Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 01:34 UTC

appliance-sh / appliance.sh

Appliance is the AI-native platform to develop and deploy web applications.

TypeScript · RustMIT★ 1 star⑂ 0 forkssince Jun 2025View on GitHub ↗

appliance-sh/appliance.sh holds a health index of 60 out of 100, placing it in the Moderate band. It scores highest on Vitality (86/100) and lowest on Community & Adoption (34/100). It was last updated today. A single contributor accounts for most of its recent work.

60
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

60
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

appliance.shOrganization
0 followers1 public reposince May 2025

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npm@appliance.sh/cli1.53.22,314706 days ago
npm@appliance.sh/sdk1.53.21,845716 days ago
npmappliance.sh1.53.21,746476 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

86Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
20.1/36Commit cadence — 29/52 weeks with commits
18/18Commit volume — 312 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year312
human_commit_share1
days_since_last_push0
active_weeks_last_year29
How it's scored
27/27Ships releases — 82 releases published
36/36Release recency — latest release 6 days ago
27/27Release cadence — a release every ~4.1 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count82
latest_release_tagv1.53.2
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases4.1

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

34At risk · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
50.3/80Monthly downloads — 5,905 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@appliance.sh/cli, @appliance.sh/sdk, appliance.sh
dependents
ecosystemsnpm
total_downloads
monthly_downloads5,905
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

49At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
37.7/38.3PR acceptance — 64/65 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs64
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs1
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
0/25Owner reach — 0 followers of appliance-sh
4.5/25Track record — 1 public repos, account ~1 yr old
Inputs used
followers0
owner_typeOrganization
is_verified
owner_loginappliance-sh
public_repos1
account_age_days425
How it's scored
25/25Published & resolvable — 3 package(s) on npm
35/35Publish recency — latest publish 6 days ago
20/20Version history — 71 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@appliance.sh/cli, @appliance.sh/sdk, appliance.sh
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

79Good · 20% of overall
How it's scored
24/24CI workflows — 6 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.mjs
0/9.6Pre-commit hooks
0/6.4.editorconfig
14/20OpenSSF Scorecard: CI-Tests — 6 out of 8 merged PRs checked by a CI test -- score normalized to 7
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.appliance.sh
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepagehttps://www.appliance.sh
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

48At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
1.8/2.5CI-Tests — 6 out of 8 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 114 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3.5
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages1
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:appliance.sh@1.53.2 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

67Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 99 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.99
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — packages/desktop/src-tauri/Cargo.toml, packages/vm/Cargo.toml (toolchain convention, no task runner)
22/22Automated tests
11/11Lint / format config — eslint.config.mjs
11/11Static type checking — packages/api-server/tsconfig.json, packages/app/tsconfig.json, packages/bootstrap/tsconfig.json, packages/cli/tsconfig.json, packages/console/tsconfig.json, packages/desktop/sidecar/tsconfig.json, packages/desktop/tsconfig.json, packages/helper/tsconfig.json, packages/infra/tsconfig.json, packages/install-aws/tsconfig.json, packages/sdk/tsconfig.json, tsconfig.json
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 65 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesCargo.lock, package-lock.json, pnpm-lock.yaml
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configspackages/api-server/tsconfig.json, packages/app/tsconfig.json, packages/bootstrap/tsconfig.json, packages/cli/tsconfig.json, packages/console/tsconfig.json, packages/desktop/sidecar/tsconfig.json, packages/desktop/tsconfig.json, packages/helper/tsconfig.json, packages/infra/tsconfig.json, packages/install-aws/tsconfig.json, packages/sdk/tsconfig.json, tsconfig.json
agent_commit_share0.65
toolchain_manifestspackages/desktop/src-tauri/Cargo.toml, packages/vm/Cargo.toml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.6/55Manageable file sizes — 3/378 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes240,157
source_files_sampled378
oversized_source_files3
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files

Key facts

1GitHub stars
1contributors
312commits, last 12 months
0days since last push
82releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'appliance-vm' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 3.5 / 10
3.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 01:34 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
7CI-Tests6 out of 8 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities114 existing vulnerabilities detected
Direct dependencies 71
RegistryPackageVersion constraintManifest
npm@appliance.sh/infraworkspace:*packages/api-server/package.json
npm@appliance.sh/sdkworkspace:*packages/api-server/package.json
npm@aws-sdk/client-ecr^3.1005.0packages/api-server/package.json
npm@aws-sdk/client-s3^3.750.0packages/api-server/package.json
npm@aws-sdk/s3-request-presigner^3.1009.0packages/api-server/package.json
npmcors^2.8.5packages/api-server/package.json
npmexpress^5.2.1packages/api-server/package.json
npm@appliance.sh/sdkworkspace:*packages/app/package.json
npm@fontsource-variable/geist^5.2.9packages/app/package.json
npm@fontsource-variable/geist-mono^5.2.8packages/app/package.json
npm@radix-ui/react-slot^1.1.1packages/app/package.json
npm@tanstack/react-query^5.60.0packages/app/package.json
npm@xterm/addon-fit^0.11.0packages/app/package.json
npm@xterm/xterm^6.0.0packages/app/package.json
npmbuffer^6.0.3packages/app/package.json
npmclass-variance-authority^0.7.1packages/app/package.json
npmclsx^2.1.1packages/app/package.json
npmlucide-react^0.468.0packages/app/package.json
npmreact-router^7.0.2packages/app/package.json
npmtailwind-merge^2.5.5packages/app/package.json
npm@appliance.sh/cliworkspace:*packages/appliance.sh/package.json
npm@appliance.sh/infraworkspace:*packages/bootstrap/package.json
npm@appliance.sh/sdkworkspace:*packages/bootstrap/package.json
npm@aws-sdk/client-ecr^3.1005.0packages/bootstrap/package.json
npm@aws-sdk/credential-providers^3.1044.0packages/bootstrap/package.json
npm@pulumi/pulumi^3.216.0packages/bootstrap/package.json
npm@appliance.sh/appworkspace:*packages/console/package.json
npmreact^19.0.0packages/console/package.json
npmreact-dom^19.0.0packages/console/package.json
npm@appliance.sh/appworkspace:*packages/desktop/package.json
npm@appliance.sh/bootstrapworkspace:*packages/desktop/package.json
npm@appliance.sh/helperworkspace:*packages/desktop/package.json
npm@tauri-apps/api^2.11.0packages/desktop/package.json
npm@tauri-apps/plugin-dialog^2.2.0packages/desktop/package.json
npm@tauri-apps/plugin-notification^2.2.0packages/desktop/package.json
npm@tauri-apps/plugin-process^2.2.0packages/desktop/package.json
npm@tauri-apps/plugin-shell^2.2.0packages/desktop/package.json
npm@tauri-apps/plugin-updater^2.2.0packages/desktop/package.json
npmreact^19.0.0packages/desktop/package.json
npmreact-dom^19.0.0packages/desktop/package.json
npmundici^8.7.0packages/helper/package.json
npm@appliance.sh/sdkworkspace:*packages/infra/package.json
npm@kubernetes/client-node^1.4.0packages/infra/package.json
npm@pulumi/aws^7.16.0packages/infra/package.json
npm@pulumi/aws-native^1.48.0packages/infra/package.json
npm@pulumi/awsx^3.1.0packages/infra/package.json
npm@pulumi/pulumi^3.216.0packages/infra/package.json
npm@appliance.sh/sdkworkspace:*packages/install-aws/package.json
npm@aws-sdk/client-cloudfront^3.955.0packages/install-aws/package.json
npmaws-cdk^2.1033.0packages/install-aws/package.json
npmaws-cdk-lib^2.230.0packages/install-aws/package.json
npmconstructs^10.4.3packages/install-aws/package.json
npmhttp-message-signatures^1.0.4packages/sdk/package.json
npmuuidv7^1.1.0packages/sdk/package.json
npmzod^4.1.13packages/sdk/package.json
npmzod-to-ts^2.0.0packages/sdk/package.json
crates.ioanyhow1packages/vm/Cargo.toml
crates.ioclap4packages/vm/Cargo.toml
crates.ioserde1packages/vm/Cargo.toml
crates.ioserde_json1packages/vm/Cargo.toml
crates.iolibc0.2packages/vm/Cargo.toml
crates.ioureq2packages/vm/Cargo.toml
crates.ioring0.17packages/vm/Cargo.toml
crates.ioflate21packages/vm/Cargo.toml
crates.iofatfs0.3packages/vm/Cargo.toml
crates.iotar0.4packages/vm/Cargo.toml
crates.iofscommon0.1packages/vm/Cargo.toml
crates.iorcgen0.13packages/vm/Cargo.toml
crates.iorustls0.23packages/vm/Cargo.toml
crates.iowebpki-roots0.26packages/vm/Cargo.toml
crates.iosmoltcp0.13.1packages/vm/Cargo.toml
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 0

Installing npm:appliance.sh@1.53.2 pulls in 1 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 4256,
      "has_wiki": false,
      "homepage": "https://www.appliance.sh",
      "languages": {
        "CSS": 3165,
        "HTML": 592,
        "Rust": 938769,
        "Shell": 5127,
        "Dockerfile": 6761,
        "JavaScript": 76310,
        "TypeScript": 2219941
      },
      "pushed_at": "2026-07-26T14:25:54Z",
      "created_at": "2025-06-02T09:55:08Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T14:26:00Z",
      "description": "Appliance is the AI-native platform to develop and deploy web applications.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": "appliance.sh",
      "type": "Organization",
      "login": "appliance-sh",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/213535970?v=4",
      "created_at": "2025-05-27T01:34:45Z",
      "is_verified": null,
      "public_repos": 1,
      "account_age_days": 425
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.53.2",
          "kind": "patch",
          "published_at": "2026-07-20T14:57:19Z"
        },
        {
          "tag": "v1.53.1",
          "kind": "patch",
          "published_at": "2026-07-20T14:05:31Z"
        },
        {
          "tag": "v1.53.0",
          "kind": "minor",
          "published_at": "2026-07-20T12:08:57Z"
        },
        {
          "tag": "v1.52.0",
          "kind": "minor",
          "published_at": "2026-07-17T12:52:11Z"
        },
        {
          "tag": "v1.51.2",
          "kind": "patch",
          "published_at": "2026-07-04T11:51:39Z"
        },
        {
          "tag": "v1.51.1",
          "kind": "patch",
          "published_at": "2026-07-04T10:30:03Z"
        },
        {
          "tag": "v1.51.0",
          "kind": "minor",
          "published_at": "2026-07-04T06:33:55Z"
        },
        {
          "tag": "v1.50.0",
          "kind": "minor",
          "published_at": "2026-07-01T01:18:25Z"
        },
        {
          "tag": "v1.49.0",
          "kind": "minor",
          "published_at": "2026-06-17T11:29:14Z"
        },
        {
          "tag": "v1.48.0",
          "kind": "minor",
          "published_at": "2026-06-13T13:15:59Z"
        },
        {
          "tag": "v1.47.0",
          "kind": "minor",
          "published_at": "2026-06-12T00:23:16Z"
        },
        {
          "tag": "v1.46.0",
          "kind": "minor",
          "published_at": "2026-06-11T13:16:27Z"
        },
        {
          "tag": "v1.45.1",
          "kind": "patch",
          "published_at": "2026-05-27T10:29:33Z"
        },
        {
          "tag": "v1.45.0",
          "kind": "minor",
          "published_at": "2026-05-27T10:12:33Z"
        },
        {
          "tag": "v1.44.1",
          "kind": "patch",
          "published_at": "2026-05-27T09:18:06Z"
        },
        {
          "tag": "v1.44.0",
          "kind": "minor",
          "published_at": "2026-05-27T09:10:22Z"
        },
        {
          "tag": "v1.43.0",
          "kind": "minor",
          "published_at": "2026-05-27T08:57:24Z"
        },
        {
          "tag": "v1.42.0",
          "kind": "minor",
          "published_at": "2026-05-27T07:06:39Z"
        },
        {
          "tag": "v1.41.0",
          "kind": "minor",
          "published_at": "2026-05-25T23:25:07Z"
        },
        {
          "tag": "v1.40.1",
          "kind": "patch",
          "published_at": "2026-05-25T13:03:51Z"
        },
        {
          "tag": "v1.40.0",
          "kind": "minor",
          "published_at": "2026-05-24T14:31:35Z"
        },
        {
          "tag": "v1.39.0",
          "kind": "minor",
          "published_at": "2026-05-10T14:13:11Z"
        },
        {
          "tag": "v1.38.0",
          "kind": "minor",
          "published_at": "2026-05-06T12:56:34Z"
        },
        {
          "tag": "v1.37.0",
          "kind": "minor",
          "published_at": "2026-05-05T12:57:19Z"
        },
        {
          "tag": "v1.36.1",
          "kind": "patch",
          "published_at": "2026-05-04T13:16:07Z"
        },
        {
          "tag": "v1.36.0",
          "kind": "minor",
          "published_at": "2026-05-03T13:10:39Z"
        },
        {
          "tag": "v1.35.0",
          "kind": "minor",
          "published_at": "2026-04-30T14:24:20Z"
        },
        {
          "tag": "v1.34.0",
          "kind": "minor",
          "published_at": "2026-04-30T13:58:49Z"
        },
        {
          "tag": "v1.33.1",
          "kind": "patch",
          "published_at": "2026-04-30T13:23:44Z"
        },
        {
          "tag": "v1.33.0",
          "kind": "minor",
          "published_at": "2026-04-29T14:09:49Z"
        },
        {
          "tag": "v1.32.6",
          "kind": "patch",
          "published_at": "2026-04-29T12:51:18Z"
        },
        {
          "tag": "v1.32.5",
          "kind": "patch",
          "published_at": "2026-04-29T12:40:40Z"
        },
        {
          "tag": "v1.32.4",
          "kind": "patch",
          "published_at": "2026-04-29T12:32:00Z"
        },
        {
          "tag": "v1.32.3",
          "kind": "patch",
          "published_at": "2026-04-29T12:21:23Z"
        },
        {
          "tag": "v1.32.2",
          "kind": "patch",
          "published_at": "2026-04-29T12:11:19Z"
        },
        {
          "tag": "v1.32.1",
          "kind": "patch",
          "published_at": "2026-04-29T11:56:50Z"
        },
        {
          "tag": "v1.32.0",
          "kind": "minor",
          "published_at": "2026-04-28T23:20:11Z"
        },
        {
          "tag": "v1.31.0",
          "kind": "minor",
          "published_at": "2026-04-28T13:06:48Z"
        },
        {
          "tag": "v1.30.0",
          "kind": "minor",
          "published_at": "2026-04-27T12:12:09Z"
        },
        {
          "tag": "v1.29.0",
          "kind": "minor",
          "published_at": "2026-04-22T14:28:17Z"
        },
        {
          "tag": "v1.28.1",
          "kind": "patch",
          "published_at": "2026-04-22T11:47:12Z"
        },
        {
          "tag": "v1.28.0",
          "kind": "minor",
          "published_at": "2026-04-20T15:32:46Z"
        },
        {
          "tag": "v1.27.3",
          "kind": "patch",
          "published_at": "2026-04-15T12:02:27Z"
        },
        {
          "tag": "v1.27.2",
          "kind": "patch",
          "published_at": "2026-04-14T14:16:21Z"
        },
        {
          "tag": "v1.27.1",
          "kind": "patch",
          "published_at": "2026-04-06T15:20:41Z"
        },
        {
          "tag": "v1.27.0",
          "kind": "minor",
          "published_at": "2026-04-04T15:13:33Z"
        },
        {
          "tag": "v1.26.3",
          "kind": "patch",
          "published_at": "2026-04-02T12:11:40Z"
        },
        {
          "tag": "v1.26.2",
          "kind": "patch",
          "published_at": "2026-04-01T14:35:56Z"
        },
        {
          "tag": "v1.26.1",
          "kind": "patch",
          "published_at": "2026-03-23T15:32:45Z"
        },
        {
          "tag": "v1.26.0",
          "kind": "minor",
          "published_at": "2026-03-16T14:43:30Z"
        },
        {
          "tag": "v1.25.0",
          "kind": "minor",
          "published_at": "2026-03-16T12:46:31Z"
        },
        {
          "tag": "v1.24.0",
          "kind": "minor",
          "published_at": "2026-03-16T12:21:26Z"
        },
        {
          "tag": "v1.23.0",
          "kind": "minor",
          "published_at": "2026-03-15T12:15:27Z"
        },
        {
          "tag": "v1.22.1",
          "kind": "patch",
          "published_at": "2026-03-11T13:51:08Z"
        },
        {
          "tag": "v1.22.0",
          "kind": "minor",
          "published_at": "2026-03-11T13:07:15Z"
        },
        {
          "tag": "v1.21.0",
          "kind": "minor",
          "published_at": "2026-03-11T00:00:59Z"
        },
        {
          "tag": "v1.20.0",
          "kind": "minor",
          "published_at": "2026-03-10T14:03:11Z"
        },
        {
          "tag": "v1.19.1",
          "kind": "patch",
          "published_at": "2026-03-10T11:08:38Z"
        },
        {
          "tag": "v1.19.0",
          "kind": "minor",
          "published_at": "2026-03-09T15:05:11Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2026-03-09T13:30:21Z"
        },
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2026-01-19T14:33:22Z"
        },
        {
          "tag": "v1.16.1",
          "kind": "patch",
          "published_at": "2026-01-18T15:37:36Z"
        },
        {
          "tag": "v1.16.0",
          "kind": "minor",
          "published_at": "2026-01-18T15:21:32Z"
        },
        {
          "tag": "v1.15.0",
          "kind": "minor",
          "published_at": "2026-01-18T14:29:55Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2026-01-14T15:20:01Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2026-01-03T15:19:06Z"
        },
        {
          "tag": "v1.12.1",
          "kind": "patch",
          "published_at": "2026-01-03T14:16:13Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-01-01T12:52:34Z"
        },
        {
          "tag": "v1.11.1",
          "kind": "patch",
          "published_at": "2025-12-30T00:03:05Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2025-12-29T15:07:15Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2025-12-28T13:11:43Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2025-12-22T15:05:07Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2025-12-22T04:41:28Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2025-12-21T15:18:21Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2025-12-21T12:55:48Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2025-12-15T15:14:34Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2025-12-01T14:59:39Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2025-12-01T14:32:05Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2025-09-13T13:44:01Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2025-06-20T14:11:06Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2025-06-15T12:51:50Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2025-06-14T13:39:27Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "28a9c2a1e69e62dba167c7eaa99a7654ac7a518e",
          "body": "… classifier parity\n\nFrom a four-angle cleanup review (reuse/simplification/efficiency/altitude)\nof the recent work:\n\n- mcp-server: a withClient wrapper replaces the per-tool getClient\n  try/catch boilerplate (5 sites); the vm tool's action ternary collapses\n  to ['vm', action, ...]; the pass-throug\n[…]\ndesktop decode copy documents why it exists and how its\n  sniff differs.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "refactor: simplify MCP handlers, reuse vm capture helper, true up WSL…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69184e862cb05ff8c523f3a8d64f205b907ac5d9",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "docs(readme): mention vm status guidance and the one-command vm reset",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "89e02b342dcfe7a6f71eabfa5a46f25a06e569e8",
          "body": "Engine resolution prefers the installed ~/.appliance/bin copy over a\nrepo build, and the version string never changes — so a weeks-stale\nengine boots silently and its failures masquerade as guest bugs (hit\nlive today: a Jul-7 engine wrote an empty api-server manifest and the\nboot hung at the ingress wait). One dim line makes which engine booted\nthe VM a printed fact.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "feat(cli): vm up names the engine binary it resolved (path + build date)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3cd9830b70c71f58deab29a6c131fe5712c3f7b2",
          "body": "…eset\n\n'appliance vm status' now prints a plain-language summary — state,\nconsole/app URLs, ports, and ALWAYS a 'Next:' line naming the command\nthat moves that state forward (init / vm up / dev / console -f) — with\n--json preserving the raw engine report for scripts. The renderer is a\npure exported \n[…]\nirm, stop\n(best-effort), delete the VM + credential profile, boot fresh.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "feat(cli): human vm status with next-step guidance + one-command vm r…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25faa91c7a999e1fcc25af8d1c95e4fda1976601",
          "body": "…le in MCP deploy links\n\nBoth found by adversarial review of the previous commits:\n\n- The deploy SIGINT note claimed 'the deployment continues server-side'\n  even during target resolution / the slow first build / the upload —\n  the exact window users most often abort, when nothing has dispatched\n  y\n[…]\n  profile instead. RunDeployParams gains linkProfile, passed explicitly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "fix(cli): honest Ctrl+C messaging pre-dispatch; record per-call profi…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a15a7bdfa8962fe918ed3732d0feb0a86d7dcbc",
          "body": "profiles.json (and the legacy credentials.json mirror) carry API-key\nsecrets; the unix writers set 0600 but on Windows the files inherited\ndefault directory ACLs in cleartext. Both writers — the CLI's\natomicWriteJson and the desktop's write_shared_profiles — now reset the\nACL via icacls /inheritance\n[…]\ncial builds) with the real key injected in CI by\nset-updater-pubkey.mjs.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "fix(security): restrict profiles.json ACL to the owning user on Windows",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1a2d5eafd8155e9c30cbefa5db772d1ec0f4df42",
          "body": "…quiet\n\nFirst boots go silent for minutes during multi-GB image pulls; the\nladder just spun, reading as a hang. Track last activity (new log line,\nrung advance, or a CHANGED cluster sub-phase — the 1.5s poll re-reports\nthe same phase and must not reset the clock) and after 2 quiet minutes\nshow a yel\n[…]\n aborts anything — the engine's own\ntimeout stays the failure authority.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "feat(desktop): reassure instead of bare-spinning when a VM boot goes …",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1075e084c2d34524dc6974893b26773182f6cb92",
          "body": "The gitignored api-server docker prep stages a prebuilt console bundle\nunder .docker-deps/; on any machine that has run it, `eslint .` drowned\nin ~2800 generated-code errors.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "chore(lint): ignore staged .docker-deps build context in eslint",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "de9466aaad784e89d446e97be6d28bf4574b74ac",
          "body": "…ths for non-developers\n\n- deploy tells the truth: after a successful rollout, probe the\n  environment-health endpoint and warn when the app is crashlooping\n  ('Deployed, but the app is not staying up (CrashLoopBackOff) — see why\n  with appliance logs <p> <e>') or still rolling out; failed deploys n\n[…]\netails.\n- container-runtime hint drops the colima suggestion on Windows.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "fix(ux): honest deploys, no stack traces, inline WSL fix — unhappy pa…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98debfd2b7cb82e93615742ddd29fbdcca2dc300",
          "body": "…ted WSL error guidance\n\nThe Windows audit's high-impact fixes:\n\n- preflight: new checkWsl (wsl --status, UTF-16LE-aware decode, failure\n  classification naming virtualization-in-BIOS / kernel-update /\n  wsl --install fixes) and checkDiskSpace (first boot imports a multi-GB\n  distro); WSL leads the \n[…]\nt in the local docker daemon'\n  help text now marked deprecated/ignored.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "fix(windows): preflight WSL2 + disk checks, no console flashes, targe…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aed6967cc453d99682f17e267676fdcdc047667f",
          "body": "…nd debug\n\nNew 'appliance mcp' subcommand serves the deploy/debug surface over the\nModel Context Protocol on stdio: overview (profiles/projects/URLs),\ndeploy (single app or stack, in-process engine), deployment_status,\nhealth (crashloop reasons via the environment-health API), logs (pod\nlogs through\n[…]\ncted fake SDK\nclient (13 specs), plus a live stdio handshake smoke test.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "feat(cli): appliance mcp — MCP server so external agents can deploy a…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf2c59808bc66d3497129102b62181a3d5ef1a4d",
          "body": "… Windows\n\nGNU tar (Git for Windows) parses an absolute 'C:\\...' -f argument as a\nremote host:path archive, so writeSupportBundle failed with 'Cannot\nconnect to C: resolve failed' whenever GNU tar won the PATH race. Pass\nthe archive name relative with cwd set to its directory (works for both\nGNU tar\n[…]\nc's\nextracted-path separators so its assertions actually run on Windows.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "fix(cli): make support-bundle tar work when GNU tar shadows bsdtar on…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7d515ffb1ace819d57a1d5a6e53837601e775632",
          "body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01EWUFMaEaRwMHYABscjNRQK",
          "is_bot": false,
          "headline": "docs(rfcs): add design RFC collection with status index",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-26T14:25:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c801905f486128ffe671c23553db684befb7e9d1",
          "body": "The app's `tsc --emitDeclarationOnly` type-checks against\n@appliance.sh/bootstrap (src/lib/host.ts imports its types), but\ndocker-prep.sh never built it, so the api-server image build failed\nwith TS2307 \"Cannot find module '@appliance.sh/bootstrap'\". Build\nbootstrap (deps sdk+infra, already built) before the app.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(api-server): build bootstrap before web console in docker-prep",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T15:02:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9e12d8e12ee162da6d59fe2c93092f9165bf7857",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.53.2",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T14:57:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3ae8790df733de0d5724d7e58411989b998e520",
          "body": "PowerShell on windows-latest parses a bare @pkg as the splatting\noperator, so `nx run-many -p @appliance.sh/cli @appliance.sh/app`\nfailed at parse time. Single-quote the names — literal in both\nPowerShell and bash — and apply to the macOS job too for consistency.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): quote scoped package names in windows desktop build",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T14:55:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4bfc4987f7c53f8a0baefb988df515c65720b1e3",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.53.1",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T14:05:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5fdc2b9bf6ad753adb461949e2f7ae475f78dad",
          "body": "The desktop build jobs read APPLE_* and Tauri updater secrets that live in\nthe `publish` GitHub environment, but declared no environment — so the\nsecrets.* refs resolved to empty strings and every release shipped an\nUNSIGNED, un-notarized bundle with a placeholder updater key. Opt both the\nmacOS and\n[…]\nodesign's DER entitlement\nencoding can't trip over them; relocate their rationale into the\nconsuming scripts (notarize-macos.mjs, sign-dev.sh).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(release): scope desktop signing to publish env + guard signed output",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T14:04:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "018be632d4d71f443ac7def6fe018cf6e06c21a3",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.53.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T12:08:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57e1502d9935c6268855d2e065e786aad321b4a6",
          "body": null,
          "is_bot": false,
          "headline": "feat(app): start machine recovery",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-20T01:44:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b38c0a2a6e8f162e6b8cf2899e6c2cad1e5506e2",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' of https://github.com/appliance-sh/appliance.sh",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-18T12:26:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f1515a438ffc42cc62a37f1246e35d91b8abcbd",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.52.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-17T12:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e99825e09ef0675531d4e811d827ad08c21b65e",
          "body": "…i-server substrate (#58)\n\n* feat(cloud): one-click deploy a local app to a connected cloud cluster (BYO)\n\nMake 'ship a local app to my cloud' a first-class, one-click action from\nthe desktop, reusing the existing base-URL-agnostic deploy + target-aware\nwizard rather than rebuilding deploy.\n\n- cloud\n[…]\nsession_01J7nGXC2jYiDRhp7YJMviBR\n\n* style: prettier fix on merged deploy.tsx\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cloud v1: one-click local→cloud deploy (k8s + AWS) + tenant-scoped ap…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-17T12:50:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "46fd82ee954110b4fb63421ff0f6d280f18fa802",
          "body": "* ci(release): serialize release runs, fix retired Intel runner, add unsigned dispatch\n\n- release.yml: concurrency group release-${{ github.ref }} with\n  cancel-in-progress: false — a new push to main supersedes a run still\n  pending environment approval without ever killing an in-flight publish.\n- \n[…]\n all kept.\nRoute + schema tests assert the token never appears in a response.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Ship-safe: version-skew immunity + release pipeline repair (#65)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-17T12:07:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2313ab7bb4dbb50269afcacf8de6ce121e3f66c9",
          "body": "…g instrumentation (#64)\n\n* feat(vm): bring-up instrumentation — phase history, timings, time budget\n\nEvery bringup phase transition now also appends {phase, detail, at} to\na per-VM bringup-history.jsonl (bringup.json is untouched for compat),\nhost-side bring-up log lines carry an elapsed-seconds pr\n[…]\nprint,\n  and timeout messages name the exact stuck step including its detail.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fast first-run: airgap image preload, honest bring-up progress, timin…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-17T03:16:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e040d5c6720c1d7f460e9d97ffbf76cfbe42df88",
          "body": "… support bundle (#63)\n\n* feat(vm): engine runtime doctor, delete-time profile pruning, launcher xtrace fix\n\n- New guest_exec module: the one-shot guest command transport (marker\n  protocol over the vsock shell PTY) lifted from mint.rs so the doctor\n  and support-bundle paths share it; mint behavior\n[…]\nappliance-doctor\n  imports DEFAULT_VM_NAME instead of hardcoding 'appliance'.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Appliance doctor: one-command runtime diagnosis, safe fixes, redacted…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-17T00:53:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5031f24989670e0950969ec0fffa69fc9ab458b",
          "body": "…, deploy entry points, log tails (#61)\n\n* fix(vm): allow dead_code on stop_request for non-Windows targets\n\nstop_request() is only called from Windows-gated code (request_stop's\nwindows variant and the WSL backend), so clippy -D warnings fails the\nmacOS/Linux build. Mirror shell_sock's cfg_attr idi\n[…]\n CTA.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "First-run polish: kill the first-deploy 500, one Dev Machine identity…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-16T13:20:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80a7e2b068795de041a48ae458b63fe13a7b4d0c",
          "body": "* fix: sync pnpm-lock.yaml with cli package.json\n\nCommit 3a5208b removed the @appliance.sh/api-server workspace dep\nfrom packages/cli but did not regenerate the lockfile, breaking\npnpm install --frozen-lockfile in CI.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* fix(vm): allow dead_cod\n[…]\ndiom.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): sync cli lockfile + allow dead_code on stop_request (#62)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-16T12:46:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3efacc36441c0b2e4c02a4b6654d7e794bace25d",
          "body": "A VM's api-server keeps its key store on the VM's data disk, so a\nfreshly created (or recreated) VM boots with zero keys. Only the\nwrapping CLI's `appliance vm up` ever minted one — an engine-only\nstart (`appliance-vm up|start|run`, a desktop engine call, a crashed\nCLI) left the store empty forever \n[…]\n, and\na reboot minted nothing (1 key in the store, profile unchanged).\n\n\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): engine-owned credential mint at bring-up (#60)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-14T13:25:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1cacc68902a1a6217e064d00f86b914f17a3a01",
          "body": "A microVM's api-server keeps its key store on the VM's data disk, so\nrecreating the VM silently invalidates every credential the desktop\nholds — a permanent, opaque 401 with no recovery path short of running\n`appliance vm up` from the CLI (which most desktop users never do).\n\nNow, when the query cac\n[…]\nch — and healing would just mask it behind\nan ever-growing key store).\n\n\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): self-heal microVM credentials on auth failure (#59)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-14T13:25:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80bcc6f870816a385ad3dd2aee3c54756d69b0ba",
          "body": null,
          "is_bot": false,
          "headline": "feat: improve documentation and user journeys",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-12T14:34:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "422020c31ec9534ccd975ab5000acfb18b955904",
          "body": "The guest api-server never became reachable: `appliance vm up` timed out\nwaiting on http://api.appliance.localhost, and the k3s auto-deploy\nmanifest at $PERSIST/k3s/server/manifests/appliance-api-server.yaml was\nwritten as a 0-byte file.\n\nCause: a comment inside the UNQUOTED `<<APIMANIFEST` heredoc \n[…]\nent, api-server on :9091, and the ingress\n/healthz returns {\"ok\":true}.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "fix(vm): stop the api-server manifest heredoc from executing the binary",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-09T05:28:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e88cbd78b5d5ebdb932e61c25713f89ab95f348",
          "body": "…lease\n\nThe installed CLI (a bun single-binary) can't build the guest control\nplane locally, so stageFromRelease() downloads appliance-api-server-\nlinux-<arch> and appliance-console.tar.gz from the GitHub release. No\nworkflow ever published them, so every installed v1.51.x CLI 404'd when\nstaging the\n[…]\nll\nthree to the release with names matching stageFromRelease() exactly.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "fix(ci): publish api-server guest binaries + console bundle in CLI re…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-08T15:18:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c67f93318f7bb2bd7aa11c66dd3738b871244dcf",
          "body": null,
          "is_bot": false,
          "headline": "feat: improve dx and cli",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-07T10:25:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c9c96e850fc9b44cd00fa21e4e92c0eb8880393",
          "body": null,
          "is_bot": false,
          "headline": "feat: microvm based builds",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-07T07:25:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a5208b8bb63687a950f8c35a48cea16d9859fbd",
          "body": null,
          "is_bot": false,
          "headline": "feat: consolidate microvm runtime",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-07T06:33:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50a400ed05506f224c131b81fb0399c9e4ceb5a1",
          "body": null,
          "is_bot": false,
          "headline": "feat: improve microvm management",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-07T03:54:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0daa1c9408665f590aebdb7799ac31b7cc22e17",
          "body": "…inary\n\nUnder a bun single-binary, import.meta.url resolves into the virtual\nbunfs and passes the exists() check, so the Node branch spawned the CLI\nwith that bogus path as argv[1] — the dispatcher then parsed `run` as an\nunknown top-level command and printed help instead of running `server\nrun`. Ga\n[…]\n(execPath is the CLI\nthere), leaving the plain-Node dev path unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "fix(cli): route server self-invocation through subcommand under bun b…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T23:39:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9a223acc5f20c0aaed14b7c2af6060dc7dd2633",
          "body": null,
          "is_bot": false,
          "headline": "chore(lint): exclude examples from eslint",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T13:43:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3df26a35dceb0e11ab45c5c9d871f3fc06550d0",
          "body": null,
          "is_bot": false,
          "headline": "feat(examples): three tier demo",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T13:43:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21230c2a9d645094839467a8b23545932c1dfcde",
          "body": null,
          "is_bot": false,
          "headline": "feat: improved server ergonomics",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T11:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d36d6f34ade8180a4a2073eb70141c59c8385809",
          "body": null,
          "is_bot": false,
          "headline": "feat: appliance stack and replica improvements",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T11:09:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35be0eac4fe820306aecfef24cf11143e0b91d7d",
          "body": null,
          "is_bot": false,
          "headline": "feat: improvements to ui and ux",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T10:20:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfcbe3c4084fdf40d6cbcd5595368c1d84a70e5f",
          "body": null,
          "is_bot": false,
          "headline": "feat: microvm for windows",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-06T08:31:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f70d4e38eb1b4fd5e5d2bc120033ec7546583df9",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.51.2",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-04T11:51:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75761fe791e664d39d62e0624998586f809ee934",
          "body": "… them\n\nThe desktop bundles a Bun-compiled `appliance` CLI as its Tauri sidecar,\nbut `cli:bundle` only COPIES packages/cli/dist/appliance — nothing in the\n`tauri:dev`/`tauri:build` chains compiled it first (unlike `vm:build`,\nwhich genuinely runs cargo). So `git pull` + `tauri:dev` silently shipped\n\n[…]\nle` stages a\nsidecar binary that contains the 1.51.1 arch-fallback fix.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "fix(build): build the CLI + workspace deps before the desktop bundles…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-04T11:49:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1effaf2b998cabdf4297a94d1e8e265974bb0a15",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.51.1",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-04T10:30:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2fc35e1c745387342d0fde52af53e62589d32d8a",
          "body": "…ong arch\n\n`appliance vm up` delivers the api-server into the VM registry via a\nhost-side `docker save --platform linux/<host-arch>`, falling back to the\npinned ghcr image when nothing local matches. That fallback was gated on\n\"no image present at all\", so a stray amd64 `appliance-api-server:latest`\n[…]\nalready resolves this via the multi-arch ghcr pull, so no change\nthere.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "fix(cli): auto-pull published api-server image when local build is wr…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-04T10:27:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d0e0d1afc529c53779af0d57491080264b183d3",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.51.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-04T06:33:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df0a92cf4e6afc6b1c3531f9440326455cc9c1fa",
          "body": "Add `appliance cluster` (list/current/use/show/rm/path) — the user-facing\nview of the credential registry in ~/.appliance/profiles.json, framed as\nclusters to match the desktop. `cluster rm` forgets a cluster from this\ndevice without touching infrastructure (deliberately distinct from\n`appliance tea\n[…]\nrea, and documents the forget-vs-teardown split in\ncontrol-plane.md §5.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "feat(cli): forget clusters without teardown",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-04T06:24:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82232a445799c9a628bac64aae8f75ae57a8b567",
          "body": null,
          "is_bot": false,
          "headline": "fix(infra): update tsbuildinfo location",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-03T11:50:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11bc60417fa16e1f821e562297d6ab127d21c3b5",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.50.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-01T01:18:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6eb90c52483175564fad157f5d07d6ddaf0d1708",
          "body": "Collapse the sprawled desktop app into 5 owner-locked areas (Setup, Clusters, Projects, Agents, Settings), staged so each phase shipped green with old routes redirecting.\n\n- Delete the 2,429-line local-runtime kitchen-sink page + dead placeholder.tsx; disperse its surfaces by job (runtime mgmt/egres\n[…]\node reviewed. verify GREEN cache-busted (18 desktop parity + 153 Rust).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "Desktop app IA: collapse the sprawl into 5 clean areas (#57)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-07-01T01:15:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ffd81f22659398deadc13786ead75f173aeb461",
          "body": "…y-before-attach (#56)\n\nKill the agent cold-start tax via two levers (VM snapshots ruled out as egress-firewall-incompatible).\n\n- S1 agent-only VM mode: appliance-sbx skips k3s/dockerd; 'agent start' gates on the vsock shell + Node (not kubeconfig). Preserves guest-ip/the netstack lease (the broker \n[…]\n -> attach skips + npm self-heal until then); before/after boot timing.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "Fast agent spin-up: agent-only VM mode + prebuilt agent image + verif…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-30T11:47:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb340d82db365d38a5f9baa42f3801e615c49447",
          "body": "…nostic broker) (#55)\n\nAdds GitHub Copilot CLI + OpenAI Codex CLI beside Claude Code via the Phase-5 agent-agnostic adapter — zero Rust broker change (the scheme rides in print-key's output).\n\n- G0: generalize the adapter for N agents (provider/install/captureMode/scheme/login); print-key --type <ag\n[…]\ns + the Copilot direct-Bearer / Codex ChatGPT-OAuth follow-ups to come.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "Multi-agent adapters: GitHub Copilot CLI + OpenAI Codex CLI (agent-ag…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-30T09:06:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df01f832900268c0fdc0d96d7877cb4bd05f5167",
          "body": "…ss nits + live-test runbook (#54)\n\nPost-merge fast-follows for #51/#52/#53 + a live-test runbook. No behavior flip (egress default stays Nat).\n\n- A2a: close the broker pre-lease TOCTOU (gate brokered injection on the EXACT leased peer; was live on the NAT path, Netstack already closed by L2 isolati\n[…]\nt-flip (Fflip) remains a separate change gated on the live walkthrough.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "Agent-stack follow-ups: broker TOCTOU fix, login/desktop polish, egre…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-30T05:04:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dce60cc5a0c08bc2aee3617ec5b93bf0287e166c",
          "body": "…n via net_link=Netstack (#53)\n\nMakes microVM egress a host-enforced default-deny + allowlist boundary, opt-in via net_link=Netstack (default stays Nat — merging changes nothing for existing/new VMs).\n\n- F1: behavior-neutral host smoltcp netstack (NAT -> VZFileHandleNetworkDeviceAttachment + socketp\n[…]\n the boundary), code (Quinn), design (Devon), product-metrics (Parker).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "Guest egress firewall — host-enforced default-deny + allowlist, opt-i…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-30T02:42:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d2e59f2f47b5cb4a77d3e8f88b53913e77c0309d",
          "body": "…ker (#52)\n\nAdds interactive OAuth/subscription login ('Sign in with Claude') alongside the API key, brokered host-side so the credential never enters the VM.\n\n- L0: agent-agnostic auth-mode abstraction (docs/agent-login.md).\n- L1+L2: appliance agent login picker (API key | Sign in with Claude -> ho\n[…]\netrics (Parker).\nLive OAuth walkthrough + L1n/L3p follow-ups to follow.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "Interactive agent login — OAuth/subscription + API key, host-side bro…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-29T22:06:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "08a9e3e50c49b9dbb933ab805cca95cb3704de37",
          "body": null,
          "is_bot": false,
          "headline": "fix: detect and handle argv indexing",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-29T15:12:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b09cbaf6e86751abda0c9fd139eb90b756a5d290",
          "body": null,
          "is_bot": false,
          "headline": "feat: support for appliance cluster destruction",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-29T15:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1067f28983764532ffae973e0560f2e0261f1bb",
          "body": "…h a host-side credential broker (#51)\n\n* docs(agent-sandbox): architecture + host cred-broker design for Phase 5 agents\n\nA0 spike decision doc. Designs running Claude Code in the microVM sandbox: the\nagent runner (a reattachable tmux session as the non-root appliance user against\nthe VirtioFS works\n[…]\nack\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Phase 5: first-class agent sandboxes — Claude Code in the microVM wit…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-29T15:03:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34c195a54bfb6d03af1f91f345e3afa2a2f94573",
          "body": "…rol plane, reattachable shells, one-tap onboarding (#50)\n\nMakes the microVM the sole local runtime and control plane.\n\n- E1: delete bare k3d; the microVM is the default local runtime (BYO-k8s + cloud paths preserved).\n- E2: non-root `appliance` guest user for shells/agents/devcontainer (unblocks Cl\n[…]\n tracked follow-ups (E3.4a, E4.3a, E4.4a, E5.2a, E5.4, E2.5) to follow.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01J7nGXC2jYiDRhp7YJMviBR",
          "is_bot": false,
          "headline": "feat: Phase 4 — microVM default runtime, non-root guest, unified cont…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-29T04:47:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "15123a1b143a3b822ce78ebc286850507d7f3b39",
          "body": null,
          "is_bot": false,
          "headline": "fix: update package with tauri build scripts",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-28T08:36:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5841213572baf70ed7651f7e244450d73116966",
          "body": "Un-reds the verify gate; the underlying appliance doctor probe-hang is filed separately.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(cli): quarantine the hanging doctor port-probe test (#49)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-28T08:30:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "416c8c36f5debbc9125ea84032bd21b3dd923669",
          "body": "…#48)\n\nRun Dockerfile / docker-compose / devcontainer projects in a microVM via\nappliance up/down/logs/status/shell, on an in-guest Docker engine. Includes\nvsock exit-code propagation, guest clock-sync + widened signature tolerance\n(fixes the desktop/CLI 401), and a pnpm verify green bar + CI. See #48.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: microVM container sandbox — appliance up + clock-sync 401 fix (…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-28T08:20:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b00b9acce3013608af81183f8c2407b21cdb5987",
          "body": "…m cluster ready (#47)\n\nBooting a microVM is multi-stage and the slow stages (first-boot image\npulls, k3s electing itself) were invisible: `appliance vm up` printed\nbare dots and, on timeout, dumped a raw host-log tail; the desktop badge\nread \"running\" the instant the host process was alive — even w\n[…]\ncached in the shared\n`~/.appliance/vm/images` dir (no-op when present), so retries don't\nre-fetch; the new `media` phase makes that observable.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): surface microVM bring-up phases; distinguish VM running fro…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-26T10:14:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5169ce1099895283225a081eb153211bfc9f862e",
          "body": "… missing\n\nThe self-heal in the dev-up path only installed appliance-vm into\n~/.appliance/bin when it was absent, so a leftover older install was used\nas-is — and since the engine reports a fixed --version, nothing detected\nthat it predated flags like --dev. The bundled CLI the desktop spawns\nresolv\n[…]\nndle (microvm_install re-signs identically, so an up-to-date install\nis byte-equal). A freshly bundled engine now always wins over a stale one.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(desktop): refresh the managed microVM engine when stale, not just…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-20T13:27:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a6554726c7c30923f42b8c9a032080d993f026c",
          "body": "Replace the kubectl-debug shell with a vsock channel: every VM runs a\nsocat PTY login-shell agent on a fixed vsock port, the resident host\nprocess bridges a per-VM Unix socket to a fresh guest connection, and\n`appliance-vm shell` drives that socket in raw mode. No SSH, no TCP\nexposure, no dependency\n[…]\nhell too (no more debugger pods)\n\nVerified end-to-end: an interactive root shell over vsock landing in\n/persist/workspace, with k3s uninvolved.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: k3s-independent shell over vsock",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-20T08:09:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f77d4969b58e1923bcd3ce1b798e8a164eb77ad9",
          "body": "Add `appliance vm dev up --mount <path>` (desktop: \"Share a folder…\"):\nthe host folder is presented to the guest over VirtioFS and mounted at\n/persist/workspace — edit on the host, run in the VM.\n\n- spec: persisted `dev_mount` on VmSpec; `--mount`/`--no-mount` on the\n  engine up/create (resolved + v\n[…]\n-to-end: host edits appear in the guest and guest writes\nappear on the host; the share persists across stop/restart and clears\nwith --no-mount.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: share a host folder into the dev microVM over VirtioFS",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-20T07:46:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8573c0041e81fce4e5308c20c1d4099c050c77bf",
          "body": "Make a microVM usable as an isolated development environment — the VM\nhost itself, provisioned to work in, not just to deploy into.\n\nEngine:\n- one-way `dev` flag on VmSpec (persisted in vm.json, surfaced in\n  status/list), threaded through `up`/`create` as `--dev`\n- guest bootstrap creates a persist\n[…]\n-to-end: dev provisioning installs the toolchain, a login\nshell lands in /persist/workspace, and the workspace + dev flag survive\nstop/restart.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: dev environments and shell inside microVMs",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-20T06:56:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd8561e884af78d8b0170ec63fc05959cb36e7a7",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.49.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-17T11:29:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da0d36158548e2c95d338cccaa6b42045badee12",
          "body": "* fix(cli): vm up falls back to pulling the published api-server image\n\nWhen no local appliance-api-server image matches and no --image is\npassed, pull the pinned ghcr.io/appliance-sh/api-server:<VERSION> (the\nsame ref the cloud bootstrap uses) before erroring, so a fresh machine\nboots a microVM wit\n[…]\n-process\nfile lock) and the cross-process concurrency gap on `config_lock`.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: microvm fleet lifecycle (#45)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-17T11:27:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a39d9a96f2c524a798833d7ef1096eaed7f4ac2c",
          "body": "* fix: align workspace deps for clean builds\n\n- sdk: add missing `typescript` devDependency (5.9.3). The build runs\n  `tsc` but never declared it, so a clean checkout failed at the first\n  build step (CI masked this via the nx remote cache).\n- desktop: bump `@tauri-apps/api` ^2.1.1 -> ^2.11.0 so it \n[…]\nre the signer into tauri:build.\n- README: document the one-time cert setup.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: dev env and microvm ux (#44)",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-15T22:14:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "11ff072ceb0794433f012cb8c2c47d1edea441a4",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.48.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-13T13:15:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d7bf25233d8b139323741e8082227ed64e16b7e",
          "body": null,
          "is_bot": false,
          "headline": "feat: improve micro vm cluster switcher and interface",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-13T06:04:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "759ed6169329bc27bb404d7485b3f6245d84d6f9",
          "body": "The dashboard get-started and the bootstrap wizard only offered the k3d\nlocal runtime, so the microVM was invisible until a user found the\nRuntimes page. Add a microVM as a peer onboarding option: a \"Start a\nmicroVM\" dashboard card and a third mode in the bootstrap mode picker\n(`?mode=microvm`), wit\n[…]\n).up()`\n— self-installing the engine binary, bootstrapping the api-server, and\nregistering the cluster — landing the user on a working cluster.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): offer the microVM engine in first-run onboarding",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-13T01:08:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "917ea5a4891ea86d375c0dc862c88b6b0d855fbf",
          "body": "The Runtimes page treated the k3d runtime as the primary engine (bare\ncontrols + rich overview) and relegated microVMs to a \"beta\" sub-section\nof cards. Now every engine — the k3d runtime and each microVM — renders\nin one shared EngineCard under a single \"Engines\" list: same header\n(name + engine ta\n[…]\nance facts row\n(Kubernetes URL, cluster id, allocated ports) for parity with the k3d\noverview, and equalizes the deploy wizard's engine badges.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(desktop): present microVMs as first-class engines, not beta add-ons",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T13:53:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6854f1b0b54e88a7f14d3198dcb1f252e0893380",
          "body": "Add a Multiple VMs section to the vm README and ARCHITECTURE-style\nmicrovm.md: per-VM port allocation (default keeps 8081/6443/5052/5053,\nothers get a block from 8100), per-VM credentials profiles, and\n`appliance vm list`.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(vm): document running multiple microVMs concurrently",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T10:31:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c72846af5c091cbc377baf0b6559b341c3649957",
          "body": "The desktop now lists every defined VM and renders a panel per VM with\nits own lifecycle, egress policy, credentials, and workloads — so one VM\ncan serve interactive development while another tests traffic. Every\nmicrovm_* command takes a VM name (defaulting to the canonical\n\"appliance\" VM); cluster\n[…]\nVM\" control names a VM whose panel's Start boots it. Adds a microvm_list\ncommand and threads the VM name through the host bridge and mock-host.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): manage multiple microVMs, each as its own cluster",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T10:30:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0530dc2eb5b469f419639d67c67adfcee426437f",
          "body": "`vm up` now reads the VM's allocated ports from its spec (ingress, api,\nregistry, egress) instead of assuming the canonical block, so a non-\ndefault VM boots, bootstraps its api-server, and registers credentials\non its own ports. Each VM gets its own profile (the default keeps\n`microvm`; others get `microvm-<name>`) so multiple runtimes coexist\nwithout clobbering credentials. Adds `appliance vm list` (table + --json).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): thread per-VM ports and profiles through `appliance vm`",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T09:57:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "485ca2adab4b587f6f69815859e284030f2ae75d",
          "body": "Each VM now persists its own egress port and gets a non-colliding block\nof four host ports (ingress/api/registry/egress) at create. The default\n\"appliance\" VM keeps the canonical 8081/6443/5052/5053; additional VMs\nget the lowest free contiguous block from 8100. Adds `vm list` and ports\nin `vm status` so callers can discover where each VM is reachable.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): per-VM port allocation so multiple microVMs run concurrently",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T09:51:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "78ecb29a2a3b4efef9f1ce71db5f516923d3d2cc",
          "body": "Give the egress traffic feed a live-monitor feel — each row now shows\nhow long ago the request was seen.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "polish(desktop): show relative time per traffic row",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T09:21:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "df9f3f314f477cf09f5284095d888b4cfa451113",
          "body": "Cover the live traffic feed (egress log + desktop allow/block) and the\nper-host credential capture/injection (apiKeyHelper) in docs/microvm.md\nand the package README.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(microvm): document egress traffic view + credential injection",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T09:19:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6b0f82c8d944cb66bd69a32f0979adb92eaf48c7",
          "body": "Add a Credentials panel to the Runtimes microVM section: per-host rules\n(capture / inject / header / apiKeyHelper command) with add + remove,\nand a masked list of stored secrets with a Forget-all control. Warns\nwhen TLS interception is off (capture/injection need it). Wires\n`microvm_creds_list|add|r\n[…]\n Tauri commands (driving\n`appliance-vm creds`), the CredentialRule/StoredSecret/CredentialsState\ntypes + host bindings, and mock-host fixtures.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): credential capture/injection config UI",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T09:13:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "967317f18a5225a2c6299f2612c29b302bb40442",
          "body": "Borrowing the apiKeyHelper idea: with TLS interception on, the proxy\ncan, per host, capture a credential header off requests into a\nhost-side secret store (outside the VM, 0600) and/or inject it onto\noutbound requests — so workloads need never hold the secret. Injection\nsources the value from the st\n[…]\ny: a request's auth\nwas captured, and a later request with no auth had the stored\ncredential injected (upstream received it). 35 vm tests pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): per-host credential capture + injection in the MITM proxy",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T09:01:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "32280e24bfdb9ec6171a9a7dfc8a18ec72d1ef35",
          "body": "Surface the proxy's recorded traffic in the Runtimes microVM panel: a\nDocker-Desktop-style live feed of recent requests (allow/deny/mitm-\ntagged, with method + host + path), polled every 4s. Each row offers\none-click Allow or Block that updates the policy live; rows already\ncovered by a rule show th\n[…]\nving `appliance-vm egress log`), the EgressEvent type + host\nbindings, mock-host sample data, and an `appliance vm egress log` CLI\npassthrough.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(desktop): live egress traffic view with per-host allow/block",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T08:50:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0910abb9233a75980c1e6911c31f926a319f0f8a",
          "body": "The proxy now logs one JSON event per request decision (host, port,\nmethod, path, allow|deny|mitm) to a bounded JSONL log under the VM\nstate dir, and `appliance-vm egress log [--tail N] [--clear]` reads it.\nThis is the data feed for a Docker-Desktop-style live traffic view\nwhere each host can be all\n[…]\n records the\nreal method + path; blind CONNECT records host only.\n\n3 unit tests + live-verified (allow/deny events captured through the\nproxy).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): record egress traffic for the desktop view",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T08:40:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4a20709c46e7e08f13f3dc59a723092879e4870c",
          "body": "The microVM is adopted as a selectable cluster by sync_microvm_cluster,\nwhich also runs on a passive `microvm_status` poll — e.g. when the VM\nwas started from the CLI or came up after the desktop launched. Only\nthe desktop-driven start/delete paths invalidated the host-config\nquery, so in those pass\n[…]\nInvalidate\n['host','config'] once per ready transition so the freshly-registered\nMicroVM Runtime cluster becomes selectable without restarting.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(desktop): refresh cluster list when the microVM registers",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T01:52:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b90ed3ddb5e4d04da90f4d2be85880063cf5dfdb",
          "body": "Replace the \"remaining productization\" note now that the api-server\nauto-injects proxy + CA into workloads from the host-published\nConfigMap.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(microvm): document automatic egress injection into workloads",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T00:33:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2119afb53fd80e686d0f253518716ffb32833b06",
          "body": "Bake the per-VM egress CA into the guest boot media\n(usr/local/share/ca-certificates/appliance-egress.crt) and run\nupdate-ca-certificates in the boot bootstrap, so node-side tooling\n(containerd, host curl) trusts the interception proxy. The CA is\ngenerated on demand during boot-media assembly and em\n[…]\ner's CA mount.\n\n3 new unit tests over the apkovl assembly (CA embedded + round-trips;\nomitted when absent). Takes effect on the VM's next boot.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): trust the egress CA in the guest system store",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T00:33:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "362170696caa4663f55690b3e8756bbbf0a68630",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.47.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T00:23:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95b5d50900ffd30487154e6e17d514a9a75d0cfc",
          "body": "The host now mirrors the egress policy into the cluster as the\n`appliance-egress` ConfigMap (proxy URL on the VM gateway, a NO_PROXY\nthat bypasses cluster-internal destinations, the mitm flag, and the CA\nPEM when interception is on). The api-server reads it to confine\nworkloads; together this closes\n[…]\ne: deny rule → ConfigMap\n  present with proxyUrl/CA; reset → ConfigMap removed. 4 new unit tests\n  (configmap rendering); 11 egress tests pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): publish egress policy to the cluster for api-server injection",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T00:18:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "452aaff570007e7059b9d3052768604989e3f278",
          "body": "When the host publishes an `appliance-egress` ConfigMap (proxy URL,\nNO_PROXY, mitm flag, CA), the deployment executor reflects it into\nevery workload's pod spec so the desktop's outbound-traffic policy\napplies without per-deploy wiring:\n\n- HTTP(S)_PROXY + NO_PROXY env (both casings; egress wins over\n[…]\nuilt — the proxy\nstill enforces allow/deny either way. renderManifest gains an optional\n`egress` param; 5 new unit tests (23 infra tests pass).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(api-server): inject egress proxy + CA into local workloads",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-12T00:08:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e796cb909ef2f0e201307162a8de4fe01dddcb50",
          "body": "…ption\n\nConnect & shell:\n- `appliance vm exec/shell` and `appliance local exec/shell` (kubectl\n  exec -it / docker exec; `vm shell` uses `kubectl debug node` + chroot)\n- desktop PTY terminal: terminal.rs (portable-pty) + Tauri\n  open/write/resize/close commands + an xterm.js \"Shell\" button on\n  runn\n[…]\n trusted the proxy\ndecrypts its HTTPS while the workload still gets a valid 200. 23 vm\nRust tests + 80 TS tests; both Rust crates clippy-clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(vm): shell into local runtimes + egress control with TLS interce…",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-11T23:37:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5b9f45bce900f809cd45676d8c89ddbcb0849d41",
          "body": null,
          "is_bot": false,
          "headline": "fix(desktop): local runtime improvements",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-11T16:00:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a675280def9b4c100cd07a7e5f99e33d4bf21aff",
          "body": null,
          "is_bot": false,
          "headline": "feat(desktop): build and copy vm image",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-11T14:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58c93944e9849011acd37c90efafe07372aef440",
          "body": null,
          "is_bot": false,
          "headline": "feat(vm): improve installation experience",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-11T14:11:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9eb457207c39f7d3021147c7797238d12d19f48",
          "body": null,
          "is_bot": false,
          "headline": "feat(vm): improve installation experience",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-11T14:09:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6045d416986a8b7ec7d27b6dad0653c320590c8",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): publish 1.46.0",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-11T13:16:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "169af3688b2d79fe0785c8b38b6c9933922dcbf0",
          "body": null,
          "is_bot": false,
          "headline": "feat: ui improvements",
          "author_name": "Eliot Lim",
          "author_login": "eliotlim",
          "committed_at": "2026-06-10T23:44:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 82,
      "commits_last_year": 312,
      "latest_release_at": "2026-07-20T14:57:19Z",
      "latest_release_tag": "v1.53.2",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 29,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 4.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@appliance.sh/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@appliance.sh/cli",
          "is_deprecated": false,
          "latest_version": "1.53.2",
          "repository_url": "https://github.com/appliance-sh/appliance.sh",
          "versions_count": 70,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2314,
          "first_published_at": "2025-12-15T15:02:47.659000Z",
          "latest_published_at": "2026-07-20T14:57:30.241000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@appliance.sh/sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@appliance.sh/sdk",
          "is_deprecated": false,
          "latest_version": "1.53.2",
          "repository_url": "https://github.com/appliance-sh/appliance.sh",
          "versions_count": 71,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1845,
          "first_published_at": "2025-12-15T15:02:41.851000Z",
          "latest_published_at": "2026-07-20T14:57:24.847000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "appliance.sh",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/appliance.sh",
          "is_deprecated": false,
          "latest_version": "1.53.2",
          "repository_url": "https://github.com/appliance-sh/appliance.sh",
          "versions_count": 47,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1746,
          "first_published_at": "2026-04-02T11:51:44.045000Z",
          "latest_published_at": "2026-07-20T14:57:35.587000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/api-server/tsconfig.json",
        "packages/app/tsconfig.json",
        "packages/bootstrap/tsconfig.json",
        "packages/cli/tsconfig.json",
        "packages/console/tsconfig.json",
        "packages/desktop/sidecar/tsconfig.json",
        "packages/desktop/tsconfig.json",
        "packages/helper/tsconfig.json",
        "packages/infra/tsconfig.json",
        "packages/install-aws/tsconfig.json",
        "packages/sdk/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "packages/desktop/src-tauri/Cargo.toml",
        "packages/vm/Cargo.toml"
      ],
      "largest_source_bytes": 240157,
      "source_files_sampled": 378,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 1,
        "malicious_count": 0,
        "assessed_package": "npm:appliance.sh@1.53.2",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@appliance.sh/infra",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@appliance.sh/sdk",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@aws-sdk/client-ecr",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1005.0"
        },
        {
          "name": "@aws-sdk/client-s3",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.750.0"
        },
        {
          "name": "@aws-sdk/s3-request-presigner",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1009.0"
        },
        {
          "name": "cors",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.5"
        },
        {
          "name": "express",
          "manifest": "packages/api-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "@appliance.sh/sdk",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@fontsource-variable/geist",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.9"
        },
        {
          "name": "@fontsource-variable/geist-mono",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.8"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@tanstack/react-query",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.60.0"
        },
        {
          "name": "@xterm/addon-fit",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.11.0"
        },
        {
          "name": "@xterm/xterm",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "buffer",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.3"
        },
        {
          "name": "class-variance-authority",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "lucide-react",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.468.0"
        },
        {
          "name": "react-router",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.2"
        },
        {
          "name": "tailwind-merge",
          "manifest": "packages/app/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.5.5"
        },
        {
          "name": "@appliance.sh/cli",
          "manifest": "packages/appliance.sh/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@appliance.sh/infra",
          "manifest": "packages/bootstrap/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@appliance.sh/sdk",
          "manifest": "packages/bootstrap/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@aws-sdk/client-ecr",
          "manifest": "packages/bootstrap/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1005.0"
        },
        {
          "name": "@aws-sdk/credential-providers",
          "manifest": "packages/bootstrap/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1044.0"
        },
        {
          "name": "@pulumi/pulumi",
          "manifest": "packages/bootstrap/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.216.0"
        },
        {
          "name": "@appliance.sh/app",
          "manifest": "packages/console/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "react",
          "manifest": "packages/console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "react-dom",
          "manifest": "packages/console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "@appliance.sh/app",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@appliance.sh/bootstrap",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@appliance.sh/helper",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@tauri-apps/api",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.11.0"
        },
        {
          "name": "@tauri-apps/plugin-dialog",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@tauri-apps/plugin-notification",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@tauri-apps/plugin-process",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@tauri-apps/plugin-shell",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@tauri-apps/plugin-updater",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "react",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "react-dom",
          "manifest": "packages/desktop/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.0.0"
        },
        {
          "name": "undici",
          "manifest": "packages/helper/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.7.0"
        },
        {
          "name": "@appliance.sh/sdk",
          "manifest": "packages/infra/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@kubernetes/client-node",
          "manifest": "packages/infra/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.0"
        },
        {
          "name": "@pulumi/aws",
          "manifest": "packages/infra/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.16.0"
        },
        {
          "name": "@pulumi/aws-native",
          "manifest": "packages/infra/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.48.0"
        },
        {
          "name": "@pulumi/awsx",
          "manifest": "packages/infra/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1.0"
        },
        {
          "name": "@pulumi/pulumi",
          "manifest": "packages/infra/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.216.0"
        },
        {
          "name": "@appliance.sh/sdk",
          "manifest": "packages/install-aws/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@aws-sdk/client-cloudfront",
          "manifest": "packages/install-aws/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.955.0"
        },
        {
          "name": "aws-cdk",
          "manifest": "packages/install-aws/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1033.0"
        },
        {
          "name": "aws-cdk-lib",
          "manifest": "packages/install-aws/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.230.0"
        },
        {
          "name": "constructs",
          "manifest": "packages/install-aws/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.4.3"
        },
        {
          "name": "http-message-signatures",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.4"
        },
        {
          "name": "uuidv7",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.0"
        },
        {
          "name": "zod",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.13"
        },
        {
          "name": "zod-to-ts",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.0"
        },
        {
          "name": "anyhow",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "clap",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "serde",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "libc",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "ureq",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "ring",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "flate2",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "fatfs",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "tar",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "fscommon",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "rcgen",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "rustls",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "webpki-roots",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26"
        },
        {
          "name": "smoltcp",
          "manifest": "packages/vm/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 64,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "eliotlim",
          "commits": 335,
          "avatar_url": "https://avatars.githubusercontent.com/u/710625?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "pr.yml",
        "release-agent-image.yml",
        "release-api-server-image.yml",
        "release-cli-binaries.yml",
        "release-desktop.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "package-lock.json",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "6 out of 8 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "114 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "28a9c2a1e69e62dba167c7eaa99a7654ac7a518e",
        "ran_at": "2026-07-27T01:34:02Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T14:25:58Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-17T12:50:06Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/appliance-sh/appliance.sh",
    "host": "github.com",
    "name": "appliance.sh",
    "owner": "appliance-sh"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 60,
      "inputs": {
        "security": 48,
        "vitality": 86,
        "community": 34,
        "governance": 49,
        "engineering": 79
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 86,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "commits_last_year": 312,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 29
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "29/52 weeks with commits",
                "points": 20.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 29
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "312 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 312
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 82,
              "latest_release_tag": "v1.53.2",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 4.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "82 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 82
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 34,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "packages": [
                "@appliance.sh/cli",
                "@appliance.sh/sdk",
                "appliance.sh"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 5905
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,905 downloads/month across npm",
                "points": 50.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5905,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "merged_prs": 64,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "64/65 decided PRs merged",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 64,
                      "decided": 65
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "appliance-sh",
              "public_repos": 1,
              "account_age_days": 425
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of appliance-sh",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "appliance-sh"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "1 public repos, account ~1 yr old",
                "points": 4.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 1
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@appliance.sh/cli",
                "@appliance.sh/sdk",
                "appliance.sh"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "3 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 3,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "71 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 71
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 79,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "6 out of 8 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://www.appliance.sh",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.appliance.sh",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "6 out of 8 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "114 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:appliance.sh@1.53.2 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:appliance.sh@1.53.2",
                  "assessed": 1
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 1,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 1,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 67,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "package-lock.json",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/api-server/tsconfig.json",
                "packages/app/tsconfig.json",
                "packages/bootstrap/tsconfig.json",
                "packages/cli/tsconfig.json",
                "packages/console/tsconfig.json",
                "packages/desktop/sidecar/tsconfig.json",
                "packages/desktop/tsconfig.json",
                "packages/helper/tsconfig.json",
                "packages/infra/tsconfig.json",
                "packages/install-aws/tsconfig.json",
                "packages/sdk/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.65,
              "toolchain_manifests": [
                "packages/desktop/src-tauri/Cargo.toml",
                "packages/vm/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "packages/desktop/src-tauri/Cargo.toml, packages/vm/Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "packages/desktop/src-tauri/Cargo.toml, packages/vm/Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/api-server/tsconfig.json, packages/app/tsconfig.json, packages/bootstrap/tsconfig.json, packages/cli/tsconfig.json, packages/console/tsconfig.json, packages/desktop/sidecar/tsconfig.json, packages/desktop/tsconfig.json, packages/helper/tsconfig.json, packages/infra/tsconfig.json, packages/install-aws/tsconfig.json, packages/sdk/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/api-server/tsconfig.json, packages/app/tsconfig.json, packages/bootstrap/tsconfig.json, packages/cli/tsconfig.json, packages/console/tsconfig.json, packages/desktop/sidecar/tsconfig.json, packages/desktop/tsconfig.json, packages/helper/tsconfig.json, packages/infra/tsconfig.json, packages/install-aws/tsconfig.json, packages/sdk/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "65 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 65,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 240157,
              "source_files_sampled": 378,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/378 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 378,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'appliance-vm' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T01:34:12.927696Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/appliance-sh/appliance.sh.svg",
  "full_name": "appliance-sh/appliance.sh",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.