientBase (resolveIssueId, getW\n[…]\nom\nField / YoutrackStateField type imports and the CUSTOM_FIELDS_STATE_FETCH\nconstant import leave src/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract issue state domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:26:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a51471e58f2c8ddb41999d8d6dd000156dfc372",
          "body": "Stage 4a of the YoutrackClient refactor. Adds src/youtrack-client/stars.ts\nwith the withStars<TBase> mixin and the StarsMixin interface (5 public\nmethods: starIssue, unstarIssue, starIssues, unstarIssues, getStarredIssues).\nThe previously private getIssueWatchers helper moves into the mixin and is\ne\n[…]\n plus the watcher helper (~220 lines) and the YoutrackIssueWatcher /\nIssueStar* type imports leave src/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract issue stars domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T08:10:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5117671f72d32ef9c61304194bc261c78ac23d1",
          "body": "Stage 3c (final piece of Stage 3) of the YoutrackClient refactor. Adds\nsrc/youtrack-client/comments.ts with the withComments<TBase> mixin and the\nCommentsMixin interface (3 public methods: getIssueComments,\ncreateIssueComment, updateIssueComment).\n\nComments only need YoutrackClientBase as the constr\n[…]\nackClientBase)))). Three methods (~90 lines) and the\nmapComment / IssueComment* type imports leave src/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract issue comments domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-06T07:28:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "64f0ef6ce5c6e7de06448ed15ab1133682ebd61e",
          "body": "Stage 3b of the YoutrackClient refactor. Adds src/youtrack-client/articles.ts\nwith the withArticles<TBase> mixin and the ArticlesMixin interface (4 public\nmethods: getArticle, listArticles, createArticle, updateArticle).\n\nwithArticles depends on the users-projects layer because listArticles needs\nfi\n[…]\n))). Four methods (~140 lines) and the YoutrackArticle /\nArticle*-input/payload type imports leave src/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract articles domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T23:48:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e9821db4c417856a47cb2e093cdcfc8c70d8a6d",
          "body": "Stage 3a of the YoutrackClient refactor. Adds src/youtrack-client/\nusers-projects.ts with the withUsersProjects<TBase> mixin and the\nUsersProjectsMixin interface. Public surface (5 methods): getCurrentUser,\ngetUserByLogin, listUsers, listProjects, getProjectByShortName. Internal\nhelpers used by othe\n[…]\nines) and the YoutrackProject /\nYoutrackProjectListPayload / YoutrackUserListPayload imports leave\nsrc/youtrack-client/index.ts.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): extract users + projects domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T23:45:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2527ba00c049ee65a12c3e866aef5fbcee5813d3",
          "body": "Stage 2 of breaking up the 3000+-line YoutrackClient. Adds\nsrc/youtrack-client/attachments.ts with the withAttachments<TBase> mixin and\nits public AttachmentsMixin interface (listAttachments, getAttachment,\ngetAttachmentDownloadInfo, uploadAttachments, deleteAttachment). The mixin\nreturns `TBase & C\n[…]\njects + articles + comments)\nbecause listArticles depends on findProject, which still lives in the\nProjects domain on the class.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "refactor(client): move attachments domain to a mixin",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T23:41:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68369f86d9e79fead2419c206eb0a72f0ad6b127",
          "body": "… violations\n\nThe previous parserOptions.project was creating a full TypeProgram for the\nwhole repo on every run. Combined with the 3000+-line src/youtrack-client/\nindex.ts left over after Stage 1, that pushed the eslint process over the\ndefault 4 GB heap and crashed before reporting anything (Ineff\n[…]\nK_ENTITY_TYPE })\ninto a single statement with inline type markers, satisfying no-duplicate-\nimports and consistent-type-imports.\n\nVerified: npm run lint = 0, npm run typecheck = 0, npm test = 117/117.",
          "is_bot": false,
          "headline": "chore(lint): switch to projectService + enable cache, fix accumulated…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T23:35:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41be4851cf8c8d7c760c88956b2bfe1e2a4a1dd0",
          "body": "Stage 1 of breaking up the 3400-line youtrack-client.ts. Adds:\n- src/youtrack-client/base.ts: YoutrackClientBase with the axios instance, the\n  per-process caches (users / projects / link types), single-flight slots,\n  pagination/error helpers (getWithFlexibleTop, processBatch, normalizeError)\n  and\n[…]\nnt.js\"`)\nkeep working through the barrel; tools and tests are unchanged. Subsequent\nstages will move domain methods (articles, attachments, work items, ...) into\nsibling files in src/youtrack-client/.",
          "is_bot": false,
          "headline": "refactor(client)!: extract YoutrackClientBase, prepare for domain split",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T23:17:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cef282b9c41035ba6877a8c86bbfa59b71ce1a0a",
          "body": "…rations\n\nIntroduce src/utils/tool-handler.ts with createToolHandler<TSchema>(schema, fn)\nthat handles the standard parse/try/catch envelope shared by every tool. The\nhandler parses rawInput through the supplied zod schema, awaits fn(input), and\nwraps the value with toolSuccess unless fn returns a f\n[…]\ning the\npublic contract identical (CallToolResult shape, validation behavior, file\nstorage flow). The local createToolHandler in issue-star-tools.ts is replaced\nby the shared one to keep a single API.",
          "is_bot": false,
          "headline": "refactor(tools): unified createToolHandler across all MCP tool regist…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T23:03:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c485b403d52ec353a4fc5eafae4ff98146673d4e",
          "body": "- README gains a Project Structure section linking back to AGENTS.md as the\n  authoritative agent-oriented layout.\n- CONTRIBUTING.md gives newcomers the local setup, the lint/typecheck/test\n  commands CI runs, and how to file bugs and PRs.",
          "is_bot": false,
          "headline": "docs: add Project Structure section and CONTRIBUTING.md",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T22:28:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "097cb0bec74ce97059b499db9401488acba07643",
          "body": "- add .github/dependabot.yml for weekly npm and github-actions updates\n- expand YouTrack configuration error with field details and setup link\n- default date utils timezone to UTC; entry point still calls initializeTimezone\n- extract shared briefOutputArg in tool-args; reuse in issue/list tools\n- extract reportUsersArgs to deduplicate the workitem report users schema\n- replace two \"what\" comments in youtrack-client with concise rationale",
          "is_bot": false,
          "headline": "chore: dependabot + clearer config error + shared briefOutputArg",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T22:23:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab2a08652ee35ca3e9f69179e51497d4057177c6",
          "body": "- Add YOUTRACK_ENTITY_TYPE map in src/types.ts and use it instead of\n  scattered \"StateIssueCustomField\"/\"Event\"/\"StateBundleElement\"\n  string literals -- a typo in any of these discriminator strings now\n  fails at compile time instead of silently breaking state transitions.\n- Replace `while (skip >= 0)` in fetchAllProjects with `for (;;)`\n  -- the previous condition was tautologically true; the actual exit\n  is always a `break` on a short page.",
          "is_bot": false,
          "headline": "refactor: typed YouTrack $type discriminators and tidy listProjects loop",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T22:08:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3218f7b60895f89bd54a7b10cf898e16745c480",
          "body": "Inline single-line `const payload = {...}; return payload;` and\n`const response = toolSuccess(...); return response;` patterns. Tool\nhandlers and youtrack-client now return directly. Multi-line payloads\nkeep the named local for readability.",
          "is_bot": false,
          "headline": "refactor(style): drop trivial intermediate const before return",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T22:05:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "661744b471ff122f473d391d41b28856def5b80f",
          "body": "- src/constants.ts: extract HTTP timeout/maxBytes constants and\n  PRE_HOLIDAY_RATIO; consume from youtrack-client/file-download/\n  streaming-client.\n- youtrack-client: cache /api/issuesGetter/count availability\n  (cachedCountSupport) -- only on permanent 404/405/501 -- so transient\n  5xx do not pois\n[…]\nres keep per-link errors as objects instead of\n  JSON.stringify-ed payload.\n- article-search-tools: comment the load-bearing `[^{}]+` regex so the\n  link to `{...}` wrapping survives future refactors.",
          "is_bot": false,
          "headline": "refactor: address minor review findings",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T22:03:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b5b0bb88f4063ec335890355ccd8bb494b98b204",
          "body": "Critical\n- updateWorkItem now creates the new record before deleting the old one\n  (compensating transaction); a failed cleanup keeps the new id and is\n  surfaced with a clear \"manual cleanup required\" message instead of\n  losing data when create succeeds and delete fails.\n- bump engines.node to >=2\n[…]\ntConnect in setupFiles, top-level\n  maxWorkers, clearMocks/restoreMocks, testTimeout/hookTimeout.\n- CI: concurrency group, timeout-minutes, typecheck step, npm test in\n  publish workflow before build.",
          "is_bot": false,
          "headline": "refactor: apply project-check review findings (security/perf/dx)",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T21:58:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cbffc934914d86ca5b53d11a8890ce92c7778394",
          "body": "- actions/checkout, actions/setup-node bumped from v4 to v6\n  (clears the deprecation warning; v6 runs on node24).\n- Publish job now runs on Node 24 directly. Node 24 ships with\n  npm 11+, which is the version required by npm Trusted Publishing.\n  This drops the previous `npm install -g npm@latest` \n[…]\ncache: false on the publish setup-node\n  (recommended for OIDC) and a node/npm version print step for\n  easier diagnostics.\n- CI matrix bumped to [22.x, 24.x] to align with the supported\n  Node range.",
          "is_bot": false,
          "headline": "ci: bump GHA actions to v6 and Node 24 for publish",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:53:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2da06ec42bf50eb6f91d3db8fcfa2124778f432",
          "body": "- Drop NODE_AUTH_TOKEN/NPM_TOKEN; rely on id-token: write + provenance.\n- Upgrade npm to latest before publish (Trusted Publishers requires npm 11.5.1+).\n- Drop emoji from Verify and Release notes; fix CHANGELOG link.",
          "is_bot": false,
          "headline": "ci(publish): switch to npm Trusted Publishers (OIDC)",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be49d67943fa67a43ad81af05d79d71afebb6955",
          "body": "- AGENTS.md: documented MCP response contract (no structuredContent),\n  URL-safety / id-validator rule, YOUTRACK_OUTPUT_DIR rule and\n  processBatch contract (single rethrow, AggregateError on multiple).\n- README.md / README-ru.md: added YOUTRACK_OUTPUT_DIR env var, new\n  Pagination and Destructive O\n[…]\n0.11.0.\n\nBREAKING CHANGE: see CHANGELOG for migration notes (processBatch error\ncontract, YOUTRACK_OUTPUT_DIR path safety, confirmation on destructive\ntools, total -> returned in pagination payloads).",
          "is_bot": false,
          "headline": "docs!: AGENTS.md, README, CHANGELOG; bump 0.11.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:29:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc9a6bfa678b0b632452f100dd0ab0aaf23ad702",
          "body": "Compact Purpose/Use cases/Parameter examples/Response fields/Limitations\nblocks for: issue_attachments_list, issue_attachment_get,\nissue_attachment_download, issue_attachment_upload,\nissue_attachment_delete.",
          "is_bot": false,
          "headline": "docs(tools): align attachment tool descriptions with AGENTS.md template",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b854f0806f4a53a6dd5ef5a169198aead2e931b9",
          "body": "….md template\n\nCompact Purpose/Use cases/Parameter examples/Response fields/Limitations\nblocks for: users_list, user_get, user_current, projects_list,\nproject_get, service_info, users_activity. service_info now passes an\nempty argsObject as the third .tool() argument.",
          "is_bot": false,
          "headline": "docs(tools): align user/project/service tool descriptions with AGENTS…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:18:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "549348d472e69f6d853b8de5daa7bc13d0d739a9",
          "body": "Compact Purpose/Use cases/Parameter examples/Response fields/Limitations\nblocks for: article_get, article_list, article_create, article_update,\narticles_search.",
          "is_bot": false,
          "headline": "docs(tools): align article tool descriptions with AGENTS.md template",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:15:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e0e95afdfaad068739aef3363b5a7fb2bed7a57",
          "body": "Compact Purpose/Use cases/Parameter examples/Response fields/Limitations\nblocks for: workitems_list, workitems_all_users, workitems_for_users,\nworkitem_create, workitem_create_idempotent, workitem_update,\nworkitem_delete, workitems_create_period, workitems_report,\nworkitems_recent, workitems_report_summary, workitems_report_invalid,\nworkitems_report_users.",
          "is_bot": false,
          "headline": "docs(tools): align workitem tool descriptions with AGENTS.md template",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30acd1f9c13bc3fe894d7617e3ebc7b802e54355",
          "body": "…emplate\n\nCompact Purpose/Use cases/Parameter examples/Response fields/Limitations\nblocks for: issue_links, issue_link_types, issue_link_add,\nissue_link_delete, issue_activities, issue_star, issue_unstar,\nissues_star_batch, issues_unstar_batch, issues_starred_list.",
          "is_bot": false,
          "headline": "docs(tools): align issue-extension tool descriptions with AGENTS.md t…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:09:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "251318eb09cea75dc9edd690fe216e1266ca8243",
          "body": "Compact Purpose/Use cases/Parameter examples/Response fields/Limitations\nblocks for: issue_lookup, issue_details, issue_comments, issue_create,\nissue_update, issue_assign, issue_comment_create, issue_comment_update,\nissues_lookup, issues_details, issues_comments, issue_change_state,\nissues_count, issues_list, issues_search, issue_status, issues_status.",
          "is_bot": false,
          "headline": "docs(tools): align core issue tool descriptions with AGENTS.md template",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T17:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d464c0432b8e3daccebf44d3ca71c7ec386063b9",
          "body": "…s, briefOutput defaults\n\n- workitem date regex anchored to ^...$\n- mappers.ts: drop redundant as-cast on customFields; YoutrackCustomFieldValue\n  gains optional login (used by Assignee field extraction)\n- youtrack-client.ts: MAX_STAR_BATCH_SIZE constant; spread Math.max replaced\n  with reduce in lastActivityDate to avoid arg-count limits\n- issue-tools.ts: briefOutput uses .default(true) and handler reads it directly\n- issue-star-tools.ts: module-scope export of arg shapes for re-use",
          "is_bot": false,
          "headline": "refactor(misc): regex anchors, type tightening, magic-number constant…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:55:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b98cdd9b7bcd3fcc97437000f34d7f98f86178b",
          "body": "…delete\n\n- both tools now mandate confirmation: true literal in input\n- mirrors existing issue_attachment_delete pattern; zod rejects missing/false\n- export workItemDelete schema and add unit tests for both tools",
          "is_bot": false,
          "headline": "feat(safety): require confirmation in workitem_delete and issue_link_…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69ade1106142134b0294c385d42ebbf1ce0d38bf",
          "body": "… project resolution\n\n- listProjects auto-pagination path serves cache when populated and shares one\n  in-flight HTTP request between parallel callers\n- listLinkTypes likewise: cache-first, single-flight refresh\n- buildIssueQuery resolves projects sequentially (cache hit after the first call)\n  instead of via Promise.all\n- closes AGENTS.md Concurrency Control gap for project / link-type lookups",
          "is_bot": false,
          "headline": "refactor(client): single-flight listProjects/listLinkTypes; serialize…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:49:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d41073f2fac5b059612f3e6bc986f89129062f0",
          "body": "…s_list, projects_list, article_list\n\n- explicit pagination params with sane defaults (limit 100, max 200)\n- backing client methods forward $top/$skip\n- listProjects keeps auto-pagination when neither limit nor skip is passed\n- closes AGENTS.md MCP Tooling Expectations gap",
          "is_bot": false,
          "headline": "feat(pagination): add limit/skip to issue_comments, issue_links, user…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62d9435f5612b11284c6164a35606737066fe0ce",
          "body": "- normalizeError no longer attaches raw response.data to YoutrackClientError\n- pickSafeErrorDetails keeps only error / error_description / message / code\n  (string|number) — drops stack traces, PII and any other unexpected payload\n- prevents internals from bubbling up via MCP responses and logs",
          "is_bot": false,
          "headline": "fix(client): whitelist error details to avoid leaking internals",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:36:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfa6f9773fcb2ef2cb28cff5ca2a9f6711f993ff",
          "body": "- both subtask and regular branches now share the same target-id resolution\n- collapses duplicated subtask INWARD/OUTWARD branches\n- throws clear error when neither targetId nor link payload provide a target",
          "is_bot": false,
          "headline": "fix(links): subtask deletion falls back to linkToDelete.issue.idReadable",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:14:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a4c3897b0afe48897e7f1c855c16f462d9299bc",
          "body": "- streaming-client uses stream-json Parser+streamArray for incremental parsing;\n  array elements are no longer tied to TCP chunk boundaries\n- switched to native node http/https (avoids axios+follow-redirects+nock issues)\n- cleans up partial files on transport error / non-2xx / pipeline failure\n- new dep: stream-json",
          "is_bot": false,
          "headline": "fix(streaming): JSONL via stream-json, partial-file cleanup",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T16:00:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac5aa59716f5c7fe09a8e1517d8d368589bdaf0a",
          "body": "- baseFilterArgs gets limit (default 100, max 200) and skip\n- listWorkItems forwards $top/$skip in a single request (no implicit while-loop)\n- workitems_list/all_users/for_users handlers exported and tested\n- listWorkItems also resolveIssueId() the issueId filter",
          "is_bot": false,
          "headline": "feat(workitems): pagination in workitems_list and friends",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:50:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b98b5ed8136facdf7ca2f3bd82d08edd0c00dba",
          "body": "- getIssueActivities accepts top/skip/categories/start/end/author\n- issue_activities tool: categories as z.enum array, limit (default 100, max 200), skip\n- removes client-side slice; pagination is now actually applied on the server\n- handler exported and tested",
          "is_bot": false,
          "headline": "feat(activities): server-side pagination and category pass-through",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8ddf81c0ecd21029654a783191b366104e0d2fb",
          "body": "- issuesSearchArgs gains overwrite field; schema derives from args via z.object\n- assignee deprecated in favor of assigneeLogin (description updated)\n- articles_search rejects '{' '}' in query (projectId/parentArticleId already\n  protected by id-validators)\n- add unit tests for both schemas",
          "is_bot": false,
          "headline": "fix(schemas): unify issuesSearchArgs and validate articles_search inputs",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:43:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41b1d67b57b61e035174d6fd5b44ac10982312a7",
          "body": "- createIssueComment, updateIssueComment, updateIssue, changeIssueState,\n  starIssue, unstarIssue normalize input.issueId via resolveIssueId\n- getIssues / getIssuesDetails / getIssuesDetailsLight normalize array of ids\n- numeric ids now correctly compose with YOUTRACK_DEFAULT_PROJECT",
          "is_bot": false,
          "headline": "fix(client): apply resolveIssueId in mutations and bulk getters",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d95dfa29024f1569c422934c8fa1a2675407b301",
          "body": "- new minimal-fields method skips possibleEvents and other custom fields\n- batch counterpart getIssuesState uses a single search query\n- issue_status and issues_status handlers exported and tested\n- avoids fetching full custom field set for batch state checks",
          "is_bot": false,
          "headline": "feat(client): add getIssueState for lightweight state lookup",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:19:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1a99bc0bcf188a3be7208bb4585014fa5e015bc",
          "body": "- expose searchIssues, searchArticles, getBaseUrl as public methods\n- tools no longer use bracket-access to private getWithFlexibleTop\n- remove unused legacy searchArticles(input: ArticleSearchInput)",
          "is_bot": false,
          "headline": "refactor(client): public searchIssues/searchArticles/getBaseUrl",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:13:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05bda644fa1089eaed7b51637b6e2d3c9b47f944",
          "body": "- axios timeout 30s, maxRedirects 0, maxBodyLength/maxContentLength 50 MiB\n- uploadAttachments overrides timeout to 120s and body/content limit to 1 GiB\n- streaming-client req.setTimeout 60s with destroy + cleanup\n- file-download.ts already uses native http with timeoutMs/maxBytes (Task 3)\n- new test: youtrack-client.timeouts (3 cases on axios defaults)",
          "is_bot": false,
          "headline": "feat(reliability): HTTP timeouts and redirect/body limits",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:08:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7da0a51e75816e6303e16eed752457bee1e7f5d8",
          "body": "- single error rethrown directly, multiple wrapped in AggregateError\n- searchIssuesByUserActivityStrict: per-issue activity fetch wrapped in\n  try/catch returning [] so a single failure does not abort the search\n- existing soft-semantic callers (getMultipleIssuesComments(Light),\n  starIssues, unstar\n[…]\nBREAKING CHANGE: batch operations now propagate errors instead of silently\nproducing undefined entries. Callers in user code that relied on the silent\nbehaviour must wrap their processor in try/catch.",
          "is_bot": false,
          "headline": "fix(reliability)!: processBatch fast-fail with AggregateError",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T15:04:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9165b245f1dd75da2c7db5bb7950f58d6d2806ce",
          "body": "…ators\n\n- new src/utils/validators.ts: issueIdSchema, attachmentIdSchema, commentIdSchema,\n  workItemIdSchema, linkIdSchema, customFieldIdSchema, projectIdSchema,\n  userLoginSchema, articleIdSchema (regex /^[A-Za-z0-9._-]+$/ family)\n- youtrack-client.ts: all 30 interpolated path segments wrapped in \n[…]\n-special chars\nare rejected by regex validators. Defense-in-depth: even if a stray character\nslipped through, encodeURIComponent on path segments prevents path injection\nwithin the same YouTrack host.",
          "is_bot": false,
          "headline": "fix(security)!: encodeURIComponent on URL segments and id regex valid…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T14:58:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5c87fa7dbd0e5027743df8a2c5fe4358270b0f5",
          "body": "- file-storage processWithFileStorage(args, data, rootDir): paths resolved\n  through resolveOutputPath, partial files removed on pipeline error\n- file-download downloadFileFromUrl({ url, targetRel, rootDir, ... }):\n  native node http(s) with timeout, maxBytes and partial cleanup; drops\n  axios + fol\n[…]\nt-tools (4)\n\nBREAKING CHANGE: filePath/downloadPath must be relative to\nYOUTRACK_OUTPUT_DIR. Absolute paths and \\`..\\` segments are rejected.\nThe result field renamed from \\`filePath\\` to \\`savedTo\\`.",
          "is_bot": false,
          "headline": "fix(security)!: apply path-safety in file ops and attachments",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T14:44:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ec8bf04b563c82cca6745d469af59572519f7fb",
          "body": "- new src/utils/path-safety.ts: resolveOutputPath, sanitizeFilename, UnsafePathError\n- config gains outputDir (default process.cwd()), creates dir if missing\n- ServiceStatusPayload.configuration extended with outputDir and timezone\n\nBREAKING CHANGE: introduces YOUTRACK_OUTPUT_DIR env. Subsequent commits will\nreject absolute paths and .. segments in saveToFile/downloadPath inputs.",
          "is_bot": false,
          "headline": "feat(security)!: add path-safety utils and YOUTRACK_OUTPUT_DIR",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T14:25:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "885d1997b49cb4c17d9e518c0a5b1ab534eff22f",
          "body": "- vitest test runner with v8 coverage\n- nock for HTTP mocking\n- npm test / test:watch / test:coverage scripts\n- vitest.config.ts: src/**/*.test.ts, node env\n- smoke test verifies infra works",
          "is_bot": false,
          "headline": "chore(test): add vitest, nock, coverage v8 with smoke test",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2026-05-05T14:20:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d5aa288172174870ad2f6e86962afbc5fa6ceb9",
          "body": null,
          "is_bot": false,
          "headline": "chore: update changelog links for v0.10.2",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-18T20:42:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee8453e5dcec8d0d852d6d1414aaac17d2c3e35a",
          "body": null,
          "is_bot": false,
          "headline": "chore: fix version to 0.10.2",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-18T20:33:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e28699995c33bba393f23a5532494a7bce87c678",
          "body": null,
          "is_bot": false,
          "headline": "0.10.3",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-18T20:32:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca1c3e8cfb967ca81f6e7e22afa6b2b22acc97ba",
          "body": null,
          "is_bot": false,
          "headline": "chore: prepare release v0.10.2",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-18T20:32:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2d50159e72c750e52d35debd72418217600788d",
          "body": "…d tool\n\n- Add downloadToFile and downloadPath parameters to issue_attachment_download\n- Implement file download functionality using axios and stream pipeline\n- Add file overwrite protection with overwrite parameter\n- Update README documentation in both English and Russian\n- Add utility functions for file downloading and filename extraction\n- Maintain backward compatibility for signed URL functionality\n\nCo-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>",
          "is_bot": false,
          "headline": "feat: Add direct file download capability to issue_attachment_downloa…",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-18T20:27:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8cde5c633fece935ad5a280a53fe5bd34dd26cf",
          "body": "Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>",
          "is_bot": false,
          "headline": "docs: Update CHANGELOG for version 0.10.1",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-16T21:50:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c43435005ac625df73d15bd9e5f480c354049642",
          "body": "- Add streaming client for direct HTTP response to file without memory accumulation\n- Implement issue_status and issues_status tools for getting issue state/status\n- Add file storage with JSON/JSONL format support and overwrite options\n- Update various tools to support saveToFile, format, and overwr\n[…]\n\n- Improve YouTrack client with streaming and custom fields support\n- Add proper streaming support for large datasets to prevent memory issues\n\nCo-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>",
          "is_bot": false,
          "headline": "feat: Add streaming functionality and issue status tools",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-16T21:47:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7050de41c92f445b3e009f22e34a2378de075fca",
          "body": null,
          "is_bot": false,
          "headline": "Release version 0.10.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-04T16:47:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "939a005ac88e94789d2a0d60cf3e8ce4b35b6423",
          "body": null,
          "is_bot": false,
          "headline": "Update CHANGELOG for version 0.10.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-04T16:47:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "094456afc3318d7f186ad40ba6278cfcbc612a8c",
          "body": "- Remove YOUTRACK_USE_STRUCTURED_CONTENT from config schema and types\n- Always return responses in content node instead of optional structured content\n- Update tool-success/error functions to always use text content format\n- Remove related configuration and utility functions\n- Update documentation files to remove references",
          "is_bot": false,
          "headline": "Remove YOUTRACK_USE_STRUCTURED_CONTENT env var support",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-04T16:44:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31c32f933c0145a7f9ac0f9e53752ecc0f414b04",
          "body": "- Implement issues_list tool with comprehensive filtering, sorting, and pagination\n- Add issue_link_delete functionality with API fallback to command-based deletion\n- Enhance issues_search with extended filter support:\n  * Add projectIds, assigneeLogin, statuses, types array filters\n  * Add date ran\n[…]\ned fallback\n- issues_search: now includes comprehensive filtering matching issues_list capabilities\n\nBREAKING CHANGE: Issues search now supports additional filter parameters for enhanced functionality",
          "is_bot": false,
          "headline": "feat: Implement missing tools and enhance search functionality",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-11-04T16:26:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf892c0b9b90834ca4e977b8854b3cb5dbb44173",
          "body": "- Add Environment Setup section to README-release.md\n- Document requirement to disable pager for consistent command output\n- Update TOC to include new section",
          "is_bot": false,
          "headline": "docs: add pager disable rule to release procedure",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T20:15:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "844dab3ff0d16921d5d33cec850452407f90c830",
          "body": null,
          "is_bot": false,
          "headline": "0.9.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T20:15:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01bbfbcfea433455fdd11dd433d4f9716e7314ca",
          "body": "- Add file storage parameters section to both English and Russian README\n- Update feature list to include file storage capability\n- Document saveToFile and filePath parameters for large datasets",
          "is_bot": false,
          "headline": "docs: update README files with file storage functionality",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T20:14:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79a1c8a9f443b8178e44c3d8d17ffa698d1acd59",
          "body": "- Add new file-storage utility module\n- Add saveToFile and filePath options to multiple tools\n- Enable saving large datasets to JSON files instead of returning directly\n- Update article search, issue tools, workitem tools, and activity tools\n- Fix linting issues and update documentation\n- Update both English and Russian README files",
          "is_bot": false,
          "headline": "feat: add file storage functionality for large tool results",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T20:13:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5887e83f1f050beefe8f260a6513fc6858cd40bb",
          "body": "- Add new file-storage utility module\n- Add saveToFile and filePath options to multiple tools\n- Enable saving large datasets to JSON files instead of returning directly\n- Update article search, issue tools, workitem tools, and activity tools\n- Fix linting issues and update documentation",
          "is_bot": false,
          "headline": "feat: add file storage functionality for large tool results",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T20:12:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab0d6bd8c45dcb6973f0f69be7f5908764926120",
          "body": "- Add new file-storage utility module\n- Add saveToFile and filePath options to multiple tools\n- Enable saving large datasets to JSON files instead of returning directly\n- Update article search, issue tools, workitem tools, and activity tools",
          "is_bot": false,
          "headline": "feat: add file storage functionality for large tool results",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T20:00:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd8dabfaa24fcc583a2c1d872d139d82582c25ad",
          "body": null,
          "is_bot": false,
          "headline": "0.8.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T18:29:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cb5032caefe34765d22de81c92a05db2bd7dae7",
          "body": null,
          "is_bot": false,
          "headline": "docs: update CHANGELOG.md for v0.8.0",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T18:29:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71f87350f47ac54af82e3b37a7f3a73b8ad8c4f6",
          "body": null,
          "is_bot": false,
          "headline": "Add activity feed tool and update documentation",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-31T18:26:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60d97ac06e317b6c81c88e7f8d2c51871efb1b1a",
          "body": null,
          "is_bot": false,
          "headline": "docs: add git --no-pager rule and strengthen emoji prohibition",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-24T15:09:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd42d0c99b8dcca19184ffc48c0d6d339970370d",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v0.7.4",
          "author_name": "Vitaly Ostanin",
          "author_login": "VitalyOstanin",
          "committed_at": "2025-10-24T15:04:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 26,
      "commits_last_year": 148,
      "latest_release_at": "2026-07-18T10:46:22Z",
      "latest_release_tag": "v0.15.1",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 8.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@vitalyostanin/youtrack-mcp",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "youtrack",
            "jetbrains",
            "issue-tracking",
            "work-items",
            "time-tracking",
            "claude"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@vitalyostanin/youtrack-mcp",
          "is_deprecated": false,
          "latest_version": "0.15.1",
          "repository_url": "https://github.com/VitalyOstanin/youtrack-mcp",
          "versions_count": 26,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2546,
          "first_published_at": "2025-10-14T20:58:18.648000Z",
          "latest_published_at": "2026-07-18T10:46:20.939000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 6,
      "stars": 5,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-25",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-05-09",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-06-30",
            "count": 1
          },
          {
            "date": "2026-07-08",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 6,
        "total_forks": 6
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 24392,
      "source_files_sampled": 79,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 19476
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@vitalyostanin/mutex-pool",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.0.3"
        },
        {
          "name": "axios",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.18.1"
        },
        {
          "name": "form-data",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.6"
        },
        {
          "name": "luxon",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.7.2"
        },
        {
          "name": "stream-json",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.5.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 8,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 21
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "VitalyOstanin",
          "commits": 140,
          "avatar_url": "https://avatars.githubusercontent.com/u/352594?v=4"
        },
        {
          "type": "User",
          "login": "duffpod",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1066047?v=4"
        },
        {
          "type": "User",
          "login": "themnts",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/119766847?v=4"
        },
        {
          "type": "User",
          "login": "alexvaut",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/20702322?v=4"
        }
      ],
      "contributors_sampled": 4,
      "top_contributor_share": 0.979
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 6,
            "reason": "5 out of 8 merged PRs checked by a CI test -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 3/25 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "09a1716815ba7a1c98c12a0afc3213fc700cf622",
        "ran_at": "2026-07-23T18:01:32Z",
        "aggregate_score": 6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T03:18:03Z",
      "oldest_open_prs": [
        {
          "number": 30,
          "created_at": "2026-07-20T03:18:00Z",
          "last_comment_at": "2026-07-20T03:18:01Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": "2026-07-18T09:34:28Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/VitalyOstanin/youtrack-mcp",
    "host": "github.com",
    "name": "youtrack-mcp",
    "owner": "VitalyOstanin"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 60,
      "inputs": {
        "security": 60,
        "vitality": 82,
        "community": 45,
        "governance": 43,
        "engineering": 69
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 82,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "commits_last_year": 148,
              "human_commit_share": 0.95,
              "days_since_last_push": 3,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "148 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 148
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v0.15.1",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 8.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 45,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "forks": 6,
              "stars": 5,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "6 forks",
                "points": 5.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "@vitalyostanin/youtrack-mcp"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2546
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,546 downloads/month across npm",
                "points": 45.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2546,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 4,
              "top_contributor_share": 0.979
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "4 contributors",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 23,
            "inputs": {
              "merged_prs": 8,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 21
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "8/29 decided PRs merged",
                "points": 10.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 8,
                      "decided": 29
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 3/25 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "followers": 5,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "VitalyOstanin",
              "public_repos": 45,
              "account_age_days": 5833
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of VitalyOstanin",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "VitalyOstanin"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "45 public repos, account ~15 yr old",
                "points": 24.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 45
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@vitalyostanin/youtrack-mcp"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "26 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 69,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "5 out of 8 merged PRs checked by a CI test -- score normalized to 6",
                "points": 12,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 60,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "5 out of 8 merged PRs checked by a CI test -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 3/25 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 71,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.926,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 19476
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "88 of 95 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 88,
                      "sampled": 95
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.05
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "5 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 5,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 24392,
              "source_files_sampled": 79,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/79 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 79,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@vitalyostanin/youtrack-mcp@0.15.1; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T18:01:44.434567Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/v/VitalyOstanin/youtrack-mcp.svg",
  "full_name": "VitalyOstanin/youtrack-mcp",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.