Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 07:37 UTC

basecradle / basecradle-python

The official Python SDK for BaseCradle — a communications platform where humans and AI are equal peers.

PythonMIT★ 0 stars⑂ 0 forkssince Jun 2026View on GitHub ↗

basecradle/basecradle-python holds a health index of 58 out of 100, placing it in the Moderate band. It scores highest on AI Readiness (73/100) and lowest on Community & Adoption (33/100). It was last updated today. A single contributor accounts for most of its recent work.

58
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

58
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

BaseCradleOrganization
3 followers5 public repossince Dec 2025

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
PyPIbasecradle0.8.03,44189 days agoagentsaiapibasecradlesdk

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

70Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
5.5/36Commit cadence — 8/52 weeks with commits
16.2/18Commit volume — 63 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year63
human_commit_share0.412
days_since_last_push0
active_weeks_last_year8
How it's scored
16.2/27Ships releases — 8 version tags (no GitHub releases)
36/36Release recency — latest release 9 days ago
27/27Release cadence — a release every ~6.4 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count8
latest_release_tagv0.8.0
releases_from_tagsyes
days_since_latest_release9
mean_days_between_releases6.4
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

33At risk · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
47.2/80Monthly downloads — 3,441 downloads/month across pypi
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesbasecradle
dependents
ecosystemspypi
total_downloads
monthly_downloads3,441
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

55Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
46/46.8Issue resolution — 98% of issues closed
37.7/38.3PR acceptance — 67/68 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/27 approved changesets -- score normalized to 0
Inputs used
merged_prs67
open_issues1
closed_issues60
issue_closed_ratio0.984
closed_unmerged_prs1
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
4.3/25Owner reach — 3 followers of basecradle
6.8/25Track record — 5 public repos, account ~0 yr old
Inputs used
followers3
owner_typeOrganization
is_verified
owner_loginbasecradle
public_repos5
account_age_days214
How it's scored
25/25Published & resolvable — 1 package(s) on pypi
35/35Publish recency — latest publish 9 days ago
20/20Version history — 8 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesbasecradle
ecosystemspypi
any_deprecatedno
min_days_since_publish9

Engineering Quality

Are baseline engineering and documentation practices in place?

67Moderate · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://basecradle.com/docs/api
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://basecradle.com/docs/api
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

64Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/27 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.5
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages6
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the pypi:basecradle@0.8.0 runtime dependency closure — what installing the published package pulls in — 6 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

73Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 28 of 28 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes32,351
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — src/basecradle/py.typed
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 26 of the last 68 commits agent-authored or agent-credited
8/8Automated maintenance — 3 of the last 68 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesuv.lock
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configssrc/basecradle/py.typed
agent_commit_share0.382
toolchain_manifests
dependency_bot_commit_share0.044
How it's scored
27/45Type-checkable code — Python with type-check config (src/basecradle/py.typed)
55/55Manageable file sizes — 0/31 source files over 60KB
Inputs used
primary_languagePython
largest_source_bytes17,407
source_files_sampled31
oversized_source_files0

Key facts

0GitHub stars
1contributors
63commits, last 12 months
0days since last push
8releases
1bus factor
1open issues
PyPIpackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 5.5 / 10
5.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 07:37 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/27 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
PyPIhttpx>=0.28pyproject.toml
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 0

Installing pypi:basecradle@0.8.0 pulls in 6 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 237,
      "has_wiki": true,
      "homepage": "https://basecradle.com/docs/api",
      "languages": {
        "Python": 237529
      },
      "pushed_at": "2026-07-27T01:31:44Z",
      "created_at": "2026-06-02T23:09:50Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-27T01:31:47Z",
      "description": "The official Python SDK for BaseCradle — a communications platform where humans and AI are equal peers.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://basecradle.com",
      "name": "BaseCradle",
      "type": "Organization",
      "login": "basecradle",
      "company": null,
      "location": "United States of America",
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/251400768?v=4",
      "created_at": "2025-12-25T01:37:07Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 214
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-17T23:54:02Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-17T09:05:42Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-14T02:23:06Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-06-13T04:17:19Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-06-10T22:32:58Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-06-03T07:04:57Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-06-03T05:13:06Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-06-03T04:43:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "de53849411bcf878f359516a1922fe256dbb31f5",
          "body": "Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.1.0 to 9.0.0.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/v8.1.0...v9.0.0)\n\n---\nupdated-dependencies:\n- dependency-name: astral-sh/setup-uv\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump astral-sh/setup-uv from 8.1.0 to 9.0.0 (#125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-27T01:31:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a39a793a7285bc65581bf0be3ed408cb99001fae",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nbot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: basecradle-ai[bot] <290973438+basecradle-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 6 to 7 (#124)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-27T01:19:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2447318050e862a133a6d63118c2e2bb89db9edf",
          "body": "…defaults (#129)\n\nRuff 0.16 expands the default rule set from 59 to 413 and begins formatting\nPython code blocks inside Markdown. This adopts 0.16 under this repo's\nconventions — keeping the expanded lint net for future code while preserving\nthe deliberate patterns the new rules would otherwise flag\n[…]\nf check .` and `ruff format --check .` both green on 0.16.0; 359 tests pass.\n\nSupersedes #127.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Adopt ruff 0.16 (Dependabot #127): green lint under the new 413-rule …",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-27T00:40:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "867a3950f2b3d1eaf2a656db99b6f38eba6742fe",
          "body": "Bumps [pytest](https://github.com/pytest-dev/pytest) from 9.0.3 to 9.1.1.\n- [Release notes](https://github.com/pytest-dev/pytest/releases)\n- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)\n- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.3...9.1.1)\n\n---\nupdated-\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pytest from 9.0.3 to 9.1.1 (#126)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-27T00:03:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f941d88e3a433897e5c496b5658a3cce54e78a9e",
          "body": "…ared-block re-sync (#123)\n\nAdopt the fleet Dependabot program (capital basecradle/basecradle#454, design\nbasecradle/basecradle#452):\n\n- Add .github/workflows/dependabot-auto-merge.yml — the sixth verbatim-shared\n  artifact (thin stub; merge policy lives in the reusable workflow in\n  basecradle/.git\n[…]\ntal main, block/whole-file diff-verified identical.\n\nHandoff: basecradle/basecradle-python#122\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Fleet Dependabot program: dependabot.yml + sixth shared artifact + sh…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-27T00:02:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dedbd2b750bd631249ac7ed880f3a435ca7ff27",
          "body": "…#121)\n\nCapital PR basecradle/basecradle#451 amended the Cross-Repo Handoffs\nCLAUDE.md block and the cross-repo-handoffs skill: the shared-artifact\nset now officially numbers five (the needs-human phone-alert stub joined\nthe Propagation enumeration) and per-artifact carrier sets are documented.\n\nByt\n[…]\nMechanical propagation, self-review-exempt.\n\nRe-sync handoff: basecradle/basecradle-python#120\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync shared artifacts: propagation now enumerates five artifacts (…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-25T22:47:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53764a489976a4b55039af293d4c1a2c4fe0326e",
          "body": "Byte-identical to the capital canonical (basecradle/basecradle\n.github/workflows/needs-human-alert.yml). On the needs-human label,\ncalls the reusable workflow in basecradle/.github, inheriting the\norg-level NTFY_TOKEN secret to push a priority alert to the founder's\nphone. Mechanical re-sync: the byte-match against the canonical is the\nreview.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Add fleet needs-human phone-alert stub workflow (ntfy push) (#118)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-25T00:53:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0c69898a626dadc79984d2c989cc252f9f16169",
          "body": "The spec-fetch temp file (a live copy of the OpenAPI spec, pulled while\ncovering DELETE /session) was accidentally swept into #114 by a broad\n`git add -A`. It is not a source artifact — remove it from the tree and\nignore `*.tmp` so a scratch spec fetch can never be committed again.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Remove stray .api.yaml.tmp; gitignore *.tmp (#116)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-17T23:54:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aecdabec39f02559e96687b1cc4543c868ea3c2a",
          "body": "… parity) (#114)\n\n* Add Task cancellation: task.cancel() (POST /tasks/{uuid}/cancellation) — API parity\n\nWithdraw a pending task before it activates. Mirrors the platform's new\ncancellation endpoint (basecradle/basecradle#437):\n\n- task.cancel() verb on the shared Task model — dispatches sync/async v\n[…]\nnesty. README + CHANGELOG (same 0.8.0).\n\nPart of the basecradle-python#113 handoff.\n\n---------\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Add task.cancel() + bc.sign_out() — task cancellation & sign-out (API…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-17T23:52:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3646ed95ed861b38c32db570fed01acd58529d50",
          "body": "Tracks the platform's per-user pending-task cap (basecradle/basecradle#434):\nthe User subject form gained max_pending_tasks, the per-timeline cap on pending\ntasks (default 3). Added to the trusted-peer cluster alongside max_timelines /\nmax_participants, with fixtures (conftest, DIRECTORY_FORM), wire\n[…]\n0.7.0, and version bump. Lockstep parity with the sibling SDK.\n\nHandoff basecradle-python#111.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Add User.max_pending_tasks (trusted-peer cluster) — API parity (#112)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-17T09:05:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a632a99e0d51d079be88489748f444ab2773563",
          "body": "…om it (#110)\n\nAdd to CLAUDE.md (Where to Start) the two procedural rules from\nconstitution.md -> How We Build (capital PR #423): \"do it now\" means\nin-session not this-instant with a strict two-reason filing test, and\nfinishing an issue includes the sub-issues it spawned plus a pre-stop\nsweep -- an arc that ends more-open-than-closed is not done.\n\nHandoff basecradle/basecradle-python#109.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Carry fleet law: an issue is a commitment to work, never an escape fr…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-14T06:50:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e4a4af606238bf6fef438c7e31122f62979ef49",
          "body": "…four creates, opt-in keyed retry (#108)\n\nTracks the platform's idempotent creates (basecradle/basecradle#328, shipped in basecradle/basecradle#421). Per-request headers on request(); idempotency_key on the four creates (sync+async); opt-in max_retries with connection/timeout retry for GETs and keyed creates only; README + CHANGELOG 0.6.0. Handoff #107 closed by hand after live verification.",
          "is_bot": true,
          "headline": "Idempotency-Key support: per-request headers, idempotency_key on the …",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-14T02:23:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce1af741d1501f6c3c574df16a1fc53a762d14c0",
          "body": "Fleet decision (founder 2026-07-08; spec basecradle-noc#185): agent homes\non the fleet server carry a swept ~/scratch and a durable ~/workspace.\nAdds a CLAUDE.md section covering both folders, the 3-day scratch sweep,\nthe ~/workspace INDEX.md discipline, and preferring these over shared\ntimeline Assets for anything private.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Document ~/scratch and ~/workspace agent home storage in charter (#106)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-08T23:48:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d3b91351fedbc7aeae94f394017c010dff1877c",
          "body": "…Part B) (#104)\n\nPart B of #102 — relocate step-by-step procedure out of the always-loaded\ncharter into on-demand skills, keeping invariants/gotchas/decision rules loaded.\n\n- New skill release-to-pypi: the 7-step tag→TestPyPI→gate→verify→close\n  procedure + version-wiring notes. Charter keeps: capta\n[…]\nin a\nskill; each section leaves a pointer at the point of need.\nCLAUDE.md 32868 → 29329 bytes.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Slim charter into skills: extract release + bot-auth procedure (#102 …",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-03T22:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9beaffab3734da88ef8cd717a3fc62a3f9bf50ee",
          "body": "…ll (basecradle#399) (#103)\n\nPart A of #102: replace the three verbatim-shared CLAUDE.md blocks\n(Cross-Repo Handoffs, Polling GitHub, Attended-Session Lifecycle Signal)\nwith the capital's slimmed canonicals from basecradle/basecradle#399, and\nadd the cross-repo-handoffs skill as the fourth verbatim-\n[…]\nhared artifact.\n\nAll four artifacts verified byte-identical to the capital canonical via diff.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync shared law to capital canonical + add cross-repo-handoffs ski…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-03T22:08:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20157256a82abc35a7f742f9f5d9cf98f6971fe0",
          "body": "… (#101)\n\nTask 1: re-sync the verbatim-shared `## Cross-Repo Handoffs` block to\ncapital main (byte-identical). Task 2: adopt the guarded local branch\ndeletion (git branch -d → verify containment → -D). Task 3: qualify the\nclosing-keyword convention line (ordinary in-repo issues only, not\nhandoff/gat\n[…]\nhon#100 — closed by hand after live\nbyte-verification (CLOSER: me), not via a closing keyword.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block + 2026-07-03 audit congruence fixes…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-03T20:56:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a072de490ea96d5d16f6268ae7b44690b1a5daa6",
          "body": "…grace (basecradle#391) (#99)\n\nVerbatim re-sync of the shared Cross-Repo Handoffs block to the capital\ncanonical. One sentence changed in Propagating this procedure: the\ndrift-guard now byte-diffs every 15 min with a ~30 min persistence grace,\nsurfacing a missed propagation in ~30-45 min. Byte-matches canonical (0 lines).\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block: drift-guard wording → persistence-…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-02T01:37:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "794257cf316bbc434e023e69e1d07fad9315846e",
          "body": "…secradle#384) (#97)\n\nAppends the governance pointer sentence to the universal-identity-rule\nbullet in the Naming subsection, byte-matching the capital canonical.\n\nRefs basecradle-python#96\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block: adopt Who This Governs pointer (ba…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-01T20:19:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34df9c6158c03328a1a57dc1b02c11eebdba4271",
          "body": "Byte-verified re-sync of the verbatim-shared `### Repo sovereignty`\nblock against basecradle/basecradle CLAUDE.md canonical (governance PR\nbasecradle/basecradle#382): D3-binds-the-capital pin, universal-read\nbullet, and D1 self-modification pointer.\n\nVerbatim byte-match re-sync — exempt from /code-review, no authored surface.\n\nRefs basecradle/basecradle-python#94\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Repo-sovereignty block to capital canonical (3 additions) (#95)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-07-01T09:10:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9f285e43bc4da4512ed09774b753f995f1c2a0f",
          "body": "…te→fallback) (#93)\n\nVerbatim re-sync of the `## Cross-Repo Handoffs` block to the capital\ncanonical (basecradle PR #379). Three spots changed: the section intro,\nthe \"human is a wake-button\" parenthetical, and the laptop-delivery\nbullet — the capital now wakes laptop sibling builders directly via t\n[…]\naste is demoted to the manual fallback.\n\nBlock confirmed byte-identical to canonical via diff.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block: capital wakes laptop siblings (pas…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-30T08:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bbd855f9b8175463ad065001a14be92f2007030b",
          "body": "Terminal-lifecycle-signal-is-not-a-coordination-channel hardening.\nByte-matches the capital canonical; docs-only, mechanical re-sync.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block to capital canonical (#90) (#91)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-30T03:52:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1facb322db4af6cad337c0e93162cffc54939a96",
          "body": "…-court protocol) (#88)\n\nAdds the ball-in-court communication protocol paragraph (needs-capital /\nneeds-human routing labels, self-poll, 6-step lifecycle) so this repo's\nshared Cross-Repo Handoffs block byte-matches the capital canonical.\n\nMechanical verbatim re-sync of the shared block; byte-match verified.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync CLAUDE.md 'Cross-Repo Handoffs' to capital canonical (ball-in…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-29T22:24:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84d8972dd74d1fde66b03871ea258a87dfd2aca5",
          "body": "…5) (#86)\n\nReframe the pypi publish gate per constitution.md -> Earned Autonomy\nthird corollary (\"Publishing is the capital's, not the founder's\",\nbasecradle#367): the capital owns and actuates every publish/release\ngate via its operator credential; the founder is out of the publish\nloop. Add the ca\n[…]\nDrop publish-approval as a human-gate example while keeping the\ngenuine human-gate convention.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync CLAUDE.md: publishing is the capital's, not the founder's (#8…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-29T05:06:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9971988e6c4a6b534ad9b38f0362b81794fe04ec",
          "body": "…4) (#83)\n\nMechanical, byte-verified re-sync of the verbatim-shared block to the\ncapital (basecradle/basecradle CLAUDE.md). Three changes propagated:\nrouter-daemon naming bullet (#363), in-repo standing-authority rule,\nand the propagation-discipline + drift-guard paragraph. The block is\nnow byte-identical to the capital canonical.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs shared block to capital canonical (PR #36…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-27T09:56:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ec30c0d73b9de980ea1b8c74bcb88c4bf20d333",
          "body": "…7) (#81)\n\nAdds the allow-list-actor clause to the 'Don't park when you have queued\nwork' paragraph in the shared Cross-Repo Handoffs block, matching the\ncapital's constitution amendment basecradle/basecradle#327. Verbatim,\nbyte-identical re-sync from the capital's CLAUDE.md.\n\nRefs basecradle/basecradle-python#80\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync CLAUDE.md: 'Don't park' roadmap-eligibility gate (capital #32…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-15T23:18:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c24fb985a566c69a2f300f9c29a2d1096b36b132",
          "body": "Verbatim re-sync of the canonical shared-law block from the capital's\nCLAUDE.md (basecradle#322), placed between the Polling and Cross-Repo\nHandoffs sections to match the capital's placement. Byte-identical to\nthe source (diff = 0). Docs-only; no behavioral change.\n\nHandoff: basecradle/basecradle-python#77 (capital basecradle#321).\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Sync 'Attended-Session Lifecycle Signal' section into CLAUDE.md (#78)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-13T08:28:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e8c3b1fef3b142986d44e6ed6482b319f36a566",
          "body": "….0) (#76)\n\nBump _version.py 0.4.1.dev0 → 0.5.0 and finalize CHANGELOG [Unreleased] →\n[0.5.0]; add the missing [0.4.0] footer link while finalizing.\n\nThe release feature (timeline.delete) shipped in #75; this is the source bump\nthe capital greenlit in basecradle/basecradle-python#74 for the joint release.\nTagging and the PyPI publish gate are the operator's.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Release 0.5.0 — finalize version + changelog (lockstep with Ruby v0.3…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-13T04:17:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52521c3a47cbbf64e1d18b77a47b4532ee70cf46",
          "body": "Mirrors the platform's new timeline-deletion capability (basecradle/basecradle#315):\na timeline owner (or admin) can permanently delete a timeline and all its contents.\n\n- timeline.delete() verb on Timeline (sync + async via the shared _verb dispatch),\n  returns None on 204; participant -> NotTimeli\n[…]\nine.deleted event; documented for when one is added.\n\nHandoff: basecradle/basecradle-python#74\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Add timeline.delete() — DELETE /timelines/{uuid} (platform parity) (#75)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-13T03:49:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccf8579e2d8c0b3c57681ca99329a1b5b8a161c3",
          "body": "…d (#73)\n\nCarries the capital's shared section verbatim, placed just before\nCross-Repo Handoffs. Byte-identical to basecradle/basecradle CLAUDE.md.\n\nRefs #72 (closed by hand after merge per the issue's definition of done).\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Sync shared 'Polling GitHub — rate-limit floor' section into CLAUDE.m…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-12T23:05:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c24864f10f26cc6db999a6c57b481b1dc0989684",
          "body": "…e' update (#71)\n\nByte-for-byte re-sync of the ## Cross-Repo Handoffs section from the\ncapital (basecradle/basecradle CLAUDE.md), matching constitution.md →\nHow We Communicate (PRs basecradle/basecradle#308, #311).\n\nRefs basecradle/basecradle-python#70\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block to the capital's 'How We Communicat…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-11T19:29:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dac2b38ed03320843441397f198d20e13ad917ca",
          "body": "Per the release convention (step 7), the first PR after a release moves\n_version.py to the next .dev0 so dev/editable builds are always distinguishable\nfrom the published release. 0.4.0 shipped to PyPI; main now becomes 0.4.1.dev0.\n\nConservative default (.dev0 of the next patch) — no next minor is k\n[…]\n The API\nis additive-only, so the eventual release retargets as needed when its content\nlands.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Post-release version bump to 0.4.1.dev0 (#69)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-10T23:26:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9acba0469806bdac2168f12bb1d303ff77b3b95",
          "body": "The platform's User subject form gained `roles` — a `list[str]` of\noperator-assigned authority — in the trusted-peer cluster (platform PR\nbasecradle/basecradle#304, live on prod). Surface it on the SDK's User model\nalongside the existing trusted-peer fields, and derive an `is_admin` convenience\n(`\"a\n[…]\nelog, and tests (present/absent + admin/non-admin/open-list) updated.\nVersion bumped to 0.4.0.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Add User.roles (trusted-peer authority) + is_admin helper (#67)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-10T22:32:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80f4a215051fc4c9017d103e5fa29455cc48d97c",
          "body": "…er self-close discipline) (#65)\n\nPropagates basecradle/basecradle#298: the close-discipline for a\nreceived handoff is now explicit — the receiving captain verifies its\nown work against the live system and closes the handoff issue by hand;\nthe closed issue plus completion comment is the signal, and \n[…]\nection now byte-matches the capital's current CLAUDE.md.\n\nRefs basecradle/basecradle-python#64\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs section from the capital (explicit receiv…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-09T03:13:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f59684b007f24e59baf5d3a505eb0a6d221ea867",
          "body": "…ates dispatch + label-trigger sharpen) (#63)\n\nPropagates basecradle/basecradle#297 outward. Replaces the entire\n\"## Cross-Repo Handoffs\" section with the capital's current version,\nfetched verbatim from basecradle/basecradle CLAUDE.md:\n\n- New rule: the capital coordinates cross-repo work; captains \n[…]\nnder allow-list corrected to the founder + capital bot only.\n\nDocs-only; no behavioral change.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs section from the capital (capital-coordin…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-09T02:16:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1836878c9492e08624b1576b3e6344ebfeb928f6",
          "body": "…delivery) (#61)\n\nThe capital (basecradle/basecradle) updated its ## Cross-Repo Handoffs\nsection after basecradle#296: it now documents how a handoff is *delivered*\nto the target agent — a new 'How a handoff is delivered: label vs. paste'\nsubsection (router-wired repos with a handoff label wake auto\n[…]\nandoff in basecradle-python issue 60 (closed by\nhand after merge, per the handoff convention).\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Re-sync Cross-Repo Handoffs section from the capital (label-vs-paste …",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-08T23:12:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f563e54181474689b4f2efd119017b42d3f4a61b",
          "body": "…tation clause (#59)\n\n* README: add Authentication section, move Installation up, fix self-rotation clause\n\nThe README had no on-ramp to a first successful call: readers hit\nBaseCradle() / bc.me assuming BASECRADLE_TOKEN was already set, with no\nexplanation of how to get a token, and ## Installation\n[…]\nn.openapi) instead of a fixed index, surviving any\n  future section added above it.\n\n---------\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "README: add Authentication section, move Installation up, fix self-ro…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-08T23:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e756c0c5e48cb00b75046fb857d672b810e4b9cc",
          "body": "…89) (#57)\n\nbasecradle#289 merged the capital-side fix to the shared block's\n'Propagating this procedure' line. Re-sync this repo's copy verbatim so\nthe ecosystem-wide block stays identical across repos: the line now\nreads 'copied from the capital's CLAUDE.md fetched from GitHub ... never\na machine-\n[…]\nThe full Cross-Repo Handoffs block is now byte-identical to\nbasecradle/basecradle's CLAUDE.md.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs block from the capital (post-basecradle#2…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-06T23:20:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3daff38b5992178e9824f564d8b914c1b68941d",
          "body": "The `## The Constitution` section pointed to a `/Users/drawk/...`\nlaptop path, unreachable from the fleet server, CI, or any other host —\nleaving the agent without its governing law everywhere but Drawk's\nmachine. Reference the constitution by its canonical GitHub location\n(`basecradle/basecradle` →\n[…]\ns rather than copied by file-system path.\n\nNo `/Users/...` path remains anywhere in CLAUDE.md.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Reference the constitution via GitHub, not the laptop path (#56)",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-06T23:09:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e864041eb387d813f746ef976f4e1f604446c1b8",
          "body": "…2) (#53)\n\nThe shared Cross-Repo Handoffs block changed on the capital\n(basecradle/basecradle#283). The Naming subsection now states the\nuniversal-slug rule explicitly: an agent's slug is its repository name\nplus -ai (never doubling the basecradle- prefix), and that one slug is\nits identity across e\n[…]\nynced verbatim from the capital's current main; the block now diffs\nbyte-identical against it.\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs: Naming gains the universal-slug rule (#5…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-06T02:06:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "962a3ae83f8a24ab9a3d9c2b74636b297b7bab70",
          "body": "…rule (#51)\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs: @handle rename + bot-identity no-header …",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-05T10:35:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e86767777adfb83a508b58f901a0ec1eac7bafe1",
          "body": "…#49)\n\nThe shared block was one capital change behind (capital basecradle/basecradle#280): re-synced verbatim from the capital's current main. Two deltas — the \"Sign cross-repo posts with a header\" paragraph becomes \"You post under your own bot identity — no signature header\", and the cross-repo hea\n[…]\n issue #48 (also satisfies #45, the blind-match guard re-sync, already present in this block).\n\nCo-authored-by: basecradle-python-ai[bot] <290976240+basecradle-python-ai[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Re-sync Cross-Repo Handoffs: retire the signature-header convention (…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-05T10:07:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a30c1754081f5879393b6db80734ab49ad7cc521",
          "body": "…ck (#47)\n\nFleet bot-identity adoption for issue #46. Adds the Fleet Bot Identity section, the self-review-before-PR convention, and re-syncs the two changed Cross-Repo Handoffs paragraphs from the capital. Docs-only.",
          "is_bot": true,
          "headline": "Adopt fleet bot identity (basecradle-python-ai) + re-sync handoff blo…",
          "author_name": "basecradle-python-ai[bot]",
          "author_login": "basecradle-python-ai[bot]",
          "committed_at": "2026-06-05T09:42:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "337806380197ed208ca74f54fd97b3a8b0dd0e87",
          "body": "…block (#44)\n\nFold a checklist-phrasing clause into the human-action-gate convention\n(numbered steps with exact site/fields/values, not prose), and re-sync the\nshared Cross-Repo Handoffs block from the capital verbatim — it gained the\n\"never auto-close a handoff issue with Closes #N\" sentence\n(basecradle/basecradle#274).\n\nRe #43 — handoff issue, closed by hand per the very rule this PR adopts\n(no Closes #N).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Tune CLAUDE.md: numbered-checklist human-gate asks + re-sync handoff …",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-05T06:23:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "977ceaaff708ab46ec9af9829d9d771806f5eed7",
          "body": "The capital corrected two phrasings written in the capital's first\nperson that read falsely when copied verbatim into a non-capital repo:\n\n- Repo sovereignty first bullet: \"This repo is the capital / constitution.md\n  lives here\" → \"Shared law lives at the capital / constitution.md lives in\n  the ca\n[…]\nal text from \"the capital's\n  CLAUDE.md\", not \"this repo's CLAUDE.md\".\n\nSection now matches the capital's current version verbatim.\n\nCloses #41\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Re-sync Cross-Repo Handoffs: fix two non-repo-agnostic phrasings (#42)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-05T01:29:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1d6da1206bc6ab42402efbf54d447c262b5e9873",
          "body": "Brings this repo's ## Cross-Repo Handoffs section in line with the\nrevised canonical version in the basecradle (capital) repo, copied\nverbatim. Changes: builder-agent naming convention (<repo> AI), GitHub\nas the cross-repo comms platform with bidirectional handoffs, completion\nreports posted as comm\n[…]\ne, signed cross-repo\nposts (sender → recipient header), trigger-only handoff prompts, and the\npaste-text `---` boundary convention.\n\nCloses #39\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Sync Cross-Repo Handoffs section from the capital repo (#40)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-05T01:01:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "96b908673f94599952a7ffb2c7ee45e1bc3cfad3",
          "body": "…#38)\n\nThe core repo ratified the ecosystem's authority model — constitutional\nfederalism — in constitution.md's \"Sovereignty and Governance\" article\n(basecradle/basecradle#261). Per the constitution's propagation rule,\nevery repo mirrors the governing principle in its own CLAUDE.md.\n\nAdds a tight \"\n[…]\nnges only at the capital. Points to\nconstitution.md → \"Sovereignty and Governance\" for the full principle\nrather than restating it.\n\nCloses #35\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Mirror the ratified \"Sovereignty and Governance\" model in CLAUDE.md (…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T23:36:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "226b94dfa0e96b73f13d3c1733847bde3e15373a",
          "body": "An activated task surfaces in timeline.items with type \"task\" (verified\nagainst production; the platform serializer has a `when Task` branch).\nThe docstring enum omitted it. Cosmetic/doc only — ApiObject reads wire\ndata regardless of annotations, so item.type == \"task\" already works at\nruntime.\n\nCloses #36\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add \"task\" to TimelineItem.type docstring enum (#37)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T23:35:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "58d23a375497e040c34b02c1a86c646c07d81f68",
          "body": "The workflow now ends with cleanup: squash-merge → delete the branch.\nMerged branches are clutter; the open branch list should be the list of\nwork in flight. Authorized and requested by the project owner after the\nv0.3.0 release left three merged branches on origin.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Convention: delete merged branches, remote and local (#34)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T07:20:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "20b3cc9709191120a048ff2f7dc379401d96a461",
          "body": "Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.3.0: version bump and changelog (#33)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T07:04:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9879b70ea74059a4507ebaeccfa0ca8fe686e315",
          "body": "…ngelog (#32)\n\nMirrors core PR #256's reshape of the Dashboard's documentation block:\n\n- Removed: `sdk` (the placeholder that was null from day one)\n- Added: `changelog` — the platform changelog pointer\n- Added: `sdks` — typed nested objects, keyed by language, each carrying\n  `repository` and `pack\n[…]\n (stale since #22)\nand bumps to 0.3.0.dev0 (first PR of the v0.3.0 cycle).\n\nPart of #30 (closed manually after the v0.3.0 release is verified).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Dashboard documentation: sdk → typed sdks keyed by language, plus cha…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T07:02:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "349b319858596259f7c11691ba6662bf75055f6b",
          "body": "Copied verbatim from the core repo's CLAUDE.md (it is written\nrepo-agnostically). This SDK both receives handoffs (platform wire-shape\nchanges to mirror) and sends them (bugs discovered in the platform), so\nboth ends now follow the same relay procedure.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document the Cross-Repo Handoffs procedure in CLAUDE.md (#31)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T07:01:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "efe7d1ae6c4d00dc2d60ef25952df17678b07897",
          "body": "The release process was established across #11 and #12 but lived only in\nissue threads and session transcripts — invisible to future contributors.\nProcedures belong in CLAUDE.md, written as they are established:\n\n- The full tag → TestPyPI → approval → PyPI sequence, with the\n  verification steps and\n[…]\nloses #N\n- The post-release dev-version bump (main → next minor .dev0)\n- The version single-source-of-truth and editable-install-metadata facts\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Document the release procedure in CLAUDE.md (#29)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T05:26:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e1410aebf40a8bd62af6c053c27d4ce3bb8ac63",
          "body": "The async release. Part of #12 — the issue closes after the publish to\nPyPI is verified.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.2.0: version bump and changelog (#28)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T05:13:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "82b3bee6574f8398844b063421541454333bdbe8",
          "body": "…ity (#27)\n\nAI agents (the harness, the next ecosystem repo) run async. This brings\nAsyncBaseCradle and refactors the sync client onto the shared core it\nwas designed for:\n\n- _ClientCore: token resolution, headers, response checking — shared;\n  BaseCradle (httpx.Client) and AsyncBaseCradle (httpx.As\n[…]\nv version; 0.2.0 releases next)\n- 70 new tests (305 total), all offline\n\nPart of #12 — the issue closes after v0.2.0 is published and verified.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Async client: AsyncBaseCradle on a shared core with full resource par…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T05:11:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "235eab1fc2b96c9f0c9cfa072911551decb548a8",
          "body": "When work blocks on something only a human can do (the pypi environment\napproval, browser/account actions), the AI contributor must lead with an\nunmissable WAITING ON YOU notice — exact action, exact link, repeated\nuntil acted on. A waiting agent looks identical to a stalled one.\n\nBorn from the v0.1.0 release, where the approval handoff wasn't\nprominent enough and the project owner had to ask.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Convention: announce human-action gates unmissably (#26)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T04:54:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "924595acf1f6479cb4c7fd81f35e623b7e48fe36",
          "body": "The first release — complete coverage of the BaseCradle API:\n\n- _version.py: 0.1.0.dev0 → 0.1.0\n- CHANGELOG.md: the 0.1.0 entry (Keep a Changelog format)\n- README: Installation section is real now; status line updated to 0.x\n\nPart of #11 — the issue closes after the publish to PyPI is verified.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "v0.1.0: version bump, changelog, installation goes live (#25)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T04:43:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cfaf50e4334231923f70aa3bbbf417c6e362810d",
          "body": "…(#24)\n\nTrusted Publishing via OIDC — zero stored credentials, mirroring the\nplatform's AWS OIDC deploys. The workflow filename and environment names\n(testpypi, pypi) are contractual: they match the pending publishers\nregistered on PyPI/TestPyPI in issue #1.\n\nThe pypi environment will carry a requir\n[…]\ne (Drawk) — the\none place in this repository where a manual human gate is correct.\n\nPart of #11 (the environments + the release itself follow).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Release workflow: tag → build → TestPyPI rehearsal → approval → PyPI …",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T04:40:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8409da135336cccad955c365b1c4d42715959126",
          "body": "…ve self-trust (#23)\n\nThe platform corrected its Dashboard JSON (core PR #254, deployed):\nthe identity section is keyed \"identity\" (was \"you\" — the one key that\ndidn't match its section label), and trust on your own subject form is\nnow reflexive (all-true: you trust yourself, axiomatically).\n\nCaught\n[…]\nlexive self-view fixture\n- README hero example: me.identity.* (doc-truth test keeps it honest)\n\nCloses #22 — unblocks #11 (the v0.1.0 release).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Match the platform's corrected Dashboard shape: me.identity + reflexi…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T04:32:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84f7455ae1cd44f4ae3c9a7679be1ede185b2f91",
          "body": "The platform's spec is generated from its tests and cannot lie; the SDK\nnow gets the reverse guarantee — it can never silently fall behind:\n\n- tests/test_drift_guard.py: the COVERAGE map (every live endpoint → the\n  SDK feature that covers it, including one documented exclusion for the\n  external-se\n[…]\nesting story updated to match reality\n- 11 new tests (233 offline + 1 live), drift-guard verified green\n  against the real live API\n\nCloses #10\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Spec drift-guard: CI fails when the live API grows beyond the SDK (#21)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T03:05:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ec58416c41c82587b47183aaf9087442fcdb9a2",
          "body": "The last API surface — the SDK now covers the entire platform:\n\n- _users.py: UsersResource (the directory — a single unpaginated request\n  per the API contract — plus get) and trust verbs on User:\n  grant_trust() / revoke_trust(), named after the API docs' own\n  vocabulary (\"Granting Trust\" / \"Revok\n[…]\nhake; the \"shape of\n  what's coming\" section is gone — everything the README promised exists\n- 18 new tests (223 total), all offline\n\nCloses #9\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Users & trust: directory, profiles, the trust handshake (#20)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T02:52:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "150cbbf074f855b0c3c6f8fa9baf79be176c073d",
          "body": "A peer manages its own credentials without a human — the platform's\nautonomy feature, surfaced in the SDK:\n\n- _sessions.py: Session model (kind, current, last_used_at, ...) with\n  revoke(), and SessionsResource (iterable via the pagination engine)\n  with revoke_all()\n- The two sharp edges are docume\n[…]\nested end-to-end: after\n  revoke_all(), the same client's next call raises UnauthorizedError\n- 13 new tests (205 total), all offline\n\nCloses #8\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Sessions: self-credential management (list, revoke, revoke-all) (#19)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T02:43:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eb3270470301cd8d94389487aa1c7eec59601c19",
          "body": "…L (#18)\n\nHow external services deliver into a timeline, and how a peer wires\nthat up programmatically:\n\n- _webhooks.py: WebhookEndpoint (with disable/enable/rotate as\n  live-object verbs — the API's singular enablement/rotation state\n  resources never appear as raw paths) and WebhookEvent (read-onl\n[…]\noint_object) works\n- README: webhooks section, doc-truth tested\n- 25 new tests (192 total), all offline; pagination engine untouched\n\nCloses #7\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Webhook endpoints & events: create, enable/disable, rotate, ingest UR…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T02:37:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5f2a9b39202e606d414eebacc8308bea16b102f2",
          "body": "The content peers actually exchange — three resources, one pattern, and\nthe first consumers of the pagination engine (reused unmodified, as its\ngenericity criterion demanded):\n\n- _items.py: Message/Asset/Task models (one shared Item envelope shape,\n  typed content per kind), top-level resources (bc.\n[…]\ns= passthrough for multipart\n- README: messages/assets/tasks sections (all doc-truth tested)\n- 44 new tests (167 total), all offline\n\nCloses #6\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Timeline items: messages, assets (multipart upload), tasks (#17)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T02:24:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "735d6980bb3585b0296fa708e238b9abe57d89dd",
          "body": "…ine (#16)\n\nTimelines are the platform's container; this also builds the two pieces\nevery future resource reuses:\n\n- _pagination.py: the shared cursor-pagination engine. One generator —\n  paginate(client, path, envelope_key, model, params) — handles\n  next_cursor → ?before= across every list endpoin\n[…]\nks now); the doc-truth test now\n  runs every python block in the README, not just the first.\n- 38 new tests (123 total), all offline\n\nCloses #5\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Timelines: list, get, create, lock, participants + the pagination eng…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T02:11:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c621f034f2864021d04acac28fb06e0e8c16a13",
          "body": "The platform's defining feature, mirrored: bc.me answers \"who am I, what\nis this place, where is everything\" — the first call any peer makes.\n\n- _models.py: the ApiObject base — the model layer every resource builds\n  on. Typed annotations document the contract; attribute access reads the\n  wire dat\n[…]\n\n  test extracts and executes it verbatim against a respx mock, so the\n  README can never lie\n- 20 new tests (85 total), all offline\n\nCloses #4\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Self-discovery: bc.me — the Dashboard as the SDK's front door (#15)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T01:47:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0e7505d3fc4cdb89bf3e23bf77b182848032fe70",
          "body": "The heart of the SDK — how a peer authenticates and how every\nrequest/response/error flows:\n\n- BaseCradle: token from arg or BASECRADLE_TOKEN, httpx.Client transport,\n  default headers (Bearer auth, Accept, User-Agent with SDK version),\n  public request() as the resource foundation and additive-API \n[…]\n _version.py so the client imports it without\n  circularity (hatchling path updated)\n- 63 new tests, all respx-mocked — zero network\n\nCloses #3\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Core client: BaseCradle class, auth, transport, typed errors (#14)",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T01:08:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d84ef37171628db436871c2b4eba167d16c2a5ed",
          "body": "…#13)\n\n* Project scaffold: pyproject, uv, ruff, pytest, package skeleton, CI\n\nThe omakase stack from CLAUDE.md, made real:\n\n- pyproject.toml: hatchling build backend, httpx as the only runtime\n  dependency, dev group (pytest, respx, ruff), ruff + pytest config\n- src layout: src/basecradle/__init__.p\n[…]\nom>\n\n* Pin setup-uv to v8.1.0 — astral publishes no moving major tag for v8\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Project scaffold: pyproject, uv, ruff, pytest, package skeleton, CI (…",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-03T00:19:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "06867109cd2075e5c5b0d9c89ce9a5d700632104",
          "body": "CLAUDE.md (project conventions + design philosophy + omakase stack), README\n(pre-release, built in the open), MIT license, Python .gitignore. The build\nitself is mapped in GitHub Issues; the SDK code starts there.\n\nBorn under the BaseCradle Constitution.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Found the BaseCradle Python SDK repository",
          "author_name": "Drawk Kwast",
          "author_login": "drawkkwast",
          "committed_at": "2026-06-02T23:09:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 8,
      "commits_last_year": 63,
      "latest_release_at": "2026-07-17T23:54:02Z",
      "latest_release_tag": "v0.8.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 8,
      "days_since_latest_release": 9,
      "mean_days_between_releases": 6.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "basecradle",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "agents",
            "ai",
            "api",
            "basecradle",
            "sdk",
            "Development Status :: 3 - Alpha",
            "Intended Audience :: Developers",
            "Operating System :: OS Independent",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.14",
            "Typing :: Typed"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/basecradle/",
          "is_deprecated": false,
          "latest_version": "0.8.0",
          "repository_url": "https://github.com/basecradle/basecradle-python",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 3441,
          "first_published_at": "2026-06-03T04:50:51.417359Z",
          "latest_published_at": "2026-07-17T23:59:35.008491Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "src/basecradle/py.typed"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 17407,
      "source_files_sampled": 31,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 32351
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 6,
        "malicious_count": 0,
        "assessed_package": "pypi:basecradle@0.8.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.28"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 67,
        "open_issues": 1,
        "closed_ratio": 0.984,
        "closed_issues": 60,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "drawkkwast",
          "commits": 28,
          "avatar_url": "https://avatars.githubusercontent.com/u/6881757?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "dependabot-auto-merge.yml",
        "needs-human-alert.yml",
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/27 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "de53849411bcf878f359516a1922fe256dbb31f5",
        "ran_at": "2026-07-27T07:37:08Z",
        "aggregate_score": 5.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T01:32:15Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-27T01:31:43Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 54,
          "created_at": "2026-06-06T22:04:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/basecradle/basecradle-python",
    "host": "github.com",
    "name": "basecradle-python",
    "owner": "basecradle"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 64,
        "vitality": 70,
        "community": 33,
        "governance": 55,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 63,
              "human_commit_share": 0.412,
              "days_since_last_push": 0,
              "active_weeks_last_year": 8
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "8/52 weeks with commits",
                "points": 5.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "63 commits in the last year",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 63
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 8,
              "latest_release_tag": "v0.8.0",
              "releases_from_tags": true,
              "days_since_latest_release": 9,
              "mean_days_between_releases": 6.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "8 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 9 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~6.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 6.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "basecradle"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 3441
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,441 downloads/month across pypi",
                "points": 47.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3441,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 67,
              "open_issues": 1,
              "closed_issues": 60,
              "issue_closed_ratio": 0.984,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "98% of issues closed",
                "points": 46,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "67/68 decided PRs merged",
                "points": 37.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 67,
                      "decided": 68
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "followers": 3,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "basecradle",
              "public_repos": 5,
              "account_age_days": 214
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of basecradle",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "basecradle"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~0 yr old",
                "points": 6.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "basecradle"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 9
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 9 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "8 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://basecradle.com/docs/api",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://basecradle.com/docs/api",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 64,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 55,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the pypi:basecradle@0.8.0 runtime dependency closure — what installing the published package pulls in — 6 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "pypi:basecradle@0.8.0",
                  "assessed": 6
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 6,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 6,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 73,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 32351
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "28 of 28 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 28,
                      "sampled": 28
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "uv.lock"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "src/basecradle/py.typed"
              ],
              "agent_commit_share": 0.382,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.044
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "src/basecradle/py.typed",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "src/basecradle/py.typed"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "26 of the last 68 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 26,
                      "sampled": 68
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 68 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 68
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 17407,
              "source_files_sampled": 31,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (src/basecradle/py.typed)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "src/basecradle/py.typed",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/31 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 31,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T07:37:25.398265Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/basecradle/basecradle-python.svg",
  "full_name": "basecradle/basecradle-python",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPyPI.